347 MB
/srv/reproducible-results/rbuild-debian/r-b-build.dm7BsU4z/b1/scap-security-guide_0.1.65-1_armhf.changes vs.
/srv/reproducible-results/rbuild-debian/r-b-build.dm7BsU4z/b2/scap-security-guide_0.1.65-1_armhf.changes
822 B
Files
    
Offset 1, 6 lines modifiedOffset 1, 6 lines modified
  
1 ·72f888d957a91ff6df881a139d45e87a·182268·admin·optional·ssg-applications_0.1.65-1_all.deb1 ·07fad0915505f2198ffac45ec022d1b8·182212·admin·optional·ssg-applications_0.1.65-1_all.deb
2 ·f7bae0738ce4e633a16dbb487c1b30d5·27788·admin·optional·ssg-base_0.1.65-1_all.deb2 ·f7bae0738ce4e633a16dbb487c1b30d5·27788·admin·optional·ssg-base_0.1.65-1_all.deb
3 ·ddf8951863546098f9f6cba3f0b950f5·3396412·admin·optional·ssg-debderived_0.1.65-1_all.deb 
4 ·2276f691ac995c3ceaaf3ed7e86fbeaa·831528·admin·optional·ssg-debian_0.1.65-1_all.deb 
5 ·354018d636fd4294f582c37bb01b8442·40448724·admin·optional·ssg-nondebian_0.1.65-1_all.deb3 ·bff3e66a6157dad72842e7ce24d2409a·3394880·admin·optional·ssg-debderived_0.1.65-1_all.deb
 4 ·4f75bdc0d191eaafd1278cb84152a082·831508·admin·optional·ssg-debian_0.1.65-1_all.deb
 5 ·f5960421f4f49aaf32852f663941d0af·40446172·admin·optional·ssg-nondebian_0.1.65-1_all.deb
777 KB
ssg-applications_0.1.65-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary
2 -rw-r--r--···0········0········0·····1732·2022-12-20·09:54:05.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1736·2022-12-20·09:54:05.000000·control.tar.xz
3 -rw-r--r--···0········0········0···180344·2022-12-20·09:54:05.000000·data.tar.xz3 -rw-r--r--···0········0········0···180284·2022-12-20·09:54:05.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
776 KB
data.tar.xz
776 KB
data.tar
74.2 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds-1.2.xml
74.1 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds-1.2.xml
Ordering differences only
    
Offset 2477, 247 lines modifiedOffset 2477, 247 lines modified
2477 ······<ocil:generator>2477 ······<ocil:generator>
2478 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2478 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2479 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>2479 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>
2480 ········<ocil:schema_version>2.0</ocil:schema_version>2480 ········<ocil:schema_version>2.0</ocil:schema_version>
2481 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>2481 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
2482 ······</ocil:generator>2482 ······</ocil:generator>
2483 ······<ocil:questionnaires>2483 ······<ocil:questionnaires>
2484 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">2484 ········<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
2485 ··········<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>2485 ··········<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
2486 ··········<ocil:actions>2486 ··········<ocil:actions>
2487 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>2487 ············<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
2488 ··········</ocil:actions>2488 ··········</ocil:actions>
2489 ········</ocil:questionnaire>2489 ········</ocil:questionnaire>
2490 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">2490 ········<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">
2491 ··········<ocil:title>Disable·Network·Prediction</ocil:title>2491 ··········<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>
2492 ··········<ocil:actions>2492 ··········<ocil:actions>
2493 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>2493 ············<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>
2494 ··········</ocil:actions>2494 ··········</ocil:actions>
2495 ········</ocil:questionnaire>2495 ········</ocil:questionnaire>
2496 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">2496 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
2497 ··········<ocil:title>Disable·Session·Cookies</ocil:title>2497 ··········<ocil:title>Disable·Session·Cookies</ocil:title>
2498 ··········<ocil:actions>2498 ··········<ocil:actions>
2499 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>2499 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
2500 ··········</ocil:actions>2500 ··········</ocil:actions>
2501 ········</ocil:questionnaire>2501 ········</ocil:questionnaire>
2502 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">2502 ········<ocil:questionnaire·id="ocil:ssg-chromium_plugins_require_authorization_ocil:questionnaire:1">
2503 ··········<ocil:title>Block·Plugins·by·Default</ocil:title>2503 ··········<ocil:title>Require·Outdated·Plugins·to·be·Authorized</ocil:title>
2504 ··········<ocil:actions>2504 ··········<ocil:actions>
2505 ············<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>2505 ············<ocil:test_action_ref>ocil:ssg-chromium_plugins_require_authorization_action:testaction:1</ocil:test_action_ref>
2506 ··········</ocil:actions>2506 ··········</ocil:actions>
2507 ········</ocil:questionnaire>2507 ········</ocil:questionnaire>
2508 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">2508 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">
2509 ··········<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>2509 ··········<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>
2510 ··········<ocil:actions>2510 ··········<ocil:actions>
2511 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>2511 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>
2512 ··········</ocil:actions>2512 ··········</ocil:actions>
2513 ········</ocil:questionnaire>2513 ········</ocil:questionnaire>
2514 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">2514 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
 2515 ··········<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
2515 ··········<ocil:title>Disable·All·Plugins·by·Default</ocil:title> 
2516 ··········<ocil:actions> 
2517 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref> 
2518 ··········</ocil:actions> 
2519 ········</ocil:questionnaire> 
2520 ········<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1"> 
2521 ··········<ocil:title>Enable·Only·Approved·Extensions</ocil:title> 
2522 ··········<ocil:actions>2516 ··········<ocil:actions>
2523 ············<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>2517 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
2524 ··········</ocil:actions>2518 ··········</ocil:actions>
2525 ········</ocil:questionnaire>2519 ········</ocil:questionnaire>
2526 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">2520 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">
2527 ··········<ocil:title>Disable·Background·Processing</ocil:title>2521 ··········<ocil:title>Disable·Outdated·Plugins</ocil:title>
2528 ··········<ocil:actions>2522 ··········<ocil:actions>
2529 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>2523 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>
2530 ··········</ocil:actions>2524 ··········</ocil:actions>
2531 ········</ocil:questionnaire>2525 ········</ocil:questionnaire>
2532 ········<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">2526 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">
2533 ··········<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>2527 ··········<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>
2534 ··········<ocil:actions>2528 ··········<ocil:actions>
2535 ············<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>2529 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>
2536 ··········</ocil:actions>2530 ··········</ocil:actions>
2537 ········</ocil:questionnaire>2531 ········</ocil:questionnaire>
2538 ········<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">2532 ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">
2539 ··········<ocil:title>Disable·Location·Tracking</ocil:title>2533 ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>
2540 ··········<ocil:actions>2534 ··········<ocil:actions>
2541 ············<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>2535 ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>
2542 ··········</ocil:actions>2536 ··········</ocil:actions>
2543 ········</ocil:questionnaire>2537 ········</ocil:questionnaire>
2544 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">2538 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">
2545 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>2539 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>
2546 ··········<ocil:actions>2540 ··········<ocil:actions>
2547 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>2541 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>
2548 ··········</ocil:actions>2542 ··········</ocil:actions>
2549 ········</ocil:questionnaire>2543 ········</ocil:questionnaire>
2550 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">2544 ········<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">
2551 ··········<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>2545 ··········<ocil:title>Set·the·Default·Home·Page</ocil:title>
2552 ··········<ocil:actions>2546 ··········<ocil:actions>
2553 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>2547 ············<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>
2554 ··········</ocil:actions>2548 ··········</ocil:actions>
2555 ········</ocil:questionnaire>2549 ········</ocil:questionnaire>
2556 ········<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">2550 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
2557 ··········<ocil:title>Disable·All·Extensions·by·Default</ocil:title>2551 ··········<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
2558 ··········<ocil:actions>2552 ··········<ocil:actions>
2559 ············<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>2553 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
2560 ··········</ocil:actions>2554 ··········</ocil:actions>
2561 ········</ocil:questionnaire>2555 ········</ocil:questionnaire>
2562 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">2556 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">
2563 ··········<ocil:title>Disable·Chromium·Password·Manager</ocil:title>2557 ··········<ocil:title>Disable·Incognito·Mode</ocil:title>
2564 ··········<ocil:actions>2558 ··········<ocil:actions>
2565 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>2559 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>
2566 ··········</ocil:actions>2560 ··········</ocil:actions>
2567 ········</ocil:questionnaire>2561 ········</ocil:questionnaire>
2568 ········<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">2562 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
2569 ··········<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>2563 ··········<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
2570 ··········<ocil:actions>2564 ··········<ocil:actions>
2571 ············<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>2565 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
2572 ··········</ocil:actions>2566 ··········</ocil:actions>
2573 ········</ocil:questionnaire>2567 ········</ocil:questionnaire>
2574 ········<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">2568 ········<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">
2575 ··········<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>2569 ··········<ocil:title>Disable·Location·Tracking</ocil:title>
2576 ··········<ocil:actions>2570 ··········<ocil:actions>
2577 ············<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>2571 ············<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>
2578 ··········</ocil:actions>2572 ··········</ocil:actions>
2579 ········</ocil:questionnaire>2573 ········</ocil:questionnaire>
2580 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">2574 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
2581 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>2575 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>
2582 ··········<ocil:actions>2576 ··········<ocil:actions>
2583 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>2577 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
2584 ··········</ocil:actions>2578 ··········</ocil:actions>
2585 ········</ocil:questionnaire>2579 ········</ocil:questionnaire>
2586 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">2580 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_safe_browsing_ocil:questionnaire:1">
2587 ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title>2581 ··········<ocil:title>Enable·the·Safe·Browsing·Feature</ocil:title>
2588 ··········<ocil:actions>2582 ··········<ocil:actions>
2589 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>2583 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_safe_browsing_action:testaction:1</ocil:test_action_ref>
2590 ··········</ocil:actions>2584 ··········</ocil:actions>
2591 ········</ocil:questionnaire>2585 ········</ocil:questionnaire>
2592 ········<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">2586 ········<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">
2593 ··········<ocil:title>Set·the·Default·Home·Page</ocil:title>2587 ··········<ocil:title>Prevent·Desktop·Notifications</ocil:title>
2594 ··········<ocil:actions>2588 ··········<ocil:actions>
2595 ············<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>2589 ············<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>
2596 ··········</ocil:actions>2590 ··········</ocil:actions>
2597 ········</ocil:questionnaire>2591 ········</ocil:questionnaire>
2598 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">2592 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
2599 ··········<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>2593 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
2600 ··········<ocil:actions>2594 ··········<ocil:actions>
2601 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>2595 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
2602 ··········</ocil:actions>2596 ··········</ocil:actions>
Max diff block lines reached; 63544/75702 bytes (83.94%) of diff not shown.
74.2 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
74.1 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
Ordering differences only
    
Offset 2477, 247 lines modifiedOffset 2477, 247 lines modified
2477 ······<ocil:generator>2477 ······<ocil:generator>
2478 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2478 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2479 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>2479 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>
2480 ········<ocil:schema_version>2.0</ocil:schema_version>2480 ········<ocil:schema_version>2.0</ocil:schema_version>
2481 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>2481 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
2482 ······</ocil:generator>2482 ······</ocil:generator>
2483 ······<ocil:questionnaires>2483 ······<ocil:questionnaires>
2484 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">2484 ········<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
2485 ··········<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>2485 ··········<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
2486 ··········<ocil:actions>2486 ··········<ocil:actions>
2487 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>2487 ············<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
2488 ··········</ocil:actions>2488 ··········</ocil:actions>
2489 ········</ocil:questionnaire>2489 ········</ocil:questionnaire>
2490 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">2490 ········<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">
2491 ··········<ocil:title>Disable·Network·Prediction</ocil:title>2491 ··········<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>
2492 ··········<ocil:actions>2492 ··········<ocil:actions>
2493 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>2493 ············<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>
2494 ··········</ocil:actions>2494 ··········</ocil:actions>
2495 ········</ocil:questionnaire>2495 ········</ocil:questionnaire>
2496 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">2496 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
2497 ··········<ocil:title>Disable·Session·Cookies</ocil:title>2497 ··········<ocil:title>Disable·Session·Cookies</ocil:title>
2498 ··········<ocil:actions>2498 ··········<ocil:actions>
2499 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>2499 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
2500 ··········</ocil:actions>2500 ··········</ocil:actions>
2501 ········</ocil:questionnaire>2501 ········</ocil:questionnaire>
2502 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">2502 ········<ocil:questionnaire·id="ocil:ssg-chromium_plugins_require_authorization_ocil:questionnaire:1">
2503 ··········<ocil:title>Block·Plugins·by·Default</ocil:title>2503 ··········<ocil:title>Require·Outdated·Plugins·to·be·Authorized</ocil:title>
2504 ··········<ocil:actions>2504 ··········<ocil:actions>
2505 ············<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>2505 ············<ocil:test_action_ref>ocil:ssg-chromium_plugins_require_authorization_action:testaction:1</ocil:test_action_ref>
2506 ··········</ocil:actions>2506 ··········</ocil:actions>
2507 ········</ocil:questionnaire>2507 ········</ocil:questionnaire>
2508 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">2508 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">
2509 ··········<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>2509 ··········<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>
2510 ··········<ocil:actions>2510 ··········<ocil:actions>
2511 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>2511 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>
2512 ··········</ocil:actions>2512 ··········</ocil:actions>
2513 ········</ocil:questionnaire>2513 ········</ocil:questionnaire>
2514 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">2514 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
 2515 ··········<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
2515 ··········<ocil:title>Disable·All·Plugins·by·Default</ocil:title> 
2516 ··········<ocil:actions> 
2517 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref> 
2518 ··········</ocil:actions> 
2519 ········</ocil:questionnaire> 
2520 ········<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1"> 
2521 ··········<ocil:title>Enable·Only·Approved·Extensions</ocil:title> 
2522 ··········<ocil:actions>2516 ··········<ocil:actions>
2523 ············<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>2517 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
2524 ··········</ocil:actions>2518 ··········</ocil:actions>
2525 ········</ocil:questionnaire>2519 ········</ocil:questionnaire>
2526 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">2520 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">
2527 ··········<ocil:title>Disable·Background·Processing</ocil:title>2521 ··········<ocil:title>Disable·Outdated·Plugins</ocil:title>
2528 ··········<ocil:actions>2522 ··········<ocil:actions>
2529 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>2523 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>
2530 ··········</ocil:actions>2524 ··········</ocil:actions>
2531 ········</ocil:questionnaire>2525 ········</ocil:questionnaire>
2532 ········<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">2526 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">
2533 ··········<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>2527 ··········<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>
2534 ··········<ocil:actions>2528 ··········<ocil:actions>
2535 ············<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>2529 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>
2536 ··········</ocil:actions>2530 ··········</ocil:actions>
2537 ········</ocil:questionnaire>2531 ········</ocil:questionnaire>
2538 ········<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">2532 ········<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">
2539 ··········<ocil:title>Disable·Location·Tracking</ocil:title>2533 ··········<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>
2540 ··········<ocil:actions>2534 ··········<ocil:actions>
2541 ············<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>2535 ············<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>
2542 ··········</ocil:actions>2536 ··········</ocil:actions>
2543 ········</ocil:questionnaire>2537 ········</ocil:questionnaire>
2544 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">2538 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">
2545 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>2539 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>
2546 ··········<ocil:actions>2540 ··········<ocil:actions>
2547 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>2541 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>
2548 ··········</ocil:actions>2542 ··········</ocil:actions>
2549 ········</ocil:questionnaire>2543 ········</ocil:questionnaire>
2550 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">2544 ········<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">
2551 ··········<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>2545 ··········<ocil:title>Set·the·Default·Home·Page</ocil:title>
2552 ··········<ocil:actions>2546 ··········<ocil:actions>
2553 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>2547 ············<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>
2554 ··········</ocil:actions>2548 ··········</ocil:actions>
2555 ········</ocil:questionnaire>2549 ········</ocil:questionnaire>
2556 ········<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">2550 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
2557 ··········<ocil:title>Disable·All·Extensions·by·Default</ocil:title>2551 ··········<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
2558 ··········<ocil:actions>2552 ··········<ocil:actions>
2559 ············<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>2553 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
2560 ··········</ocil:actions>2554 ··········</ocil:actions>
2561 ········</ocil:questionnaire>2555 ········</ocil:questionnaire>
2562 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">2556 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">
2563 ··········<ocil:title>Disable·Chromium·Password·Manager</ocil:title>2557 ··········<ocil:title>Disable·Incognito·Mode</ocil:title>
2564 ··········<ocil:actions>2558 ··········<ocil:actions>
2565 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>2559 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>
2566 ··········</ocil:actions>2560 ··········</ocil:actions>
2567 ········</ocil:questionnaire>2561 ········</ocil:questionnaire>
2568 ········<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">2562 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
2569 ··········<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>2563 ··········<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
2570 ··········<ocil:actions>2564 ··········<ocil:actions>
2571 ············<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>2565 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
2572 ··········</ocil:actions>2566 ··········</ocil:actions>
2573 ········</ocil:questionnaire>2567 ········</ocil:questionnaire>
2574 ········<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">2568 ········<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">
2575 ··········<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>2569 ··········<ocil:title>Disable·Location·Tracking</ocil:title>
2576 ··········<ocil:actions>2570 ··········<ocil:actions>
2577 ············<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>2571 ············<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>
2578 ··········</ocil:actions>2572 ··········</ocil:actions>
2579 ········</ocil:questionnaire>2573 ········</ocil:questionnaire>
2580 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">2574 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
2581 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>2575 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>
2582 ··········<ocil:actions>2576 ··········<ocil:actions>
2583 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>2577 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
2584 ··········</ocil:actions>2578 ··········</ocil:actions>
2585 ········</ocil:questionnaire>2579 ········</ocil:questionnaire>
2586 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">2580 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_safe_browsing_ocil:questionnaire:1">
2587 ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title>2581 ··········<ocil:title>Enable·the·Safe·Browsing·Feature</ocil:title>
2588 ··········<ocil:actions>2582 ··········<ocil:actions>
2589 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>2583 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_safe_browsing_action:testaction:1</ocil:test_action_ref>
2590 ··········</ocil:actions>2584 ··········</ocil:actions>
2591 ········</ocil:questionnaire>2585 ········</ocil:questionnaire>
2592 ········<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">2586 ········<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">
2593 ··········<ocil:title>Set·the·Default·Home·Page</ocil:title>2587 ··········<ocil:title>Prevent·Desktop·Notifications</ocil:title>
2594 ··········<ocil:actions>2588 ··········<ocil:actions>
2595 ············<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>2589 ············<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>
2596 ··········</ocil:actions>2590 ··········</ocil:actions>
2597 ········</ocil:questionnaire>2591 ········</ocil:questionnaire>
2598 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">2592 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
2599 ··········<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>2593 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
2600 ··········<ocil:actions>2594 ··········<ocil:actions>
2601 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>2595 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
2602 ··········</ocil:actions>2596 ··········</ocil:actions>
Max diff block lines reached; 63544/75702 bytes (83.94%) of diff not shown.
70.2 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
70.0 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
Ordering differences only
    
Offset 3, 247 lines modifiedOffset 3, 247 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
11 ······<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>11 ······<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">
17 ······<ocil:title>Disable·Network·Prediction</ocil:title>17 ······<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_session_cookies_ocil:questionnaire:1">
23 ······<ocil:title>Disable·Session·Cookies</ocil:title>23 ······<ocil:title>Disable·Session·Cookies</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_session_cookies_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-chromium_plugins_require_authorization_ocil:questionnaire:1">
29 ······<ocil:title>Block·Plugins·by·Default</ocil:title>29 ······<ocil:title>Require·Outdated·Plugins·to·be·Authorized</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chromium_plugins_require_authorization_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">
35 ······<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>35 ······<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">
 41 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>
41 ······<ocil:title>Disable·All·Plugins·by·Default</ocil:title> 
42 ······<ocil:actions> 
43 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref> 
44 ······</ocil:actions> 
45 ····</ocil:questionnaire> 
46 ····<ocil:questionnaire·id="ocil:ssg-chromium_extension_whitelist_ocil:questionnaire:1"> 
47 ······<ocil:title>Enable·Only·Approved·Extensions</ocil:title> 
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-chromium_extension_whitelist_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Background·Processing</ocil:title>47 ······<ocil:title>Disable·Outdated·Plugins</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-chromium_http_authentication_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">
59 ······<ocil:title>Set·Chromium's·HTTP·Authentication·Scheme</ocil:title>53 ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-chromium_http_authentication_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Location·Tracking</ocil:title>59 ······<ocil:title>Enable·Plugins·for·Only·Approved·URLs</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-chromium_whitelist_plugin_urls_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">
71 ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title>65 ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">
77 ······<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>71 ······<ocil:title>Set·the·Default·Home·Page</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_name_ocil:questionnaire:1">
83 ······<ocil:title>Disable·All·Extensions·by·Default</ocil:title>77 ······<ocil:title>Set·the·Default·Search·Provider's·URL</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_name_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_password_manager_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">
89 ······<ocil:title>Disable·Chromium·Password·Manager</ocil:title>83 ······<ocil:title>Disable·Incognito·Mode</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_password_manager_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
95 ······<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>89 ······<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">
101 ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>95 ······<ocil:title>Disable·Location·Tracking</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>101 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_safe_browsing_ocil:questionnaire:1">
113 ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title>107 ······<ocil:title>Enable·the·Safe·Browsing·Feature</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_safe_browsing_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-chromium_trusted_home_page_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-chromium_block_desktop_notifications_ocil:questionnaire:1">
119 ······<ocil:title>Set·the·Default·Home·Page</ocil:title>113 ······<ocil:title>Prevent·Desktop·Notifications</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-chromium_trusted_home_page_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-chromium_block_desktop_notifications_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
125 ······<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>119 ······<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
126 ······<ocil:actions>120 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
128 ······</ocil:actions>122 ······</ocil:actions>
Max diff block lines reached; 60132/71596 bytes (83.99%) of diff not shown.
140 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds-1.2.xml
140 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds-1.2.xml
Ordering differences only
    
Offset 7562, 1035 lines modifiedOffset 7562, 1179 lines modified
7562 ······<ocil:generator>7562 ······<ocil:generator>
7563 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>7563 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
7564 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>7564 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>
7565 ········<ocil:schema_version>2.0</ocil:schema_version>7565 ········<ocil:schema_version>2.0</ocil:schema_version>
7566 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7566 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
7567 ······</ocil:generator>7567 ······</ocil:generator>
7568 ······<ocil:questionnaires>7568 ······<ocil:questionnaires>
7569 ········<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">7569 ········<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
7570 ··········<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>7570 ··········<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
7571 ··········<ocil:actions>7571 ··········<ocil:actions>
7572 ············<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>7572 ············<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
7573 ··········</ocil:actions>7573 ··········</ocil:actions>
7574 ········</ocil:questionnaire>7574 ········</ocil:questionnaire>
7575 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_worker_ocil:questionnaire:1">7575 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
7576 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>7576 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
7577 ··········<ocil:actions>7577 ··········<ocil:actions>
7578 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_worker_action:testaction:1</ocil:test_action_ref>7578 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
7579 ··········</ocil:actions> 
7580 ········</ocil:questionnaire> 
7581 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
7582 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> 
7583 ··········<ocil:actions> 
7584 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref> 
7585 ··········</ocil:actions> 
7586 ········</ocil:questionnaire> 
7587 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_worker_ocil:questionnaire:1"> 
7588 ··········<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title> 
7589 ··········<ocil:actions> 
7590 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_worker_action:testaction:1</ocil:test_action_ref> 
7591 ··········</ocil:actions>7579 ··········</ocil:actions>
7592 ········</ocil:questionnaire>7580 ········</ocil:questionnaire>
7593 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">7581 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_deprecated_ocil:questionnaire:1">
7594 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>7582 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
7595 ··········<ocil:actions>7583 ··········<ocil:actions>
7596 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>7584 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_deprecated_action:testaction:1</ocil:test_action_ref>
7597 ··········</ocil:actions>7585 ··········</ocil:actions>
7598 ········</ocil:questionnaire>7586 ········</ocil:questionnaire>
7599 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_master_ocil:questionnaire:1">7587 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_master_ocil:questionnaire:1">
7600 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>7588 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
7601 ··········<ocil:actions>7589 ··········<ocil:actions>
7602 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_master_action:testaction:1</ocil:test_action_ref>7590 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_master_action:testaction:1</ocil:test_action_ref>
7603 ··········</ocil:actions>7591 ··········</ocil:actions>
7604 ········</ocil:questionnaire>7592 ········</ocil:questionnaire>
7605 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_worker_ocil:questionnaire:1">7593 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_ocil:questionnaire:1">
7606 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>7594 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
7607 ··········<ocil:actions>7595 ··········<ocil:actions>
7608 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_worker_action:testaction:1</ocil:test_action_ref>7596 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_action:testaction:1</ocil:test_action_ref>
7609 ··········</ocil:actions>7597 ··········</ocil:actions>
7610 ········</ocil:questionnaire>7598 ········</ocil:questionnaire>
7611 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_client_cert_rotation_worker_ocil:questionnaire:1">7599 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
7612 ··········<ocil:title>kubelet·-·Enable·Client·Certificate·Rotation</ocil:title>7600 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
7613 ··········<ocil:actions>7601 ··········<ocil:actions>
7614 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_client_cert_rotation_worker_action:testaction:1</ocil:test_action_ref>7602 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>
7615 ··········</ocil:actions>7603 ··········</ocil:actions>
7616 ········</ocil:questionnaire>7604 ········</ocil:questionnaire>
7617 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">7605 ········<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">
7618 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>7606 ··········<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>
7619 ··········<ocil:actions>7607 ··········<ocil:actions>
7620 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>7608 ············<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>
7621 ··········</ocil:actions>7609 ··········</ocil:actions>
7622 ········</ocil:questionnaire>7610 ········</ocil:questionnaire>
7623 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_master_ocil:questionnaire:1">7611 ········<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
7624 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>7612 ··········<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>
7625 ··········<ocil:actions>7613 ··········<ocil:actions>
7626 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_master_action:testaction:1</ocil:test_action_ref>7614 ············<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>
7627 ··········</ocil:actions>7615 ··········</ocil:actions>
7628 ········</ocil:questionnaire>7616 ········</ocil:questionnaire>
7629 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">7617 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">
7630 ··········<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>7618 ··········<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
7631 ··········<ocil:actions>7619 ··········<ocil:actions>
7632 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>7620 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
7633 ··········</ocil:actions>7621 ··········</ocil:actions>
7634 ········</ocil:questionnaire>7622 ········</ocil:questionnaire>
7635 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1"> 
7636 ··········<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title> 
7637 ··········<ocil:actions> 
7638 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref> 
7639 ··········</ocil:actions> 
7640 ········</ocil:questionnaire> 
7641 ········<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">7623 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">
 7624 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
7642 ··········<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title> 
7643 ··········<ocil:actions> 
7644 ············<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref> 
7645 ··········</ocil:actions> 
7646 ········</ocil:questionnaire> 
7647 ········<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1"> 
7648 ··········<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title> 
7649 ··········<ocil:actions>7625 ··········<ocil:actions>
7650 ············<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref>7626 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>
7651 ··········</ocil:actions>7627 ··········</ocil:actions>
7652 ········</ocil:questionnaire>7628 ········</ocil:questionnaire>
7653 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1">7629 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
7654 ··········<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>7630 ··········<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
7655 ··········<ocil:actions>7631 ··········<ocil:actions>
7656 ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>7632 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
7657 ··········</ocil:actions>7633 ··········</ocil:actions>
7658 ········</ocil:questionnaire>7634 ········</ocil:questionnaire>
7659 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_master_ocil:questionnaire:1">7635 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_deprecated_ocil:questionnaire:1">
7660 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>7636 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
7661 ··········<ocil:actions>7637 ··········<ocil:actions>
7662 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_master_action:testaction:1</ocil:test_action_ref>7638 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_deprecated_action:testaction:1</ocil:test_action_ref>
7663 ··········</ocil:actions>7639 ··········</ocil:actions>
7664 ········</ocil:questionnaire>7640 ········</ocil:questionnaire>
7665 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_ocil:questionnaire:1"> 
7666 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>7641 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
 7642 ··········<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
7667 ··········<ocil:actions>7643 ··········<ocil:actions>
7668 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_action:testaction:1</ocil:test_action_ref>7644 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
7669 ··········</ocil:actions>7645 ··········</ocil:actions>
7670 ········</ocil:questionnaire>7646 ········</ocil:questionnaire>
7671 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_worker_ocil:questionnaire:1">7647 ········<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">
7672 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>7648 ··········<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
7673 ··········<ocil:actions>7649 ··········<ocil:actions>
7674 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_worker_action:testaction:1</ocil:test_action_ref>7650 ············<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
7675 ··········</ocil:actions>7651 ··········</ocil:actions>
7676 ········</ocil:questionnaire>7652 ········</ocil:questionnaire>
7677 ········<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">7653 ········<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">
7678 ··········<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>7654 ··········<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>
7679 ··········<ocil:actions>7655 ··········<ocil:actions>
7680 ············<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>7656 ············<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>
7681 ··········</ocil:actions>7657 ··········</ocil:actions>
7682 ········</ocil:questionnaire>7658 ········</ocil:questionnaire>
7683 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">7659 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_deprecated_ocil:questionnaire:1">
7684 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>7660 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
7685 ··········<ocil:actions>7661 ··········<ocil:actions>
7686 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>7662 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_deprecated_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 131867/143567 bytes (91.85%) of diff not shown.
140 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
140 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
Ordering differences only
    
Offset 7562, 1035 lines modifiedOffset 7562, 1179 lines modified
7562 ······<ocil:generator>7562 ······<ocil:generator>
7563 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>7563 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
7564 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>7564 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>
7565 ········<ocil:schema_version>2.0</ocil:schema_version>7565 ········<ocil:schema_version>2.0</ocil:schema_version>
7566 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7566 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
7567 ······</ocil:generator>7567 ······</ocil:generator>
7568 ······<ocil:questionnaires>7568 ······<ocil:questionnaires>
7569 ········<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">7569 ········<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
7570 ··········<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>7570 ··········<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
7571 ··········<ocil:actions>7571 ··········<ocil:actions>
7572 ············<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>7572 ············<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
7573 ··········</ocil:actions>7573 ··········</ocil:actions>
7574 ········</ocil:questionnaire>7574 ········</ocil:questionnaire>
7575 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_worker_ocil:questionnaire:1">7575 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
7576 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>7576 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
7577 ··········<ocil:actions>7577 ··········<ocil:actions>
7578 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_worker_action:testaction:1</ocil:test_action_ref>7578 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
7579 ··········</ocil:actions> 
7580 ········</ocil:questionnaire> 
7581 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
7582 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> 
7583 ··········<ocil:actions> 
7584 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref> 
7585 ··········</ocil:actions> 
7586 ········</ocil:questionnaire> 
7587 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_worker_ocil:questionnaire:1"> 
7588 ··········<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title> 
7589 ··········<ocil:actions> 
7590 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_worker_action:testaction:1</ocil:test_action_ref> 
7591 ··········</ocil:actions>7579 ··········</ocil:actions>
7592 ········</ocil:questionnaire>7580 ········</ocil:questionnaire>
7593 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">7581 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_deprecated_ocil:questionnaire:1">
7594 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>7582 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
7595 ··········<ocil:actions>7583 ··········<ocil:actions>
7596 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>7584 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_deprecated_action:testaction:1</ocil:test_action_ref>
7597 ··········</ocil:actions>7585 ··········</ocil:actions>
7598 ········</ocil:questionnaire>7586 ········</ocil:questionnaire>
7599 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_master_ocil:questionnaire:1">7587 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_master_ocil:questionnaire:1">
7600 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>7588 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
7601 ··········<ocil:actions>7589 ··········<ocil:actions>
7602 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_master_action:testaction:1</ocil:test_action_ref>7590 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_master_action:testaction:1</ocil:test_action_ref>
7603 ··········</ocil:actions>7591 ··········</ocil:actions>
7604 ········</ocil:questionnaire>7592 ········</ocil:questionnaire>
7605 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_worker_ocil:questionnaire:1">7593 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_ocil:questionnaire:1">
7606 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>7594 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
7607 ··········<ocil:actions>7595 ··········<ocil:actions>
7608 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_worker_action:testaction:1</ocil:test_action_ref>7596 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_action:testaction:1</ocil:test_action_ref>
7609 ··········</ocil:actions>7597 ··········</ocil:actions>
7610 ········</ocil:questionnaire>7598 ········</ocil:questionnaire>
7611 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_client_cert_rotation_worker_ocil:questionnaire:1">7599 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
7612 ··········<ocil:title>kubelet·-·Enable·Client·Certificate·Rotation</ocil:title>7600 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
7613 ··········<ocil:actions>7601 ··········<ocil:actions>
7614 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_client_cert_rotation_worker_action:testaction:1</ocil:test_action_ref>7602 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>
7615 ··········</ocil:actions>7603 ··········</ocil:actions>
7616 ········</ocil:questionnaire>7604 ········</ocil:questionnaire>
7617 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">7605 ········<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">
7618 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>7606 ··········<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>
7619 ··········<ocil:actions>7607 ··········<ocil:actions>
7620 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>7608 ············<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>
7621 ··········</ocil:actions>7609 ··········</ocil:actions>
7622 ········</ocil:questionnaire>7610 ········</ocil:questionnaire>
7623 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_master_ocil:questionnaire:1">7611 ········<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
7624 ··········<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>7612 ··········<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>
7625 ··········<ocil:actions>7613 ··········<ocil:actions>
7626 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_master_action:testaction:1</ocil:test_action_ref>7614 ············<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>
7627 ··········</ocil:actions>7615 ··········</ocil:actions>
7628 ········</ocil:questionnaire>7616 ········</ocil:questionnaire>
7629 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">7617 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">
7630 ··········<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>7618 ··········<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
7631 ··········<ocil:actions>7619 ··········<ocil:actions>
7632 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>7620 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
7633 ··········</ocil:actions>7621 ··········</ocil:actions>
7634 ········</ocil:questionnaire>7622 ········</ocil:questionnaire>
7635 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1"> 
7636 ··········<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title> 
7637 ··········<ocil:actions> 
7638 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref> 
7639 ··········</ocil:actions> 
7640 ········</ocil:questionnaire> 
7641 ········<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">7623 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">
 7624 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
7642 ··········<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title> 
7643 ··········<ocil:actions> 
7644 ············<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref> 
7645 ··········</ocil:actions> 
7646 ········</ocil:questionnaire> 
7647 ········<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1"> 
7648 ··········<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title> 
7649 ··········<ocil:actions>7625 ··········<ocil:actions>
7650 ············<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref>7626 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>
7651 ··········</ocil:actions>7627 ··········</ocil:actions>
7652 ········</ocil:questionnaire>7628 ········</ocil:questionnaire>
7653 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1">7629 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
7654 ··········<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>7630 ··········<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
7655 ··········<ocil:actions>7631 ··········<ocil:actions>
7656 ············<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>7632 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
7657 ··········</ocil:actions>7633 ··········</ocil:actions>
7658 ········</ocil:questionnaire>7634 ········</ocil:questionnaire>
7659 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_master_ocil:questionnaire:1">7635 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_deprecated_ocil:questionnaire:1">
7660 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>7636 ··········<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
7661 ··········<ocil:actions>7637 ··········<ocil:actions>
7662 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_master_action:testaction:1</ocil:test_action_ref>7638 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_deprecated_action:testaction:1</ocil:test_action_ref>
7663 ··········</ocil:actions>7639 ··········</ocil:actions>
7664 ········</ocil:questionnaire>7640 ········</ocil:questionnaire>
7665 ········<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_ocil:questionnaire:1"> 
7666 ··········<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>7641 ········<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
 7642 ··········<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
7667 ··········<ocil:actions>7643 ··········<ocil:actions>
7668 ············<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_action:testaction:1</ocil:test_action_ref>7644 ············<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
7669 ··········</ocil:actions>7645 ··········</ocil:actions>
7670 ········</ocil:questionnaire>7646 ········</ocil:questionnaire>
7671 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_worker_ocil:questionnaire:1">7647 ········<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">
7672 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>7648 ··········<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
7673 ··········<ocil:actions>7649 ··········<ocil:actions>
7674 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_worker_action:testaction:1</ocil:test_action_ref>7650 ············<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
7675 ··········</ocil:actions>7651 ··········</ocil:actions>
7676 ········</ocil:questionnaire>7652 ········</ocil:questionnaire>
7677 ········<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">7653 ········<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">
7678 ··········<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>7654 ··········<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>
7679 ··········<ocil:actions>7655 ··········<ocil:actions>
7680 ············<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>7656 ············<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>
7681 ··········</ocil:actions>7657 ··········</ocil:actions>
7682 ········</ocil:questionnaire>7658 ········</ocil:questionnaire>
7683 ········<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">7659 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_deprecated_ocil:questionnaire:1">
7684 ··········<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>7660 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
7685 ··········<ocil:actions>7661 ··········<ocil:actions>
7686 ············<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>7662 ············<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_deprecated_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 131867/143567 bytes (91.85%) of diff not shown.
135 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
135 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
Ordering differences only
    
Offset 3, 1035 lines modifiedOffset 3, 1179 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-private_nodes_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">
11 ······<ocil:title>Ensure·Cluster·Private·Nodes</ocil:title>11 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-private_nodes_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_worker_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">
17 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>17 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_worker_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1"> 
23 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_worker_ocil:questionnaire:1"> 
29 ······<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title> 
30 ······<ocil:actions> 
31 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_worker_action:testaction:1</ocil:test_action_ref> 
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_deprecated_ocil:questionnaire:1">
35 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>23 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_deprecated_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_master_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_master_ocil:questionnaire:1">
41 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>29 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_master_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_master_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_worker_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_ocil:questionnaire:1">
47 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>35 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_worker_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_client_cert_rotation_worker_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
53 ······<ocil:title>kubelet·-·Enable·Client·Certificate·Rotation</ocil:title>41 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_client_cert_rotation_worker_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1">
59 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>47 ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_master_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
65 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>53 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_master_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">
71 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>59 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1"> 
77 ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title> 
78 ······<ocil:actions> 
79 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref> 
80 ······</ocil:actions> 
81 ····</ocil:questionnaire> 
82 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
83 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title> 
84 ······<ocil:actions> 
85 ········<ocil:test_action_ref>ocil:ssg-configure_tls_action:testaction:1</ocil:test_action_ref> 
86 ······</ocil:actions> 
87 ····</ocil:questionnaire> 
88 ····<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1"> 
89 ······<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title> 
90 ······<ocil:actions>66 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>68 ······</ocil:actions>
93 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"> 
95 ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
 71 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
96 ······<ocil:actions>72 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>74 ······</ocil:actions>
99 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_master_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_deprecated_ocil:questionnaire:1">
101 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>77 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
102 ······<ocil:actions>78 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_master_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_deprecated_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>80 ······</ocil:actions>
105 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_ocil:questionnaire:1"> 
107 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_kubelet_conf_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Group·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
108 ······<ocil:actions>84 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_deprecated_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>86 ······</ocil:actions>
111 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_worker_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>89 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
114 ······<ocil:actions>90 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_worker_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>92 ······</ocil:actions>
117 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">
119 ······<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>95 ······<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>
120 ······<ocil:actions>96 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>98 ······</ocil:actions>
123 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_deprecated_ocil:questionnaire:1">
125 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>101 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
126 ······<ocil:actions>102 ······<ocil:actions>
Max diff block lines reached; 126592/137634 bytes (91.98%) of diff not shown.
48.4 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds-1.2.xml
48.3 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds-1.2.xml
Ordering differences only
    
Offset 4950, 545 lines modifiedOffset 4950, 522 lines modified
4950 ······<ocil:generator>4950 ······<ocil:generator>
4951 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4951 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
4952 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>4952 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>
4953 ········<ocil:schema_version>2.0</ocil:schema_version>4953 ········<ocil:schema_version>2.0</ocil:schema_version>
4954 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>4954 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
4955 ······</ocil:generator>4955 ······</ocil:generator>
4956 ······<ocil:questionnaires>4956 ······<ocil:questionnaires>
4957 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1"> 
4958 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title> 
4959 ··········<ocil:actions> 
4960 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref> 
4961 ··········</ocil:actions> 
4962 ········</ocil:questionnaire> 
4963 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"> 
4964 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title> 
4965 ··········<ocil:actions> 
4966 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref> 
4967 ··········</ocil:actions> 
4968 ········</ocil:questionnaire> 
4969 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1"> 
4970 ··········<ocil:title>Disable·Firefox·network·prediction</ocil:title> 
4971 ··········<ocil:actions> 
4972 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref> 
4973 ··········</ocil:actions> 
4974 ········</ocil:questionnaire> 
4975 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">4957 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">
4976 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>4958 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>
4977 ··········<ocil:actions>4959 ··········<ocil:actions>
4978 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>4960 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>
4979 ··········</ocil:actions>4961 ··········</ocil:actions>
4980 ········</ocil:questionnaire>4962 ········</ocil:questionnaire>
4981 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">4963 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
4982 ··········<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>4964 ··········<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
4983 ··········<ocil:actions>4965 ··········<ocil:actions>
4984 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>4966 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
4985 ··········</ocil:actions>4967 ··········</ocil:actions>
4986 ········</ocil:questionnaire>4968 ········</ocil:questionnaire>
4987 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">4969 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
4988 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>4970 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
4989 ··········<ocil:actions>4971 ··········<ocil:actions>
4990 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>4972 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
4991 ··········</ocil:actions>4973 ··········</ocil:actions>
4992 ········</ocil:questionnaire>4974 ········</ocil:questionnaire>
4993 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">4975 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
4994 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>4976 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
4995 ··········<ocil:actions>4977 ··········<ocil:actions>
4996 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>4978 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
4997 ··········</ocil:actions>4979 ··········</ocil:actions>
4998 ········</ocil:questionnaire>4980 ········</ocil:questionnaire>
4999 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1"> 
5000 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title> 
5001 ··········<ocil:actions> 
5002 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref> 
5003 ··········</ocil:actions> 
5004 ········</ocil:questionnaire> 
5005 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">4981 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
5006 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>4982 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>
5007 ··········<ocil:actions>4983 ··········<ocil:actions>
5008 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>4984 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
5009 ··········</ocil:actions>4985 ··········</ocil:actions>
5010 ········</ocil:questionnaire>4986 ········</ocil:questionnaire>
5011 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">4987 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
5012 ··········<ocil:title>Disable·Firefox·Studies</ocil:title>4988 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>
5013 ··········<ocil:actions> 
5014 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref> 
5015 ··········</ocil:actions> 
5016 ········</ocil:questionnaire> 
5017 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1"> 
5018 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title> 
5019 ··········<ocil:actions>4989 ··········<ocil:actions>
5020 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>4990 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
5021 ··········</ocil:actions>4991 ··········</ocil:actions>
5022 ········</ocil:questionnaire>4992 ········</ocil:questionnaire>
5023 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">4993 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
5024 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>4994 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>
5025 ··········<ocil:actions>4995 ··········<ocil:actions>
5026 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>4996 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
5027 ··········</ocil:actions>4997 ··········</ocil:actions>
5028 ········</ocil:questionnaire>4998 ········</ocil:questionnaire>
5029 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">4999 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
5030 ··········<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>5000 ··········<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
5031 ··········<ocil:actions>5001 ··········<ocil:actions>
5032 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>5002 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
5033 ··········</ocil:actions>5003 ··········</ocil:actions>
5034 ········</ocil:questionnaire>5004 ········</ocil:questionnaire>
5035 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">5005 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
5036 ··········<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>5006 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
5037 ··········<ocil:actions>5007 ··········<ocil:actions>
5038 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>5008 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
5039 ··········</ocil:actions>5009 ··········</ocil:actions>
5040 ········</ocil:questionnaire>5010 ········</ocil:questionnaire>
5041 ········<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">5011 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
5042 ··········<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>5012 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
5043 ··········<ocil:actions>5013 ··········<ocil:actions>
5044 ············<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>5014 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
5045 ··········</ocil:actions>5015 ··········</ocil:actions>
5046 ········</ocil:questionnaire>5016 ········</ocil:questionnaire>
5047 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">5017 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
5048 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>5018 ··········<ocil:title>Disable·Firefox·network·prediction</ocil:title>
5049 ··········<ocil:actions>5019 ··········<ocil:actions>
 5020 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
 5021 ··········</ocil:actions>
 5022 ········</ocil:questionnaire>
 5023 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
 5024 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
 5025 ··········<ocil:actions>
5050 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>5026 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
 5027 ··········</ocil:actions>
 5028 ········</ocil:questionnaire>
 5029 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
 5030 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
 5031 ··········<ocil:actions>
 5032 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
5051 ··········</ocil:actions>5033 ··········</ocil:actions>
5052 ········</ocil:questionnaire>5034 ········</ocil:questionnaire>
5053 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">5035 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">
5054 ··········<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>5036 ··········<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>
5055 ··········<ocil:actions>5037 ··········<ocil:actions>
5056 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>5038 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>
5057 ··········</ocil:actions>5039 ··········</ocil:actions>
5058 ········</ocil:questionnaire>5040 ········</ocil:questionnaire>
5059 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">5041 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
5060 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>5042 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
5061 ··········<ocil:actions>5043 ··········<ocil:actions>
5062 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>5044 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
5063 ··········</ocil:actions>5045 ··········</ocil:actions>
5064 ········</ocil:questionnaire>5046 ········</ocil:questionnaire>
Max diff block lines reached; 38543/49282 bytes (78.21%) of diff not shown.
48.4 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
48.3 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
Ordering differences only
    
Offset 4950, 545 lines modifiedOffset 4950, 522 lines modified
4950 ······<ocil:generator>4950 ······<ocil:generator>
4951 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4951 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
4952 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>4952 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>
4953 ········<ocil:schema_version>2.0</ocil:schema_version>4953 ········<ocil:schema_version>2.0</ocil:schema_version>
4954 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>4954 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
4955 ······</ocil:generator>4955 ······</ocil:generator>
4956 ······<ocil:questionnaires>4956 ······<ocil:questionnaires>
4957 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1"> 
4958 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title> 
4959 ··········<ocil:actions> 
4960 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref> 
4961 ··········</ocil:actions> 
4962 ········</ocil:questionnaire> 
4963 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"> 
4964 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title> 
4965 ··········<ocil:actions> 
4966 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref> 
4967 ··········</ocil:actions> 
4968 ········</ocil:questionnaire> 
4969 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1"> 
4970 ··········<ocil:title>Disable·Firefox·network·prediction</ocil:title> 
4971 ··········<ocil:actions> 
4972 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref> 
4973 ··········</ocil:actions> 
4974 ········</ocil:questionnaire> 
4975 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">4957 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">
4976 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>4958 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>
4977 ··········<ocil:actions>4959 ··········<ocil:actions>
4978 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>4960 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>
4979 ··········</ocil:actions>4961 ··········</ocil:actions>
4980 ········</ocil:questionnaire>4962 ········</ocil:questionnaire>
4981 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">4963 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
4982 ··········<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>4964 ··········<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
4983 ··········<ocil:actions>4965 ··········<ocil:actions>
4984 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>4966 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
4985 ··········</ocil:actions>4967 ··········</ocil:actions>
4986 ········</ocil:questionnaire>4968 ········</ocil:questionnaire>
4987 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">4969 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
4988 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>4970 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
4989 ··········<ocil:actions>4971 ··········<ocil:actions>
4990 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>4972 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
4991 ··········</ocil:actions>4973 ··········</ocil:actions>
4992 ········</ocil:questionnaire>4974 ········</ocil:questionnaire>
4993 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">4975 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
4994 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>4976 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
4995 ··········<ocil:actions>4977 ··········<ocil:actions>
4996 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>4978 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
4997 ··········</ocil:actions>4979 ··········</ocil:actions>
4998 ········</ocil:questionnaire>4980 ········</ocil:questionnaire>
4999 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1"> 
5000 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title> 
5001 ··········<ocil:actions> 
5002 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref> 
5003 ··········</ocil:actions> 
5004 ········</ocil:questionnaire> 
5005 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">4981 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
5006 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>4982 ··········<ocil:title>Disable·Firefox·Pocket</ocil:title>
5007 ··········<ocil:actions>4983 ··········<ocil:actions>
5008 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>4984 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
5009 ··········</ocil:actions>4985 ··········</ocil:actions>
5010 ········</ocil:questionnaire>4986 ········</ocil:questionnaire>
5011 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">4987 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
5012 ··········<ocil:title>Disable·Firefox·Studies</ocil:title>4988 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>
5013 ··········<ocil:actions> 
5014 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref> 
5015 ··········</ocil:actions> 
5016 ········</ocil:questionnaire> 
5017 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1"> 
5018 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title> 
5019 ··········<ocil:actions>4989 ··········<ocil:actions>
5020 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>4990 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
5021 ··········</ocil:actions>4991 ··········</ocil:actions>
5022 ········</ocil:questionnaire>4992 ········</ocil:questionnaire>
5023 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">4993 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
5024 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>4994 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>
5025 ··········<ocil:actions>4995 ··········<ocil:actions>
5026 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>4996 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
5027 ··········</ocil:actions>4997 ··········</ocil:actions>
5028 ········</ocil:questionnaire>4998 ········</ocil:questionnaire>
5029 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">4999 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
5030 ··········<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>5000 ··········<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
5031 ··········<ocil:actions>5001 ··········<ocil:actions>
5032 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>5002 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
5033 ··········</ocil:actions>5003 ··········</ocil:actions>
5034 ········</ocil:questionnaire>5004 ········</ocil:questionnaire>
5035 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">5005 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
5036 ··········<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>5006 ··········<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
5037 ··········<ocil:actions>5007 ··········<ocil:actions>
5038 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>5008 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
5039 ··········</ocil:actions>5009 ··········</ocil:actions>
5040 ········</ocil:questionnaire>5010 ········</ocil:questionnaire>
5041 ········<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">5011 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
5042 ··········<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>5012 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
5043 ··········<ocil:actions>5013 ··········<ocil:actions>
5044 ············<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>5014 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
5045 ··········</ocil:actions>5015 ··········</ocil:actions>
5046 ········</ocil:questionnaire>5016 ········</ocil:questionnaire>
5047 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">5017 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
5048 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>5018 ··········<ocil:title>Disable·Firefox·network·prediction</ocil:title>
5049 ··········<ocil:actions>5019 ··········<ocil:actions>
 5020 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
 5021 ··········</ocil:actions>
 5022 ········</ocil:questionnaire>
 5023 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
 5024 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
 5025 ··········<ocil:actions>
5050 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>5026 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
 5027 ··········</ocil:actions>
 5028 ········</ocil:questionnaire>
 5029 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
 5030 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
 5031 ··········<ocil:actions>
 5032 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
5051 ··········</ocil:actions>5033 ··········</ocil:actions>
5052 ········</ocil:questionnaire>5034 ········</ocil:questionnaire>
5053 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">5035 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">
5054 ··········<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>5036 ··········<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>
5055 ··········<ocil:actions>5037 ··········<ocil:actions>
5056 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>5038 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>
5057 ··········</ocil:actions>5039 ··········</ocil:actions>
5058 ········</ocil:questionnaire>5040 ········</ocil:questionnaire>
5059 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">5041 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
5060 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>5042 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
5061 ··········<ocil:actions>5043 ··········<ocil:actions>
5062 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>5044 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
5063 ··········</ocil:actions>5045 ··········</ocil:actions>
5064 ········</ocil:questionnaire>5046 ········</ocil:questionnaire>
Max diff block lines reached; 38543/49282 bytes (78.21%) of diff not shown.
45.6 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
45.5 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
Ordering differences only
    
Offset 3, 545 lines modifiedOffset 3, 522 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1"> 
11 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1"> 
23 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">
29 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>11 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>
30 ······<ocil:actions>12 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>14 ······</ocil:actions>
33 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
35 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>17 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
36 ······<ocil:actions>18 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>20 ······</ocil:actions>
39 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
41 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>23 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
42 ······<ocil:actions>24 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>26 ······</ocil:actions>
45 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
47 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>29 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
48 ······<ocil:actions>30 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>32 ······</ocil:actions>
51 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1"> 
53 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title> 
54 ······<ocil:actions> 
55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref> 
56 ······</ocil:actions> 
57 ····</ocil:questionnaire> 
58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
59 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>35 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>
60 ······<ocil:actions>36 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>38 ······</ocil:actions>
63 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
65 ······<ocil:title>Disable·Firefox·Studies</ocil:title>41 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>
66 ······<ocil:actions> 
67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref> 
68 ······</ocil:actions> 
69 ····</ocil:questionnaire> 
70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1"> 
71 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title> 
72 ······<ocil:actions>42 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>44 ······</ocil:actions>
75 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">
77 ······<ocil:title>Enable·Certificate·Verification</ocil:title>47 ······<ocil:title>Enable·Certificate·Verification</ocil:title>
78 ······<ocil:actions>48 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>50 ······</ocil:actions>
81 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
83 ······<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>53 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
84 ······<ocil:actions>54 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>56 ······</ocil:actions>
87 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">
89 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>59 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>
90 ······<ocil:actions>60 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>62 ······</ocil:actions>
93 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1"> 
95 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
 65 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
96 ······<ocil:actions>66 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>68 ······</ocil:actions>
99 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
101 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>71 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>
102 ······<ocil:actions>72 ······<ocil:actions>
 73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
 74 ······</ocil:actions>
 75 ····</ocil:questionnaire>
 76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
 77 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
 78 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
 80 ······</ocil:actions>
 81 ····</ocil:questionnaire>
 82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">
 83 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>
 84 ······<ocil:actions>
 85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>86 ······</ocil:actions>
105 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">
107 ······<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>89 ······<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>
108 ······<ocil:actions>90 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>92 ······</ocil:actions>
111 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
113 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>95 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
114 ······<ocil:actions>96 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>98 ······</ocil:actions>
Max diff block lines reached; 36692/46433 bytes (79.02%) of diff not shown.
15.3 MB
ssg-debderived_0.1.65-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary
2 -rw-r--r--···0········0········0·····2784·2022-12-20·09:54:05.000000·control.tar.xz2 -rw-r--r--···0········0········0·····2784·2022-12-20·09:54:05.000000·control.tar.xz
3 -rw-r--r--···0········0········0··3393436·2022-12-20·09:54:05.000000·data.tar.xz3 -rw-r--r--···0········0········0··3391904·2022-12-20·09:54:05.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
15.3 MB
data.tar.xz
15.3 MB
data.tar
49.2 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_server.html
    
Offset 38493, 24 lines modifiedOffset 38493, 24 lines modified
000965c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate000965c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
000965d0:·6779·3a3c·2f74·683e·3c74·643e·636f·6e66··gy:</th><td>conf000965d0:·6779·3a3c·2f74·683e·3c74·643e·636f·6e66··gy:</th><td>conf
000965e0:·6967·7572·653c·2f74·643e·3c2f·7472·3e3c··igure</td></tr><000965e0:·6967·7572·653c·2f74·643e·3c2f·7472·3e3c··igure</td></tr><
000965f0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod000965f0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
00096600:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·00096600:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
00096610:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on00096610:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
00096620:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl00096620:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
00096630:·6174·666f·726d·730a·6966·2064·706b·672d··atforms.if·dpkg-00096630:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-
 00096640:·6620·2f73·7973·2f66·6972·6d77·6172·652f··f·/sys/firmware/
00096640:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s 
00096650:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db: 
00096660:·5374·6174·7573·2d53·7461·7475·737d·5c6e··Status-Status}\n 
00096670:·2720·2767·7275·6232·2d63·6f6d·6d6f·6e27··'·'grub2-common' 
00096680:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null· 
00096690:·7c20·6772·6570·202d·7120·696e·7374·616c··|·grep·-q·instal 
000966a0:·6c65·6420·2661·6d70·3b26·616d·703b·205b··led·&amp;&amp;·[00096650:·6566·6920·5d20·2661·6d70·3b26·616d·703b··efi·]·&amp;&amp;
000966b0:·2021·202d·6620·2f73·7973·2f66·6972·6d77···!·-f·/sys/firmw 
000966c0:·6172·652f·6566·6920·5d20·2661·6d70·3b26··are/efi·]·&amp;&00096660:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh
 00096670:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat=
 00096680:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta
 00096690:·7475·737d·5c6e·2720·2767·7275·6232·2d63··tus}\n'·'grub2-c
 000966a0:·6f6d·6d6f·6e27·2032·2667·743b·2f64·6576··ommon'·2&gt;/dev
 000966b0:·2f6e·756c·6c20·7c20·6772·6570·202d·7120··/null·|·grep·-q·
 000966c0:·696e·7374·616c·6c65·6420·2661·6d70·3b26··installed·&amp;&
000966d0:·616d·703b·207b·205b·2021·202d·6620·2f2e··amp;·{·[·!·-f·/.000966d0:·616d·703b·207b·205b·2021·202d·6620·2f2e··amp;·{·[·!·-f·/.
000966e0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp000966e0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
000966f0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r000966f0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
00096700:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv00096700:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
00096710:·205d·3b20·7d3b·2074·6865·6e0a·0a63·686f···];·};·then..cho00096710:·205d·3b20·7d3b·2074·6865·6e0a·0a63·686f···];·};·then..cho
00096720:·776e·2030·202f·626f·6f74·2f67·7275·622f··wn·0·/boot/grub/00096720:·776e·2030·202f·626f·6f74·2f67·7275·622f··wn·0·/boot/grub/
00096730:·6772·7562·2e63·6667·0a0a·656c·7365·0a20··grub.cfg..else.·00096730:·6772·7562·2e63·6667·0a0a·656c·7365·0a20··grub.cfg..else.·
Offset 38571, 22 lines modifiedOffset 38571, 22 lines modified
00096aa0:·0a2d·206e·616d·653a·2054·6573·7420·666f··.-·name:·Test·fo00096aa0:·0a2d·206e·616d·653a·2054·6573·7420·666f··.-·name:·Test·fo
00096ab0:·7220·6578·6973·7465·6e63·6520·2f62·6f6f··r·existence·/boo00096ab0:·7220·6578·6973·7465·6e63·6520·2f62·6f6f··r·existence·/boo
00096ac0:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.00096ac0:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.
00096ad0:·2020·7374·6174·3a0a·2020·2020·7061·7468····stat:.····path00096ad0:·2020·7374·6174·3a0a·2020·2020·7061·7468····stat:.····path
00096ae0:·3a20·2f62·6f6f·742f·6772·7562·2f67·7275··:·/boot/grub/gru00096ae0:·3a20·2f62·6f6f·742f·6772·7562·2f67·7275··:·/boot/grub/gru
00096af0:·622e·6366·670a·2020·7265·6769·7374·6572··b.cfg.··register00096af0:·622e·6366·670a·2020·7265·6769·7374·6572··b.cfg.··register
00096b00:·3a20·6669·6c65·5f65·7869·7374·730a·2020··:·file_exists.··00096b00:·3a20·6669·6c65·5f65·7869·7374·730a·2020··:·file_exists.··
00096b10:·7768·656e·3a0a·2020·2d20·2722·6772·7562··when:.··-·'"grub00096b10:·7768·656e·3a0a·2020·2d20·2722·2f62·6f6f··when:.··-·'"/boo
00096b20:·322d·636f·6d6d·6f6e·2220·696e·2061·6e73··2-common"·in·ans 
00096b30:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
00096b40:·6765·7327·0a20·202d·2027·222f·626f·6f74··ges'.··-·'"/boot 
00096b50:·2f65·6669·2220·6e6f·7420·696e·2061·6e73··/efi"·not·in·ans 
00096b60:·6962·6c65·5f6d·6f75·6e74·7320·7c20·6d61··ible_mounts·|·ma 
00096b70:·7028·6174·7472·6962·7574·653d·226d·6f75··p(attribute="mou 
00096b80:·6e74·2229·207c·206c·6973·7427·0a20·202d··nt")·|·list'.··-00096b20:·742f·6566·6922·206e·6f74·2069·6e20·616e··t/efi"·not·in·an
 00096b30:·7369·626c·655f·6d6f·756e·7473·207c·206d··sible_mounts·|·m
 00096b40:·6170·2861·7474·7269·6275·7465·3d22·6d6f··ap(attribute="mo
 00096b50:·756e·7422·2920·7c20·6c69·7374·270a·2020··unt")·|·list'.··
 00096b60:·2d20·2722·6772·7562·322d·636f·6d6d·6f6e··-·'"grub2-common
 00096b70:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 00096b80:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··-
00096b90:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual00096b90:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
00096ba0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not00096ba0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
00096bb0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"00096bb0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
00096bc0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·00096bc0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
00096bd0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta00096bd0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
00096be0:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·00096be0:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·
00096bf0:·202d·2043·4a49·532d·352e·352e·322e·320a···-·CJIS-5.5.2.2.00096bf0:·202d·2043·4a49·532d·352e·352e·322e·320a···-·CJIS-5.5.2.2.
Offset 38606, 22 lines modifiedOffset 38606, 22 lines modified
00096cd0:·6f74·5f6e·6565·6465·640a·0a2d·206e·616d··ot_needed..-·nam00096cd0:·6f74·5f6e·6565·6465·640a·0a2d·206e·616d··ot_needed..-·nam
00096ce0:·653a·2045·6e73·7572·6520·6f77·6e65·7220··e:·Ensure·owner·00096ce0:·653a·2045·6e73·7572·6520·6f77·6e65·7220··e:·Ensure·owner·
00096cf0:·3020·6f6e·202f·626f·6f74·2f67·7275·622f··0·on·/boot/grub/00096cf0:·3020·6f6e·202f·626f·6f74·2f67·7275·622f··0·on·/boot/grub/
00096d00:·6772·7562·2e63·6667·0a20·2066·696c·653a··grub.cfg.··file:00096d00:·6772·7562·2e63·6667·0a20·2066·696c·653a··grub.cfg.··file:
00096d10:·0a20·2020·2070·6174·683a·202f·626f·6f74··.····path:·/boot00096d10:·0a20·2020·2070·6174·683a·202f·626f·6f74··.····path:·/boot
00096d20:·2f67·7275·622f·6772·7562·2e63·6667·0a20··/grub/grub.cfg.·00096d20:·2f67·7275·622f·6772·7562·2e63·6667·0a20··/grub/grub.cfg.·
00096d30:·2020·206f·776e·6572·3a20·2730·270a·2020·····owner:·'0'.··00096d30:·2020·206f·776e·6572·3a20·2730·270a·2020·····owner:·'0'.··
00096d40:·7768·656e·3a0a·2020·2d20·2722·6772·7562··when:.··-·'"grub00096d40:·7768·656e·3a0a·2020·2d20·2722·2f62·6f6f··when:.··-·'"/boo
00096d50:·322d·636f·6d6d·6f6e·2220·696e·2061·6e73··2-common"·in·ans 
00096d60:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
00096d70:·6765·7327·0a20·202d·2027·222f·626f·6f74··ges'.··-·'"/boot 
00096d80:·2f65·6669·2220·6e6f·7420·696e·2061·6e73··/efi"·not·in·ans 
00096d90:·6962·6c65·5f6d·6f75·6e74·7320·7c20·6d61··ible_mounts·|·ma 
00096da0:·7028·6174·7472·6962·7574·653d·226d·6f75··p(attribute="mou 
00096db0:·6e74·2229·207c·206c·6973·7427·0a20·202d··nt")·|·list'.··-00096d50:·742f·6566·6922·206e·6f74·2069·6e20·616e··t/efi"·not·in·an
 00096d60:·7369·626c·655f·6d6f·756e·7473·207c·206d··sible_mounts·|·m
 00096d70:·6170·2861·7474·7269·6275·7465·3d22·6d6f··ap(attribute="mo
 00096d80:·756e·7422·2920·7c20·6c69·7374·270a·2020··unt")·|·list'.··
 00096d90:·2d20·2722·6772·7562·322d·636f·6d6d·6f6e··-·'"grub2-common
 00096da0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 00096db0:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··-
00096dc0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual00096dc0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
00096dd0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not00096dd0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
00096de0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"00096de0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
00096df0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·00096df0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
00096e00:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta00096e00:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
00096e10:·696e·6572·225d·0a20·202d·2066·696c·655f··iner"].··-·file_00096e10:·696e·6572·225d·0a20·202d·2066·696c·655f··iner"].··-·file_
00096e20:·6578·6973·7473·2e73·7461·7420·6973·2064··exists.stat·is·d00096e20:·6578·6973·7473·2e73·7461·7420·6973·2064··exists.stat·is·d
Offset 39063, 24 lines modifiedOffset 39063, 24 lines modified
00098960:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str00098960:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
00098970:·6174·6567·793a·3c2f·7468·3e3c·7464·3e63··ategy:</th><td>c00098970:·6174·6567·793a·3c2f·7468·3e3c·7464·3e63··ategy:</th><td>c
00098980:·6f6e·6669·6775·7265·3c2f·7464·3e3c·2f74··onfigure</td></t00098980:·6f6e·6669·6775·7265·3c2f·7464·3e3c·2f74··onfigure</td></t
00098990:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><00098990:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
000989a0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati000989a0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
000989b0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable000989b0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
000989c0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain000989c0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
000989d0:·2070·6c61·7466·6f72·6d73·0a69·6620·6470···platforms.if·dp000989d0:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
000989e0:·6b67·2d71·7565·7279·202d·2d73·686f·7720··kg-query·--show· 
000989f0:·2d2d·7368·6f77·666f·726d·6174·3d27·247b··--showformat='${ 
00098a00:·6462·3a53·7461·7475·732d·5374·6174·7573··db:Status-Status 
00098a10:·7d5c·6e27·2027·6772·7562·322d·636f·6d6d··}\n'·'grub2-comm 
00098a20:·6f6e·2720·3226·6774·3b2f·6465·762f·6e75··on'·2&gt;/dev/nu 
00098a30:·6c6c·207c·2067·7265·7020·2d71·2069·6e73··ll·|·grep·-q·ins 
00098a40:·7461·6c6c·6564·2026·616d·703b·2661·6d70··talled·&amp;&amp 
00098a50:·3b20·5b20·2120·2d66·202f·7379·732f·6669··;·[·!·-f·/sys/fi000989e0:·2120·2d66·202f·7379·732f·6669·726d·7761··!·-f·/sys/firmwa
00098a60:·726d·7761·7265·2f65·6669·205d·2026·616d··rmware/efi·]·&am000989f0:·7265·2f65·6669·205d·2026·616d·703b·2661··re/efi·]·&amp;&a
 00098a00:·6d70·3b20·6470·6b67·2d71·7565·7279·202d··mp;·dpkg-query·-
 00098a10:·2d73·686f·7720·2d2d·7368·6f77·666f·726d··-show·--showform
 00098a20:·6174·3d27·247b·6462·3a53·7461·7475·732d··at='${db:Status-
 00098a30:·5374·6174·7573·7d5c·6e27·2027·6772·7562··Status}\n'·'grub
 00098a40:·322d·636f·6d6d·6f6e·2720·3226·6774·3b2f··2-common'·2&gt;/
 00098a50:·6465·762f·6e75·6c6c·207c·2067·7265·7020··dev/null·|·grep·
 00098a60:·2d71·2069·6e73·7461·6c6c·6564·2026·616d··-q·installed·&am
00098a70:·703b·2661·6d70·3b20·7b20·5b20·2120·2d66··p;&amp;·{·[·!·-f00098a70:·703b·2661·6d70·3b20·7b20·5b20·2120·2d66··p;&amp;·{·[·!·-f
00098a80:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&00098a80:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
00098a90:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f00098a90:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
00098aa0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container00098aa0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
00098ab0:·656e·7620·5d3b·207d·3b20·7468·656e·0a0a··env·];·};·then..00098ab0:·656e·7620·5d3b·207d·3b20·7468·656e·0a0a··env·];·};·then..
00098ac0:·6368·6d6f·6420·752d·7873·2c67·2d78·7772··chmod·u-xs,g-xwr00098ac0:·6368·6d6f·6420·752d·7873·2c67·2d78·7772··chmod·u-xs,g-xwr
00098ad0:·732c·6f2d·7877·7274·202f·626f·6f74·2f67··s,o-xwrt·/boot/g00098ad0:·732c·6f2d·7877·7274·202f·626f·6f74·2f67··s,o-xwrt·/boot/g
Offset 39141, 21 lines modifiedOffset 39141, 21 lines modified
00098e40:·7374·2066·6f72·2065·7869·7374·656e·6365··st·for·existence00098e40:·7374·2066·6f72·2065·7869·7374·656e·6365··st·for·existence
00098e50:·202f·626f·6f74·2f67·7275·622f·6772·7562···/boot/grub/grub00098e50:·202f·626f·6f74·2f67·7275·622f·6772·7562···/boot/grub/grub
00098e60:·2e63·6667·0a20·2073·7461·743a·0a20·2020··.cfg.··stat:.···00098e60:·2e63·6667·0a20·2073·7461·743a·0a20·2020··.cfg.··stat:.···
00098e70:·2070·6174·683a·202f·626f·6f74·2f67·7275···path:·/boot/gru00098e70:·2070·6174·683a·202f·626f·6f74·2f67·7275···path:·/boot/gru
00098e80:·622f·6772·7562·2e63·6667·0a20·2072·6567··b/grub.cfg.··reg00098e80:·622f·6772·7562·2e63·6667·0a20·2072·6567··b/grub.cfg.··reg
Max diff block lines reached; 32928/42304 bytes (77.84%) of diff not shown.
7.71 KB
html2text {}
    
Offset 3203, 16 lines modifiedOffset 3203, 16 lines modified
3203 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,3203 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,
3204 ············Req-7.1,·1.5.23204 ············Req-7.1,·1.5.2
3205 Remediation_Shell_script_⇲3205 Remediation_Shell_script_⇲
3206 Complexity:·low3206 Complexity:·low
3207 Disruption:·low3207 Disruption:·low
3208 Strategy:···configure3208 Strategy:···configure
3209 #·Remediation·is·applicable·only·in·certain·platforms3209 #·Remediation·is·applicable·only·in·certain·platforms
3210 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&·[·!3210 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/
3211 -f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3211 null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3212 chown·0·/boot/grub/grub.cfg3212 chown·0·/boot/grub/grub.cfg
  
3213 else3213 else
3214 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3214 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3215 fi3215 fi
3216 Remediation_Ansible_snippet_⇲3216 Remediation_Ansible_snippet_⇲
Offset 3236, 16 lines modifiedOffset 3236, 16 lines modified
3236 ··-·no_reboot_needed3236 ··-·no_reboot_needed
  
3237 -·name:·Test·for·existence·/boot/grub/grub.cfg3237 -·name:·Test·for·existence·/boot/grub/grub.cfg
3238 ··stat:3238 ··stat:
3239 ····path:·/boot/grub/grub.cfg3239 ····path:·/boot/grub/grub.cfg
3240 ··register:·file_exists3240 ··register:·file_exists
3241 ··when:3241 ··when:
3242 ··-·'"grub2-common"·in·ansible_facts.packages' 
3243 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3242 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3243 ··-·'"grub2-common"·in·ansible_facts.packages'
3244 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3244 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3245 ··tags:3245 ··tags:
3246 ··-·CJIS-5.5.2.23246 ··-·CJIS-5.5.2.2
3247 ··-·NIST-800-171-3.4.53247 ··-·NIST-800-171-3.4.5
3248 ··-·NIST-800-53-AC-6(1)3248 ··-·NIST-800-53-AC-6(1)
3249 ··-·NIST-800-53-CM-6(a)3249 ··-·NIST-800-53-CM-6(a)
3250 ··-·PCI-DSS-Req-7.13250 ··-·PCI-DSS-Req-7.1
Offset 3257, 16 lines modifiedOffset 3257, 16 lines modified
3257 ··-·no_reboot_needed3257 ··-·no_reboot_needed
  
3258 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg3258 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
3259 ··file:3259 ··file:
3260 ····path:·/boot/grub/grub.cfg3260 ····path:·/boot/grub/grub.cfg
3261 ····owner:·'0'3261 ····owner:·'0'
3262 ··when:3262 ··when:
3263 ··-·'"grub2-common"·in·ansible_facts.packages' 
3264 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3263 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3264 ··-·'"grub2-common"·in·ansible_facts.packages'
3265 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3265 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3266 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3266 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3267 ··tags:3267 ··tags:
3268 ··-·CJIS-5.5.2.23268 ··-·CJIS-5.5.2.2
3269 ··-·NIST-800-171-3.4.53269 ··-·NIST-800-171-3.4.5
3270 ··-·NIST-800-53-AC-6(1)3270 ··-·NIST-800-53-AC-6(1)
3271 ··-·NIST-800-53-CM-6(a)3271 ··-·NIST-800-53-CM-6(a)
Offset 3292, 16 lines modifiedOffset 3292, 16 lines modified
3292 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),3292 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),
3293 ············PR.AC-4,·PR.DS-5,·1.5.23293 ············PR.AC-4,·PR.DS-5,·1.5.2
3294 Remediation_Shell_script_⇲3294 Remediation_Shell_script_⇲
3295 Complexity:·low3295 Complexity:·low
3296 Disruption:·low3296 Disruption:·low
3297 Strategy:···configure3297 Strategy:···configure
3298 #·Remediation·is·applicable·only·in·certain·platforms3298 #·Remediation·is·applicable·only·in·certain·platforms
3299 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&3299 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/
3300 [·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3300 dev/null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3301 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg3301 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg
  
3302 else3302 else
3303 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3303 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3304 fi3304 fi
3305 Remediation_Ansible_snippet_⇲3305 Remediation_Ansible_snippet_⇲
Offset 3323, 16 lines modifiedOffset 3323, 16 lines modified
3323 ··-·no_reboot_needed3323 ··-·no_reboot_needed
  
3324 -·name:·Test·for·existence·/boot/grub/grub.cfg3324 -·name:·Test·for·existence·/boot/grub/grub.cfg
3325 ··stat:3325 ··stat:
3326 ····path:·/boot/grub/grub.cfg3326 ····path:·/boot/grub/grub.cfg
3327 ··register:·file_exists3327 ··register:·file_exists
3328 ··when:3328 ··when:
3329 ··-·'"grub2-common"·in·ansible_facts.packages' 
3330 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3329 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3330 ··-·'"grub2-common"·in·ansible_facts.packages'
3331 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3331 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3332 ··tags:3332 ··tags:
3333 ··-·NIST-800-171-3.4.53333 ··-·NIST-800-171-3.4.5
3334 ··-·NIST-800-53-AC-6(1)3334 ··-·NIST-800-53-AC-6(1)
3335 ··-·NIST-800-53-CM-6(a)3335 ··-·NIST-800-53-CM-6(a)
3336 ··-·configure_strategy3336 ··-·configure_strategy
3337 ··-·file_permissions_grub2_cfg3337 ··-·file_permissions_grub2_cfg
Offset 3342, 16 lines modifiedOffset 3342, 16 lines modified
3342 ··-·no_reboot_needed3342 ··-·no_reboot_needed
  
3343 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg3343 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
3344 ··file:3344 ··file:
3345 ····path:·/boot/grub/grub.cfg3345 ····path:·/boot/grub/grub.cfg
3346 ····mode:·u-xs,g-xwrs,o-xwrt3346 ····mode:·u-xs,g-xwrs,o-xwrt
3347 ··when:3347 ··when:
3348 ··-·'"grub2-common"·in·ansible_facts.packages' 
3349 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3348 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3349 ··-·'"grub2-common"·in·ansible_facts.packages'
3350 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3350 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3351 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3351 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3352 ··tags:3352 ··tags:
3353 ··-·NIST-800-171-3.4.53353 ··-·NIST-800-171-3.4.5
3354 ··-·NIST-800-53-AC-6(1)3354 ··-·NIST-800-53-AC-6(1)
3355 ··-·NIST-800-53-CM-6(a)3355 ··-·NIST-800-53-CM-6(a)
3356 ··-·configure_strategy3356 ··-·configure_strategy
Offset 10636, 14 lines modifiedOffset 10636, 30 lines modified
10636 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,10636 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,
10637 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,10637 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,
10638 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,10638 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,
10639 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR10639 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR
10640 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,10640 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,
10641 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,10641 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,
10642 ············2.2.310642 ············2.2.3
 10643 Remediation_OSBuild_Blueprint_snippet_⇲
  
 10644 [customizations.services]
 10645 disabled·=·["avahi-daemon"]
 10646 Remediation_Puppet_snippet_⇲
 10647 Complexity:·low
 10648 Disruption:·low
 10649 Strategy:···enable
 10650 include·disable_avahi-daemon
  
 10651 class·disable_avahi-daemon·{
 10652 ··service·{'avahi-daemon':
 10653 ····enable·=>·false,
 10654 ····ensure·=>·'stopped',
Max diff block lines reached; 2796/7875 bytes (35.50%) of diff not shown.
33.3 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_workstation.html
    
Offset 40057, 23 lines modifiedOffset 40057, 23 lines modified
0009c780:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0009c780:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0009c790:·7464·3e63·6f6e·6669·6775·7265·3c2f·7464··td>configure</td0009c790:·7464·3e63·6f6e·6669·6775·7265·3c2f·7464··td>configure</td
0009c7a0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0009c7a0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0009c7b0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed0009c7b0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
0009c7c0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic0009c7c0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
0009c7d0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer0009c7d0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
0009c7e0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i0009c7e0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 0009c7f0:·6620·5b20·2120·2d66·202f·7379·732f·6669··f·[·!·-f·/sys/fi
0009c7f0:·6620·6470·6b67·2d71·7565·7279·202d·2d73··f·dpkg-query·--s 
0009c800:·686f·7720·2d2d·7368·6f77·666f·726d·6174··how·--showformat 
0009c810:·3d27·247b·6462·3a53·7461·7475·732d·5374··='${db:Status-St 
0009c820:·6174·7573·7d5c·6e27·2027·6772·7562·322d··atus}\n'·'grub2- 
0009c830:·636f·6d6d·6f6e·2720·3226·6774·3b2f·6465··common'·2&gt;/de 
0009c840:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q 
0009c850:·2069·6e73·7461·6c6c·6564·2026·616d·703b···installed·&amp; 
0009c860:·2661·6d70·3b20·5b20·2120·2d66·202f·7379··&amp;·[·!·-f·/sy 
0009c870:·732f·6669·726d·7761·7265·2f65·6669·205d··s/firmware/efi·]0009c800:·726d·7761·7265·2f65·6669·205d·2026·616d··rmware/efi·]·&am
 0009c810:·703b·2661·6d70·3b20·6470·6b67·2d71·7565··p;&amp;·dpkg-que
 0009c820:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show
 0009c830:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta
 0009c840:·7475·732d·5374·6174·7573·7d5c·6e27·2027··tus-Status}\n'·'
 0009c850:·6772·7562·322d·636f·6d6d·6f6e·2720·3226··grub2-common'·2&
 0009c860:·6774·3b2f·6465·762f·6e75·6c6c·207c·2067··gt;/dev/null·|·g
 0009c870:·7265·7020·2d71·2069·6e73·7461·6c6c·6564··rep·-q·installed
0009c880:·2026·616d·703b·2661·6d70·3b20·7b20·5b20···&amp;&amp;·{·[·0009c880:·2026·616d·703b·2661·6d70·3b20·7b20·5b20···&amp;&amp;·{·[·
0009c890:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv0009c890:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
0009c8a0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·0009c8a0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
0009c8b0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta0009c8b0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
0009c8c0:·696e·6572·656e·7620·5d3b·207d·3b20·7468··inerenv·];·};·th0009c8c0:·696e·6572·656e·7620·5d3b·207d·3b20·7468··inerenv·];·};·th
0009c8d0:·656e·0a0a·6368·6f77·6e20·3020·2f62·6f6f··en..chown·0·/boo0009c8d0:·656e·0a0a·6368·6f77·6e20·3020·2f62·6f6f··en..chown·0·/boo
0009c8e0:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.0009c8e0:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.
Offset 40135, 22 lines modifiedOffset 40135, 22 lines modified
0009cc60:·5465·7374·2066·6f72·2065·7869·7374·656e··Test·for·existen0009cc60:·5465·7374·2066·6f72·2065·7869·7374·656e··Test·for·existen
0009cc70:·6365·202f·626f·6f74·2f67·7275·622f·6772··ce·/boot/grub/gr0009cc70:·6365·202f·626f·6f74·2f67·7275·622f·6772··ce·/boot/grub/gr
0009cc80:·7562·2e63·6667·0a20·2073·7461·743a·0a20··ub.cfg.··stat:.·0009cc80:·7562·2e63·6667·0a20·2073·7461·743a·0a20··ub.cfg.··stat:.·
0009cc90:·2020·2070·6174·683a·202f·626f·6f74·2f67·····path:·/boot/g0009cc90:·2020·2070·6174·683a·202f·626f·6f74·2f67·····path:·/boot/g
0009cca0:·7275·622f·6772·7562·2e63·6667·0a20·2072··rub/grub.cfg.··r0009cca0:·7275·622f·6772·7562·2e63·6667·0a20·2072··rub/grub.cfg.··r
0009ccb0:·6567·6973·7465·723a·2066·696c·655f·6578··egister:·file_ex0009ccb0:·6567·6973·7465·723a·2066·696c·655f·6578··egister:·file_ex
0009ccc0:·6973·7473·0a20·2077·6865·6e3a·0a20·202d··ists.··when:.··-0009ccc0:·6973·7473·0a20·2077·6865·6e3a·0a20·202d··ists.··when:.··-
 0009ccd0:·2027·222f·626f·6f74·2f65·6669·2220·6e6f···'"/boot/efi"·no
 0009cce0:·7420·696e·2061·6e73·6962·6c65·5f6d·6f75··t·in·ansible_mou
 0009ccf0:·6e74·7320·7c20·6d61·7028·6174·7472·6962··nts·|·map(attrib
0009ccd0:·2027·2267·7275·6232·2d63·6f6d·6d6f·6e22···'"grub2-common" 
0009cce0:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
0009ccf0:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-· 
0009cd00:·2722·2f62·6f6f·742f·6566·6922·206e·6f74··'"/boot/efi"·not 
0009cd10:·2069·6e20·616e·7369·626c·655f·6d6f·756e···in·ansible_moun 
0009cd20:·7473·207c·206d·6170·2861·7474·7269·6275··ts·|·map(attribu 
0009cd30:·7465·3d22·6d6f·756e·7422·2920·7c20·6c69··te="mount")·|·li0009cd00:·7574·653d·226d·6f75·6e74·2229·207c·206c··ute="mount")·|·l
 0009cd10:·6973·7427·0a20·202d·2027·2267·7275·6232··ist'.··-·'"grub2
 0009cd20:·2d63·6f6d·6d6f·6e22·2069·6e20·616e·7369··-common"·in·ansi
 0009cd30:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
0009cd40:·7374·270a·2020·2d20·616e·7369·626c·655f··st'.··-·ansible_0009cd40:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_
0009cd50:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t0009cd50:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
0009cd60:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc0009cd60:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
0009cd70:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op0009cd70:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
0009cd80:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",0009cd80:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
0009cd90:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··0009cd90:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
0009cda0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50009cda0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0009cdb0:·2e35·2e32·2e32·0a20·202d·204e·4953·542d··.5.2.2.··-·NIST-0009cdb0:·2e35·2e32·2e32·0a20·202d·204e·4953·542d··.5.2.2.··-·NIST-
Offset 40170, 22 lines modifiedOffset 40170, 22 lines modified
0009ce90:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure0009ce90:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure
0009cea0:·206f·776e·6572·2030·206f·6e20·2f62·6f6f···owner·0·on·/boo0009cea0:·206f·776e·6572·2030·206f·6e20·2f62·6f6f···owner·0·on·/boo
0009ceb0:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.0009ceb0:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.
0009cec0:·2020·6669·6c65·3a0a·2020·2020·7061·7468····file:.····path0009cec0:·2020·6669·6c65·3a0a·2020·2020·7061·7468····file:.····path
0009ced0:·3a20·2f62·6f6f·742f·6772·7562·2f67·7275··:·/boot/grub/gru0009ced0:·3a20·2f62·6f6f·742f·6772·7562·2f67·7275··:·/boot/grub/gru
0009cee0:·622e·6366·670a·2020·2020·6f77·6e65·723a··b.cfg.····owner:0009cee0:·622e·6366·670a·2020·2020·6f77·6e65·723a··b.cfg.····owner:
0009cef0:·2027·3027·0a20·2077·6865·6e3a·0a20·202d···'0'.··when:.··-0009cef0:·2027·3027·0a20·2077·6865·6e3a·0a20·202d···'0'.··when:.··-
 0009cf00:·2027·222f·626f·6f74·2f65·6669·2220·6e6f···'"/boot/efi"·no
 0009cf10:·7420·696e·2061·6e73·6962·6c65·5f6d·6f75··t·in·ansible_mou
 0009cf20:·6e74·7320·7c20·6d61·7028·6174·7472·6962··nts·|·map(attrib
0009cf00:·2027·2267·7275·6232·2d63·6f6d·6d6f·6e22···'"grub2-common" 
0009cf10:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
0009cf20:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-· 
0009cf30:·2722·2f62·6f6f·742f·6566·6922·206e·6f74··'"/boot/efi"·not 
0009cf40:·2069·6e20·616e·7369·626c·655f·6d6f·756e···in·ansible_moun 
0009cf50:·7473·207c·206d·6170·2861·7474·7269·6275··ts·|·map(attribu 
0009cf60:·7465·3d22·6d6f·756e·7422·2920·7c20·6c69··te="mount")·|·li0009cf30:·7574·653d·226d·6f75·6e74·2229·207c·206c··ute="mount")·|·l
 0009cf40:·6973·7427·0a20·202d·2027·2267·7275·6232··ist'.··-·'"grub2
 0009cf50:·2d63·6f6d·6d6f·6e22·2069·6e20·616e·7369··-common"·in·ansi
 0009cf60:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
0009cf70:·7374·270a·2020·2d20·616e·7369·626c·655f··st'.··-·ansible_0009cf70:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_
0009cf80:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t0009cf80:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
0009cf90:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc0009cf90:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
0009cfa0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op0009cfa0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
0009cfb0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",0009cfb0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
0009cfc0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··0009cfc0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
0009cfd0:·2d20·6669·6c65·5f65·7869·7374·732e·7374··-·file_exists.st0009cfd0:·2d20·6669·6c65·5f65·7869·7374·732e·7374··-·file_exists.st
0009cfe0:·6174·2069·7320·6465·6669·6e65·6420·616e··at·is·defined·an0009cfe0:·6174·2069·7320·6465·6669·6e65·6420·616e··at·is·defined·an
Offset 40627, 24 lines modifiedOffset 40627, 24 lines modified
0009eb20:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0009eb20:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0009eb30:·683e·3c74·643e·636f·6e66·6967·7572·653c··h><td>configure<0009eb30:·683e·3c74·643e·636f·6e66·6967·7572·653c··h><td>configure<
0009eb40:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0009eb40:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0009eb50:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re0009eb50:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
0009eb60:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app0009eb60:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
0009eb70:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·0009eb70:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
0009eb80:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform0009eb80:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0009eb90:·730a·6966·205b·2021·202d·6620·2f73·7973··s.if·[·!·-f·/sys
0009eb90:·730a·6966·2064·706b·672d·7175·6572·7920··s.if·dpkg-query· 
0009eba0:·2d2d·7368·6f77·202d·2d73·686f·7766·6f72··--show·--showfor 
0009ebb0:·6d61·743d·2724·7b64·623a·5374·6174·7573··mat='${db:Status 
0009ebc0:·2d53·7461·7475·737d·5c6e·2720·2767·7275··-Status}\n'·'gru 
0009ebd0:·6232·2d63·6f6d·6d6f·6e27·2032·2667·743b··b2-common'·2&gt; 
0009ebe0:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep 
0009ebf0:·202d·7120·696e·7374·616c·6c65·6420·2661···-q·installed·&a 
0009ec00:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
0009ec10:·2f73·7973·2f66·6972·6d77·6172·652f·6566··/sys/firmware/ef0009eba0:·2f66·6972·6d77·6172·652f·6566·6920·5d20··/firmware/efi·]·
 0009ebb0:·2661·6d70·3b26·616d·703b·2064·706b·672d··&amp;&amp;·dpkg-
 0009ebc0:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s
 0009ebd0:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db:
 0009ebe0:·5374·6174·7573·2d53·7461·7475·737d·5c6e··Status-Status}\n
 0009ebf0:·2720·2767·7275·6232·2d63·6f6d·6d6f·6e27··'·'grub2-common'
 0009ec00:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null·
 0009ec10:·7c20·6772·6570·202d·7120·696e·7374·616c··|·grep·-q·instal
0009ec20:·6920·5d20·2661·6d70·3b26·616d·703b·207b··i·]·&amp;&amp;·{0009ec20:·6c65·6420·2661·6d70·3b26·616d·703b·207b··led·&amp;&amp;·{
0009ec30:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker0009ec30:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
0009ec40:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;0009ec40:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
0009ec50:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co0009ec50:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
0009ec60:·6e74·6169·6e65·7265·6e76·205d·3b20·7d3b··ntainerenv·];·};0009ec60:·6e74·6169·6e65·7265·6e76·205d·3b20·7d3b··ntainerenv·];·};
0009ec70:·2074·6865·6e0a·0a63·686d·6f64·2075·2d78···then..chmod·u-x0009ec70:·2074·6865·6e0a·0a63·686d·6f64·2075·2d78···then..chmod·u-x
0009ec80:·732c·672d·7877·7273·2c6f·2d78·7772·7420··s,g-xwrs,o-xwrt·0009ec80:·732c·672d·7877·7273·2c6f·2d78·7772·7420··s,g-xwrs,o-xwrt·
0009ec90:·2f62·6f6f·742f·6772·7562·2f67·7275·622e··/boot/grub/grub.0009ec90:·2f62·6f6f·742f·6772·7562·2f67·7275·622e··/boot/grub/grub.
Offset 40704, 22 lines modifiedOffset 40704, 22 lines modified
0009eff0:·616d·653a·2054·6573·7420·666f·7220·6578··ame:·Test·for·ex0009eff0:·616d·653a·2054·6573·7420·666f·7220·6578··ame:·Test·for·ex
0009f000:·6973·7465·6e63·6520·2f62·6f6f·742f·6772··istence·/boot/gr0009f000:·6973·7465·6e63·6520·2f62·6f6f·742f·6772··istence·/boot/gr
0009f010:·7562·2f67·7275·622e·6366·670a·2020·7374··ub/grub.cfg.··st0009f010:·7562·2f67·7275·622e·6366·670a·2020·7374··ub/grub.cfg.··st
0009f020:·6174·3a0a·2020·2020·7061·7468·3a20·2f62··at:.····path:·/b0009f020:·6174·3a0a·2020·2020·7061·7468·3a20·2f62··at:.····path:·/b
Max diff block lines reached; 18753/27922 bytes (67.16%) of diff not shown.
5.84 KB
html2text {}
    
Offset 3439, 16 lines modifiedOffset 3439, 16 lines modified
3439 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,3439 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,
3440 ············Req-7.1,·1.5.23440 ············Req-7.1,·1.5.2
3441 Remediation_Shell_script_⇲3441 Remediation_Shell_script_⇲
3442 Complexity:·low3442 Complexity:·low
3443 Disruption:·low3443 Disruption:·low
3444 Strategy:···configure3444 Strategy:···configure
3445 #·Remediation·is·applicable·only·in·certain·platforms3445 #·Remediation·is·applicable·only·in·certain·platforms
3446 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&·[·!3446 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/
3447 -f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3447 null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3448 chown·0·/boot/grub/grub.cfg3448 chown·0·/boot/grub/grub.cfg
  
3449 else3449 else
3450 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3450 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3451 fi3451 fi
3452 Remediation_Ansible_snippet_⇲3452 Remediation_Ansible_snippet_⇲
Offset 3472, 16 lines modifiedOffset 3472, 16 lines modified
3472 ··-·no_reboot_needed3472 ··-·no_reboot_needed
  
3473 -·name:·Test·for·existence·/boot/grub/grub.cfg3473 -·name:·Test·for·existence·/boot/grub/grub.cfg
3474 ··stat:3474 ··stat:
3475 ····path:·/boot/grub/grub.cfg3475 ····path:·/boot/grub/grub.cfg
3476 ··register:·file_exists3476 ··register:·file_exists
3477 ··when:3477 ··when:
3478 ··-·'"grub2-common"·in·ansible_facts.packages' 
3479 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3478 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3479 ··-·'"grub2-common"·in·ansible_facts.packages'
3480 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3480 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3481 ··tags:3481 ··tags:
3482 ··-·CJIS-5.5.2.23482 ··-·CJIS-5.5.2.2
3483 ··-·NIST-800-171-3.4.53483 ··-·NIST-800-171-3.4.5
3484 ··-·NIST-800-53-AC-6(1)3484 ··-·NIST-800-53-AC-6(1)
3485 ··-·NIST-800-53-CM-6(a)3485 ··-·NIST-800-53-CM-6(a)
3486 ··-·PCI-DSS-Req-7.13486 ··-·PCI-DSS-Req-7.1
Offset 3493, 16 lines modifiedOffset 3493, 16 lines modified
3493 ··-·no_reboot_needed3493 ··-·no_reboot_needed
  
3494 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg3494 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
3495 ··file:3495 ··file:
3496 ····path:·/boot/grub/grub.cfg3496 ····path:·/boot/grub/grub.cfg
3497 ····owner:·'0'3497 ····owner:·'0'
3498 ··when:3498 ··when:
3499 ··-·'"grub2-common"·in·ansible_facts.packages' 
3500 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3499 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3500 ··-·'"grub2-common"·in·ansible_facts.packages'
3501 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3501 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3502 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3502 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3503 ··tags:3503 ··tags:
3504 ··-·CJIS-5.5.2.23504 ··-·CJIS-5.5.2.2
3505 ··-·NIST-800-171-3.4.53505 ··-·NIST-800-171-3.4.5
3506 ··-·NIST-800-53-AC-6(1)3506 ··-·NIST-800-53-AC-6(1)
3507 ··-·NIST-800-53-CM-6(a)3507 ··-·NIST-800-53-CM-6(a)
Offset 3528, 16 lines modifiedOffset 3528, 16 lines modified
3528 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),3528 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),
3529 ············PR.AC-4,·PR.DS-5,·1.5.23529 ············PR.AC-4,·PR.DS-5,·1.5.2
3530 Remediation_Shell_script_⇲3530 Remediation_Shell_script_⇲
3531 Complexity:·low3531 Complexity:·low
3532 Disruption:·low3532 Disruption:·low
3533 Strategy:···configure3533 Strategy:···configure
3534 #·Remediation·is·applicable·only·in·certain·platforms3534 #·Remediation·is·applicable·only·in·certain·platforms
3535 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&3535 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/
3536 [·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3536 dev/null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3537 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg3537 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg
  
3538 else3538 else
3539 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3539 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3540 fi3540 fi
3541 Remediation_Ansible_snippet_⇲3541 Remediation_Ansible_snippet_⇲
Offset 3559, 16 lines modifiedOffset 3559, 16 lines modified
3559 ··-·no_reboot_needed3559 ··-·no_reboot_needed
  
3560 -·name:·Test·for·existence·/boot/grub/grub.cfg3560 -·name:·Test·for·existence·/boot/grub/grub.cfg
3561 ··stat:3561 ··stat:
3562 ····path:·/boot/grub/grub.cfg3562 ····path:·/boot/grub/grub.cfg
3563 ··register:·file_exists3563 ··register:·file_exists
3564 ··when:3564 ··when:
3565 ··-·'"grub2-common"·in·ansible_facts.packages' 
3566 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3565 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3566 ··-·'"grub2-common"·in·ansible_facts.packages'
3567 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3567 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3568 ··tags:3568 ··tags:
3569 ··-·NIST-800-171-3.4.53569 ··-·NIST-800-171-3.4.5
3570 ··-·NIST-800-53-AC-6(1)3570 ··-·NIST-800-53-AC-6(1)
3571 ··-·NIST-800-53-CM-6(a)3571 ··-·NIST-800-53-CM-6(a)
3572 ··-·configure_strategy3572 ··-·configure_strategy
3573 ··-·file_permissions_grub2_cfg3573 ··-·file_permissions_grub2_cfg
Offset 3578, 16 lines modifiedOffset 3578, 16 lines modified
3578 ··-·no_reboot_needed3578 ··-·no_reboot_needed
  
3579 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg3579 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
3580 ··file:3580 ··file:
3581 ····path:·/boot/grub/grub.cfg3581 ····path:·/boot/grub/grub.cfg
3582 ····mode:·u-xs,g-xwrs,o-xwrt3582 ····mode:·u-xs,g-xwrs,o-xwrt
3583 ··when:3583 ··when:
3584 ··-·'"grub2-common"·in·ansible_facts.packages' 
3585 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3584 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3585 ··-·'"grub2-common"·in·ansible_facts.packages'
3586 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3586 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3587 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3587 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3588 ··tags:3588 ··tags:
3589 ··-·NIST-800-171-3.4.53589 ··-·NIST-800-171-3.4.5
3590 ··-·NIST-800-53-AC-6(1)3590 ··-·NIST-800-53-AC-6(1)
3591 ··-·NIST-800-53-CM-6(a)3591 ··-·NIST-800-53-CM-6(a)
3592 ··-·configure_strategy3592 ··-·configure_strategy
Offset 10544, 14 lines modifiedOffset 10544, 30 lines modified
10544 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,10544 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,
10545 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,10545 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,
10546 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,10546 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,
10547 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR10547 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR
10548 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,10548 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,
10549 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,10549 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,
10550 ············2.2.310550 ············2.2.3
 10551 Remediation_OSBuild_Blueprint_snippet_⇲
  
 10552 [customizations.services]
 10553 disabled·=·["avahi-daemon"]
 10554 Remediation_Puppet_snippet_⇲
 10555 Complexity:·low
 10556 Disruption:·low
 10557 Strategy:···enable
 10558 include·disable_avahi-daemon
  
 10559 class·disable_avahi-daemon·{
 10560 ··service·{'avahi-daemon':
 10561 ····enable·=>·false,
 10562 ····ensure·=>·'stopped',
Max diff block lines reached; 877/5956 bytes (14.72%) of diff not shown.
765 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_server.html
    
Offset 41121, 25 lines modifiedOffset 41121, 25 lines modified
000a0a00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000a0a00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
000a0a10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i000a0a10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
000a0a20:·643d·2269·646d·3132·3637·3822·3e3c·7072··d="idm12678"><pr000a0a20:·643d·2269·646d·3132·3637·3822·3e3c·7072··d="idm12678"><pr
000a0a30:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi000a0a30:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
000a0a40:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica000a0a40:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
000a0a50:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert000a0a50:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
000a0a60:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if000a0a60:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 000a0a70:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh
 000a0a80:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat=
 000a0a90:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta
 000a0aa0:·7475·737d·5c6e·2720·2761·7564·6974·6427··tus}\n'·'auditd'
 000a0ab0:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null·
 000a0ac0:·7c20·6772·6570·202d·7120·696e·7374·616c··|·grep·-q·instal
 000a0ad0:·6c65·6420·2661·6d70·3b26·616d·703b·205b··led·&amp;&amp;·[
000a0a70:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker000a0ae0:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
000a0a80:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;000a0af0:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
000a0a90:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co000a0b00:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
000a0aa0:·6e74·6169·6e65·7265·6e76·205d·2026·616d··ntainerenv·]·&am000a0b10:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
000a0ab0:·703b·2661·6d70·3b20·6470·6b67·2d71·7565··p;&amp;·dpkg-que 
000a0ac0:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show 
000a0ad0:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta 
000a0ae0:·7475·732d·5374·6174·7573·7d5c·6e27·2027··tus-Status}\n'·' 
000a0af0:·6175·6469·7464·2720·3226·6774·3b2f·6465··auditd'·2&gt;/de 
000a0b00:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q 
000a0b10:·2069·6e73·7461·6c6c·6564·3b20·7468·656e···installed;·then 
000a0b20:·0a0a·2320·4669·7273·7420·7065·7266·6f72··..#·First·perfor000a0b20:·0a0a·2320·4669·7273·7420·7065·7266·6f72··..#·First·perfor
000a0b30:·6d20·7468·6520·7265·6d65·6469·6174·696f··m·the·remediatio000a0b30:·6d20·7468·6520·7265·6d65·6469·6174·696f··m·the·remediatio
000a0b40:·6e20·6f66·2074·6865·2073·7973·6361·6c6c··n·of·the·syscall000a0b40:·6e20·6f66·2074·6865·2073·7973·6361·6c6c··n·of·the·syscall
000a0b50:·2072·756c·650a·2320·5265·7472·6965·7665···rule.#·Retrieve000a0b50:·2072·756c·650a·2320·5265·7472·6965·7665···rule.#·Retrieve
000a0b60:·2068·6172·6477·6172·6520·6172·6368·6974···hardware·archit000a0b60:·2068·6172·6477·6172·6520·6172·6368·6974···hardware·archit
000a0b70:·6563·7475·7265·206f·6620·7468·6520·756e··ecture·of·the·un000a0b70:·6563·7475·7265·206f·6620·7468·6520·756e··ecture·of·the·un
000a0b80:·6465·726c·7969·6e67·2073·7973·7465·6d0a··derlying·system.000a0b80:·6465·726c·7969·6e67·2073·7973·7465·6d0a··derlying·system.
Offset 42019, 23 lines modifiedOffset 42019, 23 lines modified
000a4220:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest000a4220:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest
000a4230:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-000a4230:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-
000a4240:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi000a4240:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi
000a4250:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi000a4250:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi
000a4260:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··000a4260:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··
000a4270:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au000a4270:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au
000a4280:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··000a4280:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··
000a4290:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl000a4290:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi
000a42a0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
000a42b0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
000a42c0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
000a42d0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
000a42e0:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"]. 
000a42f0:·2020·2d20·2722·6175·6469·7464·2220·696e····-·'"auditd"·in 
000a4300:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p 
000a4310:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans000a42a0:·7464·2220·696e·2061·6e73·6962·6c65·5f66··td"·in·ansible_f
 000a42b0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·
 000a42c0:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu
 000a42d0:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 000a42e0:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 000a42f0:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 000a4300:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 000a4310:·7461·696e·6572·225d·0a20·202d·2061·6e73··tainer"].··-·ans
000a4320:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur000a4320:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
000a4330:·6520·3d3d·2022·6161·7263·6836·3422·206f··e·==·"aarch64"·o000a4330:·6520·3d3d·2022·6161·7263·6836·3422·206f··e·==·"aarch64"·o
000a4340:·7220·616e·7369·626c·655f·6172·6368·6974··r·ansible_archit000a4340:·7220·616e·7369·626c·655f·6172·6368·6974··r·ansible_archit
000a4350:·6563·7475·7265·203d·3d20·2270·7063·3634··ecture·==·"ppc64000a4350:·6563·7475·7265·203d·3d20·2270·7063·3634··ecture·==·"ppc64
000a4360:·2220·6f72·2061·6e73·6962·6c65·5f61·7263··"·or·ansible_arc000a4360:·2220·6f72·2061·6e73·6962·6c65·5f61·7263··"·or·ansible_arc
000a4370:·6869·7465·6374·7572·650a·2020·2020·3d3d··hitecture.····==000a4370:·6869·7465·6374·7572·650a·2020·2020·3d3d··hitecture.····==
000a4380:·2022·7070·6336·346c·6522·206f·7220·616e···"ppc64le"·or·an000a4380:·2022·7070·6336·346c·6522·206f·7220·616e···"ppc64le"·or·an
Offset 42342, 23 lines modifiedOffset 42342, 23 lines modified
000a5650:·202d·4620·6b65·793d·7065·726d·5f6d·6f64···-F·key=perm_mod000a5650:·202d·4620·6b65·793d·7065·726d·5f6d·6f64···-F·key=perm_mod
000a5660:·0a20·2020·2020·2063·7265·6174·653a·2074··.······create:·t000a5660:·0a20·2020·2020·2063·7265·6174·653a·2074··.······create:·t
000a5670:·7275·650a·2020·2020·2020·6d6f·6465·3a20··rue.······mode:·000a5670:·7275·650a·2020·2020·2020·6d6f·6465·3a20··rue.······mode:·
000a5680:·6f2d·7277·780a·2020·2020·2020·7374·6174··o-rwx.······stat000a5680:·6f2d·7277·780a·2020·2020·2020·7374·6174··o-rwx.······stat
000a5690:·653a·2070·7265·7365·6e74·0a20·2020·2077··e:·present.····w000a5690:·653a·2070·7265·7365·6e74·0a20·2020·2077··e:·present.····w
000a56a0:·6865·6e3a·2073·7973·6361·6c6c·735f·666f··hen:·syscalls_fo000a56a0:·6865·6e3a·2073·7973·6361·6c6c·735f·666f··hen:·syscalls_fo
000a56b0:·756e·6420·7c20·6c65·6e67·7468·203d·3d20··und·|·length·==·000a56b0:·756e·6420·7c20·6c65·6e67·7468·203d·3d20··und·|·length·==·
000a56c0:·300a·2020·7768·656e·3a0a·2020·2d20·616e··0.··when:.··-·an000a56c0:·300a·2020·7768·656e·3a0a·2020·2d20·2722··0.··when:.··-·'"
000a56d0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
000a56e0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
000a56f0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
000a5700:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
000a5710:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe 
000a5720:·7222·5d0a·2020·2d20·2722·6175·6469·7464··r"].··-·'"auditd 
000a5730:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
000a5740:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t000a56d0:·6175·6469·7464·2220·696e·2061·6e73·6962··auditd"·in·ansib
 000a56e0:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
 000a56f0:·7327·0a20·202d·2061·6e73·6962·6c65·5f76··s'.··-·ansible_v
 000a5700:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 000a5710:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 000a5720:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 000a5730:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 000a5740:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t
000a5750:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.000a5750:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5.
000a5760:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S000a5760:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S
000a5770:·5449·472d·5542·5455·2d32·302d·3031·3031··TIG-UBTU-20-0101000a5770:·5449·472d·5542·5455·2d32·302d·3031·3031··TIG-UBTU-20-0101
000a5780:·3532·0a20·202d·204e·4953·542d·3830·302d··52.··-·NIST-800-000a5780:·3532·0a20·202d·204e·4953·542d·3830·302d··52.··-·NIST-800-
000a5790:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI000a5790:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI
000a57a0:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(000a57a0:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(
000a57b0:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-000a57b0:·6329·0a20·202d·204e·4953·542d·3830·302d··c).··-·NIST-800-
Offset 42654, 23 lines modifiedOffset 42654, 23 lines modified
000a69d0:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····000a69d0:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····
000a69e0:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·000a69e0:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·
000a69f0:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx000a69f0:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx
000a6a00:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr000a6a00:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr
000a6a10:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·000a6a10:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·
000a6a20:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|000a6a20:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|
000a6a30:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w000a6a30:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w
000a6a40:·6865·6e3a·0a20·202d·2061·6e73·6962·6c65··hen:.··-·ansible000a6a40:·6865·6e3a·0a20·202d·2027·2261·7564·6974··hen:.··-·'"audit
000a6a50:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
000a6a60:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
000a6a70:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
000a6a80:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
000a6a90:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].· 
000a6aa0:·202d·2027·2261·7564·6974·6422·2069·6e20···-·'"auditd"·in· 
000a6ab0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa000a6a50:·6422·2069·6e20·616e·7369·626c·655f·6661··d"·in·ansible_fa
 000a6a60:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
 000a6a70:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
 000a6a80:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
 000a6a90:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
 000a6aa0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
 000a6ab0:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
000a6ac0:·636b·6167·6573·270a·2020·2d20·6175·6469··ckages'.··-·audi000a6ac0:·6169·6e65·7222·5d0a·2020·2d20·6175·6469··ainer"].··-·audi
000a6ad0:·745f·6172·6368·203d·3d20·2262·3634·220a··t_arch·==·"b64".000a6ad0:·745f·6172·6368·203d·3d20·2262·3634·220a··t_arch·==·"b64".
000a6ae0:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS000a6ae0:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS
000a6af0:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS000a6af0:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS
000a6b00:·412d·5354·4947·2d55·4254·552d·3230·2d30··A-STIG-UBTU-20-0000a6b00:·412d·5354·4947·2d55·4254·552d·3230·2d30··A-STIG-UBTU-20-0
000a6b10:·3130·3135·320a·2020·2d20·4e49·5354·2d38··10152.··-·NIST-8000a6b10:·3130·3135·320a·2020·2d20·4e49·5354·2d38··10152.··-·NIST-8
000a6b20:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-000a6b20:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-
000a6b30:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-000a6b30:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
Offset 43622, 25 lines modifiedOffset 43622, 25 lines modified
000aa650:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla000aa650:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
000aa660:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id000aa660:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
Max diff block lines reached; 580365/589810 bytes (98.40%) of diff not shown.
189 KB
html2text {}
    
Offset 3389, 16 lines modifiedOffset 3389, 16 lines modified
3389 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,3389 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,
3390 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-3390 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-
3391 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-3391 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-
3392 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,3392 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,
3393 ············SRG-OS-000474-VMM-001940,·UBTU-20-010152,·4.1.93393 ············SRG-OS-000474-VMM-001940,·UBTU-20-010152,·4.1.9
3394 Remediation_Shell_script_⇲3394 Remediation_Shell_script_⇲
3395 #·Remediation·is·applicable·only·in·certain·platforms3395 #·Remediation·is·applicable·only·in·certain·platforms
3396 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·dpkg-query·--show·--showformat='${db:Status- 
3397 Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed;·then3396 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed·&&·[·!·-
 3397 f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
3398 #·First·perform·the·remediation·of·the·syscall·rule3398 #·First·perform·the·remediation·of·the·syscall·rule
3399 #·Retrieve·hardware·architecture·of·the·underlying·system3399 #·Retrieve·hardware·architecture·of·the·underlying·system
3400 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3400 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3401 for·ARCH·in·"${RULE_ARCHS[@]}"3401 for·ARCH·in·"${RULE_ARCHS[@]}"
3402 do3402 do
Offset 3754, 16 lines modifiedOffset 3754, 16 lines modified
3754 ··-·reboot_required3754 ··-·reboot_required
3755 ··-·restrict_strategy3755 ··-·restrict_strategy
  
3756 -·name:·Set·architecture·for·audit·chmod·tasks3756 -·name:·Set·architecture·for·audit·chmod·tasks
3757 ··set_fact:3757 ··set_fact:
3758 ····audit_arch:·b643758 ····audit_arch:·b64
3759 ··when:3759 ··when:
3760 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3761 ··-·'"auditd"·in·ansible_facts.packages'3760 ··-·'"auditd"·in·ansible_facts.packages'
 3761 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3762 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3762 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3763 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3763 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3764 ··tags:3764 ··tags:
3765 ··-·CJIS-5.4.1.13765 ··-·CJIS-5.4.1.1
3766 ··-·DISA-STIG-UBTU-20-0101523766 ··-·DISA-STIG-UBTU-20-010152
3767 ··-·NIST-800-171-3.1.73767 ··-·NIST-800-171-3.1.7
3768 ··-·NIST-800-53-AU-12(c)3768 ··-·NIST-800-53-AU-12(c)
Offset 3900, 16 lines modifiedOffset 3900, 16 lines modified
3900 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003900 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3901 ········-F·auid!=unset·-F·key=perm_mod3901 ········-F·auid!=unset·-F·key=perm_mod
3902 ······create:·true3902 ······create:·true
3903 ······mode:·o-rwx3903 ······mode:·o-rwx
3904 ······state:·present3904 ······state:·present
3905 ····when:·syscalls_found·|·length·==·03905 ····when:·syscalls_found·|·length·==·0
3906 ··when:3906 ··when:
3907 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3908 ··-·'"auditd"·in·ansible_facts.packages'3907 ··-·'"auditd"·in·ansible_facts.packages'
 3908 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3909 ··tags:3909 ··tags:
3910 ··-·CJIS-5.4.1.13910 ··-·CJIS-5.4.1.1
3911 ··-·DISA-STIG-UBTU-20-0101523911 ··-·DISA-STIG-UBTU-20-010152
3912 ··-·NIST-800-171-3.1.73912 ··-·NIST-800-171-3.1.7
3913 ··-·NIST-800-53-AU-12(c)3913 ··-·NIST-800-53-AU-12(c)
3914 ··-·NIST-800-53-AU-2(d)3914 ··-·NIST-800-53-AU-2(d)
3915 ··-·NIST-800-53-CM-6(a)3915 ··-·NIST-800-53-CM-6(a)
Offset 4044, 16 lines modifiedOffset 4044, 16 lines modified
4044 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004044 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4045 ········-F·auid!=unset·-F·key=perm_mod4045 ········-F·auid!=unset·-F·key=perm_mod
4046 ······create:·true4046 ······create:·true
4047 ······mode:·o-rwx4047 ······mode:·o-rwx
4048 ······state:·present4048 ······state:·present
4049 ····when:·syscalls_found·|·length·==·04049 ····when:·syscalls_found·|·length·==·0
4050 ··when:4050 ··when:
4051 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4052 ··-·'"auditd"·in·ansible_facts.packages'4051 ··-·'"auditd"·in·ansible_facts.packages'
 4052 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4053 ··-·audit_arch·==·"b64"4053 ··-·audit_arch·==·"b64"
4054 ··tags:4054 ··tags:
4055 ··-·CJIS-5.4.1.14055 ··-·CJIS-5.4.1.1
4056 ··-·DISA-STIG-UBTU-20-0101524056 ··-·DISA-STIG-UBTU-20-010152
4057 ··-·NIST-800-171-3.1.74057 ··-·NIST-800-171-3.1.7
4058 ··-·NIST-800-53-AU-12(c)4058 ··-·NIST-800-53-AU-12(c)
4059 ··-·NIST-800-53-AU-2(d)4059 ··-·NIST-800-53-AU-2(d)
Offset 4099, 16 lines modifiedOffset 4099, 16 lines modified
4099 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,4099 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,
4100 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-4100 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-
4101 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-4101 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-
4102 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,4102 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,
4103 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·UBTU-20-010148,·4.1.94103 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·UBTU-20-010148,·4.1.9
4104 Remediation_Shell_script_⇲4104 Remediation_Shell_script_⇲
4105 #·Remediation·is·applicable·only·in·certain·platforms4105 #·Remediation·is·applicable·only·in·certain·platforms
4106 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·dpkg-query·--show·--showformat='${db:Status- 
4107 Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed;·then4106 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed·&&·[·!·-
 4107 f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
4108 #·First·perform·the·remediation·of·the·syscall·rule4108 #·First·perform·the·remediation·of·the·syscall·rule
4109 #·Retrieve·hardware·architecture·of·the·underlying·system4109 #·Retrieve·hardware·architecture·of·the·underlying·system
4110 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4110 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4111 for·ARCH·in·"${RULE_ARCHS[@]}"4111 for·ARCH·in·"${RULE_ARCHS[@]}"
4112 do4112 do
Offset 4464, 16 lines modifiedOffset 4464, 16 lines modified
4464 ··-·reboot_required4464 ··-·reboot_required
4465 ··-·restrict_strategy4465 ··-·restrict_strategy
  
4466 -·name:·Set·architecture·for·audit·chown·tasks4466 -·name:·Set·architecture·for·audit·chown·tasks
4467 ··set_fact:4467 ··set_fact:
4468 ····audit_arch:·b644468 ····audit_arch:·b64
4469 ··when:4469 ··when:
4470 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4471 ··-·'"auditd"·in·ansible_facts.packages'4470 ··-·'"auditd"·in·ansible_facts.packages'
 4471 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4472 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4472 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4473 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4473 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4474 ··tags:4474 ··tags:
4475 ··-·CJIS-5.4.1.14475 ··-·CJIS-5.4.1.1
4476 ··-·DISA-STIG-UBTU-20-0101484476 ··-·DISA-STIG-UBTU-20-010148
4477 ··-·NIST-800-171-3.1.74477 ··-·NIST-800-171-3.1.7
4478 ··-·NIST-800-53-AU-12(c)4478 ··-·NIST-800-53-AU-12(c)
Offset 4612, 16 lines modifiedOffset 4612, 16 lines modified
4612 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004612 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4613 ········-F·auid!=unset·-F·key=perm_mod4613 ········-F·auid!=unset·-F·key=perm_mod
4614 ······create:·true4614 ······create:·true
4615 ······mode:·o-rwx4615 ······mode:·o-rwx
4616 ······state:·present4616 ······state:·present
4617 ····when:·syscalls_found·|·length·==·04617 ····when:·syscalls_found·|·length·==·0
4618 ··when:4618 ··when:
4619 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4620 ··-·'"auditd"·in·ansible_facts.packages'4619 ··-·'"auditd"·in·ansible_facts.packages'
 4620 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4621 ··tags:4621 ··tags:
4622 ··-·CJIS-5.4.1.14622 ··-·CJIS-5.4.1.1
4623 ··-·DISA-STIG-UBTU-20-0101484623 ··-·DISA-STIG-UBTU-20-010148
4624 ··-·NIST-800-171-3.1.74624 ··-·NIST-800-171-3.1.7
4625 ··-·NIST-800-53-AU-12(c)4625 ··-·NIST-800-53-AU-12(c)
4626 ··-·NIST-800-53-AU-2(d)4626 ··-·NIST-800-53-AU-2(d)
4627 ··-·NIST-800-53-CM-6(a)4627 ··-·NIST-800-53-CM-6(a)
Offset 4758, 16 lines modifiedOffset 4758, 16 lines modified
4758 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004758 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
Max diff block lines reached; 188110/193881 bytes (97.02%) of diff not shown.
767 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_workstation.html
    
Offset 42689, 26 lines modifiedOffset 42689, 26 lines modified
000a6c00:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan000a6c00:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
000a6c10:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll000a6c10:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
000a6c20:·6170·7365·2220·6964·3d22·6964·6d31·3236··apse"·id="idm126000a6c20:·6170·7365·2220·6964·3d22·6964·6d31·3236··apse"·id="idm126
000a6c30:·3738·223e·3c70·7265·3e3c·636f·6465·3e23··78"><pre><code>#000a6c30:·3738·223e·3c70·7265·3e3c·636f·6465·3e23··78"><pre><code>#
000a6c40:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·000a6c40:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
000a6c50:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·000a6c50:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
000a6c60:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf000a6c60:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
000a6c70:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
000a6c80:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am000a6c70:·6f72·6d73·0a69·6620·6470·6b67·2d71·7565··orms.if·dpkg-que
 000a6c80:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show
 000a6c90:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta
 000a6ca0:·7475·732d·5374·6174·7573·7d5c·6e27·2027··tus-Status}\n'·'
 000a6cb0:·6175·6469·7464·2720·3226·6774·3b2f·6465··auditd'·2&gt;/de
 000a6cc0:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q
 000a6cd0:·2069·6e73·7461·6c6c·6564·2026·616d·703b···installed·&amp;
000a6c90:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/000a6ce0:·2661·6d70·3b20·5b20·2120·2d66·202f·2e64··&amp;·[·!·-f·/.d
 000a6cf0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;
 000a6d00:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru
000a6ca0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren000a6d10:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·
000a6cb0:·7620·5d20·2661·6d70·3b26·616d·703b·2064··v·]·&amp;&amp;·d 
000a6cc0:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show 
000a6cd0:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$ 
000a6ce0:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu 
000a6cf0:·737d·5c6e·2720·2761·7564·6974·6427·2032··s}\n'·'auditd'·2 
000a6d00:·2667·743b·2f64·6576·2f6e·756c·6c20·7c20··&gt;/dev/null·|· 
000a6d10:·6772·6570·202d·7120·696e·7374·616c·6c65··grep·-q·installe 
000a6d20:·643b·2074·6865·6e0a·0a23·2046·6972·7374··d;·then..#·First000a6d20:·5d3b·2074·6865·6e0a·0a23·2046·6972·7374··];·then..#·First
000a6d30:·2070·6572·666f·726d·2074·6865·2072·656d···perform·the·rem000a6d30:·2070·6572·666f·726d·2074·6865·2072·656d···perform·the·rem
000a6d40:·6564·6961·7469·6f6e·206f·6620·7468·6520··ediation·of·the·000a6d40:·6564·6961·7469·6f6e·206f·6620·7468·6520··ediation·of·the·
000a6d50:·7379·7363·616c·6c20·7275·6c65·0a23·2052··syscall·rule.#·R000a6d50:·7379·7363·616c·6c20·7275·6c65·0a23·2052··syscall·rule.#·R
000a6d60:·6574·7269·6576·6520·6861·7264·7761·7265··etrieve·hardware000a6d60:·6574·7269·6576·6520·6861·7264·7761·7265··etrieve·hardware
000a6d70:·2061·7263·6869·7465·6374·7572·6520·6f66···architecture·of000a6d70:·2061·7263·6869·7465·6374·7572·6520·6f66···architecture·of
000a6d80:·2074·6865·2075·6e64·6572·6c79·696e·6720···the·underlying·000a6d80:·2074·6865·2075·6e64·6572·6c79·696e·6720···the·underlying·
000a6d90:·7379·7374·656d·0a5b·2022·2428·6765·7463··system.[·"$(getc000a6d90:·7379·7374·656d·0a5b·2022·2428·6765·7463··system.[·"$(getc
Offset 43588, 22 lines modifiedOffset 43588, 22 lines modified
000aa430:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra000aa430:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra
000aa440:·7465·6779·0a0a·2d20·6e61·6d65·3a20·5365··tegy..-·name:·Se000aa440:·7465·6779·0a0a·2d20·6e61·6d65·3a20·5365··tegy..-·name:·Se
000aa450:·7420·6172·6368·6974·6563·7475·7265·2066··t·architecture·f000aa450:·7420·6172·6368·6974·6563·7475·7265·2066··t·architecture·f
000aa460:·6f72·2061·7564·6974·2063·686d·6f64·2074··or·audit·chmod·t000aa460:·6f72·2061·7564·6974·2063·686d·6f64·2074··or·audit·chmod·t
000aa470:·6173·6b73·0a20·2073·6574·5f66·6163·743a··asks.··set_fact:000aa470:·6173·6b73·0a20·2073·6574·5f66·6163·743a··asks.··set_fact:
000aa480:·0a20·2020·2061·7564·6974·5f61·7263·683a··.····audit_arch:000aa480:·0a20·2020·2061·7564·6974·5f61·7263·683a··.····audit_arch:
000aa490:·2062·3634·0a20·2077·6865·6e3a·0a20·202d···b64.··when:.··-000aa490:·2062·3634·0a20·2077·6865·6e3a·0a20·202d···b64.··when:.··-
000aa4a0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual 
000aa4b0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not 
000aa4c0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·" 
000aa4d0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",· 
000aa4e0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta 
000aa4f0:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud 
000aa500:·6974·6422·2069·6e20·616e·7369·626c·655f··itd"·in·ansible_ 
000aa510:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.000aa4a0:·2027·2261·7564·6974·6422·2069·6e20·616e···'"auditd"·in·an
 000aa4b0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 000aa4c0:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
 000aa4d0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000aa4e0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000aa4f0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000aa500:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 000aa510:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
000aa520:·2020·2d20·616e·7369·626c·655f·6172·6368····-·ansible_arch000aa520:·2020·2d20·616e·7369·626c·655f·6172·6368····-·ansible_arch
000aa530:·6974·6563·7475·7265·203d·3d20·2261·6172··itecture·==·"aar000aa530:·6974·6563·7475·7265·203d·3d20·2261·6172··itecture·==·"aar
000aa540:·6368·3634·2220·6f72·2061·6e73·6962·6c65··ch64"·or·ansible000aa540:·6368·3634·2220·6f72·2061·6e73·6962·6c65··ch64"·or·ansible
000aa550:·5f61·7263·6869·7465·6374·7572·6520·3d3d··_architecture·==000aa550:·5f61·7263·6869·7465·6374·7572·6520·3d3d··_architecture·==
000aa560:·2022·7070·6336·3422·206f·7220·616e·7369···"ppc64"·or·ansi000aa560:·2022·7070·6336·3422·206f·7220·616e·7369···"ppc64"·or·ansi
000aa570:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture000aa570:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
000aa580:·0a20·2020·203d·3d20·2270·7063·3634·6c65··.····==·"ppc64le000aa580:·0a20·2020·203d·3d20·2270·7063·3634·6c65··.····==·"ppc64le
Offset 43911, 23 lines modifiedOffset 43911, 23 lines modified
000ab860:·6572·6d5f·6d6f·640a·2020·2020·2020·6372··erm_mod.······cr000ab860:·6572·6d5f·6d6f·640a·2020·2020·2020·6372··erm_mod.······cr
000ab870:·6561·7465·3a20·7472·7565·0a20·2020·2020··eate:·true.·····000ab870:·6561·7465·3a20·7472·7565·0a20·2020·2020··eate:·true.·····
000ab880:·206d·6f64·653a·206f·2d72·7778·0a20·2020···mode:·o-rwx.···000ab880:·206d·6f64·653a·206f·2d72·7778·0a20·2020···mode:·o-rwx.···
000ab890:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen000ab890:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen
000ab8a0:·740a·2020·2020·7768·656e·3a20·7379·7363··t.····when:·sysc000ab8a0:·740a·2020·2020·7768·656e·3a20·7379·7363··t.····when:·sysc
000ab8b0:·616c·6c73·5f66·6f75·6e64·207c·206c·656e··alls_found·|·len000ab8b0:·616c·6c73·5f66·6f75·6e64·207c·206c·656e··alls_found·|·len
000ab8c0:·6774·6820·3d3d·2030·0a20·2077·6865·6e3a··gth·==·0.··when:000ab8c0:·6774·6820·3d3d·2030·0a20·2077·6865·6e3a··gth·==·0.··when:
000ab8d0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
000ab8e0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
000ab8f0:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
000ab900:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
000ab910:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
000ab920:·6f6e·7461·696e·6572·225d·0a20·202d·2027··ontainer"].··-·' 
000ab930:·2261·7564·6974·6422·2069·6e20·616e·7369··"auditd"·in·ansi 
000ab940:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag000ab8d0:·0a20·202d·2027·2261·7564·6974·6422·2069··.··-·'"auditd"·i
 000ab8e0:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 000ab8f0:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an
 000ab900:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
 000ab910:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
 000ab920:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc
 000ab930:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po
 000ab940:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe
000ab950:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·000ab950:·7222·5d0a·2020·7461·6773·3a0a·2020·2d20··r"].··tags:.··-·
000ab960:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-000ab960:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-
000ab970:·2044·4953·412d·5354·4947·2d55·4254·552d···DISA-STIG-UBTU-000ab970:·2044·4953·412d·5354·4947·2d55·4254·552d···DISA-STIG-UBTU-
000ab980:·3230·2d30·3130·3135·320a·2020·2d20·4e49··20-010152.··-·NI000ab980:·3230·2d30·3130·3135·320a·2020·2d20·4e49··20-010152.··-·NI
000ab990:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.7000ab990:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.7
000ab9a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53000ab9a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
000ab9b0:·2d41·552d·3132·2863·290a·2020·2d20·4e49··-AU-12(c).··-·NI000ab9b0:·2d41·552d·3132·2863·290a·2020·2d20·4e49··-AU-12(c).··-·NI
000ab9c0:·5354·2d38·3030·2d35·332d·4155·2d32·2864··ST-800-53-AU-2(d000ab9c0:·5354·2d38·3030·2d35·332d·4155·2d32·2864··ST-800-53-AU-2(d
Offset 44223, 22 lines modifiedOffset 44223, 22 lines modified
000acbe0:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:000acbe0:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:
000acbf0:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode000acbf0:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode
000acc00:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st000acc00:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st
000acc10:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···000acc10:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···
000acc20:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_000acc20:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_
000acc30:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=000acc30:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=
000acc40:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·000acc40:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·
000acc50:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali 
000acc60:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not· 
000acc70:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l 
000acc80:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·" 
000acc90:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai 
000acca0:·6e65·7222·5d0a·2020·2d20·2722·6175·6469··ner"].··-·'"audi 
000accb0:·7464·2220·696e·2061·6e73·6962·6c65·5f66··td"·in·ansible_f 
000accc0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·000acc50:·2722·6175·6469·7464·2220·696e·2061·6e73··'"auditd"·in·ans
 000acc60:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
 000acc70:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible
 000acc80:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
 000acc90:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
 000acca0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
 000accb0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
 000accc0:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
000accd0:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==000accd0:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==
000acce0:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·000acce0:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·
000accf0:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.000accf0:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.
000acd00:·2020·2d20·4449·5341·2d53·5449·472d·5542····-·DISA-STIG-UB000acd00:·2020·2d20·4449·5341·2d53·5449·472d·5542····-·DISA-STIG-UB
000acd10:·5455·2d32·302d·3031·3031·3532·0a20·202d··TU-20-010152.··-000acd10:·5455·2d32·302d·3031·3031·3532·0a20·202d··TU-20-010152.··-
000acd20:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000acd20:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
000acd30:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800000acd30:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
Offset 45190, 25 lines modifiedOffset 45190, 25 lines modified
000b0850:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane000b0850:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
Max diff block lines reached; 581820/591058 bytes (98.44%) of diff not shown.
189 KB
html2text {}
    
Offset 3626, 16 lines modifiedOffset 3626, 16 lines modified
3626 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,3626 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,
3627 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-3627 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-
3628 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-3628 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-
3629 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,3629 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,
3630 ············SRG-OS-000474-VMM-001940,·UBTU-20-010152,·4.1.93630 ············SRG-OS-000474-VMM-001940,·UBTU-20-010152,·4.1.9
3631 Remediation_Shell_script_⇲3631 Remediation_Shell_script_⇲
3632 #·Remediation·is·applicable·only·in·certain·platforms3632 #·Remediation·is·applicable·only·in·certain·platforms
3633 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·dpkg-query·--show·--showformat='${db:Status- 
3634 Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed;·then3633 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed·&&·[·!·-
 3634 f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
3635 #·First·perform·the·remediation·of·the·syscall·rule3635 #·First·perform·the·remediation·of·the·syscall·rule
3636 #·Retrieve·hardware·architecture·of·the·underlying·system3636 #·Retrieve·hardware·architecture·of·the·underlying·system
3637 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3637 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3638 for·ARCH·in·"${RULE_ARCHS[@]}"3638 for·ARCH·in·"${RULE_ARCHS[@]}"
3639 do3639 do
Offset 3991, 16 lines modifiedOffset 3991, 16 lines modified
3991 ··-·reboot_required3991 ··-·reboot_required
3992 ··-·restrict_strategy3992 ··-·restrict_strategy
  
3993 -·name:·Set·architecture·for·audit·chmod·tasks3993 -·name:·Set·architecture·for·audit·chmod·tasks
3994 ··set_fact:3994 ··set_fact:
3995 ····audit_arch:·b643995 ····audit_arch:·b64
3996 ··when:3996 ··when:
3997 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3998 ··-·'"auditd"·in·ansible_facts.packages'3997 ··-·'"auditd"·in·ansible_facts.packages'
 3998 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3999 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3999 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4000 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4000 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4001 ··tags:4001 ··tags:
4002 ··-·CJIS-5.4.1.14002 ··-·CJIS-5.4.1.1
4003 ··-·DISA-STIG-UBTU-20-0101524003 ··-·DISA-STIG-UBTU-20-010152
4004 ··-·NIST-800-171-3.1.74004 ··-·NIST-800-171-3.1.7
4005 ··-·NIST-800-53-AU-12(c)4005 ··-·NIST-800-53-AU-12(c)
Offset 4137, 16 lines modifiedOffset 4137, 16 lines modified
4137 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004137 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4138 ········-F·auid!=unset·-F·key=perm_mod4138 ········-F·auid!=unset·-F·key=perm_mod
4139 ······create:·true4139 ······create:·true
4140 ······mode:·o-rwx4140 ······mode:·o-rwx
4141 ······state:·present4141 ······state:·present
4142 ····when:·syscalls_found·|·length·==·04142 ····when:·syscalls_found·|·length·==·0
4143 ··when:4143 ··when:
4144 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4145 ··-·'"auditd"·in·ansible_facts.packages'4144 ··-·'"auditd"·in·ansible_facts.packages'
 4145 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4146 ··tags:4146 ··tags:
4147 ··-·CJIS-5.4.1.14147 ··-·CJIS-5.4.1.1
4148 ··-·DISA-STIG-UBTU-20-0101524148 ··-·DISA-STIG-UBTU-20-010152
4149 ··-·NIST-800-171-3.1.74149 ··-·NIST-800-171-3.1.7
4150 ··-·NIST-800-53-AU-12(c)4150 ··-·NIST-800-53-AU-12(c)
4151 ··-·NIST-800-53-AU-2(d)4151 ··-·NIST-800-53-AU-2(d)
4152 ··-·NIST-800-53-CM-6(a)4152 ··-·NIST-800-53-CM-6(a)
Offset 4281, 16 lines modifiedOffset 4281, 16 lines modified
4281 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004281 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4282 ········-F·auid!=unset·-F·key=perm_mod4282 ········-F·auid!=unset·-F·key=perm_mod
4283 ······create:·true4283 ······create:·true
4284 ······mode:·o-rwx4284 ······mode:·o-rwx
4285 ······state:·present4285 ······state:·present
4286 ····when:·syscalls_found·|·length·==·04286 ····when:·syscalls_found·|·length·==·0
4287 ··when:4287 ··when:
4288 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4289 ··-·'"auditd"·in·ansible_facts.packages'4288 ··-·'"auditd"·in·ansible_facts.packages'
 4289 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4290 ··-·audit_arch·==·"b64"4290 ··-·audit_arch·==·"b64"
4291 ··tags:4291 ··tags:
4292 ··-·CJIS-5.4.1.14292 ··-·CJIS-5.4.1.1
4293 ··-·DISA-STIG-UBTU-20-0101524293 ··-·DISA-STIG-UBTU-20-010152
4294 ··-·NIST-800-171-3.1.74294 ··-·NIST-800-171-3.1.7
4295 ··-·NIST-800-53-AU-12(c)4295 ··-·NIST-800-53-AU-12(c)
4296 ··-·NIST-800-53-AU-2(d)4296 ··-·NIST-800-53-AU-2(d)
Offset 4336, 16 lines modifiedOffset 4336, 16 lines modified
4336 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,4336 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,
4337 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-4337 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-
4338 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-4338 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-
4339 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,4339 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,
4340 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·UBTU-20-010148,·4.1.94340 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·UBTU-20-010148,·4.1.9
4341 Remediation_Shell_script_⇲4341 Remediation_Shell_script_⇲
4342 #·Remediation·is·applicable·only·in·certain·platforms4342 #·Remediation·is·applicable·only·in·certain·platforms
4343 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·dpkg-query·--show·--showformat='${db:Status- 
4344 Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed;·then4343 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed·&&·[·!·-
 4344 f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
4345 #·First·perform·the·remediation·of·the·syscall·rule4345 #·First·perform·the·remediation·of·the·syscall·rule
4346 #·Retrieve·hardware·architecture·of·the·underlying·system4346 #·Retrieve·hardware·architecture·of·the·underlying·system
4347 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4347 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4348 for·ARCH·in·"${RULE_ARCHS[@]}"4348 for·ARCH·in·"${RULE_ARCHS[@]}"
4349 do4349 do
Offset 4701, 16 lines modifiedOffset 4701, 16 lines modified
4701 ··-·reboot_required4701 ··-·reboot_required
4702 ··-·restrict_strategy4702 ··-·restrict_strategy
  
4703 -·name:·Set·architecture·for·audit·chown·tasks4703 -·name:·Set·architecture·for·audit·chown·tasks
4704 ··set_fact:4704 ··set_fact:
4705 ····audit_arch:·b644705 ····audit_arch:·b64
4706 ··when:4706 ··when:
4707 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4708 ··-·'"auditd"·in·ansible_facts.packages'4707 ··-·'"auditd"·in·ansible_facts.packages'
 4708 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4709 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4709 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4710 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4710 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4711 ··tags:4711 ··tags:
4712 ··-·CJIS-5.4.1.14712 ··-·CJIS-5.4.1.1
4713 ··-·DISA-STIG-UBTU-20-0101484713 ··-·DISA-STIG-UBTU-20-010148
4714 ··-·NIST-800-171-3.1.74714 ··-·NIST-800-171-3.1.7
4715 ··-·NIST-800-53-AU-12(c)4715 ··-·NIST-800-53-AU-12(c)
Offset 4849, 16 lines modifiedOffset 4849, 16 lines modified
4849 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004849 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4850 ········-F·auid!=unset·-F·key=perm_mod4850 ········-F·auid!=unset·-F·key=perm_mod
4851 ······create:·true4851 ······create:·true
4852 ······mode:·o-rwx4852 ······mode:·o-rwx
4853 ······state:·present4853 ······state:·present
4854 ····when:·syscalls_found·|·length·==·04854 ····when:·syscalls_found·|·length·==·0
4855 ··when:4855 ··when:
4856 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4857 ··-·'"auditd"·in·ansible_facts.packages'4856 ··-·'"auditd"·in·ansible_facts.packages'
 4857 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4858 ··tags:4858 ··tags:
4859 ··-·CJIS-5.4.1.14859 ··-·CJIS-5.4.1.1
4860 ··-·DISA-STIG-UBTU-20-0101484860 ··-·DISA-STIG-UBTU-20-010148
4861 ··-·NIST-800-171-3.1.74861 ··-·NIST-800-171-3.1.7
4862 ··-·NIST-800-53-AU-12(c)4862 ··-·NIST-800-53-AU-12(c)
4863 ··-·NIST-800-53-AU-2(d)4863 ··-·NIST-800-53-AU-2(d)
4864 ··-·NIST-800-53-CM-6(a)4864 ··-·NIST-800-53-CM-6(a)
Offset 4995, 16 lines modifiedOffset 4995, 16 lines modified
4995 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004995 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
Max diff block lines reached; 188112/193883 bytes (97.02%) of diff not shown.
15.9 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-standard.html
    
Offset 31363, 112 lines modifiedOffset 31363, 112 lines modified
0007a820:·6574·3d22·2369·646d·3335·3231·3922·2074··et="#idm35219"·t0007a820:·6574·3d22·2369·646d·3335·3231·3922·2074··et="#idm35219"·t
0007a830:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0007a830:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0007a840:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0007a840:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0007a850:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0007a850:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0007a860:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0007a860:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0007a870:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0007a870:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0007a880:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0007a880:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0007a890:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0007a8a0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0007a8b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0007a8c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0007a8d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0007a8e0:·646d·3335·3231·3922·3e3c·7072·653e·3c63··dm35219"><pre><c
 0007a8f0:·6f64·653e·0a5b·6375·7374·6f6d·697a·6174··ode>.[customizat
 0007a900:·696f·6e73·2e73·6572·7669·6365·735d·0a64··ions.services].d
 0007a910:·6973·6162·6c65·6420·3d20·5b22·6170·706f··isabled·=·["appo
 0007a920:·7274·225d·0a3c·2f63·6f64·653e·3c2f·7072··rt"].</code></pr
 0007a930:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0007a940:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0007a950:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0007a960:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0007a970:·6172·6765·743d·2223·6964·6d33·3532·3230··arget="#idm35220
 0007a980:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0007a990:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0007a9a0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0007a9b0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0007a9c0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0007a9d0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0007a9e0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 0007a9f0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0007aa00:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0007aa10:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0007aa20:·6522·2069·643d·2269·646d·3335·3232·3022··e"·id="idm35220"
 0007aa30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0007aa40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0007aa50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0007aa60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0007aa70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0007aa80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0007aa90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0007aaa0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0007aab0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0007aac0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0007aad0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0007aae0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0007aaf0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0007ab00:·653e·696e·636c·7564·6520·6469·7361·626c··e>include·disabl
 0007ab10:·655f·6170·706f·7274·0a0a·636c·6173·7320··e_apport..class·
 0007ab20:·6469·7361·626c·655f·6170·706f·7274·207b··disable_apport·{
 0007ab30:·0a20·2073·6572·7669·6365·207b·2761·7070··.··service·{'app
 0007ab40:·6f72·7427·3a0a·2020·2020·656e·6162·6c65··ort':.····enable
 0007ab50:·203d·2667·743b·2066·616c·7365·2c0a·2020···=&gt;·false,.··
 0007ab60:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0007ab70:·7374·6f70·7065·6427·2c0a·2020·7d0a·7d0a··stopped',.··}.}.
 0007ab80:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0007ab90:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0007aba0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0007abb0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0007abc0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0007abd0:·3d22·2369·646d·3335·3232·3122·2074·6162··="#idm35221"·tab
 0007abe0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0007abf0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0007ac00:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0007ac10:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0007ac20:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0007ac30:·2122·3e52·656d·6564·6961·7469·6f6e·204b··!">Remediation·K
0007a890:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip0007ac40:·7562·6572·6e65·7465·7320·736e·6970·7065··ubernetes·snippe
0007a8a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0007ac50:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0007a8b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0007ac60:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0007a8c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0007ac70:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0007a8d0:·7365·2220·6964·3d22·6964·6d33·3532·3139··se"·id="idm352190007ac80:·2220·6964·3d22·6964·6d33·3532·3231·223e··"·id="idm35221">
0007a8e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0007ac90:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0007a8f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0007aca0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0007a900:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0007acb0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0007a910:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0007acc0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0007a920:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0007acd0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0007a930:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0007ace0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0007a940:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0007acf0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0007a950:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0007ad00:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0007a960:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<0007ad10:·7468·3e3c·7464·3e6d·6564·6975·6d3c·2f74··th><td>medium</t
0007a970:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0007ad20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0007a980:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0007ad30:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e74··eboot:</th><td>t
0007a990:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><0007ad40:·7275·653c·2f74·643e·3c2f·7472·3e3c·7472··rue</td></tr><tr
0007a9a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0007ad50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0007a9b0:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable0007ad60:·7468·3e3c·7464·3e64·6973·6162·6c65·3c2f··th><td>disable</
0007a9c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0007ad70:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0007a9d0:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api0007ad80:·3c70·7265·3e3c·636f·6465·3e61·7069·5665··<pre><code>apiVe
0007a9e0:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine0007ad90:·7273·696f·6e3a·206d·6163·6869·6e65·636f··rsion:·machineco
0007a9f0:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op0007ada0:·6e66·6967·7572·6174·696f·6e2e·6f70·656e··nfiguration.open
0007aa00:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki0007adb0:·7368·6966·742e·696f·2f76·310a·6b69·6e64··shift.io/v1.kind
0007aa10:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi0007adc0:·3a20·4d61·6368·696e·6543·6f6e·6669·670a··:·MachineConfig.
0007aa20:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config0007add0:·7370·6563·3a0a·2020·636f·6e66·6967·3a0a··spec:.··config:.
0007aa30:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.0007ade0:·2020·2020·6967·6e69·7469·6f6e·3a0a·2020······ignition:.··
0007aa40:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·30007adf0:·2020·2020·7665·7273·696f·6e3a·2033·2e31······version:·3.1
0007aa50:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd0007ae00:·2e30·0a20·2020·2073·7973·7465·6d64·3a0a··.0.····systemd:.
0007aa60:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·0007ae10:·2020·2020·2020·756e·6974·733a·0a20·2020········units:.···
0007aa70:·2020·2020·202d·206e·616d·653a·2061·7070·······-·name:·app0007ae20:·2020·202d·206e·616d·653a·2061·7070·6f72·····-·name:·appor
0007aa80:·6f72·742e·7365·7276·6963·650a·2020·2020··ort.service.····0007ae30:·742e·7365·7276·6963·650a·2020·2020·2020··t.service.······
0007aa90:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal0007ae40:·2020·656e·6162·6c65·643a·2066·616c·7365····enabled:·false
0007aaa0:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask:0007ae50:·0a20·2020·2020·2020·206d·6173·6b3a·2074··.········mask:·t
0007aab0:·2074·7275·650a·2020·2020·2020·2d20·6e61···true.······-·na0007ae60:·7275·650a·2020·2020·2020·2d20·6e61·6d65··rue.······-·name
0007aac0:·6d65·3a20·6170·706f·7274·2e73·6f63·6b65··me:·apport.socke0007ae70:·3a20·6170·706f·7274·2e73·6f63·6b65·740a··:·apport.socket.
0007aad0:·740a·2020·2020·2020·2020·656e·6162·6c65··t.········enable0007ae80:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled:
0007aae0:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······0007ae90:·2066·616c·7365·0a20·2020·2020·2020·206d···false.········m
0007aaf0:·206d·6173·6b3a·2074·7275·650a·3c2f·636f···mask:·true.</co0007aea0:·6173·6b3a·2074·7275·650a·3c2f·636f·6465··ask:·true.</code
0007ab00:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0007ab10:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0007ab20:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0007ab30:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0007ab40:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0007ab50:·646d·3335·3232·3022·2074·6162·696e·6465··dm35220"·tabinde 
0007ab60:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0007ab70:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0007ab80:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0007ab90:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0007aba0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0007abb0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
0007abc0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0007abd0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0007abe0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0007abf0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0007ac00:·7073·6522·2069·643d·2269·646d·3335·3232··pse"·id="idm3522 
0007ac10:·3022·3e3c·7072·653e·3c63·6f64·653e·0a5b··0"><pre><code>.[ 
0007ac20:·6375·7374·6f6d·697a·6174·696f·6e73·2e73··customizations.s 
0007ac30:·6572·7669·6365·735d·0a64·6973·6162·6c65··ervices].disable 
0007ac40:·6420·3d20·5b22·6170·706f·7274·225d·0a3c··d·=·["apport"].< 
0007ac50:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
Max diff block lines reached; 414/14518 bytes (2.85%) of diff not shown.
1.57 KB
html2text {}
    
Offset 2162, 14 lines modifiedOffset 2162, 30 lines modified
2162 $·sudo·systemctl·mask·--now·apport.service2162 $·sudo·systemctl·mask·--now·apport.service
2163 ···························The·Apport·service·modifies·the·kernel·fs.suid_dumpable2163 ···························The·Apport·service·modifies·the·kernel·fs.suid_dumpable
2164 Rationale:·················configuration·at·runtime·which·prevents·other·hardening·from2164 Rationale:·················configuration·at·runtime·which·prevents·other·hardening·from
2165 ···························being·persistent.·Disabling·the·service·prevents·this·behavior.2165 ···························being·persistent.·Disabling·the·service·prevents·this·behavior.
2166 Severity: ················unknown2166 Severity: ················unknown
2167 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_apport_disabled2167 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_apport_disabled
2168 Identifiers·and·References2168 Identifiers·and·References
 2169 Remediation_OSBuild_Blueprint_snippet_⇲
  
 2170 [customizations.services]
 2171 disabled·=·["apport"]
 2172 Remediation_Puppet_snippet_⇲
 2173 Complexity:·low
 2174 Disruption:·low
 2175 Strategy:···enable
 2176 include·disable_apport
  
 2177 class·disable_apport·{
 2178 ··service·{'apport':
 2179 ····enable·=>·false,
 2180 ····ensure·=>·'stopped',
 2181 ··}
 2182 }
2169 Remediation_Kubernetes_snippet_⇲2183 Remediation_Kubernetes_snippet_⇲
2170 Complexity:·low2184 Complexity:·low
2171 Disruption:·medium2185 Disruption:·medium
2172 Reboot:·····true2186 Reboot:·····true
2173 Strategy:···disable2187 Strategy:···disable
2174 apiVersion:·machineconfiguration.openshift.io/v12188 apiVersion:·machineconfiguration.openshift.io/v1
2175 kind:·MachineConfig2189 kind:·MachineConfig
Offset 2181, 30 lines modifiedOffset 2197, 14 lines modified
2181 ······units:2197 ······units:
2182 ······-·name:·apport.service2198 ······-·name:·apport.service
2183 ········enabled:·false2199 ········enabled:·false
2184 ········mask:·true2200 ········mask:·true
2185 ······-·name:·apport.socket2201 ······-·name:·apport.socket
2186 ········enabled:·false2202 ········enabled:·false
2187 ········mask:·true2203 ········mask:·true
2188 Remediation_OSBuild_Blueprint_snippet_⇲ 
  
2189 [customizations.services] 
2190 disabled·=·["apport"] 
2191 Remediation_Puppet_snippet_⇲ 
2192 Complexity:·low 
2193 Disruption:·low 
2194 Strategy:···enable 
2195 include·disable_apport 
  
2196 class·disable_apport·{ 
2197 ··service·{'apport': 
2198 ····enable·=>·false, 
2199 ····ensure·=>·'stopped', 
2200 ··} 
2201 } 
2202 Remediation_Shell_script_⇲2204 Remediation_Shell_script_⇲
2203 Complexity:·low2205 Complexity:·low
2204 Disruption:·low2206 Disruption:·low
2205 Strategy:···disable2207 Strategy:···disable
  
  
2206 SYSTEMCTL_EXEC='/usr/bin/systemctl'2208 SYSTEMCTL_EXEC='/usr/bin/systemctl'
773 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-stig.html
    
Offset 42994, 25 lines modifiedOffset 42994, 25 lines modified
000a7f10:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c000a7f10:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
000a7f20:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse000a7f20:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
000a7f30:·2220·6964·3d22·6964·6d31·3236·3738·223e··"·id="idm12678">000a7f30:·2220·6964·3d22·6964·6d31·3236·3738·223e··"·id="idm12678">
000a7f40:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem000a7f40:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
000a7f50:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl000a7f50:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
000a7f60:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c000a7f60:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
000a7f70:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms000a7f70:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 000a7f80:·0a69·6620·6470·6b67·2d71·7565·7279·202d··.if·dpkg-query·-
 000a7f90:·2d73·686f·7720·2d2d·7368·6f77·666f·726d··-show·--showform
 000a7fa0:·6174·3d27·247b·6462·3a53·7461·7475·732d··at='${db:Status-
 000a7fb0:·5374·6174·7573·7d5c·6e27·2027·6175·6469··Status}\n'·'audi
 000a7fc0:·7464·2720·3226·6774·3b2f·6465·762f·6e75··td'·2&gt;/dev/nu
 000a7fd0:·6c6c·207c·2067·7265·7020·2d71·2069·6e73··ll·|·grep·-q·ins
 000a7fe0:·7461·6c6c·6564·2026·616d·703b·2661·6d70··talled·&amp;&amp
000a7f80:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc000a7ff0:·3b20·5b20·2120·2d66·202f·2e64·6f63·6b65··;·[·!·-f·/.docke
000a7f90:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a000a8000:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
000a7fa0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/000a8010:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
000a7fb0:·2e63·6f6e·7461·696e·6572·656e·7620·5d20··.containerenv·]·000a8020:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t
000a7fc0:·2661·6d70·3b26·616d·703b·2064·706b·672d··&amp;&amp;·dpkg- 
000a7fd0:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s 
000a7fe0:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db: 
000a7ff0:·5374·6174·7573·2d53·7461·7475·737d·5c6e··Status-Status}\n 
000a8000:·2720·2761·7564·6974·6427·2032·2667·743b··'·'auditd'·2&gt; 
000a8010:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep 
000a8020:·202d·7120·696e·7374·616c·6c65·643b·2074···-q·installed;·t 
000a8030:·6865·6e0a·0a23·2046·6972·7374·2070·6572··hen..#·First·per000a8030:·6865·6e0a·0a23·2046·6972·7374·2070·6572··hen..#·First·per
000a8040:·666f·726d·2074·6865·2072·656d·6564·6961··form·the·remedia000a8040:·666f·726d·2074·6865·2072·656d·6564·6961··form·the·remedia
000a8050:·7469·6f6e·206f·6620·7468·6520·7379·7363··tion·of·the·sysc000a8050:·7469·6f6e·206f·6620·7468·6520·7379·7363··tion·of·the·sysc
000a8060:·616c·6c20·7275·6c65·0a23·2052·6574·7269··all·rule.#·Retri000a8060:·616c·6c20·7275·6c65·0a23·2052·6574·7269··all·rule.#·Retri
000a8070:·6576·6520·6861·7264·7761·7265·2061·7263··eve·hardware·arc000a8070:·6576·6520·6861·7264·7761·7265·2061·7263··eve·hardware·arc
000a8080:·6869·7465·6374·7572·6520·6f66·2074·6865··hitecture·of·the000a8080:·6869·7465·6374·7572·6520·6f66·2074·6865··hitecture·of·the
000a8090:·2075·6e64·6572·6c79·696e·6720·7379·7374···underlying·syst000a8090:·2075·6e64·6572·6c79·696e·6720·7379·7374···underlying·syst
Offset 43892, 23 lines modifiedOffset 43892, 23 lines modified
000ab730:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r000ab730:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r
000ab740:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy000ab740:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
000ab750:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar000ab750:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar
000ab760:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a000ab760:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a
000ab770:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks000ab770:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks
000ab780:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···000ab780:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
000ab790:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b64000ab790:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b64
000ab7a0:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans000ab7a0:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a
000ab7b0:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat 
000ab7c0:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in· 
000ab7d0:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc" 
000ab7e0:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod 
000ab7f0:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container 
000ab800:·225d·0a20·202d·2027·2261·7564·6974·6422··"].··-·'"auditd" 
000ab810:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
000ab820:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·000ab7b0:·7564·6974·6422·2069·6e20·616e·7369·626c··uditd"·in·ansibl
 000ab7c0:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 000ab7d0:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi
 000ab7e0:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 000ab7f0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 000ab800:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 000ab810:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 000ab820:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·
000ab830:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec000ab830:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec
000ab840:·7475·7265·203d·3d20·2261·6172·6368·3634··ture·==·"aarch64000ab840:·7475·7265·203d·3d20·2261·6172·6368·3634··ture·==·"aarch64
000ab850:·2220·6f72·2061·6e73·6962·6c65·5f61·7263··"·or·ansible_arc000ab850:·2220·6f72·2061·6e73·6962·6c65·5f61·7263··"·or·ansible_arc
000ab860:·6869·7465·6374·7572·6520·3d3d·2022·7070··hitecture·==·"pp000ab860:·6869·7465·6374·7572·6520·3d3d·2022·7070··hitecture·==·"pp
000ab870:·6336·3422·206f·7220·616e·7369·626c·655f··c64"·or·ansible_000ab870:·6336·3422·206f·7220·616e·7369·626c·655f··c64"·or·ansible_
000ab880:·6172·6368·6974·6563·7475·7265·0a20·2020··architecture.···000ab880:·6172·6368·6974·6563·7475·7265·0a20·2020··architecture.···
000ab890:·203d·3d20·2270·7063·3634·6c65·2220·6f72···==·"ppc64le"·or000ab890:·203d·3d20·2270·7063·3634·6c65·2220·6f72···==·"ppc64le"·or
Offset 44216, 22 lines modifiedOffset 44216, 22 lines modified
000acb70:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create000acb70:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create
000acb80:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod000acb80:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod
000acb90:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s000acb90:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s
000acba0:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··000acba0:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
000acbb0:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls000acbb0:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls
000acbc0:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·000acbc0:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·
000acbd0:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-000acbd0:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-
000acbe0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual 
000acbf0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not 
000acc00:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·" 
000acc10:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",· 
000acc20:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta 
000acc30:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud 
000acc40:·6974·6422·2069·6e20·616e·7369·626c·655f··itd"·in·ansible_ 
000acc50:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.000acbe0:·2027·2261·7564·6974·6422·2069·6e20·616e···'"auditd"·in·an
 000acbf0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 000acc00:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
 000acc10:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000acc20:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000acc30:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000acc40:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 000acc50:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
000acc60:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS000acc60:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS
000acc70:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS000acc70:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS
000acc80:·412d·5354·4947·2d55·4254·552d·3230·2d30··A-STIG-UBTU-20-0000acc80:·412d·5354·4947·2d55·4254·552d·3230·2d30··A-STIG-UBTU-20-0
000acc90:·3130·3135·320a·2020·2d20·4e49·5354·2d38··10152.··-·NIST-8000acc90:·3130·3135·320a·2020·2d20·4e49·5354·2d38··10152.··-·NIST-8
000acca0:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-000acca0:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-
000accb0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-000accb0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
000accc0:·3132·2863·290a·2020·2d20·4e49·5354·2d38··12(c).··-·NIST-8000accc0:·3132·2863·290a·2020·2d20·4e49·5354·2d38··12(c).··-·NIST-8
Offset 44527, 23 lines modifiedOffset 44527, 23 lines modified
000adee0:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·000adee0:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·
000adef0:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru000adef0:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru
000adf00:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-000adf00:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-
000adf10:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:000adf10:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:
000adf20:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe000adf20:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe
000adf30:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun000adf30:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun
000adf40:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.000adf40:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.
000adf50:·2020·7768·656e·3a0a·2020·2d20·616e·7369····when:.··-·ansi000adf50:·2020·7768·656e·3a0a·2020·2d20·2722·6175····when:.··-·'"au
000adf60:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
000adf70:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
000adf80:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
000adf90:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
000adfa0:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container" 
000adfb0:·5d0a·2020·2d20·2722·6175·6469·7464·2220··].··-·'"auditd"· 
000adfc0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
000adfd0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a000adf60:·6469·7464·2220·696e·2061·6e73·6962·6c65··ditd"·in·ansible
 000adf70:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
 000adf80:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir
 000adf90:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 000adfa0:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 000adfb0:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 000adfc0:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 000adfd0:·6f6e·7461·696e·6572·225d·0a20·202d·2061··ontainer"].··-·a
000adfe0:·7564·6974·5f61·7263·6820·3d3d·2022·6236··udit_arch·==·"b6000adfe0:·7564·6974·5f61·7263·6820·3d3d·2022·6236··udit_arch·==·"b6
000adff0:·3422·0a20·2074·6167·733a·0a20·202d·2043··4".··tags:.··-·C000adff0:·3422·0a20·2074·6167·733a·0a20·202d·2043··4".··tags:.··-·C
000ae000:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·000ae000:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·
000ae010:·4449·5341·2d53·5449·472d·5542·5455·2d32··DISA-STIG-UBTU-2000ae010:·4449·5341·2d53·5449·472d·5542·5455·2d32··DISA-STIG-UBTU-2
000ae020:·302d·3031·3031·3532·0a20·202d·204e·4953··0-010152.··-·NIS000ae020:·302d·3031·3031·3532·0a20·202d·204e·4953··0-010152.··-·NIS
000ae030:·542d·3830·302d·3137·312d·332e·312e·370a··T-800-171-3.1.7.000ae030:·542d·3830·302d·3137·312d·332e·312e·370a··T-800-171-3.1.7.
000ae040:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-000ae040:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
Offset 45495, 25 lines modifiedOffset 45495, 25 lines modified
000b1b60:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000b1b60:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
000b1b70:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"000b1b70:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
Max diff block lines reached; 579187/588494 bytes (98.42%) of diff not shown.
198 KB
html2text {}
    
Offset 3759, 16 lines modifiedOffset 3759, 16 lines modified
3759 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,3759 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,
3760 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-3760 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-
3761 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-3761 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-
3762 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,3762 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,
3763 ············SRG-OS-000474-VMM-001940,·UBTU-20-010152,·4.1.93763 ············SRG-OS-000474-VMM-001940,·UBTU-20-010152,·4.1.9
3764 Remediation_Shell_script_⇲3764 Remediation_Shell_script_⇲
3765 #·Remediation·is·applicable·only·in·certain·platforms3765 #·Remediation·is·applicable·only·in·certain·platforms
3766 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·dpkg-query·--show·--showformat='${db:Status- 
3767 Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed;·then3766 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed·&&·[·!·-
 3767 f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
3768 #·First·perform·the·remediation·of·the·syscall·rule3768 #·First·perform·the·remediation·of·the·syscall·rule
3769 #·Retrieve·hardware·architecture·of·the·underlying·system3769 #·Retrieve·hardware·architecture·of·the·underlying·system
3770 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3770 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3771 for·ARCH·in·"${RULE_ARCHS[@]}"3771 for·ARCH·in·"${RULE_ARCHS[@]}"
3772 do3772 do
Offset 4124, 16 lines modifiedOffset 4124, 16 lines modified
4124 ··-·reboot_required4124 ··-·reboot_required
4125 ··-·restrict_strategy4125 ··-·restrict_strategy
  
4126 -·name:·Set·architecture·for·audit·chmod·tasks4126 -·name:·Set·architecture·for·audit·chmod·tasks
4127 ··set_fact:4127 ··set_fact:
4128 ····audit_arch:·b644128 ····audit_arch:·b64
4129 ··when:4129 ··when:
4130 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4131 ··-·'"auditd"·in·ansible_facts.packages'4130 ··-·'"auditd"·in·ansible_facts.packages'
 4131 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4132 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4132 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4133 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4133 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4134 ··tags:4134 ··tags:
4135 ··-·CJIS-5.4.1.14135 ··-·CJIS-5.4.1.1
4136 ··-·DISA-STIG-UBTU-20-0101524136 ··-·DISA-STIG-UBTU-20-010152
4137 ··-·NIST-800-171-3.1.74137 ··-·NIST-800-171-3.1.7
4138 ··-·NIST-800-53-AU-12(c)4138 ··-·NIST-800-53-AU-12(c)
Offset 4270, 16 lines modifiedOffset 4270, 16 lines modified
4270 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004270 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4271 ········-F·auid!=unset·-F·key=perm_mod4271 ········-F·auid!=unset·-F·key=perm_mod
4272 ······create:·true4272 ······create:·true
4273 ······mode:·o-rwx4273 ······mode:·o-rwx
4274 ······state:·present4274 ······state:·present
4275 ····when:·syscalls_found·|·length·==·04275 ····when:·syscalls_found·|·length·==·0
4276 ··when:4276 ··when:
4277 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4278 ··-·'"auditd"·in·ansible_facts.packages'4277 ··-·'"auditd"·in·ansible_facts.packages'
 4278 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4279 ··tags:4279 ··tags:
4280 ··-·CJIS-5.4.1.14280 ··-·CJIS-5.4.1.1
4281 ··-·DISA-STIG-UBTU-20-0101524281 ··-·DISA-STIG-UBTU-20-010152
4282 ··-·NIST-800-171-3.1.74282 ··-·NIST-800-171-3.1.7
4283 ··-·NIST-800-53-AU-12(c)4283 ··-·NIST-800-53-AU-12(c)
4284 ··-·NIST-800-53-AU-2(d)4284 ··-·NIST-800-53-AU-2(d)
4285 ··-·NIST-800-53-CM-6(a)4285 ··-·NIST-800-53-CM-6(a)
Offset 4414, 16 lines modifiedOffset 4414, 16 lines modified
4414 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004414 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4415 ········-F·auid!=unset·-F·key=perm_mod4415 ········-F·auid!=unset·-F·key=perm_mod
4416 ······create:·true4416 ······create:·true
4417 ······mode:·o-rwx4417 ······mode:·o-rwx
4418 ······state:·present4418 ······state:·present
4419 ····when:·syscalls_found·|·length·==·04419 ····when:·syscalls_found·|·length·==·0
4420 ··when:4420 ··when:
4421 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4422 ··-·'"auditd"·in·ansible_facts.packages'4421 ··-·'"auditd"·in·ansible_facts.packages'
 4422 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4423 ··-·audit_arch·==·"b64"4423 ··-·audit_arch·==·"b64"
4424 ··tags:4424 ··tags:
4425 ··-·CJIS-5.4.1.14425 ··-·CJIS-5.4.1.1
4426 ··-·DISA-STIG-UBTU-20-0101524426 ··-·DISA-STIG-UBTU-20-010152
4427 ··-·NIST-800-171-3.1.74427 ··-·NIST-800-171-3.1.7
4428 ··-·NIST-800-53-AU-12(c)4428 ··-·NIST-800-53-AU-12(c)
4429 ··-·NIST-800-53-AU-2(d)4429 ··-·NIST-800-53-AU-2(d)
Offset 4469, 16 lines modifiedOffset 4469, 16 lines modified
4469 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,4469 ············DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,
4470 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-4470 ············FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-
4471 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-4471 ············GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-
4472 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,4472 ············000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,
4473 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·UBTU-20-010148,·4.1.94473 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·UBTU-20-010148,·4.1.9
4474 Remediation_Shell_script_⇲4474 Remediation_Shell_script_⇲
4475 #·Remediation·is·applicable·only·in·certain·platforms4475 #·Remediation·is·applicable·only·in·certain·platforms
4476 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·dpkg-query·--show·--showformat='${db:Status- 
4477 Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed;·then4476 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'auditd'·2>/dev/null·|·grep·-q·installed·&&·[·!·-
 4477 f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
4478 #·First·perform·the·remediation·of·the·syscall·rule4478 #·First·perform·the·remediation·of·the·syscall·rule
4479 #·Retrieve·hardware·architecture·of·the·underlying·system4479 #·Retrieve·hardware·architecture·of·the·underlying·system
4480 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4480 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4481 for·ARCH·in·"${RULE_ARCHS[@]}"4481 for·ARCH·in·"${RULE_ARCHS[@]}"
4482 do4482 do
Offset 4834, 16 lines modifiedOffset 4834, 16 lines modified
4834 ··-·reboot_required4834 ··-·reboot_required
4835 ··-·restrict_strategy4835 ··-·restrict_strategy
  
4836 -·name:·Set·architecture·for·audit·chown·tasks4836 -·name:·Set·architecture·for·audit·chown·tasks
4837 ··set_fact:4837 ··set_fact:
4838 ····audit_arch:·b644838 ····audit_arch:·b64
4839 ··when:4839 ··when:
4840 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4841 ··-·'"auditd"·in·ansible_facts.packages'4840 ··-·'"auditd"·in·ansible_facts.packages'
 4841 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4842 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4842 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4843 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4843 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4844 ··tags:4844 ··tags:
4845 ··-·CJIS-5.4.1.14845 ··-·CJIS-5.4.1.1
4846 ··-·DISA-STIG-UBTU-20-0101484846 ··-·DISA-STIG-UBTU-20-010148
4847 ··-·NIST-800-171-3.1.74847 ··-·NIST-800-171-3.1.7
4848 ··-·NIST-800-53-AU-12(c)4848 ··-·NIST-800-53-AU-12(c)
Offset 4982, 16 lines modifiedOffset 4982, 16 lines modified
4982 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004982 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4983 ········-F·auid!=unset·-F·key=perm_mod4983 ········-F·auid!=unset·-F·key=perm_mod
4984 ······create:·true4984 ······create:·true
4985 ······mode:·o-rwx4985 ······mode:·o-rwx
4986 ······state:·present4986 ······state:·present
4987 ····when:·syscalls_found·|·length·==·04987 ····when:·syscalls_found·|·length·==·0
4988 ··when:4988 ··when:
4989 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4990 ··-·'"auditd"·in·ansible_facts.packages'4989 ··-·'"auditd"·in·ansible_facts.packages'
 4990 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4991 ··tags:4991 ··tags:
4992 ··-·CJIS-5.4.1.14992 ··-·CJIS-5.4.1.1
4993 ··-·DISA-STIG-UBTU-20-0101484993 ··-·DISA-STIG-UBTU-20-010148
4994 ··-·NIST-800-171-3.1.74994 ··-·NIST-800-171-3.1.7
4995 ··-·NIST-800-53-AU-12(c)4995 ··-·NIST-800-53-AU-12(c)
4996 ··-·NIST-800-53-AU-2(d)4996 ··-·NIST-800-53-AU-2(d)
4997 ··-·NIST-800-53-CM-6(a)4997 ··-·NIST-800-53-CM-6(a)
Offset 5128, 16 lines modifiedOffset 5128, 16 lines modified
5128 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005128 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
Max diff block lines reached; 196721/202492 bytes (97.15%) of diff not shown.
49.4 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_server.html
    
Offset 38072, 24 lines modifiedOffset 38072, 24 lines modified
00094b70:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>00094b70:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
00094b80:·3c74·643e·636f·6e66·6967·7572·653c·2f74··<td>configure</t00094b80:·3c74·643e·636f·6e66·6967·7572·653c·2f74··<td>configure</t
00094b90:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><00094b90:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
00094ba0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme00094ba0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
00094bb0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli00094bb0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
00094bc0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce00094bc0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
00094bd0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.00094bd0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00094be0:·6966·205b·2021·202d·6620·2f73·7973·2f66··if·[·!·-f·/sys/f
00094be0:·6966·2064·706b·672d·7175·6572·7920·2d2d··if·dpkg-query·-- 
00094bf0:·7368·6f77·202d·2d73·686f·7766·6f72·6d61··show·--showforma 
00094c00:·743d·2724·7b64·623a·5374·6174·7573·2d53··t='${db:Status-S 
00094c10:·7461·7475·737d·5c6e·2720·2767·7275·6232··tatus}\n'·'grub2 
00094c20:·2d63·6f6d·6d6f·6e27·2032·2667·743b·2f64··-common'·2&gt;/d 
00094c30:·6576·2f6e·756c·6c20·7c20·6772·6570·202d··ev/null·|·grep·- 
00094c40:·7120·696e·7374·616c·6c65·6420·2661·6d70··q·installed·&amp 
00094c50:·3b26·616d·703b·205b·2021·202d·6620·2f73··;&amp;·[·!·-f·/s 
00094c60:·7973·2f66·6972·6d77·6172·652f·6566·6920··ys/firmware/efi·00094bf0:·6972·6d77·6172·652f·6566·6920·5d20·2661··irmware/efi·]·&a
 00094c00:·6d70·3b26·616d·703b·2064·706b·672d·7175··mp;&amp;·dpkg-qu
 00094c10:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho
 00094c20:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St
 00094c30:·6174·7573·2d53·7461·7475·737d·5c6e·2720··atus-Status}\n'·
 00094c40:·2767·7275·6232·2d63·6f6d·6d6f·6e27·2032··'grub2-common'·2
 00094c50:·2667·743b·2f64·6576·2f6e·756c·6c20·7c20··&gt;/dev/null·|·
 00094c60:·6772·6570·202d·7120·696e·7374·616c·6c65··grep·-q·installe
00094c70:·5d20·2661·6d70·3b26·616d·703b·207b·205b··]·&amp;&amp;·{·[00094c70:·6420·2661·6d70·3b26·616d·703b·207b·205b··d·&amp;&amp;·{·[
00094c80:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren00094c80:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
00094c90:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[00094c90:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
00094ca0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont00094ca0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
00094cb0:·6169·6e65·7265·6e76·205d·3b20·7d3b·2074··ainerenv·];·};·t00094cb0:·6169·6e65·7265·6e76·205d·3b20·7d3b·2074··ainerenv·];·};·t
00094cc0:·6865·6e0a·0a63·686f·776e·2030·202f·626f··hen..chown·0·/bo00094cc0:·6865·6e0a·0a63·686f·776e·2030·202f·626f··hen..chown·0·/bo
00094cd0:·6f74·2f67·7275·622f·6772·7562·2e63·6667··ot/grub/grub.cfg00094cd0:·6f74·2f67·7275·622f·6772·7562·2e63·6667··ot/grub/grub.cfg
00094ce0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&00094ce0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
Offset 38150, 22 lines modifiedOffset 38150, 22 lines modified
00095050:·2054·6573·7420·666f·7220·6578·6973·7465···Test·for·existe00095050:·2054·6573·7420·666f·7220·6578·6973·7465···Test·for·existe
00095060:·6e63·6520·2f62·6f6f·742f·6772·7562·2f67··nce·/boot/grub/g00095060:·6e63·6520·2f62·6f6f·742f·6772·7562·2f67··nce·/boot/grub/g
00095070:·7275·622e·6366·670a·2020·7374·6174·3a0a··rub.cfg.··stat:.00095070:·7275·622e·6366·670a·2020·7374·6174·3a0a··rub.cfg.··stat:.
00095080:·2020·2020·7061·7468·3a20·2f62·6f6f·742f······path:·/boot/00095080:·2020·2020·7061·7468·3a20·2f62·6f6f·742f······path:·/boot/
00095090:·6772·7562·2f67·7275·622e·6366·670a·2020··grub/grub.cfg.··00095090:·6772·7562·2f67·7275·622e·6366·670a·2020··grub/grub.cfg.··
000950a0:·7265·6769·7374·6572·3a20·6669·6c65·5f65··register:·file_e000950a0:·7265·6769·7374·6572·3a20·6669·6c65·5f65··register:·file_e
000950b0:·7869·7374·730a·2020·7768·656e·3a0a·2020··xists.··when:.··000950b0:·7869·7374·730a·2020·7768·656e·3a0a·2020··xists.··when:.··
000950c0:·2d20·2722·6772·7562·322d·636f·6d6d·6f6e··-·'"grub2-common 
000950d0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
000950e0:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··- 
000950f0:·2027·222f·626f·6f74·2f65·6669·2220·6e6f···'"/boot/efi"·no 
00095100:·7420·696e·2061·6e73·6962·6c65·5f6d·6f75··t·in·ansible_mou 
00095110:·6e74·7320·7c20·6d61·7028·6174·7472·6962··nts·|·map(attrib 
00095120:·7574·653d·226d·6f75·6e74·2229·207c·206c··ute="mount")·|·l000950c0:·2d20·2722·2f62·6f6f·742f·6566·6922·206e··-·'"/boot/efi"·n
 000950d0:·6f74·2069·6e20·616e·7369·626c·655f·6d6f··ot·in·ansible_mo
 000950e0:·756e·7473·207c·206d·6170·2861·7474·7269··unts·|·map(attri
 000950f0:·6275·7465·3d22·6d6f·756e·7422·2920·7c20··bute="mount")·|·
 00095100:·6c69·7374·270a·2020·2d20·2722·6772·7562··list'.··-·'"grub
 00095110:·322d·636f·6d6d·6f6e·2220·696e·2061·6e73··2-common"·in·ans
 00095120:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
00095130:·6973·7427·0a20·202d·2061·6e73·6962·6c65··ist'.··-·ansible00095130:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible
00095140:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_00095140:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
00095150:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do00095150:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
00095160:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o00095160:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
00095170:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"00095170:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
00095180:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·00095180:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
00095190:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-00095190:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-
000951a0:·352e·352e·322e·320a·2020·2d20·4e49·5354··5.5.2.2.··-·NIST000951a0:·352e·352e·322e·320a·2020·2d20·4e49·5354··5.5.2.2.··-·NIST
Offset 38185, 22 lines modifiedOffset 38185, 22 lines modified
00095280:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur00095280:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur
00095290:·6520·6f77·6e65·7220·3020·6f6e·202f·626f··e·owner·0·on·/bo00095290:·6520·6f77·6e65·7220·3020·6f6e·202f·626f··e·owner·0·on·/bo
000952a0:·6f74·2f67·7275·622f·6772·7562·2e63·6667··ot/grub/grub.cfg000952a0:·6f74·2f67·7275·622f·6772·7562·2e63·6667··ot/grub/grub.cfg
000952b0:·0a20·2066·696c·653a·0a20·2020·2070·6174··.··file:.····pat000952b0:·0a20·2066·696c·653a·0a20·2020·2070·6174··.··file:.····pat
000952c0:·683a·202f·626f·6f74·2f67·7275·622f·6772··h:·/boot/grub/gr000952c0:·683a·202f·626f·6f74·2f67·7275·622f·6772··h:·/boot/grub/gr
000952d0:·7562·2e63·6667·0a20·2020·206f·776e·6572··ub.cfg.····owner000952d0:·7562·2e63·6667·0a20·2020·206f·776e·6572··ub.cfg.····owner
000952e0:·3a20·2730·270a·2020·7768·656e·3a0a·2020··:·'0'.··when:.··000952e0:·3a20·2730·270a·2020·7768·656e·3a0a·2020··:·'0'.··when:.··
000952f0:·2d20·2722·6772·7562·322d·636f·6d6d·6f6e··-·'"grub2-common 
00095300:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
00095310:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··- 
00095320:·2027·222f·626f·6f74·2f65·6669·2220·6e6f···'"/boot/efi"·no 
00095330:·7420·696e·2061·6e73·6962·6c65·5f6d·6f75··t·in·ansible_mou 
00095340:·6e74·7320·7c20·6d61·7028·6174·7472·6962··nts·|·map(attrib 
00095350:·7574·653d·226d·6f75·6e74·2229·207c·206c··ute="mount")·|·l000952f0:·2d20·2722·2f62·6f6f·742f·6566·6922·206e··-·'"/boot/efi"·n
 00095300:·6f74·2069·6e20·616e·7369·626c·655f·6d6f··ot·in·ansible_mo
 00095310:·756e·7473·207c·206d·6170·2861·7474·7269··unts·|·map(attri
 00095320:·6275·7465·3d22·6d6f·756e·7422·2920·7c20··bute="mount")·|·
 00095330:·6c69·7374·270a·2020·2d20·2722·6772·7562··list'.··-·'"grub
 00095340:·322d·636f·6d6d·6f6e·2220·696e·2061·6e73··2-common"·in·ans
 00095350:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
00095360:·6973·7427·0a20·202d·2061·6e73·6962·6c65··ist'.··-·ansible00095360:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible
00095370:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_00095370:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
00095380:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do00095380:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
00095390:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o00095390:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
000953a0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"000953a0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
000953b0:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·000953b0:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
000953c0:·202d·2066·696c·655f·6578·6973·7473·2e73···-·file_exists.s000953c0:·202d·2066·696c·655f·6578·6973·7473·2e73···-·file_exists.s
000953d0:·7461·7420·6973·2064·6566·696e·6564·2061··tat·is·defined·a000953d0:·7461·7420·6973·2064·6566·696e·6564·2061··tat·is·defined·a
Offset 38642, 24 lines modifiedOffset 38642, 24 lines modified
00096f10:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</00096f10:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
00096f20:·7468·3e3c·7464·3e63·6f6e·6669·6775·7265··th><td>configure00096f20:·7468·3e3c·7464·3e63·6f6e·6669·6775·7265··th><td>configure
00096f30:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl00096f30:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
00096f40:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R00096f40:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
00096f50:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap00096f50:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
00096f60:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in00096f60:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
00096f70:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor00096f70:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 00096f80:·6d73·0a69·6620·5b20·2120·2d66·202f·7379··ms.if·[·!·-f·/sy
00096f80:·6d73·0a69·6620·6470·6b67·2d71·7565·7279··ms.if·dpkg-query 
00096f90:·202d·2d73·686f·7720·2d2d·7368·6f77·666f···--show·--showfo 
00096fa0:·726d·6174·3d27·247b·6462·3a53·7461·7475··rmat='${db:Statu 
00096fb0:·732d·5374·6174·7573·7d5c·6e27·2027·6772··s-Status}\n'·'gr 
00096fc0:·7562·322d·636f·6d6d·6f6e·2720·3226·6774··ub2-common'·2&gt 
00096fd0:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre 
00096fe0:·7020·2d71·2069·6e73·7461·6c6c·6564·2026··p·-q·installed·& 
00096ff0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
00097000:·202f·7379·732f·6669·726d·7761·7265·2f65···/sys/firmware/e00096f90:·732f·6669·726d·7761·7265·2f65·6669·205d··s/firmware/efi·]
 00096fa0:·2026·616d·703b·2661·6d70·3b20·6470·6b67···&amp;&amp;·dpkg
 00096fb0:·2d71·7565·7279·202d·2d73·686f·7720·2d2d··-query·--show·--
 00096fc0:·7368·6f77·666f·726d·6174·3d27·247b·6462··showformat='${db
 00096fd0:·3a53·7461·7475·732d·5374·6174·7573·7d5c··:Status-Status}\
 00096fe0:·6e27·2027·6772·7562·322d·636f·6d6d·6f6e··n'·'grub2-common
 00096ff0:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null
 00097000:·207c·2067·7265·7020·2d71·2069·6e73·7461···|·grep·-q·insta
00097010:·6669·205d·2026·616d·703b·2661·6d70·3b20··fi·]·&amp;&amp;·00097010:·6c6c·6564·2026·616d·703b·2661·6d70·3b20··lled·&amp;&amp;·
00097020:·7b20·5b20·2120·2d66·202f·2e64·6f63·6b65··{·[·!·-f·/.docke00097020:·7b20·5b20·2120·2d66·202f·2e64·6f63·6b65··{·[·!·-f·/.docke
00097030:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp00097030:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
00097040:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c00097040:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
00097050:·6f6e·7461·696e·6572·656e·7620·5d3b·207d··ontainerenv·];·}00097050:·6f6e·7461·696e·6572·656e·7620·5d3b·207d··ontainerenv·];·}
00097060:·3b20·7468·656e·0a0a·6368·6d6f·6420·752d··;·then..chmod·u-00097060:·3b20·7468·656e·0a0a·6368·6d6f·6420·752d··;·then..chmod·u-
00097070:·7873·2c67·2d78·7772·732c·6f2d·7877·7274··xs,g-xwrs,o-xwrt00097070:·7873·2c67·2d78·7772·732c·6f2d·7877·7274··xs,g-xwrs,o-xwrt
00097080:·202f·626f·6f74·2f67·7275·622f·6772·7562···/boot/grub/grub00097080:·202f·626f·6f74·2f67·7275·622f·6772·7562···/boot/grub/grub
Offset 38719, 22 lines modifiedOffset 38719, 22 lines modified
000973e0:·6e61·6d65·3a20·5465·7374·2066·6f72·2065··name:·Test·for·e000973e0:·6e61·6d65·3a20·5465·7374·2066·6f72·2065··name:·Test·for·e
000973f0:·7869·7374·656e·6365·202f·626f·6f74·2f67··xistence·/boot/g000973f0:·7869·7374·656e·6365·202f·626f·6f74·2f67··xistence·/boot/g
00097400:·7275·622f·6772·7562·2e63·6667·0a20·2073··rub/grub.cfg.··s00097400:·7275·622f·6772·7562·2e63·6667·0a20·2073··rub/grub.cfg.··s
Max diff block lines reached; 33342/42580 bytes (78.30%) of diff not shown.
7.71 KB
html2text {}
    
Offset 3133, 16 lines modifiedOffset 3133, 16 lines modified
3133 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,3133 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,
3134 ············Req-7.1,·1.5.23134 ············Req-7.1,·1.5.2
3135 Remediation_Shell_script_⇲3135 Remediation_Shell_script_⇲
3136 Complexity:·low3136 Complexity:·low
3137 Disruption:·low3137 Disruption:·low
3138 Strategy:···configure3138 Strategy:···configure
3139 #·Remediation·is·applicable·only·in·certain·platforms3139 #·Remediation·is·applicable·only·in·certain·platforms
3140 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&·[·!3140 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/
3141 -f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3141 null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3142 chown·0·/boot/grub/grub.cfg3142 chown·0·/boot/grub/grub.cfg
  
3143 else3143 else
3144 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3144 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3145 fi3145 fi
3146 Remediation_Ansible_snippet_⇲3146 Remediation_Ansible_snippet_⇲
Offset 3166, 16 lines modifiedOffset 3166, 16 lines modified
3166 ··-·no_reboot_needed3166 ··-·no_reboot_needed
  
3167 -·name:·Test·for·existence·/boot/grub/grub.cfg3167 -·name:·Test·for·existence·/boot/grub/grub.cfg
3168 ··stat:3168 ··stat:
3169 ····path:·/boot/grub/grub.cfg3169 ····path:·/boot/grub/grub.cfg
3170 ··register:·file_exists3170 ··register:·file_exists
3171 ··when:3171 ··when:
3172 ··-·'"grub2-common"·in·ansible_facts.packages' 
3173 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3172 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3173 ··-·'"grub2-common"·in·ansible_facts.packages'
3174 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3174 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3175 ··tags:3175 ··tags:
3176 ··-·CJIS-5.5.2.23176 ··-·CJIS-5.5.2.2
3177 ··-·NIST-800-171-3.4.53177 ··-·NIST-800-171-3.4.5
3178 ··-·NIST-800-53-AC-6(1)3178 ··-·NIST-800-53-AC-6(1)
3179 ··-·NIST-800-53-CM-6(a)3179 ··-·NIST-800-53-CM-6(a)
3180 ··-·PCI-DSS-Req-7.13180 ··-·PCI-DSS-Req-7.1
Offset 3187, 16 lines modifiedOffset 3187, 16 lines modified
3187 ··-·no_reboot_needed3187 ··-·no_reboot_needed
  
3188 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg3188 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
3189 ··file:3189 ··file:
3190 ····path:·/boot/grub/grub.cfg3190 ····path:·/boot/grub/grub.cfg
3191 ····owner:·'0'3191 ····owner:·'0'
3192 ··when:3192 ··when:
3193 ··-·'"grub2-common"·in·ansible_facts.packages' 
3194 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3193 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3194 ··-·'"grub2-common"·in·ansible_facts.packages'
3195 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3195 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3196 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3196 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3197 ··tags:3197 ··tags:
3198 ··-·CJIS-5.5.2.23198 ··-·CJIS-5.5.2.2
3199 ··-·NIST-800-171-3.4.53199 ··-·NIST-800-171-3.4.5
3200 ··-·NIST-800-53-AC-6(1)3200 ··-·NIST-800-53-AC-6(1)
3201 ··-·NIST-800-53-CM-6(a)3201 ··-·NIST-800-53-CM-6(a)
Offset 3222, 16 lines modifiedOffset 3222, 16 lines modified
3222 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),3222 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),
3223 ············PR.AC-4,·PR.DS-5,·1.5.23223 ············PR.AC-4,·PR.DS-5,·1.5.2
3224 Remediation_Shell_script_⇲3224 Remediation_Shell_script_⇲
3225 Complexity:·low3225 Complexity:·low
3226 Disruption:·low3226 Disruption:·low
3227 Strategy:···configure3227 Strategy:···configure
3228 #·Remediation·is·applicable·only·in·certain·platforms3228 #·Remediation·is·applicable·only·in·certain·platforms
3229 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&3229 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/
3230 [·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3230 dev/null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3231 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg3231 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg
  
3232 else3232 else
3233 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3233 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3234 fi3234 fi
3235 Remediation_Ansible_snippet_⇲3235 Remediation_Ansible_snippet_⇲
Offset 3253, 16 lines modifiedOffset 3253, 16 lines modified
3253 ··-·no_reboot_needed3253 ··-·no_reboot_needed
  
3254 -·name:·Test·for·existence·/boot/grub/grub.cfg3254 -·name:·Test·for·existence·/boot/grub/grub.cfg
3255 ··stat:3255 ··stat:
3256 ····path:·/boot/grub/grub.cfg3256 ····path:·/boot/grub/grub.cfg
3257 ··register:·file_exists3257 ··register:·file_exists
3258 ··when:3258 ··when:
3259 ··-·'"grub2-common"·in·ansible_facts.packages' 
3260 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3259 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3260 ··-·'"grub2-common"·in·ansible_facts.packages'
3261 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3261 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3262 ··tags:3262 ··tags:
3263 ··-·NIST-800-171-3.4.53263 ··-·NIST-800-171-3.4.5
3264 ··-·NIST-800-53-AC-6(1)3264 ··-·NIST-800-53-AC-6(1)
3265 ··-·NIST-800-53-CM-6(a)3265 ··-·NIST-800-53-CM-6(a)
3266 ··-·configure_strategy3266 ··-·configure_strategy
3267 ··-·file_permissions_grub2_cfg3267 ··-·file_permissions_grub2_cfg
Offset 3272, 16 lines modifiedOffset 3272, 16 lines modified
3272 ··-·no_reboot_needed3272 ··-·no_reboot_needed
  
3273 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg3273 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
3274 ··file:3274 ··file:
3275 ····path:·/boot/grub/grub.cfg3275 ····path:·/boot/grub/grub.cfg
3276 ····mode:·u-xs,g-xwrs,o-xwrt3276 ····mode:·u-xs,g-xwrs,o-xwrt
3277 ··when:3277 ··when:
3278 ··-·'"grub2-common"·in·ansible_facts.packages' 
3279 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3278 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3279 ··-·'"grub2-common"·in·ansible_facts.packages'
3280 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3280 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3281 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3281 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3282 ··tags:3282 ··tags:
3283 ··-·NIST-800-171-3.4.53283 ··-·NIST-800-171-3.4.5
3284 ··-·NIST-800-53-AC-6(1)3284 ··-·NIST-800-53-AC-6(1)
3285 ··-·NIST-800-53-CM-6(a)3285 ··-·NIST-800-53-CM-6(a)
3286 ··-·configure_strategy3286 ··-·configure_strategy
Offset 10517, 14 lines modifiedOffset 10517, 30 lines modified
10517 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,10517 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,
10518 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,10518 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,
10519 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,10519 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,
10520 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR10520 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR
10521 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,10521 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,
10522 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,10522 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,
10523 ············2.2.310523 ············2.2.3
 10524 Remediation_OSBuild_Blueprint_snippet_⇲
  
 10525 [customizations.services]
 10526 disabled·=·["avahi-daemon"]
 10527 Remediation_Puppet_snippet_⇲
 10528 Complexity:·low
 10529 Disruption:·low
 10530 Strategy:···enable
 10531 include·disable_avahi-daemon
  
 10532 class·disable_avahi-daemon·{
 10533 ··service·{'avahi-daemon':
 10534 ····enable·=>·false,
 10535 ····ensure·=>·'stopped',
Max diff block lines reached; 2796/7875 bytes (35.50%) of diff not shown.
33.3 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_workstation.html
    
Offset 39621, 24 lines modifiedOffset 39621, 24 lines modified
0009ac40:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0009ac40:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0009ac50:·3e3c·7464·3e63·6f6e·6669·6775·7265·3c2f··><td>configure</0009ac50:·3e3c·7464·3e63·6f6e·6669·6775·7265·3c2f··><td>configure</
0009ac60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0009ac60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0009ac70:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem0009ac70:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
0009ac80:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl0009ac80:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
0009ac90:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c0009ac90:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
0009aca0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms0009aca0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0009acb0:·0a69·6620·5b20·2120·2d66·202f·7379·732f··.if·[·!·-f·/sys/
0009acb0:·0a69·6620·6470·6b67·2d71·7565·7279·202d··.if·dpkg-query·- 
0009acc0:·2d73·686f·7720·2d2d·7368·6f77·666f·726d··-show·--showform 
0009acd0:·6174·3d27·247b·6462·3a53·7461·7475·732d··at='${db:Status- 
0009ace0:·5374·6174·7573·7d5c·6e27·2027·6772·7562··Status}\n'·'grub 
0009acf0:·322d·636f·6d6d·6f6e·2720·3226·6774·3b2f··2-common'·2&gt;/ 
0009ad00:·6465·762f·6e75·6c6c·207c·2067·7265·7020··dev/null·|·grep· 
0009ad10:·2d71·2069·6e73·7461·6c6c·6564·2026·616d··-q·installed·&am 
0009ad20:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0009ad30:·7379·732f·6669·726d·7761·7265·2f65·6669··sys/firmware/efi0009acc0:·6669·726d·7761·7265·2f65·6669·205d·2026··firmware/efi·]·&
 0009acd0:·616d·703b·2661·6d70·3b20·6470·6b67·2d71··amp;&amp;·dpkg-q
 0009ace0:·7565·7279·202d·2d73·686f·7720·2d2d·7368··uery·--show·--sh
 0009acf0:·6f77·666f·726d·6174·3d27·247b·6462·3a53··owformat='${db:S
 0009ad00:·7461·7475·732d·5374·6174·7573·7d5c·6e27··tatus-Status}\n'
 0009ad10:·2027·6772·7562·322d·636f·6d6d·6f6e·2720···'grub2-common'·
 0009ad20:·3226·6774·3b2f·6465·762f·6e75·6c6c·207c··2&gt;/dev/null·|
 0009ad30:·2067·7265·7020·2d71·2069·6e73·7461·6c6c···grep·-q·install
0009ad40:·205d·2026·616d·703b·2661·6d70·3b20·7b20···]·&amp;&amp;·{·0009ad40:·6564·2026·616d·703b·2661·6d70·3b20·7b20··ed·&amp;&amp;·{·
0009ad50:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere0009ad50:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
0009ad60:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·0009ad60:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
0009ad70:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con0009ad70:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
0009ad80:·7461·696e·6572·656e·7620·5d3b·207d·3b20··tainerenv·];·};·0009ad80:·7461·696e·6572·656e·7620·5d3b·207d·3b20··tainerenv·];·};·
0009ad90:·7468·656e·0a0a·6368·6f77·6e20·3020·2f62··then..chown·0·/b0009ad90:·7468·656e·0a0a·6368·6f77·6e20·3020·2f62··then..chown·0·/b
0009ada0:·6f6f·742f·6772·7562·2f67·7275·622e·6366··oot/grub/grub.cf0009ada0:·6f6f·742f·6772·7562·2f67·7275·622e·6366··oot/grub/grub.cf
0009adb0:·670a·0a65·6c73·650a·2020·2020·2667·743b··g..else.····&gt;0009adb0:·670a·0a65·6c73·650a·2020·2020·2667·743b··g..else.····&gt;
Offset 39699, 22 lines modifiedOffset 39699, 22 lines modified
0009b120:·3a20·5465·7374·2066·6f72·2065·7869·7374··:·Test·for·exist0009b120:·3a20·5465·7374·2066·6f72·2065·7869·7374··:·Test·for·exist
0009b130:·656e·6365·202f·626f·6f74·2f67·7275·622f··ence·/boot/grub/0009b130:·656e·6365·202f·626f·6f74·2f67·7275·622f··ence·/boot/grub/
0009b140:·6772·7562·2e63·6667·0a20·2073·7461·743a··grub.cfg.··stat:0009b140:·6772·7562·2e63·6667·0a20·2073·7461·743a··grub.cfg.··stat:
0009b150:·0a20·2020·2070·6174·683a·202f·626f·6f74··.····path:·/boot0009b150:·0a20·2020·2070·6174·683a·202f·626f·6f74··.····path:·/boot
0009b160:·2f67·7275·622f·6772·7562·2e63·6667·0a20··/grub/grub.cfg.·0009b160:·2f67·7275·622f·6772·7562·2e63·6667·0a20··/grub/grub.cfg.·
0009b170:·2072·6567·6973·7465·723a·2066·696c·655f···register:·file_0009b170:·2072·6567·6973·7465·723a·2066·696c·655f···register:·file_
0009b180:·6578·6973·7473·0a20·2077·6865·6e3a·0a20··exists.··when:.·0009b180:·6578·6973·7473·0a20·2077·6865·6e3a·0a20··exists.··when:.·
0009b190:·202d·2027·2267·7275·6232·2d63·6f6d·6d6f···-·'"grub2-commo 
0009b1a0:·6e22·2069·6e20·616e·7369·626c·655f·6661··n"·in·ansible_fa 
0009b1b0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
0009b1c0:·2d20·2722·2f62·6f6f·742f·6566·6922·206e··-·'"/boot/efi"·n 
0009b1d0:·6f74·2069·6e20·616e·7369·626c·655f·6d6f··ot·in·ansible_mo 
0009b1e0:·756e·7473·207c·206d·6170·2861·7474·7269··unts·|·map(attri 
0009b1f0:·6275·7465·3d22·6d6f·756e·7422·2920·7c20··bute="mount")·|·0009b190:·202d·2027·222f·626f·6f74·2f65·6669·2220···-·'"/boot/efi"·
 0009b1a0:·6e6f·7420·696e·2061·6e73·6962·6c65·5f6d··not·in·ansible_m
 0009b1b0:·6f75·6e74·7320·7c20·6d61·7028·6174·7472··ounts·|·map(attr
 0009b1c0:·6962·7574·653d·226d·6f75·6e74·2229·207c··ibute="mount")·|
 0009b1d0:·206c·6973·7427·0a20·202d·2027·2267·7275···list'.··-·'"gru
 0009b1e0:·6232·2d63·6f6d·6d6f·6e22·2069·6e20·616e··b2-common"·in·an
 0009b1f0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
0009b200:·6c69·7374·270a·2020·2d20·616e·7369·626c··list'.··-·ansibl0009b200:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
0009b210:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization0009b210:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
0009b220:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d0009b220:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
0009b230:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"0009b230:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
0009b240:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman0009b240:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
0009b250:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].0009b250:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
0009b260:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS0009b260:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS
0009b270:·2d35·2e35·2e32·2e32·0a20·202d·204e·4953··-5.5.2.2.··-·NIS0009b270:·2d35·2e35·2e32·2e32·0a20·202d·204e·4953··-5.5.2.2.··-·NIS
Offset 39734, 22 lines modifiedOffset 39734, 22 lines modified
0009b350:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu0009b350:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu
0009b360:·7265·206f·776e·6572·2030·206f·6e20·2f62··re·owner·0·on·/b0009b360:·7265·206f·776e·6572·2030·206f·6e20·2f62··re·owner·0·on·/b
0009b370:·6f6f·742f·6772·7562·2f67·7275·622e·6366··oot/grub/grub.cf0009b370:·6f6f·742f·6772·7562·2f67·7275·622e·6366··oot/grub/grub.cf
0009b380:·670a·2020·6669·6c65·3a0a·2020·2020·7061··g.··file:.····pa0009b380:·670a·2020·6669·6c65·3a0a·2020·2020·7061··g.··file:.····pa
0009b390:·7468·3a20·2f62·6f6f·742f·6772·7562·2f67··th:·/boot/grub/g0009b390:·7468·3a20·2f62·6f6f·742f·6772·7562·2f67··th:·/boot/grub/g
0009b3a0:·7275·622e·6366·670a·2020·2020·6f77·6e65··rub.cfg.····owne0009b3a0:·7275·622e·6366·670a·2020·2020·6f77·6e65··rub.cfg.····owne
0009b3b0:·723a·2027·3027·0a20·2077·6865·6e3a·0a20··r:·'0'.··when:.·0009b3b0:·723a·2027·3027·0a20·2077·6865·6e3a·0a20··r:·'0'.··when:.·
0009b3c0:·202d·2027·2267·7275·6232·2d63·6f6d·6d6f···-·'"grub2-commo 
0009b3d0:·6e22·2069·6e20·616e·7369·626c·655f·6661··n"·in·ansible_fa 
0009b3e0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
0009b3f0:·2d20·2722·2f62·6f6f·742f·6566·6922·206e··-·'"/boot/efi"·n 
0009b400:·6f74·2069·6e20·616e·7369·626c·655f·6d6f··ot·in·ansible_mo 
0009b410:·756e·7473·207c·206d·6170·2861·7474·7269··unts·|·map(attri 
0009b420:·6275·7465·3d22·6d6f·756e·7422·2920·7c20··bute="mount")·|·0009b3c0:·202d·2027·222f·626f·6f74·2f65·6669·2220···-·'"/boot/efi"·
 0009b3d0:·6e6f·7420·696e·2061·6e73·6962·6c65·5f6d··not·in·ansible_m
 0009b3e0:·6f75·6e74·7320·7c20·6d61·7028·6174·7472··ounts·|·map(attr
 0009b3f0:·6962·7574·653d·226d·6f75·6e74·2229·207c··ibute="mount")·|
 0009b400:·206c·6973·7427·0a20·202d·2027·2267·7275···list'.··-·'"gru
 0009b410:·6232·2d63·6f6d·6d6f·6e22·2069·6e20·616e··b2-common"·in·an
 0009b420:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
0009b430:·6c69·7374·270a·2020·2d20·616e·7369·626c··list'.··-·ansibl0009b430:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
0009b440:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization0009b440:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
0009b450:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d0009b450:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
0009b460:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"0009b460:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
0009b470:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman0009b470:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
0009b480:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].0009b480:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
0009b490:·2020·2d20·6669·6c65·5f65·7869·7374·732e····-·file_exists.0009b490:·2020·2d20·6669·6c65·5f65·7869·7374·732e····-·file_exists.
0009b4a0:·7374·6174·2069·7320·6465·6669·6e65·6420··stat·is·defined·0009b4a0:·7374·6174·2069·7320·6465·6669·6e65·6420··stat·is·defined·
Offset 40191, 24 lines modifiedOffset 40191, 24 lines modified
0009cfe0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0009cfe0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0009cff0:·2f74·683e·3c74·643e·636f·6e66·6967·7572··/th><td>configur0009cff0:·2f74·683e·3c74·643e·636f·6e66·6967·7572··/th><td>configur
0009d000:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0009d000:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0009d010:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·0009d010:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
0009d020:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a0009d020:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
0009d030:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i0009d030:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
0009d040:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo0009d040:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0009d050:·726d·730a·6966·205b·2021·202d·6620·2f73··rms.if·[·!·-f·/s
0009d050:·726d·730a·6966·2064·706b·672d·7175·6572··rms.if·dpkg-quer 
0009d060:·7920·2d2d·7368·6f77·202d·2d73·686f·7766··y·--show·--showf 
0009d070:·6f72·6d61·743d·2724·7b64·623a·5374·6174··ormat='${db:Stat 
0009d080:·7573·2d53·7461·7475·737d·5c6e·2720·2767··us-Status}\n'·'g 
0009d090:·7275·6232·2d63·6f6d·6d6f·6e27·2032·2667··rub2-common'·2&g 
0009d0a0:·743b·2f64·6576·2f6e·756c·6c20·7c20·6772··t;/dev/null·|·gr 
0009d0b0:·6570·202d·7120·696e·7374·616c·6c65·6420··ep·-q·installed· 
0009d0c0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·- 
0009d0d0:·6620·2f73·7973·2f66·6972·6d77·6172·652f··f·/sys/firmware/0009d060:·7973·2f66·6972·6d77·6172·652f·6566·6920··ys/firmware/efi·
 0009d070:·5d20·2661·6d70·3b26·616d·703b·2064·706b··]·&amp;&amp;·dpk
 0009d080:·672d·7175·6572·7920·2d2d·7368·6f77·202d··g-query·--show·-
 0009d090:·2d73·686f·7766·6f72·6d61·743d·2724·7b64··-showformat='${d
 0009d0a0:·623a·5374·6174·7573·2d53·7461·7475·737d··b:Status-Status}
 0009d0b0:·5c6e·2720·2767·7275·6232·2d63·6f6d·6d6f··\n'·'grub2-commo
 0009d0c0:·6e27·2032·2667·743b·2f64·6576·2f6e·756c··n'·2&gt;/dev/nul
 0009d0d0:·6c20·7c20·6772·6570·202d·7120·696e·7374··l·|·grep·-q·inst
0009d0e0:·6566·6920·5d20·2661·6d70·3b26·616d·703b··efi·]·&amp;&amp;0009d0e0:·616c·6c65·6420·2661·6d70·3b26·616d·703b··alled·&amp;&amp;
0009d0f0:·207b·205b·2021·202d·6620·2f2e·646f·636b···{·[·!·-f·/.dock0009d0f0:·207b·205b·2021·202d·6620·2f2e·646f·636b···{·[·!·-f·/.dock
0009d100:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am0009d100:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
0009d110:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.0009d110:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
0009d120:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·0009d120:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·
0009d130:·7d3b·2074·6865·6e0a·0a63·686d·6f64·2075··};·then..chmod·u0009d130:·7d3b·2074·6865·6e0a·0a63·686d·6f64·2075··};·then..chmod·u
0009d140:·2d78·732c·672d·7877·7273·2c6f·2d78·7772··-xs,g-xwrs,o-xwr0009d140:·2d78·732c·672d·7877·7273·2c6f·2d78·7772··-xs,g-xwrs,o-xwr
0009d150:·7420·2f62·6f6f·742f·6772·7562·2f67·7275··t·/boot/grub/gru0009d150:·7420·2f62·6f6f·742f·6772·7562·2f67·7275··t·/boot/grub/gru
Offset 40268, 22 lines modifiedOffset 40268, 22 lines modified
0009d4b0:·206e·616d·653a·2054·6573·7420·666f·7220···name:·Test·for·0009d4b0:·206e·616d·653a·2054·6573·7420·666f·7220···name:·Test·for·
0009d4c0:·6578·6973·7465·6e63·6520·2f62·6f6f·742f··existence·/boot/0009d4c0:·6578·6973·7465·6e63·6520·2f62·6f6f·742f··existence·/boot/
0009d4d0:·6772·7562·2f67·7275·622e·6366·670a·2020··grub/grub.cfg.··0009d4d0:·6772·7562·2f67·7275·622e·6366·670a·2020··grub/grub.cfg.··
Max diff block lines reached; 18684/27922 bytes (66.91%) of diff not shown.
5.84 KB
html2text {}
    
Offset 3369, 16 lines modifiedOffset 3369, 16 lines modified
3369 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,3369 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,
3370 ············Req-7.1,·1.5.23370 ············Req-7.1,·1.5.2
3371 Remediation_Shell_script_⇲3371 Remediation_Shell_script_⇲
3372 Complexity:·low3372 Complexity:·low
3373 Disruption:·low3373 Disruption:·low
3374 Strategy:···configure3374 Strategy:···configure
3375 #·Remediation·is·applicable·only·in·certain·platforms3375 #·Remediation·is·applicable·only·in·certain·platforms
3376 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&·[·!3376 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/
3377 -f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3377 null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3378 chown·0·/boot/grub/grub.cfg3378 chown·0·/boot/grub/grub.cfg
  
3379 else3379 else
3380 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3380 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3381 fi3381 fi
3382 Remediation_Ansible_snippet_⇲3382 Remediation_Ansible_snippet_⇲
Offset 3402, 16 lines modifiedOffset 3402, 16 lines modified
3402 ··-·no_reboot_needed3402 ··-·no_reboot_needed
  
3403 -·name:·Test·for·existence·/boot/grub/grub.cfg3403 -·name:·Test·for·existence·/boot/grub/grub.cfg
3404 ··stat:3404 ··stat:
3405 ····path:·/boot/grub/grub.cfg3405 ····path:·/boot/grub/grub.cfg
3406 ··register:·file_exists3406 ··register:·file_exists
3407 ··when:3407 ··when:
3408 ··-·'"grub2-common"·in·ansible_facts.packages' 
3409 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3408 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3409 ··-·'"grub2-common"·in·ansible_facts.packages'
3410 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3410 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3411 ··tags:3411 ··tags:
3412 ··-·CJIS-5.5.2.23412 ··-·CJIS-5.5.2.2
3413 ··-·NIST-800-171-3.4.53413 ··-·NIST-800-171-3.4.5
3414 ··-·NIST-800-53-AC-6(1)3414 ··-·NIST-800-53-AC-6(1)
3415 ··-·NIST-800-53-CM-6(a)3415 ··-·NIST-800-53-CM-6(a)
3416 ··-·PCI-DSS-Req-7.13416 ··-·PCI-DSS-Req-7.1
Offset 3423, 16 lines modifiedOffset 3423, 16 lines modified
3423 ··-·no_reboot_needed3423 ··-·no_reboot_needed
  
3424 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg3424 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
3425 ··file:3425 ··file:
3426 ····path:·/boot/grub/grub.cfg3426 ····path:·/boot/grub/grub.cfg
3427 ····owner:·'0'3427 ····owner:·'0'
3428 ··when:3428 ··when:
3429 ··-·'"grub2-common"·in·ansible_facts.packages' 
3430 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3429 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3430 ··-·'"grub2-common"·in·ansible_facts.packages'
3431 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3431 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3432 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3432 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3433 ··tags:3433 ··tags:
3434 ··-·CJIS-5.5.2.23434 ··-·CJIS-5.5.2.2
3435 ··-·NIST-800-171-3.4.53435 ··-·NIST-800-171-3.4.5
3436 ··-·NIST-800-53-AC-6(1)3436 ··-·NIST-800-53-AC-6(1)
3437 ··-·NIST-800-53-CM-6(a)3437 ··-·NIST-800-53-CM-6(a)
Offset 3458, 16 lines modifiedOffset 3458, 16 lines modified
3458 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),3458 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),
3459 ············PR.AC-4,·PR.DS-5,·1.5.23459 ············PR.AC-4,·PR.DS-5,·1.5.2
3460 Remediation_Shell_script_⇲3460 Remediation_Shell_script_⇲
3461 Complexity:·low3461 Complexity:·low
3462 Disruption:·low3462 Disruption:·low
3463 Strategy:···configure3463 Strategy:···configure
3464 #·Remediation·is·applicable·only·in·certain·platforms3464 #·Remediation·is·applicable·only·in·certain·platforms
3465 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&3465 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/
3466 [·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3466 dev/null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3467 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg3467 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg
  
3468 else3468 else
3469 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3469 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3470 fi3470 fi
3471 Remediation_Ansible_snippet_⇲3471 Remediation_Ansible_snippet_⇲
Offset 3489, 16 lines modifiedOffset 3489, 16 lines modified
3489 ··-·no_reboot_needed3489 ··-·no_reboot_needed
  
3490 -·name:·Test·for·existence·/boot/grub/grub.cfg3490 -·name:·Test·for·existence·/boot/grub/grub.cfg
3491 ··stat:3491 ··stat:
3492 ····path:·/boot/grub/grub.cfg3492 ····path:·/boot/grub/grub.cfg
3493 ··register:·file_exists3493 ··register:·file_exists
3494 ··when:3494 ··when:
3495 ··-·'"grub2-common"·in·ansible_facts.packages' 
3496 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3495 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3496 ··-·'"grub2-common"·in·ansible_facts.packages'
3497 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3497 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3498 ··tags:3498 ··tags:
3499 ··-·NIST-800-171-3.4.53499 ··-·NIST-800-171-3.4.5
3500 ··-·NIST-800-53-AC-6(1)3500 ··-·NIST-800-53-AC-6(1)
3501 ··-·NIST-800-53-CM-6(a)3501 ··-·NIST-800-53-CM-6(a)
3502 ··-·configure_strategy3502 ··-·configure_strategy
3503 ··-·file_permissions_grub2_cfg3503 ··-·file_permissions_grub2_cfg
Offset 3508, 16 lines modifiedOffset 3508, 16 lines modified
3508 ··-·no_reboot_needed3508 ··-·no_reboot_needed
  
3509 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg3509 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
3510 ··file:3510 ··file:
3511 ····path:·/boot/grub/grub.cfg3511 ····path:·/boot/grub/grub.cfg
3512 ····mode:·u-xs,g-xwrs,o-xwrt3512 ····mode:·u-xs,g-xwrs,o-xwrt
3513 ··when:3513 ··when:
3514 ··-·'"grub2-common"·in·ansible_facts.packages' 
3515 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3514 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3515 ··-·'"grub2-common"·in·ansible_facts.packages'
3516 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3516 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3517 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists3517 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
3518 ··tags:3518 ··tags:
3519 ··-·NIST-800-171-3.4.53519 ··-·NIST-800-171-3.4.5
3520 ··-·NIST-800-53-AC-6(1)3520 ··-·NIST-800-53-AC-6(1)
3521 ··-·NIST-800-53-CM-6(a)3521 ··-·NIST-800-53-CM-6(a)
3522 ··-·configure_strategy3522 ··-·configure_strategy
Offset 10430, 14 lines modifiedOffset 10430, 30 lines modified
10430 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,10430 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,
10431 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,10431 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,
10432 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,10432 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,
10433 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR10433 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR
10434 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,10434 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,
10435 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,10435 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,
10436 ············2.2.310436 ············2.2.3
 10437 Remediation_OSBuild_Blueprint_snippet_⇲
  
 10438 [customizations.services]
 10439 disabled·=·["avahi-daemon"]
 10440 Remediation_Puppet_snippet_⇲
 10441 Complexity:·low
 10442 Disruption:·low
 10443 Strategy:···enable
 10444 include·disable_avahi-daemon
  
 10445 class·disable_avahi-daemon·{
 10446 ··service·{'avahi-daemon':
 10447 ····enable·=>·false,
 10448 ····ensure·=>·'stopped',
Max diff block lines reached; 877/5956 bytes (14.72%) of diff not shown.
49.3 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_server.html
    
Offset 174995, 24 lines modifiedOffset 174995, 24 lines modified
002ab920:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t002ab920:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
002ab930:·683e·3c74·643e·636f·6e66·6967·7572·653c··h><td>configure<002ab930:·683e·3c74·643e·636f·6e66·6967·7572·653c··h><td>configure<
002ab940:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table002ab940:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
002ab950:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re002ab950:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
002ab960:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app002ab960:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
002ab970:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·002ab970:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
002ab980:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform002ab980:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 002ab990:·730a·6966·205b·2021·202d·6620·2f73·7973··s.if·[·!·-f·/sys
002ab990:·730a·6966·2064·706b·672d·7175·6572·7920··s.if·dpkg-query· 
002ab9a0:·2d2d·7368·6f77·202d·2d73·686f·7766·6f72··--show·--showfor 
002ab9b0:·6d61·743d·2724·7b64·623a·5374·6174·7573··mat='${db:Status 
002ab9c0:·2d53·7461·7475·737d·5c6e·2720·2767·7275··-Status}\n'·'gru 
002ab9d0:·6232·2d63·6f6d·6d6f·6e27·2032·2667·743b··b2-common'·2&gt; 
002ab9e0:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep 
002ab9f0:·202d·7120·696e·7374·616c·6c65·6420·2661···-q·installed·&a 
002aba00:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
002aba10:·2f73·7973·2f66·6972·6d77·6172·652f·6566··/sys/firmware/ef002ab9a0:·2f66·6972·6d77·6172·652f·6566·6920·5d20··/firmware/efi·]·
 002ab9b0:·2661·6d70·3b26·616d·703b·2064·706b·672d··&amp;&amp;·dpkg-
 002ab9c0:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s
 002ab9d0:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db:
 002ab9e0:·5374·6174·7573·2d53·7461·7475·737d·5c6e··Status-Status}\n
 002ab9f0:·2720·2767·7275·6232·2d63·6f6d·6d6f·6e27··'·'grub2-common'
 002aba00:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null·
 002aba10:·7c20·6772·6570·202d·7120·696e·7374·616c··|·grep·-q·instal
002aba20:·6920·5d20·2661·6d70·3b26·616d·703b·207b··i·]·&amp;&amp;·{002aba20:·6c65·6420·2661·6d70·3b26·616d·703b·207b··led·&amp;&amp;·{
002aba30:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker002aba30:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
002aba40:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;002aba40:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
002aba50:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co002aba50:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
002aba60:·6e74·6169·6e65·7265·6e76·205d·3b20·7d3b··ntainerenv·];·};002aba60:·6e74·6169·6e65·7265·6e76·205d·3b20·7d3b··ntainerenv·];·};
002aba70:·2074·6865·6e0a·0a63·686f·776e·2030·202f···then..chown·0·/002aba70:·2074·6865·6e0a·0a63·686f·776e·2030·202f···then..chown·0·/
002aba80:·626f·6f74·2f67·7275·622f·6772·7562·2e63··boot/grub/grub.c002aba80:·626f·6f74·2f67·7275·622f·6772·7562·2e63··boot/grub/grub.c
002aba90:·6667·0a0a·656c·7365·0a20·2020·2026·6774··fg..else.····&gt002aba90:·6667·0a0a·656c·7365·0a20·2020·2026·6774··fg..else.····&gt
Offset 175073, 22 lines modifiedOffset 175073, 22 lines modified
002abe00:·653a·2054·6573·7420·666f·7220·6578·6973··e:·Test·for·exis002abe00:·653a·2054·6573·7420·666f·7220·6578·6973··e:·Test·for·exis
002abe10:·7465·6e63·6520·2f62·6f6f·742f·6772·7562··tence·/boot/grub002abe10:·7465·6e63·6520·2f62·6f6f·742f·6772·7562··tence·/boot/grub
002abe20:·2f67·7275·622e·6366·670a·2020·7374·6174··/grub.cfg.··stat002abe20:·2f67·7275·622e·6366·670a·2020·7374·6174··/grub.cfg.··stat
002abe30:·3a0a·2020·2020·7061·7468·3a20·2f62·6f6f··:.····path:·/boo002abe30:·3a0a·2020·2020·7061·7468·3a20·2f62·6f6f··:.····path:·/boo
002abe40:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.002abe40:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.
002abe50:·2020·7265·6769·7374·6572·3a20·6669·6c65····register:·file002abe50:·2020·7265·6769·7374·6572·3a20·6669·6c65····register:·file
002abe60:·5f65·7869·7374·730a·2020·7768·656e·3a0a··_exists.··when:.002abe60:·5f65·7869·7374·730a·2020·7768·656e·3a0a··_exists.··when:.
002abe70:·2020·2d20·2722·6772·7562·322d·636f·6d6d····-·'"grub2-comm 
002abe80:·6f6e·2220·696e·2061·6e73·6962·6c65·5f66··on"·in·ansible_f 
002abe90:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
002abea0:·202d·2027·222f·626f·6f74·2f65·6669·2220···-·'"/boot/efi"· 
002abeb0:·6e6f·7420·696e·2061·6e73·6962·6c65·5f6d··not·in·ansible_m 
002abec0:·6f75·6e74·7320·7c20·6d61·7028·6174·7472··ounts·|·map(attr 
002abed0:·6962·7574·653d·226d·6f75·6e74·2229·207c··ibute="mount")·|002abe70:·2020·2d20·2722·2f62·6f6f·742f·6566·6922····-·'"/boot/efi"
 002abe80:·206e·6f74·2069·6e20·616e·7369·626c·655f···not·in·ansible_
 002abe90:·6d6f·756e·7473·207c·206d·6170·2861·7474··mounts·|·map(att
 002abea0:·7269·6275·7465·3d22·6d6f·756e·7422·2920··ribute="mount")·
 002abeb0:·7c20·6c69·7374·270a·2020·2d20·2722·6772··|·list'.··-·'"gr
 002abec0:·7562·322d·636f·6d6d·6f6e·2220·696e·2061··ub2-common"·in·a
 002abed0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
002abee0:·206c·6973·7427·0a20·202d·2061·6e73·6962···list'.··-·ansib002abee0:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib
002abef0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio002abef0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
002abf00:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["002abf00:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
002abf10:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·002abf10:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
002abf20:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma002abf20:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
002abf30:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]002abf30:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
002abf40:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI002abf40:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
002abf50:·532d·352e·352e·322e·320a·2020·2d20·4e49··S-5.5.2.2.··-·NI002abf50:·532d·352e·352e·322e·320a·2020·2d20·4e49··S-5.5.2.2.··-·NI
Offset 175108, 22 lines modifiedOffset 175108, 22 lines modified
002ac030:·6465·640a·0a2d·206e·616d·653a·2045·6e73··ded..-·name:·Ens002ac030:·6465·640a·0a2d·206e·616d·653a·2045·6e73··ded..-·name:·Ens
002ac040:·7572·6520·6f77·6e65·7220·3020·6f6e·202f··ure·owner·0·on·/002ac040:·7572·6520·6f77·6e65·7220·3020·6f6e·202f··ure·owner·0·on·/
002ac050:·626f·6f74·2f67·7275·622f·6772·7562·2e63··boot/grub/grub.c002ac050:·626f·6f74·2f67·7275·622f·6772·7562·2e63··boot/grub/grub.c
002ac060:·6667·0a20·2066·696c·653a·0a20·2020·2070··fg.··file:.····p002ac060:·6667·0a20·2066·696c·653a·0a20·2020·2070··fg.··file:.····p
002ac070:·6174·683a·202f·626f·6f74·2f67·7275·622f··ath:·/boot/grub/002ac070:·6174·683a·202f·626f·6f74·2f67·7275·622f··ath:·/boot/grub/
002ac080:·6772·7562·2e63·6667·0a20·2020·206f·776e··grub.cfg.····own002ac080:·6772·7562·2e63·6667·0a20·2020·206f·776e··grub.cfg.····own
002ac090:·6572·3a20·2730·270a·2020·7768·656e·3a0a··er:·'0'.··when:.002ac090:·6572·3a20·2730·270a·2020·7768·656e·3a0a··er:·'0'.··when:.
002ac0a0:·2020·2d20·2722·6772·7562·322d·636f·6d6d····-·'"grub2-comm 
002ac0b0:·6f6e·2220·696e·2061·6e73·6962·6c65·5f66··on"·in·ansible_f 
002ac0c0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
002ac0d0:·202d·2027·222f·626f·6f74·2f65·6669·2220···-·'"/boot/efi"· 
002ac0e0:·6e6f·7420·696e·2061·6e73·6962·6c65·5f6d··not·in·ansible_m 
002ac0f0:·6f75·6e74·7320·7c20·6d61·7028·6174·7472··ounts·|·map(attr 
002ac100:·6962·7574·653d·226d·6f75·6e74·2229·207c··ibute="mount")·|002ac0a0:·2020·2d20·2722·2f62·6f6f·742f·6566·6922····-·'"/boot/efi"
 002ac0b0:·206e·6f74·2069·6e20·616e·7369·626c·655f···not·in·ansible_
 002ac0c0:·6d6f·756e·7473·207c·206d·6170·2861·7474··mounts·|·map(att
 002ac0d0:·7269·6275·7465·3d22·6d6f·756e·7422·2920··ribute="mount")·
 002ac0e0:·7c20·6c69·7374·270a·2020·2d20·2722·6772··|·list'.··-·'"gr
 002ac0f0:·7562·322d·636f·6d6d·6f6e·2220·696e·2061··ub2-common"·in·a
 002ac100:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
002ac110:·206c·6973·7427·0a20·202d·2061·6e73·6962···list'.··-·ansib002ac110:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib
002ac120:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio002ac120:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
002ac130:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["002ac130:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
002ac140:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·002ac140:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
002ac150:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma002ac150:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
002ac160:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]002ac160:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
002ac170:·0a20·202d·2066·696c·655f·6578·6973·7473··.··-·file_exists002ac170:·0a20·202d·2066·696c·655f·6578·6973·7473··.··-·file_exists
002ac180:·2e73·7461·7420·6973·2064·6566·696e·6564··.stat·is·defined002ac180:·2e73·7461·7420·6973·2064·6566·696e·6564··.stat·is·defined
Offset 175565, 24 lines modifiedOffset 175565, 24 lines modified
002adcc0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:002adcc0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
002adcd0:·3c2f·7468·3e3c·7464·3e63·6f6e·6669·6775··</th><td>configu002adcd0:·3c2f·7468·3e3c·7464·3e63·6f6e·6669·6775··</th><td>configu
002adce0:·7265·3c2f·7464·3e3c·2f74·723e·3c2f·7461··re</td></tr></ta002adce0:·7265·3c2f·7464·3e3c·2f74·723e·3c2f·7461··re</td></tr></ta
002adcf0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#002adcf0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
002add00:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·002add00:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
002add10:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·002add10:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
002add20:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf002add20:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 002add30:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
 002add40:·7379·732f·6669·726d·7761·7265·2f65·6669··sys/firmware/efi
002add30:·6f72·6d73·0a69·6620·6470·6b67·2d71·7565··orms.if·dpkg-que 
002add40:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show 
002add50:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta 
002add60:·7475·732d·5374·6174·7573·7d5c·6e27·2027··tus-Status}\n'·' 
002add70:·6772·7562·322d·636f·6d6d·6f6e·2720·3226··grub2-common'·2& 
002add80:·6774·3b2f·6465·762f·6e75·6c6c·207c·2067··gt;/dev/null·|·g 
002add90:·7265·7020·2d71·2069·6e73·7461·6c6c·6564··rep·-q·installed 
002adda0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·002add50:·205d·2026·616d·703b·2661·6d70·3b20·6470···]·&amp;&amp;·dp
002addb0:·2d66·202f·7379·732f·6669·726d·7761·7265··-f·/sys/firmware002add60:·6b67·2d71·7565·7279·202d·2d73·686f·7720··kg-query·--show·
 002add70:·2d2d·7368·6f77·666f·726d·6174·3d27·247b··--showformat='${
 002add80:·6462·3a53·7461·7475·732d·5374·6174·7573··db:Status-Status
 002add90:·7d5c·6e27·2027·6772·7562·322d·636f·6d6d··}\n'·'grub2-comm
 002adda0:·6f6e·2720·3226·6774·3b2f·6465·762f·6e75··on'·2&gt;/dev/nu
 002addb0:·6c6c·207c·2067·7265·7020·2d71·2069·6e73··ll·|·grep·-q·ins
002addc0:·2f65·6669·205d·2026·616d·703b·2661·6d70··/efi·]·&amp;&amp002addc0:·7461·6c6c·6564·2026·616d·703b·2661·6d70··talled·&amp;&amp
002addd0:·3b20·7b20·5b20·2120·2d66·202f·2e64·6f63··;·{·[·!·-f·/.doc002addd0:·3b20·7b20·5b20·2120·2d66·202f·2e64·6f63··;·{·[·!·-f·/.doc
002adde0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a002adde0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
002addf0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/002addf0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
002ade00:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];002ade00:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
002ade10:·207d·3b20·7468·656e·0a0a·6368·6d6f·6420···};·then..chmod·002ade10:·207d·3b20·7468·656e·0a0a·6368·6d6f·6420···};·then..chmod·
002ade20:·752d·7873·2c67·2d78·7772·732c·6f2d·7877··u-xs,g-xwrs,o-xw002ade20:·752d·7873·2c67·2d78·7772·732c·6f2d·7877··u-xs,g-xwrs,o-xw
002ade30:·7274·202f·626f·6f74·2f67·7275·622f·6772··rt·/boot/grub/gr002ade30:·7274·202f·626f·6f74·2f67·7275·622f·6772··rt·/boot/grub/gr
Offset 175642, 22 lines modifiedOffset 175642, 22 lines modified
002ae190:·2d20·6e61·6d65·3a20·5465·7374·2066·6f72··-·name:·Test·for002ae190:·2d20·6e61·6d65·3a20·5465·7374·2066·6f72··-·name:·Test·for
002ae1a0:·2065·7869·7374·656e·6365·202f·626f·6f74···existence·/boot002ae1a0:·2065·7869·7374·656e·6365·202f·626f·6f74···existence·/boot
002ae1b0:·2f67·7275·622f·6772·7562·2e63·6667·0a20··/grub/grub.cfg.·002ae1b0:·2f67·7275·622f·6772·7562·2e63·6667·0a20··/grub/grub.cfg.·
002ae1c0:·2073·7461·743a·0a20·2020·2070·6174·683a···stat:.····path:002ae1c0:·2073·7461·743a·0a20·2020·2070·6174·683a···stat:.····path:
Max diff block lines reached; 33139/42456 bytes (78.05%) of diff not shown.
7.73 KB
html2text {}
    
Offset 39152, 16 lines modifiedOffset 39152, 16 lines modified
39152 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,39152 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,
39153 ············Req-7.1,·1.5.239153 ············Req-7.1,·1.5.2
39154 Remediation_Shell_script_⇲39154 Remediation_Shell_script_⇲
39155 Complexity:·low39155 Complexity:·low
39156 Disruption:·low39156 Disruption:·low
39157 Strategy:···configure39157 Strategy:···configure
39158 #·Remediation·is·applicable·only·in·certain·platforms39158 #·Remediation·is·applicable·only·in·certain·platforms
39159 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&·[·!39159 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/
39160 -f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then39160 null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
39161 chown·0·/boot/grub/grub.cfg39161 chown·0·/boot/grub/grub.cfg
  
39162 else39162 else
39163 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'39163 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
39164 fi39164 fi
39165 Remediation_Ansible_snippet_⇲39165 Remediation_Ansible_snippet_⇲
Offset 39185, 16 lines modifiedOffset 39185, 16 lines modified
39185 ··-·no_reboot_needed39185 ··-·no_reboot_needed
  
39186 -·name:·Test·for·existence·/boot/grub/grub.cfg39186 -·name:·Test·for·existence·/boot/grub/grub.cfg
39187 ··stat:39187 ··stat:
39188 ····path:·/boot/grub/grub.cfg39188 ····path:·/boot/grub/grub.cfg
39189 ··register:·file_exists39189 ··register:·file_exists
39190 ··when:39190 ··when:
39191 ··-·'"grub2-common"·in·ansible_facts.packages' 
39192 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'39191 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 39192 ··-·'"grub2-common"·in·ansible_facts.packages'
39193 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]39193 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
39194 ··tags:39194 ··tags:
39195 ··-·CJIS-5.5.2.239195 ··-·CJIS-5.5.2.2
39196 ··-·NIST-800-171-3.4.539196 ··-·NIST-800-171-3.4.5
39197 ··-·NIST-800-53-AC-6(1)39197 ··-·NIST-800-53-AC-6(1)
39198 ··-·NIST-800-53-CM-6(a)39198 ··-·NIST-800-53-CM-6(a)
39199 ··-·PCI-DSS-Req-7.139199 ··-·PCI-DSS-Req-7.1
Offset 39206, 16 lines modifiedOffset 39206, 16 lines modified
39206 ··-·no_reboot_needed39206 ··-·no_reboot_needed
  
39207 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg39207 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
39208 ··file:39208 ··file:
39209 ····path:·/boot/grub/grub.cfg39209 ····path:·/boot/grub/grub.cfg
39210 ····owner:·'0'39210 ····owner:·'0'
39211 ··when:39211 ··when:
39212 ··-·'"grub2-common"·in·ansible_facts.packages' 
39213 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'39212 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 39213 ··-·'"grub2-common"·in·ansible_facts.packages'
39214 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]39214 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
39215 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists39215 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
39216 ··tags:39216 ··tags:
39217 ··-·CJIS-5.5.2.239217 ··-·CJIS-5.5.2.2
39218 ··-·NIST-800-171-3.4.539218 ··-·NIST-800-171-3.4.5
39219 ··-·NIST-800-53-AC-6(1)39219 ··-·NIST-800-53-AC-6(1)
39220 ··-·NIST-800-53-CM-6(a)39220 ··-·NIST-800-53-CM-6(a)
Offset 39241, 16 lines modifiedOffset 39241, 16 lines modified
39241 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),39241 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),
39242 ············PR.AC-4,·PR.DS-5,·1.5.239242 ············PR.AC-4,·PR.DS-5,·1.5.2
39243 Remediation_Shell_script_⇲39243 Remediation_Shell_script_⇲
39244 Complexity:·low39244 Complexity:·low
39245 Disruption:·low39245 Disruption:·low
39246 Strategy:···configure39246 Strategy:···configure
39247 #·Remediation·is·applicable·only·in·certain·platforms39247 #·Remediation·is·applicable·only·in·certain·platforms
39248 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&39248 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/
39249 [·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then39249 dev/null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
39250 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg39250 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg
  
39251 else39251 else
39252 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'39252 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
39253 fi39253 fi
39254 Remediation_Ansible_snippet_⇲39254 Remediation_Ansible_snippet_⇲
Offset 39272, 16 lines modifiedOffset 39272, 16 lines modified
39272 ··-·no_reboot_needed39272 ··-·no_reboot_needed
  
39273 -·name:·Test·for·existence·/boot/grub/grub.cfg39273 -·name:·Test·for·existence·/boot/grub/grub.cfg
39274 ··stat:39274 ··stat:
39275 ····path:·/boot/grub/grub.cfg39275 ····path:·/boot/grub/grub.cfg
39276 ··register:·file_exists39276 ··register:·file_exists
39277 ··when:39277 ··when:
39278 ··-·'"grub2-common"·in·ansible_facts.packages' 
39279 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'39278 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 39279 ··-·'"grub2-common"·in·ansible_facts.packages'
39280 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]39280 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
39281 ··tags:39281 ··tags:
39282 ··-·NIST-800-171-3.4.539282 ··-·NIST-800-171-3.4.5
39283 ··-·NIST-800-53-AC-6(1)39283 ··-·NIST-800-53-AC-6(1)
39284 ··-·NIST-800-53-CM-6(a)39284 ··-·NIST-800-53-CM-6(a)
39285 ··-·configure_strategy39285 ··-·configure_strategy
39286 ··-·file_permissions_grub2_cfg39286 ··-·file_permissions_grub2_cfg
Offset 39291, 16 lines modifiedOffset 39291, 16 lines modified
39291 ··-·no_reboot_needed39291 ··-·no_reboot_needed
  
39292 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg39292 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
39293 ··file:39293 ··file:
39294 ····path:·/boot/grub/grub.cfg39294 ····path:·/boot/grub/grub.cfg
39295 ····mode:·u-xs,g-xwrs,o-xwrt39295 ····mode:·u-xs,g-xwrs,o-xwrt
39296 ··when:39296 ··when:
39297 ··-·'"grub2-common"·in·ansible_facts.packages' 
39298 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'39297 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 39298 ··-·'"grub2-common"·in·ansible_facts.packages'
39299 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]39299 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
39300 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists39300 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
39301 ··tags:39301 ··tags:
39302 ··-·NIST-800-171-3.4.539302 ··-·NIST-800-171-3.4.5
39303 ··-·NIST-800-53-AC-6(1)39303 ··-·NIST-800-53-AC-6(1)
39304 ··-·NIST-800-53-CM-6(a)39304 ··-·NIST-800-53-CM-6(a)
39305 ··-·configure_strategy39305 ··-·configure_strategy
Offset 46780, 14 lines modifiedOffset 46780, 30 lines modified
46780 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,46780 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,
46781 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,46781 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,
46782 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,46782 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,
46783 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR46783 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR
46784 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,46784 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,
46785 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,46785 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,
46786 ············2.2.346786 ············2.2.3
 46787 Remediation_OSBuild_Blueprint_snippet_⇲
  
 46788 [customizations.services]
 46789 disabled·=·["avahi-daemon"]
 46790 Remediation_Puppet_snippet_⇲
 46791 Complexity:·low
 46792 Disruption:·low
 46793 Strategy:···enable
 46794 include·disable_avahi-daemon
  
 46795 class·disable_avahi-daemon·{
 46796 ··service·{'avahi-daemon':
 46797 ····enable·=>·false,
 46798 ····ensure·=>·'stopped',
Max diff block lines reached; 2796/7887 bytes (35.45%) of diff not shown.
49.3 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_workstation.html
    
Offset 176549, 24 lines modifiedOffset 176549, 24 lines modified
002b1a40:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</002b1a40:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
002b1a50:·7468·3e3c·7464·3e63·6f6e·6669·6775·7265··th><td>configure002b1a50:·7468·3e3c·7464·3e63·6f6e·6669·6775·7265··th><td>configure
002b1a60:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl002b1a60:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
002b1a70:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R002b1a70:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
002b1a80:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap002b1a80:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
002b1a90:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in002b1a90:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
002b1aa0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor002b1aa0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 002b1ab0:·6d73·0a69·6620·5b20·2120·2d66·202f·7379··ms.if·[·!·-f·/sy
002b1ab0:·6d73·0a69·6620·6470·6b67·2d71·7565·7279··ms.if·dpkg-query 
002b1ac0:·202d·2d73·686f·7720·2d2d·7368·6f77·666f···--show·--showfo 
002b1ad0:·726d·6174·3d27·247b·6462·3a53·7461·7475··rmat='${db:Statu 
002b1ae0:·732d·5374·6174·7573·7d5c·6e27·2027·6772··s-Status}\n'·'gr 
002b1af0:·7562·322d·636f·6d6d·6f6e·2720·3226·6774··ub2-common'·2&gt 
002b1b00:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre 
002b1b10:·7020·2d71·2069·6e73·7461·6c6c·6564·2026··p·-q·installed·& 
002b1b20:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
002b1b30:·202f·7379·732f·6669·726d·7761·7265·2f65···/sys/firmware/e002b1ac0:·732f·6669·726d·7761·7265·2f65·6669·205d··s/firmware/efi·]
 002b1ad0:·2026·616d·703b·2661·6d70·3b20·6470·6b67···&amp;&amp;·dpkg
 002b1ae0:·2d71·7565·7279·202d·2d73·686f·7720·2d2d··-query·--show·--
 002b1af0:·7368·6f77·666f·726d·6174·3d27·247b·6462··showformat='${db
 002b1b00:·3a53·7461·7475·732d·5374·6174·7573·7d5c··:Status-Status}\
 002b1b10:·6e27·2027·6772·7562·322d·636f·6d6d·6f6e··n'·'grub2-common
 002b1b20:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null
 002b1b30:·207c·2067·7265·7020·2d71·2069·6e73·7461···|·grep·-q·insta
002b1b40:·6669·205d·2026·616d·703b·2661·6d70·3b20··fi·]·&amp;&amp;·002b1b40:·6c6c·6564·2026·616d·703b·2661·6d70·3b20··lled·&amp;&amp;·
002b1b50:·7b20·5b20·2120·2d66·202f·2e64·6f63·6b65··{·[·!·-f·/.docke002b1b50:·7b20·5b20·2120·2d66·202f·2e64·6f63·6b65··{·[·!·-f·/.docke
002b1b60:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp002b1b60:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
002b1b70:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c002b1b70:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
002b1b80:·6f6e·7461·696e·6572·656e·7620·5d3b·207d··ontainerenv·];·}002b1b80:·6f6e·7461·696e·6572·656e·7620·5d3b·207d··ontainerenv·];·}
002b1b90:·3b20·7468·656e·0a0a·6368·6f77·6e20·3020··;·then..chown·0·002b1b90:·3b20·7468·656e·0a0a·6368·6f77·6e20·3020··;·then..chown·0·
002b1ba0:·2f62·6f6f·742f·6772·7562·2f67·7275·622e··/boot/grub/grub.002b1ba0:·2f62·6f6f·742f·6772·7562·2f67·7275·622e··/boot/grub/grub.
002b1bb0:·6366·670a·0a65·6c73·650a·2020·2020·2667··cfg..else.····&g002b1bb0:·6366·670a·0a65·6c73·650a·2020·2020·2667··cfg..else.····&g
Offset 176627, 22 lines modifiedOffset 176627, 22 lines modified
002b1f20:·6d65·3a20·5465·7374·2066·6f72·2065·7869··me:·Test·for·exi002b1f20:·6d65·3a20·5465·7374·2066·6f72·2065·7869··me:·Test·for·exi
002b1f30:·7374·656e·6365·202f·626f·6f74·2f67·7275··stence·/boot/gru002b1f30:·7374·656e·6365·202f·626f·6f74·2f67·7275··stence·/boot/gru
002b1f40:·622f·6772·7562·2e63·6667·0a20·2073·7461··b/grub.cfg.··sta002b1f40:·622f·6772·7562·2e63·6667·0a20·2073·7461··b/grub.cfg.··sta
002b1f50:·743a·0a20·2020·2070·6174·683a·202f·626f··t:.····path:·/bo002b1f50:·743a·0a20·2020·2070·6174·683a·202f·626f··t:.····path:·/bo
002b1f60:·6f74·2f67·7275·622f·6772·7562·2e63·6667··ot/grub/grub.cfg002b1f60:·6f74·2f67·7275·622f·6772·7562·2e63·6667··ot/grub/grub.cfg
002b1f70:·0a20·2072·6567·6973·7465·723a·2066·696c··.··register:·fil002b1f70:·0a20·2072·6567·6973·7465·723a·2066·696c··.··register:·fil
002b1f80:·655f·6578·6973·7473·0a20·2077·6865·6e3a··e_exists.··when:002b1f80:·655f·6578·6973·7473·0a20·2077·6865·6e3a··e_exists.··when:
002b1f90:·0a20·202d·2027·2267·7275·6232·2d63·6f6d··.··-·'"grub2-com 
002b1fa0:·6d6f·6e22·2069·6e20·616e·7369·626c·655f··mon"·in·ansible_ 
002b1fb0:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
002b1fc0:·2020·2d20·2722·2f62·6f6f·742f·6566·6922····-·'"/boot/efi" 
002b1fd0:·206e·6f74·2069·6e20·616e·7369·626c·655f···not·in·ansible_ 
002b1fe0:·6d6f·756e·7473·207c·206d·6170·2861·7474··mounts·|·map(att 
002b1ff0:·7269·6275·7465·3d22·6d6f·756e·7422·2920··ribute="mount")·002b1f90:·0a20·202d·2027·222f·626f·6f74·2f65·6669··.··-·'"/boot/efi
 002b1fa0:·2220·6e6f·7420·696e·2061·6e73·6962·6c65··"·not·in·ansible
 002b1fb0:·5f6d·6f75·6e74·7320·7c20·6d61·7028·6174··_mounts·|·map(at
 002b1fc0:·7472·6962·7574·653d·226d·6f75·6e74·2229··tribute="mount")
 002b1fd0:·207c·206c·6973·7427·0a20·202d·2027·2267···|·list'.··-·'"g
 002b1fe0:·7275·6232·2d63·6f6d·6d6f·6e22·2069·6e20··rub2-common"·in·
 002b1ff0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
002b2000:·7c20·6c69·7374·270a·2020·2d20·616e·7369··|·list'.··-·ansi002b2000:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi
002b2010:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati002b2010:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
002b2020:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[002b2020:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
002b2030:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",002b2030:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
002b2040:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm002b2040:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
002b2050:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"002b2050:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
002b2060:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ002b2060:·5d0a·2020·7461·6773·3a0a·2020·2d20·434a··].··tags:.··-·CJ
002b2070:·4953·2d35·2e35·2e32·2e32·0a20·202d·204e··IS-5.5.2.2.··-·N002b2070:·4953·2d35·2e35·2e32·2e32·0a20·202d·204e··IS-5.5.2.2.··-·N
Offset 176662, 22 lines modifiedOffset 176662, 22 lines modified
002b2150:·6564·6564·0a0a·2d20·6e61·6d65·3a20·456e··eded..-·name:·En002b2150:·6564·6564·0a0a·2d20·6e61·6d65·3a20·456e··eded..-·name:·En
002b2160:·7375·7265·206f·776e·6572·2030·206f·6e20··sure·owner·0·on·002b2160:·7375·7265·206f·776e·6572·2030·206f·6e20··sure·owner·0·on·
002b2170:·2f62·6f6f·742f·6772·7562·2f67·7275·622e··/boot/grub/grub.002b2170:·2f62·6f6f·742f·6772·7562·2f67·7275·622e··/boot/grub/grub.
002b2180:·6366·670a·2020·6669·6c65·3a0a·2020·2020··cfg.··file:.····002b2180:·6366·670a·2020·6669·6c65·3a0a·2020·2020··cfg.··file:.····
002b2190:·7061·7468·3a20·2f62·6f6f·742f·6772·7562··path:·/boot/grub002b2190:·7061·7468·3a20·2f62·6f6f·742f·6772·7562··path:·/boot/grub
002b21a0:·2f67·7275·622e·6366·670a·2020·2020·6f77··/grub.cfg.····ow002b21a0:·2f67·7275·622e·6366·670a·2020·2020·6f77··/grub.cfg.····ow
002b21b0:·6e65·723a·2027·3027·0a20·2077·6865·6e3a··ner:·'0'.··when:002b21b0:·6e65·723a·2027·3027·0a20·2077·6865·6e3a··ner:·'0'.··when:
002b21c0:·0a20·202d·2027·2267·7275·6232·2d63·6f6d··.··-·'"grub2-com 
002b21d0:·6d6f·6e22·2069·6e20·616e·7369·626c·655f··mon"·in·ansible_ 
002b21e0:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
002b21f0:·2020·2d20·2722·2f62·6f6f·742f·6566·6922····-·'"/boot/efi" 
002b2200:·206e·6f74·2069·6e20·616e·7369·626c·655f···not·in·ansible_ 
002b2210:·6d6f·756e·7473·207c·206d·6170·2861·7474··mounts·|·map(att 
002b2220:·7269·6275·7465·3d22·6d6f·756e·7422·2920··ribute="mount")·002b21c0:·0a20·202d·2027·222f·626f·6f74·2f65·6669··.··-·'"/boot/efi
 002b21d0:·2220·6e6f·7420·696e·2061·6e73·6962·6c65··"·not·in·ansible
 002b21e0:·5f6d·6f75·6e74·7320·7c20·6d61·7028·6174··_mounts·|·map(at
 002b21f0:·7472·6962·7574·653d·226d·6f75·6e74·2229··tribute="mount")
 002b2200:·207c·206c·6973·7427·0a20·202d·2027·2267···|·list'.··-·'"g
 002b2210:·7275·6232·2d63·6f6d·6d6f·6e22·2069·6e20··rub2-common"·in·
 002b2220:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
002b2230:·7c20·6c69·7374·270a·2020·2d20·616e·7369··|·list'.··-·ansi002b2230:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi
002b2240:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati002b2240:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
002b2250:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[002b2250:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
002b2260:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",002b2260:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
002b2270:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm002b2270:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
002b2280:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"002b2280:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
002b2290:·5d0a·2020·2d20·6669·6c65·5f65·7869·7374··].··-·file_exist002b2290:·5d0a·2020·2d20·6669·6c65·5f65·7869·7374··].··-·file_exist
002b22a0:·732e·7374·6174·2069·7320·6465·6669·6e65··s.stat·is·define002b22a0:·732e·7374·6174·2069·7320·6465·6669·6e65··s.stat·is·define
Offset 177119, 24 lines modifiedOffset 177119, 24 lines modified
002b3de0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy002b3de0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
002b3df0:·3a3c·2f74·683e·3c74·643e·636f·6e66·6967··:</th><td>config002b3df0:·3a3c·2f74·683e·3c74·643e·636f·6e66·6967··:</th><td>config
002b3e00:·7572·653c·2f74·643e·3c2f·7472·3e3c·2f74··ure</td></tr></t002b3e00:·7572·653c·2f74·643e·3c2f·7472·3e3c·2f74··ure</td></tr></t
002b3e10:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>002b3e10:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
002b3e20:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is002b3e20:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
002b3e30:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only002b3e30:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
002b3e40:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat002b3e40:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 002b3e50:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
002b3e50:·666f·726d·730a·6966·2064·706b·672d·7175··forms.if·dpkg-qu 
002b3e60:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho 
002b3e70:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St 
002b3e80:·6174·7573·2d53·7461·7475·737d·5c6e·2720··atus-Status}\n'· 
002b3e90:·2767·7275·6232·2d63·6f6d·6d6f·6e27·2032··'grub2-common'·2 
002b3ea0:·2667·743b·2f64·6576·2f6e·756c·6c20·7c20··&gt;/dev/null·|· 
002b3eb0:·6772·6570·202d·7120·696e·7374·616c·6c65··grep·-q·installe 
002b3ec0:·6420·2661·6d70·3b26·616d·703b·205b·2021··d·&amp;&amp;·[·! 
002b3ed0:·202d·6620·2f73·7973·2f66·6972·6d77·6172···-f·/sys/firmwar002b3e60:·2f73·7973·2f66·6972·6d77·6172·652f·6566··/sys/firmware/ef
002b3ee0:·652f·6566·6920·5d20·2661·6d70·3b26·616d··e/efi·]·&amp;&am002b3e70:·6920·5d20·2661·6d70·3b26·616d·703b·2064··i·]·&amp;&amp;·d
 002b3e80:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show
 002b3e90:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$
 002b3ea0:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu
 002b3eb0:·737d·5c6e·2720·2767·7275·6232·2d63·6f6d··s}\n'·'grub2-com
 002b3ec0:·6d6f·6e27·2032·2667·743b·2f64·6576·2f6e··mon'·2&gt;/dev/n
 002b3ed0:·756c·6c20·7c20·6772·6570·202d·7120·696e··ull·|·grep·-q·in
 002b3ee0:·7374·616c·6c65·6420·2661·6d70·3b26·616d··stalled·&amp;&am
002b3ef0:·703b·207b·205b·2021·202d·6620·2f2e·646f··p;·{·[·!·-f·/.do002b3ef0:·703b·207b·205b·2021·202d·6620·2f2e·646f··p;·{·[·!·-f·/.do
002b3f00:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&002b3f00:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&
002b3f10:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run002b3f10:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run
002b3f20:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]002b3f20:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]
002b3f30:·3b20·7d3b·2074·6865·6e0a·0a63·686d·6f64··;·};·then..chmod002b3f30:·3b20·7d3b·2074·6865·6e0a·0a63·686d·6f64··;·};·then..chmod
002b3f40:·2075·2d78·732c·672d·7877·7273·2c6f·2d78···u-xs,g-xwrs,o-x002b3f40:·2075·2d78·732c·672d·7877·7273·2c6f·2d78···u-xs,g-xwrs,o-x
002b3f50:·7772·7420·2f62·6f6f·742f·6772·7562·2f67··wrt·/boot/grub/g002b3f50:·7772·7420·2f62·6f6f·742f·6772·7562·2f67··wrt·/boot/grub/g
Offset 177196, 22 lines modifiedOffset 177196, 22 lines modified
002b42b0:·0a2d·206e·616d·653a·2054·6573·7420·666f··.-·name:·Test·fo002b42b0:·0a2d·206e·616d·653a·2054·6573·7420·666f··.-·name:·Test·fo
002b42c0:·7220·6578·6973·7465·6e63·6520·2f62·6f6f··r·existence·/boo002b42c0:·7220·6578·6973·7465·6e63·6520·2f62·6f6f··r·existence·/boo
002b42d0:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.002b42d0:·742f·6772·7562·2f67·7275·622e·6366·670a··t/grub/grub.cfg.
Max diff block lines reached; 33208/42456 bytes (78.22%) of diff not shown.
7.73 KB
html2text {}
    
Offset 39389, 16 lines modifiedOffset 39389, 16 lines modified
39389 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,39389 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,
39390 ············Req-7.1,·1.5.239390 ············Req-7.1,·1.5.2
39391 Remediation_Shell_script_⇲39391 Remediation_Shell_script_⇲
39392 Complexity:·low39392 Complexity:·low
39393 Disruption:·low39393 Disruption:·low
39394 Strategy:···configure39394 Strategy:···configure
39395 #·Remediation·is·applicable·only·in·certain·platforms39395 #·Remediation·is·applicable·only·in·certain·platforms
39396 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&·[·!39396 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/
39397 -f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then39397 null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
39398 chown·0·/boot/grub/grub.cfg39398 chown·0·/boot/grub/grub.cfg
  
39399 else39399 else
39400 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'39400 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
39401 fi39401 fi
39402 Remediation_Ansible_snippet_⇲39402 Remediation_Ansible_snippet_⇲
Offset 39422, 16 lines modifiedOffset 39422, 16 lines modified
39422 ··-·no_reboot_needed39422 ··-·no_reboot_needed
  
39423 -·name:·Test·for·existence·/boot/grub/grub.cfg39423 -·name:·Test·for·existence·/boot/grub/grub.cfg
39424 ··stat:39424 ··stat:
39425 ····path:·/boot/grub/grub.cfg39425 ····path:·/boot/grub/grub.cfg
39426 ··register:·file_exists39426 ··register:·file_exists
39427 ··when:39427 ··when:
39428 ··-·'"grub2-common"·in·ansible_facts.packages' 
39429 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'39428 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 39429 ··-·'"grub2-common"·in·ansible_facts.packages'
39430 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]39430 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
39431 ··tags:39431 ··tags:
39432 ··-·CJIS-5.5.2.239432 ··-·CJIS-5.5.2.2
39433 ··-·NIST-800-171-3.4.539433 ··-·NIST-800-171-3.4.5
39434 ··-·NIST-800-53-AC-6(1)39434 ··-·NIST-800-53-AC-6(1)
39435 ··-·NIST-800-53-CM-6(a)39435 ··-·NIST-800-53-CM-6(a)
39436 ··-·PCI-DSS-Req-7.139436 ··-·PCI-DSS-Req-7.1
Offset 39443, 16 lines modifiedOffset 39443, 16 lines modified
39443 ··-·no_reboot_needed39443 ··-·no_reboot_needed
  
39444 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg39444 -·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
39445 ··file:39445 ··file:
39446 ····path:·/boot/grub/grub.cfg39446 ····path:·/boot/grub/grub.cfg
39447 ····owner:·'0'39447 ····owner:·'0'
39448 ··when:39448 ··when:
39449 ··-·'"grub2-common"·in·ansible_facts.packages' 
39450 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'39449 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 39450 ··-·'"grub2-common"·in·ansible_facts.packages'
39451 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]39451 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
39452 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists39452 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
39453 ··tags:39453 ··tags:
39454 ··-·CJIS-5.5.2.239454 ··-·CJIS-5.5.2.2
39455 ··-·NIST-800-171-3.4.539455 ··-·NIST-800-171-3.4.5
39456 ··-·NIST-800-53-AC-6(1)39456 ··-·NIST-800-53-AC-6(1)
39457 ··-·NIST-800-53-CM-6(a)39457 ··-·NIST-800-53-CM-6(a)
Offset 39478, 16 lines modifiedOffset 39478, 16 lines modified
39478 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),39478 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),
39479 ············PR.AC-4,·PR.DS-5,·1.5.239479 ············PR.AC-4,·PR.DS-5,·1.5.2
39480 Remediation_Shell_script_⇲39480 Remediation_Shell_script_⇲
39481 Complexity:·low39481 Complexity:·low
39482 Disruption:·low39482 Disruption:·low
39483 Strategy:···configure39483 Strategy:···configure
39484 #·Remediation·is·applicable·only·in·certain·platforms39484 #·Remediation·is·applicable·only·in·certain·platforms
39485 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/dev/null·|·grep·-q·installed·&&39485 if·[·!·-f·/sys/firmware/efi·]·&&·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/
39486 [·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then39486 dev/null·|·grep·-q·installed·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
39487 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg39487 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub/grub.cfg
  
39488 else39488 else
39489 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'39489 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
39490 fi39490 fi
39491 Remediation_Ansible_snippet_⇲39491 Remediation_Ansible_snippet_⇲
Offset 39509, 16 lines modifiedOffset 39509, 16 lines modified
39509 ··-·no_reboot_needed39509 ··-·no_reboot_needed
  
39510 -·name:·Test·for·existence·/boot/grub/grub.cfg39510 -·name:·Test·for·existence·/boot/grub/grub.cfg
39511 ··stat:39511 ··stat:
39512 ····path:·/boot/grub/grub.cfg39512 ····path:·/boot/grub/grub.cfg
39513 ··register:·file_exists39513 ··register:·file_exists
39514 ··when:39514 ··when:
39515 ··-·'"grub2-common"·in·ansible_facts.packages' 
39516 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'39515 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 39516 ··-·'"grub2-common"·in·ansible_facts.packages'
39517 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]39517 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
39518 ··tags:39518 ··tags:
39519 ··-·NIST-800-171-3.4.539519 ··-·NIST-800-171-3.4.5
39520 ··-·NIST-800-53-AC-6(1)39520 ··-·NIST-800-53-AC-6(1)
39521 ··-·NIST-800-53-CM-6(a)39521 ··-·NIST-800-53-CM-6(a)
39522 ··-·configure_strategy39522 ··-·configure_strategy
39523 ··-·file_permissions_grub2_cfg39523 ··-·file_permissions_grub2_cfg
Offset 39528, 16 lines modifiedOffset 39528, 16 lines modified
39528 ··-·no_reboot_needed39528 ··-·no_reboot_needed
  
39529 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg39529 -·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
39530 ··file:39530 ··file:
39531 ····path:·/boot/grub/grub.cfg39531 ····path:·/boot/grub/grub.cfg
39532 ····mode:·u-xs,g-xwrs,o-xwrt39532 ····mode:·u-xs,g-xwrs,o-xwrt
39533 ··when:39533 ··when:
39534 ··-·'"grub2-common"·in·ansible_facts.packages' 
39535 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'39534 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 39535 ··-·'"grub2-common"·in·ansible_facts.packages'
39536 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]39536 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
39537 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists39537 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
39538 ··tags:39538 ··tags:
39539 ··-·NIST-800-171-3.4.539539 ··-·NIST-800-171-3.4.5
39540 ··-·NIST-800-53-AC-6(1)39540 ··-·NIST-800-53-AC-6(1)
39541 ··-·NIST-800-53-CM-6(a)39541 ··-·NIST-800-53-CM-6(a)
39542 ··-·configure_strategy39542 ··-·configure_strategy
Offset 47017, 14 lines modifiedOffset 47017, 30 lines modified
47017 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,47017 ············CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,
47018 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,47018 Identifiers·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,
47019 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,47019 and·········4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,
47020 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR47020 References··SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR
47021 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,47021 ············1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,
47022 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,47022 ············A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,
47023 ············2.2.347023 ············2.2.3
 47024 Remediation_OSBuild_Blueprint_snippet_⇲
  
 47025 [customizations.services]
 47026 disabled·=·["avahi-daemon"]
 47027 Remediation_Puppet_snippet_⇲
 47028 Complexity:·low
 47029 Disruption:·low
 47030 Strategy:···enable
 47031 include·disable_avahi-daemon
  
 47032 class·disable_avahi-daemon·{
 47033 ··service·{'avahi-daemon':
 47034 ····enable·=>·false,
 47035 ····ensure·=>·'stopped',
Max diff block lines reached; 2796/7887 bytes (35.45%) of diff not shown.
15.9 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-standard.html
    
Offset 31332, 112 lines modifiedOffset 31332, 112 lines modified
0007a630:·6765·743d·2223·6964·6d33·3436·3534·2220··get="#idm34654"·0007a630:·6765·743d·2223·6964·6d33·3436·3534·2220··get="#idm34654"·
0007a640:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0007a640:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0007a650:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0007a650:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0007a660:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0007a660:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0007a670:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0007a670:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0007a680:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0007a680:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0007a690:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0007a690:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0007a6a0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0007a6b0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0007a6c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0007a6d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0007a6e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0007a6f0:·6964·6d33·3436·3534·223e·3c70·7265·3e3c··idm34654"><pre><
 0007a700:·636f·6465·3e0a·5b63·7573·746f·6d69·7a61··code>.[customiza
 0007a710:·7469·6f6e·732e·7365·7276·6963·6573·5d0a··tions.services].
 0007a720:·6469·7361·626c·6564·203d·205b·2261·7070··disabled·=·["app
 0007a730:·6f72·7422·5d0a·3c2f·636f·6465·3e3c·2f70··ort"].</code></p
 0007a740:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0007a750:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0007a760:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0007a770:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0007a780:·7461·7267·6574·3d22·2369·646d·3334·3635··target="#idm3465
 0007a790:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·
 0007a7a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0007a7b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0007a7c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0007a7d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0007a7e0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0007a7f0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
 0007a800:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0007a810:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0007a820:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0007a830:·7365·2220·6964·3d22·6964·6d33·3436·3535··se"·id="idm34655
 0007a840:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0007a850:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0007a860:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0007a870:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0007a880:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0007a890:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0007a8a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0007a8b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0007a8c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0007a8d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0007a8e0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0007a8f0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0007a900:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0007a910:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab
 0007a920:·6c65·5f61·7070·6f72·740a·0a63·6c61·7373··le_apport..class
 0007a930:·2064·6973·6162·6c65·5f61·7070·6f72·7420···disable_apport·
 0007a940:·7b0a·2020·7365·7276·6963·6520·7b27·6170··{.··service·{'ap
 0007a950:·706f·7274·273a·0a20·2020·2065·6e61·626c··port':.····enabl
 0007a960:·6520·3d26·6774·3b20·6661·6c73·652c·0a20··e·=&gt;·false,.·
 0007a970:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0007a980:·2773·746f·7070·6564·272c·0a20·207d·0a7d··'stopped',.··}.}
 0007a990:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0007a9a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0007a9b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0007a9c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0007a9d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0007a9e0:·743d·2223·6964·6d33·3436·3536·2220·7461··t="#idm34656"·ta
 0007a9f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0007aa00:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0007aa10:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0007aa20:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0007aa30:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0007aa40:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0007a6a0:·6e20·4b75·6265·726e·6574·6573·2073·6e69··n·Kubernetes·sni0007aa50:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp
0007a6b0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0007aa60:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0007a6c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0007aa70:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0007a6d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0007aa80:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0007a6e0:·7073·6522·2069·643d·2269·646d·3334·3635··pse"·id="idm34650007aa90:·6522·2069·643d·2269·646d·3334·3635·3622··e"·id="idm34656"
0007a6f0:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=0007aaa0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0007a700:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0007aab0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0007a710:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0007aac0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0007a720:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0007aad0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0007a730:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0007aae0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0007a740:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0007aaf0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0007a750:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0007ab00:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0007a760:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0007ab10:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0007a770:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium0007ab20:·2f74·683e·3c74·643e·6d65·6469·756d·3c2f··/th><td>medium</
0007a780:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0007ab30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0007a790:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0007ab40:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0007a7a0:·643e·7472·7565·3c2f·7464·3e3c·2f74·723e··d>true</td></tr>0007ab50:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t
0007a7b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0007ab60:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0007a7c0:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl0007ab70:·2f74·683e·3c74·643e·6469·7361·626c·653c··/th><td>disable<
0007a7d0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0007ab80:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0007a7e0:·6c65·3e3c·7072·653e·3c63·6f64·653e·6170··le><pre><code>ap0007ab90:·3e3c·7072·653e·3c63·6f64·653e·6170·6956··><pre><code>apiV
0007a7f0:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin0007aba0:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec
0007a800:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o0007abb0:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope
0007a810:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k0007abc0:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin
0007a820:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf0007abd0:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig
0007a830:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi0007abe0:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:
0007a840:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:0007abf0:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·
0007a850:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·0007ac00:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3.
0007a860:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system0007ac10:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd:
0007a870:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:.0007ac20:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.··
0007a880:·2020·2020·2020·2d20·6e61·6d65·3a20·6170········-·name:·ap0007ac30:·2020·2020·2d20·6e61·6d65·3a20·6170·706f······-·name:·appo
0007a890:·706f·7274·2e73·6572·7669·6365·0a20·2020··port.service.···0007ac40:·7274·2e73·6572·7669·6365·0a20·2020·2020··rt.service.·····
0007a8a0:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa0007ac50:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals
0007a8b0:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask0007ac60:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:·
0007a8c0:·3a20·7472·7565·0a20·2020·2020·202d·206e··:·true.······-·n0007ac70:·7472·7565·0a20·2020·2020·202d·206e·616d··true.······-·nam
0007a8d0:·616d·653a·2061·7070·6f72·742e·736f·636b··ame:·apport.sock0007ac80:·653a·2061·7070·6f72·742e·736f·636b·6574··e:·apport.socket
0007a8e0:·6574·0a20·2020·2020·2020·2065·6e61·626c··et.········enabl0007ac90:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled
0007a8f0:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······0007aca0:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
0007a900:·2020·6d61·736b·3a20·7472·7565·0a3c·2f63····mask:·true.</c0007acb0:·6d61·736b·3a20·7472·7565·0a3c·2f63·6f64··mask:·true.</cod
0007a910:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0007a920:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0007a930:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0007a940:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0007a950:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0007a960:·6964·6d33·3436·3535·2220·7461·6269·6e64··idm34655"·tabind 
0007a970:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0007a980:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0007a990:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0007a9a0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0007a9b0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0007a9c0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu 
0007a9d0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0007a9e0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0007a9f0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0007aa00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0007aa10:·6170·7365·2220·6964·3d22·6964·6d33·3436··apse"·id="idm346 
0007aa20:·3535·223e·3c70·7265·3e3c·636f·6465·3e0a··55"><pre><code>. 
0007aa30:·5b63·7573·746f·6d69·7a61·7469·6f6e·732e··[customizations. 
0007aa40:·7365·7276·6963·6573·5d0a·6469·7361·626c··services].disabl 
0007aa50:·6564·203d·205b·2261·7070·6f72·7422·5d0a··ed·=·["apport"]. 
0007aa60:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
Max diff block lines reached; 414/14518 bytes (2.85%) of diff not shown.
1.57 KB
html2text {}
    
Offset 2157, 14 lines modifiedOffset 2157, 30 lines modified
2157 $·sudo·systemctl·mask·--now·apport.service2157 $·sudo·systemctl·mask·--now·apport.service
2158 ···························The·Apport·service·modifies·the·kernel·fs.suid_dumpable2158 ···························The·Apport·service·modifies·the·kernel·fs.suid_dumpable
2159 Rationale:·················configuration·at·runtime·which·prevents·other·hardening·from2159 Rationale:·················configuration·at·runtime·which·prevents·other·hardening·from
2160 ···························being·persistent.·Disabling·the·service·prevents·this·behavior.2160 ···························being·persistent.·Disabling·the·service·prevents·this·behavior.
2161 Severity: ················unknown2161 Severity: ················unknown
2162 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_apport_disabled2162 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_apport_disabled
2163 Identifiers·and·References2163 Identifiers·and·References
 2164 Remediation_OSBuild_Blueprint_snippet_⇲
  
 2165 [customizations.services]
 2166 disabled·=·["apport"]
 2167 Remediation_Puppet_snippet_⇲
 2168 Complexity:·low
 2169 Disruption:·low
 2170 Strategy:···enable
 2171 include·disable_apport
  
 2172 class·disable_apport·{
 2173 ··service·{'apport':
 2174 ····enable·=>·false,
 2175 ····ensure·=>·'stopped',
 2176 ··}
 2177 }
2164 Remediation_Kubernetes_snippet_⇲2178 Remediation_Kubernetes_snippet_⇲
2165 Complexity:·low2179 Complexity:·low
2166 Disruption:·medium2180 Disruption:·medium
2167 Reboot:·····true2181 Reboot:·····true
2168 Strategy:···disable2182 Strategy:···disable
2169 apiVersion:·machineconfiguration.openshift.io/v12183 apiVersion:·machineconfiguration.openshift.io/v1
2170 kind:·MachineConfig2184 kind:·MachineConfig
Offset 2176, 30 lines modifiedOffset 2192, 14 lines modified
2176 ······units:2192 ······units:
2177 ······-·name:·apport.service2193 ······-·name:·apport.service
2178 ········enabled:·false2194 ········enabled:·false
2179 ········mask:·true2195 ········mask:·true
2180 ······-·name:·apport.socket2196 ······-·name:·apport.socket
2181 ········enabled:·false2197 ········enabled:·false
2182 ········mask:·true2198 ········mask:·true
2183 Remediation_OSBuild_Blueprint_snippet_⇲ 
  
2184 [customizations.services] 
2185 disabled·=·["apport"] 
2186 Remediation_Puppet_snippet_⇲ 
2187 Complexity:·low 
2188 Disruption:·low 
2189 Strategy:···enable 
2190 include·disable_apport 
  
2191 class·disable_apport·{ 
2192 ··service·{'apport': 
2193 ····enable·=>·false, 
2194 ····ensure·=>·'stopped', 
2195 ··} 
2196 } 
2197 Remediation_Shell_script_⇲2199 Remediation_Shell_script_⇲
2198 Complexity:·low2200 Complexity:·low
2199 Disruption:·low2201 Disruption:·low
2200 Strategy:···disable2202 Strategy:···disable
  
  
2201 SYSTEMCTL_EXEC='/usr/bin/systemctl'2203 SYSTEMCTL_EXEC='/usr/bin/systemctl'
2.71 KB
./usr/share/scap-security-guide/ansible/ubuntu2004-playbook-cis_level1_server.yml
Ordering differences only
    
Offset 1092, 16 lines modifiedOffset 1092, 16 lines modified
1092 ······-·no_reboot_needed1092 ······-·no_reboot_needed
  
1093 ····-·name:·Test·for·existence·/boot/grub/grub.cfg1093 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
1094 ······stat:1094 ······stat:
1095 ········path:·/boot/grub/grub.cfg1095 ········path:·/boot/grub/grub.cfg
1096 ······register:·file_exists1096 ······register:·file_exists
1097 ······when:1097 ······when:
1098 ······-·'"grub2-common"·in·ansible_facts.packages' 
1099 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1098 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1099 ······-·'"grub2-common"·in·ansible_facts.packages'
1100 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1100 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1101 ······tags:1101 ······tags:
1102 ······-·CJIS-5.5.2.21102 ······-·CJIS-5.5.2.2
1103 ······-·NIST-800-171-3.4.51103 ······-·NIST-800-171-3.4.5
1104 ······-·NIST-800-53-AC-6(1)1104 ······-·NIST-800-53-AC-6(1)
1105 ······-·NIST-800-53-CM-6(a)1105 ······-·NIST-800-53-CM-6(a)
1106 ······-·PCI-DSS-Req-7.11106 ······-·PCI-DSS-Req-7.1
Offset 1113, 16 lines modifiedOffset 1113, 16 lines modified
1113 ······-·no_reboot_needed1113 ······-·no_reboot_needed
  
1114 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg1114 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
1115 ······file:1115 ······file:
1116 ········path:·/boot/grub/grub.cfg1116 ········path:·/boot/grub/grub.cfg
1117 ········owner:·'0'1117 ········owner:·'0'
1118 ······when:1118 ······when:
1119 ······-·'"grub2-common"·in·ansible_facts.packages' 
1120 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1119 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1120 ······-·'"grub2-common"·in·ansible_facts.packages'
1121 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1121 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1122 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1122 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1123 ······tags:1123 ······tags:
1124 ······-·CJIS-5.5.2.21124 ······-·CJIS-5.5.2.2
1125 ······-·NIST-800-171-3.4.51125 ······-·NIST-800-171-3.4.5
1126 ······-·NIST-800-53-AC-6(1)1126 ······-·NIST-800-53-AC-6(1)
1127 ······-·NIST-800-53-CM-6(a)1127 ······-·NIST-800-53-CM-6(a)
Offset 1150, 16 lines modifiedOffset 1150, 16 lines modified
1150 ······-·no_reboot_needed1150 ······-·no_reboot_needed
  
1151 ····-·name:·Test·for·existence·/boot/grub/grub.cfg1151 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
1152 ······stat:1152 ······stat:
1153 ········path:·/boot/grub/grub.cfg1153 ········path:·/boot/grub/grub.cfg
1154 ······register:·file_exists1154 ······register:·file_exists
1155 ······when:1155 ······when:
1156 ······-·'"grub2-common"·in·ansible_facts.packages' 
1157 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1156 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1157 ······-·'"grub2-common"·in·ansible_facts.packages'
1158 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1158 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1159 ······tags:1159 ······tags:
1160 ······-·NIST-800-171-3.4.51160 ······-·NIST-800-171-3.4.5
1161 ······-·NIST-800-53-AC-6(1)1161 ······-·NIST-800-53-AC-6(1)
1162 ······-·NIST-800-53-CM-6(a)1162 ······-·NIST-800-53-CM-6(a)
1163 ······-·configure_strategy1163 ······-·configure_strategy
1164 ······-·file_permissions_grub2_cfg1164 ······-·file_permissions_grub2_cfg
Offset 1169, 16 lines modifiedOffset 1169, 16 lines modified
1169 ······-·no_reboot_needed1169 ······-·no_reboot_needed
  
1170 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg1170 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
1171 ······file:1171 ······file:
1172 ········path:·/boot/grub/grub.cfg1172 ········path:·/boot/grub/grub.cfg
1173 ········mode:·u-xs,g-xwrs,o-xwrt1173 ········mode:·u-xs,g-xwrs,o-xwrt
1174 ······when:1174 ······when:
1175 ······-·'"grub2-common"·in·ansible_facts.packages' 
1176 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1175 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1176 ······-·'"grub2-common"·in·ansible_facts.packages'
1177 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1177 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1178 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1178 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1179 ······tags:1179 ······tags:
1180 ······-·NIST-800-171-3.4.51180 ······-·NIST-800-171-3.4.5
1181 ······-·NIST-800-53-AC-6(1)1181 ······-·NIST-800-53-AC-6(1)
1182 ······-·NIST-800-53-CM-6(a)1182 ······-·NIST-800-53-CM-6(a)
1183 ······-·configure_strategy1183 ······-·configure_strategy
2.71 KB
./usr/share/scap-security-guide/ansible/ubuntu2004-playbook-cis_level1_workstation.yml
Ordering differences only
    
Offset 1061, 16 lines modifiedOffset 1061, 16 lines modified
1061 ······-·no_reboot_needed1061 ······-·no_reboot_needed
  
1062 ····-·name:·Test·for·existence·/boot/grub/grub.cfg1062 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
1063 ······stat:1063 ······stat:
1064 ········path:·/boot/grub/grub.cfg1064 ········path:·/boot/grub/grub.cfg
1065 ······register:·file_exists1065 ······register:·file_exists
1066 ······when:1066 ······when:
1067 ······-·'"grub2-common"·in·ansible_facts.packages' 
1068 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1067 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1068 ······-·'"grub2-common"·in·ansible_facts.packages'
1069 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1069 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1070 ······tags:1070 ······tags:
1071 ······-·CJIS-5.5.2.21071 ······-·CJIS-5.5.2.2
1072 ······-·NIST-800-171-3.4.51072 ······-·NIST-800-171-3.4.5
1073 ······-·NIST-800-53-AC-6(1)1073 ······-·NIST-800-53-AC-6(1)
1074 ······-·NIST-800-53-CM-6(a)1074 ······-·NIST-800-53-CM-6(a)
1075 ······-·PCI-DSS-Req-7.11075 ······-·PCI-DSS-Req-7.1
Offset 1082, 16 lines modifiedOffset 1082, 16 lines modified
1082 ······-·no_reboot_needed1082 ······-·no_reboot_needed
  
1083 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg1083 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
1084 ······file:1084 ······file:
1085 ········path:·/boot/grub/grub.cfg1085 ········path:·/boot/grub/grub.cfg
1086 ········owner:·'0'1086 ········owner:·'0'
1087 ······when:1087 ······when:
1088 ······-·'"grub2-common"·in·ansible_facts.packages' 
1089 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1088 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1089 ······-·'"grub2-common"·in·ansible_facts.packages'
1090 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1090 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1091 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1091 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1092 ······tags:1092 ······tags:
1093 ······-·CJIS-5.5.2.21093 ······-·CJIS-5.5.2.2
1094 ······-·NIST-800-171-3.4.51094 ······-·NIST-800-171-3.4.5
1095 ······-·NIST-800-53-AC-6(1)1095 ······-·NIST-800-53-AC-6(1)
1096 ······-·NIST-800-53-CM-6(a)1096 ······-·NIST-800-53-CM-6(a)
Offset 1119, 16 lines modifiedOffset 1119, 16 lines modified
1119 ······-·no_reboot_needed1119 ······-·no_reboot_needed
  
1120 ····-·name:·Test·for·existence·/boot/grub/grub.cfg1120 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
1121 ······stat:1121 ······stat:
1122 ········path:·/boot/grub/grub.cfg1122 ········path:·/boot/grub/grub.cfg
1123 ······register:·file_exists1123 ······register:·file_exists
1124 ······when:1124 ······when:
1125 ······-·'"grub2-common"·in·ansible_facts.packages' 
1126 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1125 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1126 ······-·'"grub2-common"·in·ansible_facts.packages'
1127 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1127 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1128 ······tags:1128 ······tags:
1129 ······-·NIST-800-171-3.4.51129 ······-·NIST-800-171-3.4.5
1130 ······-·NIST-800-53-AC-6(1)1130 ······-·NIST-800-53-AC-6(1)
1131 ······-·NIST-800-53-CM-6(a)1131 ······-·NIST-800-53-CM-6(a)
1132 ······-·configure_strategy1132 ······-·configure_strategy
1133 ······-·file_permissions_grub2_cfg1133 ······-·file_permissions_grub2_cfg
Offset 1138, 16 lines modifiedOffset 1138, 16 lines modified
1138 ······-·no_reboot_needed1138 ······-·no_reboot_needed
  
1139 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg1139 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
1140 ······file:1140 ······file:
1141 ········path:·/boot/grub/grub.cfg1141 ········path:·/boot/grub/grub.cfg
1142 ········mode:·u-xs,g-xwrs,o-xwrt1142 ········mode:·u-xs,g-xwrs,o-xwrt
1143 ······when:1143 ······when:
1144 ······-·'"grub2-common"·in·ansible_facts.packages' 
1145 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1144 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1145 ······-·'"grub2-common"·in·ansible_facts.packages'
1146 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1146 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1147 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1147 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1148 ······tags:1148 ······tags:
1149 ······-·NIST-800-171-3.4.51149 ······-·NIST-800-171-3.4.5
1150 ······-·NIST-800-53-AC-6(1)1150 ······-·NIST-800-53-AC-6(1)
1151 ······-·NIST-800-53-CM-6(a)1151 ······-·NIST-800-53-CM-6(a)
1152 ······-·configure_strategy1152 ······-·configure_strategy
136 KB
./usr/share/scap-security-guide/ansible/ubuntu2004-playbook-cis_level2_server.yml
Ordering differences only
    
Offset 1183, 16 lines modifiedOffset 1183, 16 lines modified
  
1183 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1183 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1184 ······find:1184 ······find:
1185 ········paths:·/etc/audit/rules.d/1185 ········paths:·/etc/audit/rules.d/
1186 ········patterns:·'*.rules'1186 ········patterns:·'*.rules'
1187 ······register:·find_rules_d1187 ······register:·find_rules_d
1188 ······when:1188 ······when:
1189 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1190 ······-·'"auditd"·in·ansible_facts.packages'1189 ······-·'"auditd"·in·ansible_facts.packages'
 1190 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1191 ······tags:1191 ······tags:
1192 ······-·CJIS-5.4.1.11192 ······-·CJIS-5.4.1.1
1193 ······-·NIST-800-171-3.3.11193 ······-·NIST-800-171-3.3.1
1194 ······-·NIST-800-171-3.4.31194 ······-·NIST-800-171-3.4.3
1195 ······-·NIST-800-53-AC-6(9)1195 ······-·NIST-800-53-AC-6(9)
1196 ······-·NIST-800-53-CM-6(a)1196 ······-·NIST-800-53-CM-6(a)
1197 ······-·PCI-DSS-Req-10.5.21197 ······-·PCI-DSS-Req-10.5.2
Offset 1207, 16 lines modifiedOffset 1207, 16 lines modified
1207 ······lineinfile:1207 ······lineinfile:
1208 ········path:·'{{·item·}}'1208 ········path:·'{{·item·}}'
1209 ········regexp:·^\s*(?:-e)\s+.*$1209 ········regexp:·^\s*(?:-e)\s+.*$
1210 ········state:·absent1210 ········state:·absent
1211 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1211 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1212 ········}}'1212 ········}}'
1213 ······when:1213 ······when:
1214 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1215 ······-·'"auditd"·in·ansible_facts.packages'1214 ······-·'"auditd"·in·ansible_facts.packages'
 1215 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1216 ······tags:1216 ······tags:
1217 ······-·CJIS-5.4.1.11217 ······-·CJIS-5.4.1.1
1218 ······-·NIST-800-171-3.3.11218 ······-·NIST-800-171-3.3.1
1219 ······-·NIST-800-171-3.4.31219 ······-·NIST-800-171-3.4.3
1220 ······-·NIST-800-53-AC-6(9)1220 ······-·NIST-800-53-AC-6(9)
1221 ······-·NIST-800-53-CM-6(a)1221 ······-·NIST-800-53-CM-6(a)
1222 ······-·PCI-DSS-Req-10.5.21222 ······-·PCI-DSS-Req-10.5.2
Offset 1233, 16 lines modifiedOffset 1233, 16 lines modified
1233 ········create:·true1233 ········create:·true
1234 ········line:·-e·21234 ········line:·-e·2
1235 ········mode:·o-rwx1235 ········mode:·o-rwx
1236 ······loop:1236 ······loop:
1237 ······-·/etc/audit/audit.rules1237 ······-·/etc/audit/audit.rules
1238 ······-·/etc/audit/rules.d/immutable.rules1238 ······-·/etc/audit/rules.d/immutable.rules
1239 ······when:1239 ······when:
1240 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1241 ······-·'"auditd"·in·ansible_facts.packages'1240 ······-·'"auditd"·in·ansible_facts.packages'
 1241 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1242 ······tags:1242 ······tags:
1243 ······-·CJIS-5.4.1.11243 ······-·CJIS-5.4.1.1
1244 ······-·NIST-800-171-3.3.11244 ······-·NIST-800-171-3.3.1
1245 ······-·NIST-800-171-3.4.31245 ······-·NIST-800-171-3.4.3
1246 ······-·NIST-800-53-AC-6(9)1246 ······-·NIST-800-53-AC-6(9)
1247 ······-·NIST-800-53-CM-6(a)1247 ······-·NIST-800-53-CM-6(a)
1248 ······-·PCI-DSS-Req-10.5.21248 ······-·PCI-DSS-Req-10.5.2
Offset 1277, 16 lines modifiedOffset 1277, 16 lines modified
1277 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/1277 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
1278 ······find:1278 ······find:
1279 ········paths:·/etc/audit/rules.d1279 ········paths:·/etc/audit/rules.d
1280 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+1280 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
1281 ········patterns:·'*.rules'1281 ········patterns:·'*.rules'
1282 ······register:·find_existing_watch_rules_d1282 ······register:·find_existing_watch_rules_d
1283 ······when:1283 ······when:
1284 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1285 ······-·'"auditd"·in·ansible_facts.packages'1284 ······-·'"auditd"·in·ansible_facts.packages'
 1285 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1286 ······tags:1286 ······tags:
1287 ······-·CJIS-5.4.1.11287 ······-·CJIS-5.4.1.1
1288 ······-·NIST-800-171-3.1.71288 ······-·NIST-800-171-3.1.7
1289 ······-·NIST-800-53-AC-2(7)(b)1289 ······-·NIST-800-53-AC-2(7)(b)
1290 ······-·NIST-800-53-AC-6(9)1290 ······-·NIST-800-53-AC-6(9)
1291 ······-·NIST-800-53-AU-12(c)1291 ······-·NIST-800-53-AU-12(c)
1292 ······-·NIST-800-53-AU-2(d)1292 ······-·NIST-800-53-AU-2(d)
Offset 1303, 16 lines modifiedOffset 1303, 16 lines modified
1303 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions1303 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
1304 ······find:1304 ······find:
1305 ········paths:·/etc/audit/rules.d1305 ········paths:·/etc/audit/rules.d
1306 ········contains:·^.*(?:-F·key=|-k\s+)actions$1306 ········contains:·^.*(?:-F·key=|-k\s+)actions$
1307 ········patterns:·'*.rules'1307 ········patterns:·'*.rules'
1308 ······register:·find_watch_key1308 ······register:·find_watch_key
1309 ······when:1309 ······when:
1310 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1311 ······-·'"auditd"·in·ansible_facts.packages'1310 ······-·'"auditd"·in·ansible_facts.packages'
 1311 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1312 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1312 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1313 ········==·01313 ········==·0
1314 ······tags:1314 ······tags:
1315 ······-·CJIS-5.4.1.11315 ······-·CJIS-5.4.1.1
1316 ······-·NIST-800-171-3.1.71316 ······-·NIST-800-171-3.1.7
1317 ······-·NIST-800-53-AC-2(7)(b)1317 ······-·NIST-800-53-AC-2(7)(b)
1318 ······-·NIST-800-53-AC-6(9)1318 ······-·NIST-800-53-AC-6(9)
Offset 1329, 16 lines modifiedOffset 1329, 16 lines modified
1329 ······-·restrict_strategy1329 ······-·restrict_strategy
  
1330 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule1330 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule
1331 ······set_fact:1331 ······set_fact:
1332 ········all_files:1332 ········all_files:
1333 ········-·/etc/audit/rules.d/actions.rules1333 ········-·/etc/audit/rules.d/actions.rules
1334 ······when:1334 ······when:
1335 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1336 ······-·'"auditd"·in·ansible_facts.packages'1335 ······-·'"auditd"·in·ansible_facts.packages'
 1336 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1337 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1337 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1338 ········is·defined·and·find_existing_watch_rules_d.matched·==·01338 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1339 ······tags:1339 ······tags:
1340 ······-·CJIS-5.4.1.11340 ······-·CJIS-5.4.1.1
1341 ······-·NIST-800-171-3.1.71341 ······-·NIST-800-171-3.1.7
1342 ······-·NIST-800-53-AC-2(7)(b)1342 ······-·NIST-800-53-AC-2(7)(b)
1343 ······-·NIST-800-53-AC-6(9)1343 ······-·NIST-800-53-AC-6(9)
Offset 1355, 16 lines modifiedOffset 1355, 16 lines modified
1355 ······-·restrict_strategy1355 ······-·restrict_strategy
  
1356 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1356 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1357 ······set_fact:1357 ······set_fact:
1358 ········all_files:1358 ········all_files:
1359 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1359 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1360 ······when:1360 ······when:
1361 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1362 ······-·'"auditd"·in·ansible_facts.packages'1361 ······-·'"auditd"·in·ansible_facts.packages'
 1362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1363 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1363 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1364 ········is·defined·and·find_existing_watch_rules_d.matched·==·01364 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1365 ······tags:1365 ······tags:
1366 ······-·CJIS-5.4.1.11366 ······-·CJIS-5.4.1.1
1367 ······-·NIST-800-171-3.1.71367 ······-·NIST-800-171-3.1.7
1368 ······-·NIST-800-53-AC-2(7)(b)1368 ······-·NIST-800-53-AC-2(7)(b)
1369 ······-·NIST-800-53-AC-6(9)1369 ······-·NIST-800-53-AC-6(9)
Offset 1383, 16 lines modifiedOffset 1383, 16 lines modified
1383 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/1383 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/
Max diff block lines reached; 133550/138587 bytes (96.37%) of diff not shown.
136 KB
./usr/share/scap-security-guide/ansible/ubuntu2004-playbook-cis_level2_workstation.yml
Ordering differences only
    
Offset 1152, 16 lines modifiedOffset 1152, 16 lines modified
  
1152 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1152 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1153 ······find:1153 ······find:
1154 ········paths:·/etc/audit/rules.d/1154 ········paths:·/etc/audit/rules.d/
1155 ········patterns:·'*.rules'1155 ········patterns:·'*.rules'
1156 ······register:·find_rules_d1156 ······register:·find_rules_d
1157 ······when:1157 ······when:
1158 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1159 ······-·'"auditd"·in·ansible_facts.packages'1158 ······-·'"auditd"·in·ansible_facts.packages'
 1159 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1160 ······tags:1160 ······tags:
1161 ······-·CJIS-5.4.1.11161 ······-·CJIS-5.4.1.1
1162 ······-·NIST-800-171-3.3.11162 ······-·NIST-800-171-3.3.1
1163 ······-·NIST-800-171-3.4.31163 ······-·NIST-800-171-3.4.3
1164 ······-·NIST-800-53-AC-6(9)1164 ······-·NIST-800-53-AC-6(9)
1165 ······-·NIST-800-53-CM-6(a)1165 ······-·NIST-800-53-CM-6(a)
1166 ······-·PCI-DSS-Req-10.5.21166 ······-·PCI-DSS-Req-10.5.2
Offset 1176, 16 lines modifiedOffset 1176, 16 lines modified
1176 ······lineinfile:1176 ······lineinfile:
1177 ········path:·'{{·item·}}'1177 ········path:·'{{·item·}}'
1178 ········regexp:·^\s*(?:-e)\s+.*$1178 ········regexp:·^\s*(?:-e)\s+.*$
1179 ········state:·absent1179 ········state:·absent
1180 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1180 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1181 ········}}'1181 ········}}'
1182 ······when:1182 ······when:
1183 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1184 ······-·'"auditd"·in·ansible_facts.packages'1183 ······-·'"auditd"·in·ansible_facts.packages'
 1184 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1185 ······tags:1185 ······tags:
1186 ······-·CJIS-5.4.1.11186 ······-·CJIS-5.4.1.1
1187 ······-·NIST-800-171-3.3.11187 ······-·NIST-800-171-3.3.1
1188 ······-·NIST-800-171-3.4.31188 ······-·NIST-800-171-3.4.3
1189 ······-·NIST-800-53-AC-6(9)1189 ······-·NIST-800-53-AC-6(9)
1190 ······-·NIST-800-53-CM-6(a)1190 ······-·NIST-800-53-CM-6(a)
1191 ······-·PCI-DSS-Req-10.5.21191 ······-·PCI-DSS-Req-10.5.2
Offset 1202, 16 lines modifiedOffset 1202, 16 lines modified
1202 ········create:·true1202 ········create:·true
1203 ········line:·-e·21203 ········line:·-e·2
1204 ········mode:·o-rwx1204 ········mode:·o-rwx
1205 ······loop:1205 ······loop:
1206 ······-·/etc/audit/audit.rules1206 ······-·/etc/audit/audit.rules
1207 ······-·/etc/audit/rules.d/immutable.rules1207 ······-·/etc/audit/rules.d/immutable.rules
1208 ······when:1208 ······when:
1209 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1210 ······-·'"auditd"·in·ansible_facts.packages'1209 ······-·'"auditd"·in·ansible_facts.packages'
 1210 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1211 ······tags:1211 ······tags:
1212 ······-·CJIS-5.4.1.11212 ······-·CJIS-5.4.1.1
1213 ······-·NIST-800-171-3.3.11213 ······-·NIST-800-171-3.3.1
1214 ······-·NIST-800-171-3.4.31214 ······-·NIST-800-171-3.4.3
1215 ······-·NIST-800-53-AC-6(9)1215 ······-·NIST-800-53-AC-6(9)
1216 ······-·NIST-800-53-CM-6(a)1216 ······-·NIST-800-53-CM-6(a)
1217 ······-·PCI-DSS-Req-10.5.21217 ······-·PCI-DSS-Req-10.5.2
Offset 1246, 16 lines modifiedOffset 1246, 16 lines modified
1246 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/1246 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
1247 ······find:1247 ······find:
1248 ········paths:·/etc/audit/rules.d1248 ········paths:·/etc/audit/rules.d
1249 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+1249 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
1250 ········patterns:·'*.rules'1250 ········patterns:·'*.rules'
1251 ······register:·find_existing_watch_rules_d1251 ······register:·find_existing_watch_rules_d
1252 ······when:1252 ······when:
1253 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1254 ······-·'"auditd"·in·ansible_facts.packages'1253 ······-·'"auditd"·in·ansible_facts.packages'
 1254 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1255 ······tags:1255 ······tags:
1256 ······-·CJIS-5.4.1.11256 ······-·CJIS-5.4.1.1
1257 ······-·NIST-800-171-3.1.71257 ······-·NIST-800-171-3.1.7
1258 ······-·NIST-800-53-AC-2(7)(b)1258 ······-·NIST-800-53-AC-2(7)(b)
1259 ······-·NIST-800-53-AC-6(9)1259 ······-·NIST-800-53-AC-6(9)
1260 ······-·NIST-800-53-AU-12(c)1260 ······-·NIST-800-53-AU-12(c)
1261 ······-·NIST-800-53-AU-2(d)1261 ······-·NIST-800-53-AU-2(d)
Offset 1272, 16 lines modifiedOffset 1272, 16 lines modified
1272 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions1272 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
1273 ······find:1273 ······find:
1274 ········paths:·/etc/audit/rules.d1274 ········paths:·/etc/audit/rules.d
1275 ········contains:·^.*(?:-F·key=|-k\s+)actions$1275 ········contains:·^.*(?:-F·key=|-k\s+)actions$
1276 ········patterns:·'*.rules'1276 ········patterns:·'*.rules'
1277 ······register:·find_watch_key1277 ······register:·find_watch_key
1278 ······when:1278 ······when:
1279 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1280 ······-·'"auditd"·in·ansible_facts.packages'1279 ······-·'"auditd"·in·ansible_facts.packages'
 1280 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1281 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1281 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1282 ········==·01282 ········==·0
1283 ······tags:1283 ······tags:
1284 ······-·CJIS-5.4.1.11284 ······-·CJIS-5.4.1.1
1285 ······-·NIST-800-171-3.1.71285 ······-·NIST-800-171-3.1.7
1286 ······-·NIST-800-53-AC-2(7)(b)1286 ······-·NIST-800-53-AC-2(7)(b)
1287 ······-·NIST-800-53-AC-6(9)1287 ······-·NIST-800-53-AC-6(9)
Offset 1298, 16 lines modifiedOffset 1298, 16 lines modified
1298 ······-·restrict_strategy1298 ······-·restrict_strategy
  
1299 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule1299 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule
1300 ······set_fact:1300 ······set_fact:
1301 ········all_files:1301 ········all_files:
1302 ········-·/etc/audit/rules.d/actions.rules1302 ········-·/etc/audit/rules.d/actions.rules
1303 ······when:1303 ······when:
1304 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1305 ······-·'"auditd"·in·ansible_facts.packages'1304 ······-·'"auditd"·in·ansible_facts.packages'
 1305 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1306 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1306 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1307 ········is·defined·and·find_existing_watch_rules_d.matched·==·01307 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1308 ······tags:1308 ······tags:
1309 ······-·CJIS-5.4.1.11309 ······-·CJIS-5.4.1.1
1310 ······-·NIST-800-171-3.1.71310 ······-·NIST-800-171-3.1.7
1311 ······-·NIST-800-53-AC-2(7)(b)1311 ······-·NIST-800-53-AC-2(7)(b)
1312 ······-·NIST-800-53-AC-6(9)1312 ······-·NIST-800-53-AC-6(9)
Offset 1324, 16 lines modifiedOffset 1324, 16 lines modified
1324 ······-·restrict_strategy1324 ······-·restrict_strategy
  
1325 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1325 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1326 ······set_fact:1326 ······set_fact:
1327 ········all_files:1327 ········all_files:
1328 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1328 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1329 ······when:1329 ······when:
1330 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1331 ······-·'"auditd"·in·ansible_facts.packages'1330 ······-·'"auditd"·in·ansible_facts.packages'
 1331 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1332 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1332 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1333 ········is·defined·and·find_existing_watch_rules_d.matched·==·01333 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1334 ······tags:1334 ······tags:
1335 ······-·CJIS-5.4.1.11335 ······-·CJIS-5.4.1.1
1336 ······-·NIST-800-171-3.1.71336 ······-·NIST-800-171-3.1.7
1337 ······-·NIST-800-53-AC-2(7)(b)1337 ······-·NIST-800-53-AC-2(7)(b)
1338 ······-·NIST-800-53-AC-6(9)1338 ······-·NIST-800-53-AC-6(9)
Offset 1352, 16 lines modifiedOffset 1352, 16 lines modified
1352 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/1352 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/
Max diff block lines reached; 133550/138587 bytes (96.37%) of diff not shown.
126 KB
./usr/share/scap-security-guide/ansible/ubuntu2004-playbook-stig.yml
Ordering differences only
    
Offset 779, 16 lines modifiedOffset 779, 16 lines modified
779 ····-·name:·Check·if·watch·rule·for·/etc/group·already·exists·in·/etc/audit/rules.d/779 ····-·name:·Check·if·watch·rule·for·/etc/group·already·exists·in·/etc/audit/rules.d/
780 ······find:780 ······find:
781 ········paths:·/etc/audit/rules.d781 ········paths:·/etc/audit/rules.d
782 ········contains:·^\s*-w\s+/etc/group\s+-p\s+wa(\s|$)+782 ········contains:·^\s*-w\s+/etc/group\s+-p\s+wa(\s|$)+
783 ········patterns:·'*.rules'783 ········patterns:·'*.rules'
784 ······register:·find_existing_watch_rules_d784 ······register:·find_existing_watch_rules_d
785 ······when:785 ······when:
786 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
787 ······-·'"auditd"·in·ansible_facts.packages'786 ······-·'"auditd"·in·ansible_facts.packages'
 787 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
788 ······tags:788 ······tags:
789 ······-·CJIS-5.4.1.1789 ······-·CJIS-5.4.1.1
790 ······-·DISA-STIG-UBTU-20-010101790 ······-·DISA-STIG-UBTU-20-010101
791 ······-·NIST-800-171-3.1.7791 ······-·NIST-800-171-3.1.7
792 ······-·NIST-800-53-AC-2(4)792 ······-·NIST-800-53-AC-2(4)
793 ······-·NIST-800-53-AC-6(9)793 ······-·NIST-800-53-AC-6(9)
794 ······-·NIST-800-53-AU-12(c)794 ······-·NIST-800-53-AU-12(c)
Offset 805, 16 lines modifiedOffset 805, 16 lines modified
805 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_usergroup_modification805 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_usergroup_modification
806 ······find:806 ······find:
807 ········paths:·/etc/audit/rules.d807 ········paths:·/etc/audit/rules.d
808 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_usergroup_modification$808 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_usergroup_modification$
809 ········patterns:·'*.rules'809 ········patterns:·'*.rules'
810 ······register:·find_watch_key810 ······register:·find_watch_key
811 ······when:811 ······when:
812 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
813 ······-·'"auditd"·in·ansible_facts.packages'812 ······-·'"auditd"·in·ansible_facts.packages'
 813 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
814 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched814 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
815 ········==·0815 ········==·0
816 ······tags:816 ······tags:
817 ······-·CJIS-5.4.1.1817 ······-·CJIS-5.4.1.1
818 ······-·DISA-STIG-UBTU-20-010101818 ······-·DISA-STIG-UBTU-20-010101
819 ······-·NIST-800-171-3.1.7819 ······-·NIST-800-171-3.1.7
820 ······-·NIST-800-53-AC-2(4)820 ······-·NIST-800-53-AC-2(4)
Offset 832, 16 lines modifiedOffset 832, 16 lines modified
  
832 ····-·name:·Use·/etc/audit/rules.d/audit_rules_usergroup_modification.rules·as·the·recipient832 ····-·name:·Use·/etc/audit/rules.d/audit_rules_usergroup_modification.rules·as·the·recipient
833 ········for·the·rule833 ········for·the·rule
834 ······set_fact:834 ······set_fact:
835 ········all_files:835 ········all_files:
836 ········-·/etc/audit/rules.d/audit_rules_usergroup_modification.rules836 ········-·/etc/audit/rules.d/audit_rules_usergroup_modification.rules
837 ······when:837 ······when:
838 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
839 ······-·'"auditd"·in·ansible_facts.packages'838 ······-·'"auditd"·in·ansible_facts.packages'
 839 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
840 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched840 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
841 ········is·defined·and·find_existing_watch_rules_d.matched·==·0841 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
842 ······tags:842 ······tags:
843 ······-·CJIS-5.4.1.1843 ······-·CJIS-5.4.1.1
844 ······-·DISA-STIG-UBTU-20-010101844 ······-·DISA-STIG-UBTU-20-010101
845 ······-·NIST-800-171-3.1.7845 ······-·NIST-800-171-3.1.7
846 ······-·NIST-800-53-AC-2(4)846 ······-·NIST-800-53-AC-2(4)
Offset 858, 16 lines modifiedOffset 858, 16 lines modified
858 ······-·restrict_strategy858 ······-·restrict_strategy
  
859 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule859 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
860 ······set_fact:860 ······set_fact:
861 ········all_files:861 ········all_files:
862 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'862 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
863 ······when:863 ······when:
864 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
865 ······-·'"auditd"·in·ansible_facts.packages'864 ······-·'"auditd"·in·ansible_facts.packages'
 865 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
866 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched866 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
867 ········is·defined·and·find_existing_watch_rules_d.matched·==·0867 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
868 ······tags:868 ······tags:
869 ······-·CJIS-5.4.1.1869 ······-·CJIS-5.4.1.1
870 ······-·DISA-STIG-UBTU-20-010101870 ······-·DISA-STIG-UBTU-20-010101
871 ······-·NIST-800-171-3.1.7871 ······-·NIST-800-171-3.1.7
872 ······-·NIST-800-53-AC-2(4)872 ······-·NIST-800-53-AC-2(4)
Offset 886, 16 lines modifiedOffset 886, 16 lines modified
886 ····-·name:·Add·watch·rule·for·/etc/group·in·/etc/audit/rules.d/886 ····-·name:·Add·watch·rule·for·/etc/group·in·/etc/audit/rules.d/
887 ······lineinfile:887 ······lineinfile:
888 ········path:·'{{·all_files[0]·}}'888 ········path:·'{{·all_files[0]·}}'
889 ········line:·-w·/etc/group·-p·wa·-k·audit_rules_usergroup_modification889 ········line:·-w·/etc/group·-p·wa·-k·audit_rules_usergroup_modification
890 ········create:·true890 ········create:·true
891 ········mode:·'0640'891 ········mode:·'0640'
892 ······when:892 ······when:
893 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
894 ······-·'"auditd"·in·ansible_facts.packages'893 ······-·'"auditd"·in·ansible_facts.packages'
 894 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
895 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched895 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
896 ········==·0896 ········==·0
897 ······tags:897 ······tags:
898 ······-·CJIS-5.4.1.1898 ······-·CJIS-5.4.1.1
899 ······-·DISA-STIG-UBTU-20-010101899 ······-·DISA-STIG-UBTU-20-010101
900 ······-·NIST-800-171-3.1.7900 ······-·NIST-800-171-3.1.7
901 ······-·NIST-800-53-AC-2(4)901 ······-·NIST-800-53-AC-2(4)
Offset 914, 16 lines modifiedOffset 914, 16 lines modified
914 ····-·name:·Check·if·watch·rule·for·/etc/group·already·exists·in·/etc/audit/audit.rules914 ····-·name:·Check·if·watch·rule·for·/etc/group·already·exists·in·/etc/audit/audit.rules
915 ······find:915 ······find:
916 ········paths:·/etc/audit/916 ········paths:·/etc/audit/
917 ········contains:·^\s*-w\s+/etc/group\s+-p\s+wa(\s|$)+917 ········contains:·^\s*-w\s+/etc/group\s+-p\s+wa(\s|$)+
918 ········patterns:·audit.rules918 ········patterns:·audit.rules
919 ······register:·find_existing_watch_audit_rules919 ······register:·find_existing_watch_audit_rules
920 ······when:920 ······when:
921 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
922 ······-·'"auditd"·in·ansible_facts.packages'921 ······-·'"auditd"·in·ansible_facts.packages'
 922 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
923 ······tags:923 ······tags:
924 ······-·CJIS-5.4.1.1924 ······-·CJIS-5.4.1.1
925 ······-·DISA-STIG-UBTU-20-010101925 ······-·DISA-STIG-UBTU-20-010101
926 ······-·NIST-800-171-3.1.7926 ······-·NIST-800-171-3.1.7
927 ······-·NIST-800-53-AC-2(4)927 ······-·NIST-800-53-AC-2(4)
928 ······-·NIST-800-53-AC-6(9)928 ······-·NIST-800-53-AC-6(9)
929 ······-·NIST-800-53-AU-12(c)929 ······-·NIST-800-53-AU-12(c)
Offset 941, 16 lines modifiedOffset 941, 16 lines modified
941 ······lineinfile:941 ······lineinfile:
942 ········line:·-w·/etc/group·-p·wa·-k·audit_rules_usergroup_modification942 ········line:·-w·/etc/group·-p·wa·-k·audit_rules_usergroup_modification
943 ········state:·present943 ········state:·present
944 ········dest:·/etc/audit/audit.rules944 ········dest:·/etc/audit/audit.rules
945 ········create:·true945 ········create:·true
946 ········mode:·'0640'946 ········mode:·'0640'
947 ······when:947 ······when:
948 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
949 ······-·'"auditd"·in·ansible_facts.packages'948 ······-·'"auditd"·in·ansible_facts.packages'
 949 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
950 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched950 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
951 ········==·0951 ········==·0
952 ······tags:952 ······tags:
953 ······-·CJIS-5.4.1.1953 ······-·CJIS-5.4.1.1
954 ······-·DISA-STIG-UBTU-20-010101954 ······-·DISA-STIG-UBTU-20-010101
955 ······-·NIST-800-171-3.1.7955 ······-·NIST-800-171-3.1.7
956 ······-·NIST-800-53-AC-2(4)956 ······-·NIST-800-53-AC-2(4)
Offset 990, 16 lines modifiedOffset 990, 16 lines modified
990 ····-·name:·Check·if·watch·rule·for·/etc/gshadow·already·exists·in·/etc/audit/rules.d/990 ····-·name:·Check·if·watch·rule·for·/etc/gshadow·already·exists·in·/etc/audit/rules.d/
Max diff block lines reached; 123095/128504 bytes (95.79%) of diff not shown.
2.71 KB
./usr/share/scap-security-guide/ansible/ubuntu2204-playbook-cis_level1_server.yml
Ordering differences only
    
Offset 1062, 16 lines modifiedOffset 1062, 16 lines modified
1062 ······-·no_reboot_needed1062 ······-·no_reboot_needed
  
1063 ····-·name:·Test·for·existence·/boot/grub/grub.cfg1063 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
1064 ······stat:1064 ······stat:
1065 ········path:·/boot/grub/grub.cfg1065 ········path:·/boot/grub/grub.cfg
1066 ······register:·file_exists1066 ······register:·file_exists
1067 ······when:1067 ······when:
1068 ······-·'"grub2-common"·in·ansible_facts.packages' 
1069 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1068 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1069 ······-·'"grub2-common"·in·ansible_facts.packages'
1070 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1070 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1071 ······tags:1071 ······tags:
1072 ······-·CJIS-5.5.2.21072 ······-·CJIS-5.5.2.2
1073 ······-·NIST-800-171-3.4.51073 ······-·NIST-800-171-3.4.5
1074 ······-·NIST-800-53-AC-6(1)1074 ······-·NIST-800-53-AC-6(1)
1075 ······-·NIST-800-53-CM-6(a)1075 ······-·NIST-800-53-CM-6(a)
1076 ······-·PCI-DSS-Req-7.11076 ······-·PCI-DSS-Req-7.1
Offset 1083, 16 lines modifiedOffset 1083, 16 lines modified
1083 ······-·no_reboot_needed1083 ······-·no_reboot_needed
  
1084 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg1084 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
1085 ······file:1085 ······file:
1086 ········path:·/boot/grub/grub.cfg1086 ········path:·/boot/grub/grub.cfg
1087 ········owner:·'0'1087 ········owner:·'0'
1088 ······when:1088 ······when:
1089 ······-·'"grub2-common"·in·ansible_facts.packages' 
1090 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1089 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1090 ······-·'"grub2-common"·in·ansible_facts.packages'
1091 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1091 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1092 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1092 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1093 ······tags:1093 ······tags:
1094 ······-·CJIS-5.5.2.21094 ······-·CJIS-5.5.2.2
1095 ······-·NIST-800-171-3.4.51095 ······-·NIST-800-171-3.4.5
1096 ······-·NIST-800-53-AC-6(1)1096 ······-·NIST-800-53-AC-6(1)
1097 ······-·NIST-800-53-CM-6(a)1097 ······-·NIST-800-53-CM-6(a)
Offset 1120, 16 lines modifiedOffset 1120, 16 lines modified
1120 ······-·no_reboot_needed1120 ······-·no_reboot_needed
  
1121 ····-·name:·Test·for·existence·/boot/grub/grub.cfg1121 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
1122 ······stat:1122 ······stat:
1123 ········path:·/boot/grub/grub.cfg1123 ········path:·/boot/grub/grub.cfg
1124 ······register:·file_exists1124 ······register:·file_exists
1125 ······when:1125 ······when:
1126 ······-·'"grub2-common"·in·ansible_facts.packages' 
1127 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1126 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1127 ······-·'"grub2-common"·in·ansible_facts.packages'
1128 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1128 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1129 ······tags:1129 ······tags:
1130 ······-·NIST-800-171-3.4.51130 ······-·NIST-800-171-3.4.5
1131 ······-·NIST-800-53-AC-6(1)1131 ······-·NIST-800-53-AC-6(1)
1132 ······-·NIST-800-53-CM-6(a)1132 ······-·NIST-800-53-CM-6(a)
1133 ······-·configure_strategy1133 ······-·configure_strategy
1134 ······-·file_permissions_grub2_cfg1134 ······-·file_permissions_grub2_cfg
Offset 1139, 16 lines modifiedOffset 1139, 16 lines modified
1139 ······-·no_reboot_needed1139 ······-·no_reboot_needed
  
1140 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg1140 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
1141 ······file:1141 ······file:
1142 ········path:·/boot/grub/grub.cfg1142 ········path:·/boot/grub/grub.cfg
1143 ········mode:·u-xs,g-xwrs,o-xwrt1143 ········mode:·u-xs,g-xwrs,o-xwrt
1144 ······when:1144 ······when:
1145 ······-·'"grub2-common"·in·ansible_facts.packages' 
1146 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1145 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1146 ······-·'"grub2-common"·in·ansible_facts.packages'
1147 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1147 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1148 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1148 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1149 ······tags:1149 ······tags:
1150 ······-·NIST-800-171-3.4.51150 ······-·NIST-800-171-3.4.5
1151 ······-·NIST-800-53-AC-6(1)1151 ······-·NIST-800-53-AC-6(1)
1152 ······-·NIST-800-53-CM-6(a)1152 ······-·NIST-800-53-CM-6(a)
1153 ······-·configure_strategy1153 ······-·configure_strategy
2.71 KB
./usr/share/scap-security-guide/ansible/ubuntu2204-playbook-cis_level1_workstation.yml
Ordering differences only
    
Offset 1031, 16 lines modifiedOffset 1031, 16 lines modified
1031 ······-·no_reboot_needed1031 ······-·no_reboot_needed
  
1032 ····-·name:·Test·for·existence·/boot/grub/grub.cfg1032 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
1033 ······stat:1033 ······stat:
1034 ········path:·/boot/grub/grub.cfg1034 ········path:·/boot/grub/grub.cfg
1035 ······register:·file_exists1035 ······register:·file_exists
1036 ······when:1036 ······when:
1037 ······-·'"grub2-common"·in·ansible_facts.packages' 
1038 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1037 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1038 ······-·'"grub2-common"·in·ansible_facts.packages'
1039 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1039 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1040 ······tags:1040 ······tags:
1041 ······-·CJIS-5.5.2.21041 ······-·CJIS-5.5.2.2
1042 ······-·NIST-800-171-3.4.51042 ······-·NIST-800-171-3.4.5
1043 ······-·NIST-800-53-AC-6(1)1043 ······-·NIST-800-53-AC-6(1)
1044 ······-·NIST-800-53-CM-6(a)1044 ······-·NIST-800-53-CM-6(a)
1045 ······-·PCI-DSS-Req-7.11045 ······-·PCI-DSS-Req-7.1
Offset 1052, 16 lines modifiedOffset 1052, 16 lines modified
1052 ······-·no_reboot_needed1052 ······-·no_reboot_needed
  
1053 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg1053 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
1054 ······file:1054 ······file:
1055 ········path:·/boot/grub/grub.cfg1055 ········path:·/boot/grub/grub.cfg
1056 ········owner:·'0'1056 ········owner:·'0'
1057 ······when:1057 ······when:
1058 ······-·'"grub2-common"·in·ansible_facts.packages' 
1059 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1058 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1059 ······-·'"grub2-common"·in·ansible_facts.packages'
1060 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1060 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1061 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1061 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1062 ······tags:1062 ······tags:
1063 ······-·CJIS-5.5.2.21063 ······-·CJIS-5.5.2.2
1064 ······-·NIST-800-171-3.4.51064 ······-·NIST-800-171-3.4.5
1065 ······-·NIST-800-53-AC-6(1)1065 ······-·NIST-800-53-AC-6(1)
1066 ······-·NIST-800-53-CM-6(a)1066 ······-·NIST-800-53-CM-6(a)
Offset 1089, 16 lines modifiedOffset 1089, 16 lines modified
1089 ······-·no_reboot_needed1089 ······-·no_reboot_needed
  
1090 ····-·name:·Test·for·existence·/boot/grub/grub.cfg1090 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
1091 ······stat:1091 ······stat:
1092 ········path:·/boot/grub/grub.cfg1092 ········path:·/boot/grub/grub.cfg
1093 ······register:·file_exists1093 ······register:·file_exists
1094 ······when:1094 ······when:
1095 ······-·'"grub2-common"·in·ansible_facts.packages' 
1096 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1095 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1096 ······-·'"grub2-common"·in·ansible_facts.packages'
1097 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1097 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1098 ······tags:1098 ······tags:
1099 ······-·NIST-800-171-3.4.51099 ······-·NIST-800-171-3.4.5
1100 ······-·NIST-800-53-AC-6(1)1100 ······-·NIST-800-53-AC-6(1)
1101 ······-·NIST-800-53-CM-6(a)1101 ······-·NIST-800-53-CM-6(a)
1102 ······-·configure_strategy1102 ······-·configure_strategy
1103 ······-·file_permissions_grub2_cfg1103 ······-·file_permissions_grub2_cfg
Offset 1108, 16 lines modifiedOffset 1108, 16 lines modified
1108 ······-·no_reboot_needed1108 ······-·no_reboot_needed
  
1109 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg1109 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
1110 ······file:1110 ······file:
1111 ········path:·/boot/grub/grub.cfg1111 ········path:·/boot/grub/grub.cfg
1112 ········mode:·u-xs,g-xwrs,o-xwrt1112 ········mode:·u-xs,g-xwrs,o-xwrt
1113 ······when:1113 ······when:
1114 ······-·'"grub2-common"·in·ansible_facts.packages' 
1115 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'1114 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1115 ······-·'"grub2-common"·in·ansible_facts.packages'
1116 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1116 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1117 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1117 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1118 ······tags:1118 ······tags:
1119 ······-·NIST-800-171-3.4.51119 ······-·NIST-800-171-3.4.5
1120 ······-·NIST-800-53-AC-6(1)1120 ······-·NIST-800-53-AC-6(1)
1121 ······-·NIST-800-53-CM-6(a)1121 ······-·NIST-800-53-CM-6(a)
1122 ······-·configure_strategy1122 ······-·configure_strategy
2.71 KB
./usr/share/scap-security-guide/ansible/ubuntu2204-playbook-cis_level2_server.yml
Ordering differences only
    
Offset 16207, 16 lines modifiedOffset 16207, 16 lines modified
16207 ······-·no_reboot_needed16207 ······-·no_reboot_needed
  
16208 ····-·name:·Test·for·existence·/boot/grub/grub.cfg16208 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
16209 ······stat:16209 ······stat:
16210 ········path:·/boot/grub/grub.cfg16210 ········path:·/boot/grub/grub.cfg
16211 ······register:·file_exists16211 ······register:·file_exists
16212 ······when:16212 ······when:
16213 ······-·'"grub2-common"·in·ansible_facts.packages' 
16214 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'16213 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 16214 ······-·'"grub2-common"·in·ansible_facts.packages'
16215 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]16215 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
16216 ······tags:16216 ······tags:
16217 ······-·CJIS-5.5.2.216217 ······-·CJIS-5.5.2.2
16218 ······-·NIST-800-171-3.4.516218 ······-·NIST-800-171-3.4.5
16219 ······-·NIST-800-53-AC-6(1)16219 ······-·NIST-800-53-AC-6(1)
16220 ······-·NIST-800-53-CM-6(a)16220 ······-·NIST-800-53-CM-6(a)
16221 ······-·PCI-DSS-Req-7.116221 ······-·PCI-DSS-Req-7.1
Offset 16228, 16 lines modifiedOffset 16228, 16 lines modified
16228 ······-·no_reboot_needed16228 ······-·no_reboot_needed
  
16229 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg16229 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
16230 ······file:16230 ······file:
16231 ········path:·/boot/grub/grub.cfg16231 ········path:·/boot/grub/grub.cfg
16232 ········owner:·'0'16232 ········owner:·'0'
16233 ······when:16233 ······when:
16234 ······-·'"grub2-common"·in·ansible_facts.packages' 
16235 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'16234 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 16235 ······-·'"grub2-common"·in·ansible_facts.packages'
16236 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]16236 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
16237 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists16237 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
16238 ······tags:16238 ······tags:
16239 ······-·CJIS-5.5.2.216239 ······-·CJIS-5.5.2.2
16240 ······-·NIST-800-171-3.4.516240 ······-·NIST-800-171-3.4.5
16241 ······-·NIST-800-53-AC-6(1)16241 ······-·NIST-800-53-AC-6(1)
16242 ······-·NIST-800-53-CM-6(a)16242 ······-·NIST-800-53-CM-6(a)
Offset 16265, 16 lines modifiedOffset 16265, 16 lines modified
16265 ······-·no_reboot_needed16265 ······-·no_reboot_needed
  
16266 ····-·name:·Test·for·existence·/boot/grub/grub.cfg16266 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
16267 ······stat:16267 ······stat:
16268 ········path:·/boot/grub/grub.cfg16268 ········path:·/boot/grub/grub.cfg
16269 ······register:·file_exists16269 ······register:·file_exists
16270 ······when:16270 ······when:
16271 ······-·'"grub2-common"·in·ansible_facts.packages' 
16272 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'16271 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 16272 ······-·'"grub2-common"·in·ansible_facts.packages'
16273 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]16273 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
16274 ······tags:16274 ······tags:
16275 ······-·NIST-800-171-3.4.516275 ······-·NIST-800-171-3.4.5
16276 ······-·NIST-800-53-AC-6(1)16276 ······-·NIST-800-53-AC-6(1)
16277 ······-·NIST-800-53-CM-6(a)16277 ······-·NIST-800-53-CM-6(a)
16278 ······-·configure_strategy16278 ······-·configure_strategy
16279 ······-·file_permissions_grub2_cfg16279 ······-·file_permissions_grub2_cfg
Offset 16284, 16 lines modifiedOffset 16284, 16 lines modified
16284 ······-·no_reboot_needed16284 ······-·no_reboot_needed
  
16285 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg16285 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
16286 ······file:16286 ······file:
16287 ········path:·/boot/grub/grub.cfg16287 ········path:·/boot/grub/grub.cfg
16288 ········mode:·u-xs,g-xwrs,o-xwrt16288 ········mode:·u-xs,g-xwrs,o-xwrt
16289 ······when:16289 ······when:
16290 ······-·'"grub2-common"·in·ansible_facts.packages' 
16291 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'16290 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 16291 ······-·'"grub2-common"·in·ansible_facts.packages'
16292 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]16292 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
16293 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists16293 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
16294 ······tags:16294 ······tags:
16295 ······-·NIST-800-171-3.4.516295 ······-·NIST-800-171-3.4.5
16296 ······-·NIST-800-53-AC-6(1)16296 ······-·NIST-800-53-AC-6(1)
16297 ······-·NIST-800-53-CM-6(a)16297 ······-·NIST-800-53-CM-6(a)
16298 ······-·configure_strategy16298 ······-·configure_strategy
2.72 KB
./usr/share/scap-security-guide/ansible/ubuntu2204-playbook-cis_level2_workstation.yml
Ordering differences only
    
Offset 16176, 16 lines modifiedOffset 16176, 16 lines modified
16176 ······-·no_reboot_needed16176 ······-·no_reboot_needed
  
16177 ····-·name:·Test·for·existence·/boot/grub/grub.cfg16177 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
16178 ······stat:16178 ······stat:
16179 ········path:·/boot/grub/grub.cfg16179 ········path:·/boot/grub/grub.cfg
16180 ······register:·file_exists16180 ······register:·file_exists
16181 ······when:16181 ······when:
16182 ······-·'"grub2-common"·in·ansible_facts.packages' 
16183 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'16182 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 16183 ······-·'"grub2-common"·in·ansible_facts.packages'
16184 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]16184 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
16185 ······tags:16185 ······tags:
16186 ······-·CJIS-5.5.2.216186 ······-·CJIS-5.5.2.2
16187 ······-·NIST-800-171-3.4.516187 ······-·NIST-800-171-3.4.5
16188 ······-·NIST-800-53-AC-6(1)16188 ······-·NIST-800-53-AC-6(1)
16189 ······-·NIST-800-53-CM-6(a)16189 ······-·NIST-800-53-CM-6(a)
16190 ······-·PCI-DSS-Req-7.116190 ······-·PCI-DSS-Req-7.1
Offset 16197, 16 lines modifiedOffset 16197, 16 lines modified
16197 ······-·no_reboot_needed16197 ······-·no_reboot_needed
  
16198 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg16198 ····-·name:·Ensure·owner·0·on·/boot/grub/grub.cfg
16199 ······file:16199 ······file:
16200 ········path:·/boot/grub/grub.cfg16200 ········path:·/boot/grub/grub.cfg
16201 ········owner:·'0'16201 ········owner:·'0'
16202 ······when:16202 ······when:
16203 ······-·'"grub2-common"·in·ansible_facts.packages' 
16204 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'16203 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 16204 ······-·'"grub2-common"·in·ansible_facts.packages'
16205 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]16205 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
16206 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists16206 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
16207 ······tags:16207 ······tags:
16208 ······-·CJIS-5.5.2.216208 ······-·CJIS-5.5.2.2
16209 ······-·NIST-800-171-3.4.516209 ······-·NIST-800-171-3.4.5
16210 ······-·NIST-800-53-AC-6(1)16210 ······-·NIST-800-53-AC-6(1)
16211 ······-·NIST-800-53-CM-6(a)16211 ······-·NIST-800-53-CM-6(a)
Offset 16234, 16 lines modifiedOffset 16234, 16 lines modified
16234 ······-·no_reboot_needed16234 ······-·no_reboot_needed
  
16235 ····-·name:·Test·for·existence·/boot/grub/grub.cfg16235 ····-·name:·Test·for·existence·/boot/grub/grub.cfg
16236 ······stat:16236 ······stat:
16237 ········path:·/boot/grub/grub.cfg16237 ········path:·/boot/grub/grub.cfg
16238 ······register:·file_exists16238 ······register:·file_exists
16239 ······when:16239 ······when:
16240 ······-·'"grub2-common"·in·ansible_facts.packages' 
16241 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'16240 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 16241 ······-·'"grub2-common"·in·ansible_facts.packages'
16242 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]16242 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
16243 ······tags:16243 ······tags:
16244 ······-·NIST-800-171-3.4.516244 ······-·NIST-800-171-3.4.5
16245 ······-·NIST-800-53-AC-6(1)16245 ······-·NIST-800-53-AC-6(1)
16246 ······-·NIST-800-53-CM-6(a)16246 ······-·NIST-800-53-CM-6(a)
16247 ······-·configure_strategy16247 ······-·configure_strategy
16248 ······-·file_permissions_grub2_cfg16248 ······-·file_permissions_grub2_cfg
Offset 16253, 16 lines modifiedOffset 16253, 16 lines modified
16253 ······-·no_reboot_needed16253 ······-·no_reboot_needed
  
16254 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg16254 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub/grub.cfg
16255 ······file:16255 ······file:
16256 ········path:·/boot/grub/grub.cfg16256 ········path:·/boot/grub/grub.cfg
16257 ········mode:·u-xs,g-xwrs,o-xwrt16257 ········mode:·u-xs,g-xwrs,o-xwrt
16258 ······when:16258 ······when:
16259 ······-·'"grub2-common"·in·ansible_facts.packages' 
16260 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'16259 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 16260 ······-·'"grub2-common"·in·ansible_facts.packages'
16261 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]16261 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
16262 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists16262 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
16263 ······tags:16263 ······tags:
16264 ······-·NIST-800-171-3.4.516264 ······-·NIST-800-171-3.4.5
16265 ······-·NIST-800-53-AC-6(1)16265 ······-·NIST-800-53-AC-6(1)
16266 ······-·NIST-800-53-CM-6(a)16266 ······-·NIST-800-53-CM-6(a)
16267 ······-·configure_strategy16267 ······-·configure_strategy
692 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds-1.2.xml
692 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds-1.2.xml
Ordering differences only
    
Offset 143, 92 lines modifiedOffset 143, 92 lines modified
143 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>143 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
144 ······</xccdf-1.2:front-matter>144 ······</xccdf-1.2:front-matter>
145 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered145 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
146 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other146 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
147 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their147 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
148 respective·companies.</xccdf-1.2:rear-matter>148 respective·companies.</xccdf-1.2:rear-matter>
149 ······<cpe-lang:platform-specification>149 ······<cpe-lang:platform-specification>
150 ········<cpe-lang:platform·id="pam">150 ········<cpe-lang:platform·id="sssd">
151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
152 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>152 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
153 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
154 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
155 ········<cpe-lang:platform·id="sudo">155 ········<cpe-lang:platform·id="gdm">
156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
157 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>157 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
158 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
159 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
160 ········<cpe-lang:platform·id="aarch64_arch">160 ········<cpe-lang:platform·id="login_defs">
161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
162 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>162 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
163 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
164 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
165 ········<cpe-lang:platform·id="s390x_arch">165 ········<cpe-lang:platform·id="chrony">
166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
167 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>167 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
168 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
169 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
170 ········<cpe-lang:platform·id="machine">170 ········<cpe-lang:platform·id="audit">
171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
172 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>172 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>
173 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
174 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
175 ········<cpe-lang:platform·id="chrony">175 ········<cpe-lang:platform·id="not_s390x_arch">
176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
177 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>177 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
178 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
179 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
180 ········<cpe-lang:platform·id="grub2">180 ········<cpe-lang:platform·id="ntp">
181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
182 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>182 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
183 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
184 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
185 ········<cpe-lang:platform·id="audit">185 ········<cpe-lang:platform·id="pam">
186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
187 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>187 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>
188 ··········</cpe-lang:logical-test>188 ··········</cpe-lang:logical-test>
189 ········</cpe-lang:platform>189 ········</cpe-lang:platform>
190 ········<cpe-lang:platform·id="postfix">190 ········<cpe-lang:platform·id="aarch64_arch">
191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
192 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>192 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
193 ··········</cpe-lang:logical-test>193 ··········</cpe-lang:logical-test>
194 ········</cpe-lang:platform>194 ········</cpe-lang:platform>
195 ········<cpe-lang:platform·id="sssd">195 ········<cpe-lang:platform·id="postfix">
196 ··········<cpe-lang:logical-test·operator="AND"·negate="false">196 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
197 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>197 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
198 ··········</cpe-lang:logical-test>198 ··········</cpe-lang:logical-test>
199 ········</cpe-lang:platform>199 ········</cpe-lang:platform>
200 ········<cpe-lang:platform·id="gdm">200 ········<cpe-lang:platform·id="non-uefi">
201 ··········<cpe-lang:logical-test·operator="AND"·negate="false">201 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
202 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>202 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
203 ··········</cpe-lang:logical-test>203 ··········</cpe-lang:logical-test>
204 ········</cpe-lang:platform>204 ········</cpe-lang:platform>
205 ········<cpe-lang:platform·id="ntp">205 ········<cpe-lang:platform·id="uefi">
206 ··········<cpe-lang:logical-test·operator="AND"·negate="false">206 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
207 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>207 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
208 ··········</cpe-lang:logical-test>208 ··········</cpe-lang:logical-test>
209 ········</cpe-lang:platform>209 ········</cpe-lang:platform>
210 ········<cpe-lang:platform·id="non-uefi">210 ········<cpe-lang:platform·id="sudo">
211 ··········<cpe-lang:logical-test·operator="AND"·negate="false">211 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
212 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>212 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
213 ··········</cpe-lang:logical-test>213 ··········</cpe-lang:logical-test>
214 ········</cpe-lang:platform>214 ········</cpe-lang:platform>
215 ········<cpe-lang:platform·id="not_s390x_arch">215 ········<cpe-lang:platform·id="grub2">
216 ··········<cpe-lang:logical-test·operator="AND"·negate="false">216 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
217 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>217 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
218 ··········</cpe-lang:logical-test>218 ··········</cpe-lang:logical-test>
219 ········</cpe-lang:platform>219 ········</cpe-lang:platform>
220 ········<cpe-lang:platform·id="uefi">220 ········<cpe-lang:platform·id="s390x_arch">
221 ··········<cpe-lang:logical-test·operator="AND"·negate="false">221 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
222 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>222 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
223 ··········</cpe-lang:logical-test>223 ··········</cpe-lang:logical-test>
224 ········</cpe-lang:platform>224 ········</cpe-lang:platform>
225 ········<cpe-lang:platform·id="login_defs">225 ········<cpe-lang:platform·id="machine">
226 ··········<cpe-lang:logical-test·operator="AND"·negate="false">226 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
227 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>227 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
228 ··········</cpe-lang:logical-test>228 ··········</cpe-lang:logical-test>
229 ········</cpe-lang:platform>229 ········</cpe-lang:platform>
230 ······</cpe-lang:platform-specification>230 ······</cpe-lang:platform-specification>
231 ······<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~"/>231 ······<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~"/>
232 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>232 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
233 ······<xccdf-1.2:metadata>233 ······<xccdf-1.2:metadata>
234 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>234 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 54114, 38 lines modifiedOffset 54114, 38 lines modified
  
54114 The54114 The
54115 ··················<html:code>netfs</html:code>54115 ··················<html:code>netfs</html:code>
54116 ··················service·can·be·disabled·with·the·following·command:54116 ··················service·can·be·disabled·with·the·following·command:
54117 ··················<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>54117 ··················<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>
54118 ················</xccdf-1.2:description>54118 ················</xccdf-1.2:description>
54119 ················<xccdf-1.2:rationale/>54119 ················<xccdf-1.2:rationale/>
 54120 ················<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services]
 54121 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix>
 54122 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs
  
 54123 class·disable_netfs·{
 54124 ··service·{'netfs':
 54125 ····enable·=&gt;·false,
 54126 ····ensure·=&gt;·'stopped',
 54127 ··}
 54128 }</xccdf-1.2:fix>
54120 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v154129 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v1
54121 kind:·MachineConfig54130 kind:·MachineConfig
54122 spec:54131 spec:
54123 ··config:54132 ··config:
54124 ····ignition:54133 ····ignition:
54125 ······version:·3.1.054134 ······version:·3.1.0
54126 ····systemd:54135 ····systemd:
54127 ······units:54136 ······units:
54128 ······-·name:·netfs.service54137 ······-·name:·netfs.service
54129 ········enabled:·false54138 ········enabled:·false
54130 ········mask:·true54139 ········mask:·true
54131 ······-·name:·netfs.socket54140 ······-·name:·netfs.socket
54132 ········enabled:·false54141 ········enabled:·false
54133 ········mask:·true</xccdf-1.2:fix>54142 ········mask:·true</xccdf-1.2:fix>
54134 ················<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services] 
54135 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix> 
54136 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs 
Max diff block lines reached; 700535/708604 bytes (98.86%) of diff not shown.
692 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
692 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
Ordering differences only
    
Offset 145, 92 lines modifiedOffset 145, 92 lines modified
145 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>145 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
146 ······</xccdf-1.2:front-matter>146 ······</xccdf-1.2:front-matter>
147 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered147 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
148 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other148 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
149 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their149 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
150 respective·companies.</xccdf-1.2:rear-matter>150 respective·companies.</xccdf-1.2:rear-matter>
151 ······<cpe-lang:platform-specification>151 ······<cpe-lang:platform-specification>
152 ········<cpe-lang:platform·id="pam">152 ········<cpe-lang:platform·id="sssd">
153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">153 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
154 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>154 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
155 ··········</cpe-lang:logical-test>155 ··········</cpe-lang:logical-test>
156 ········</cpe-lang:platform>156 ········</cpe-lang:platform>
157 ········<cpe-lang:platform·id="sudo">157 ········<cpe-lang:platform·id="gdm">
158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">158 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
159 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>159 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
160 ··········</cpe-lang:logical-test>160 ··········</cpe-lang:logical-test>
161 ········</cpe-lang:platform>161 ········</cpe-lang:platform>
162 ········<cpe-lang:platform·id="aarch64_arch">162 ········<cpe-lang:platform·id="login_defs">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
164 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>164 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
165 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="s390x_arch">167 ········<cpe-lang:platform·id="chrony">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>169 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
170 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="machine">172 ········<cpe-lang:platform·id="audit">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>174 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>
175 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="chrony">177 ········<cpe-lang:platform·id="not_s390x_arch">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>179 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
180 ··········</cpe-lang:logical-test>180 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>181 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="grub2">182 ········<cpe-lang:platform·id="ntp">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>184 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
185 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="audit">187 ········<cpe-lang:platform·id="pam">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>189 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>
190 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
191 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
192 ········<cpe-lang:platform·id="postfix">192 ········<cpe-lang:platform·id="aarch64_arch">
193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
194 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>194 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
195 ··········</cpe-lang:logical-test>195 ··········</cpe-lang:logical-test>
196 ········</cpe-lang:platform>196 ········</cpe-lang:platform>
197 ········<cpe-lang:platform·id="sssd">197 ········<cpe-lang:platform·id="postfix">
198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
199 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>199 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
200 ··········</cpe-lang:logical-test>200 ··········</cpe-lang:logical-test>
201 ········</cpe-lang:platform>201 ········</cpe-lang:platform>
202 ········<cpe-lang:platform·id="gdm">202 ········<cpe-lang:platform·id="non-uefi">
203 ··········<cpe-lang:logical-test·operator="AND"·negate="false">203 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
204 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>204 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
205 ··········</cpe-lang:logical-test>205 ··········</cpe-lang:logical-test>
206 ········</cpe-lang:platform>206 ········</cpe-lang:platform>
207 ········<cpe-lang:platform·id="ntp">207 ········<cpe-lang:platform·id="uefi">
208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
209 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>209 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
210 ··········</cpe-lang:logical-test>210 ··········</cpe-lang:logical-test>
211 ········</cpe-lang:platform>211 ········</cpe-lang:platform>
212 ········<cpe-lang:platform·id="non-uefi">212 ········<cpe-lang:platform·id="sudo">
213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
214 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>214 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
215 ··········</cpe-lang:logical-test>215 ··········</cpe-lang:logical-test>
216 ········</cpe-lang:platform>216 ········</cpe-lang:platform>
217 ········<cpe-lang:platform·id="not_s390x_arch">217 ········<cpe-lang:platform·id="grub2">
218 ··········<cpe-lang:logical-test·operator="AND"·negate="false">218 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
219 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>219 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
220 ··········</cpe-lang:logical-test>220 ··········</cpe-lang:logical-test>
221 ········</cpe-lang:platform>221 ········</cpe-lang:platform>
222 ········<cpe-lang:platform·id="uefi">222 ········<cpe-lang:platform·id="s390x_arch">
223 ··········<cpe-lang:logical-test·operator="AND"·negate="false">223 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
224 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>224 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
225 ··········</cpe-lang:logical-test>225 ··········</cpe-lang:logical-test>
226 ········</cpe-lang:platform>226 ········</cpe-lang:platform>
227 ········<cpe-lang:platform·id="login_defs">227 ········<cpe-lang:platform·id="machine">
228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
229 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>229 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
230 ··········</cpe-lang:logical-test>230 ··········</cpe-lang:logical-test>
231 ········</cpe-lang:platform>231 ········</cpe-lang:platform>
232 ······</cpe-lang:platform-specification>232 ······</cpe-lang:platform-specification>
233 ······<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~"/>233 ······<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~"/>
234 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>234 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
235 ······<xccdf-1.2:metadata>235 ······<xccdf-1.2:metadata>
236 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>236 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 54116, 38 lines modifiedOffset 54116, 38 lines modified
  
54116 The54116 The
54117 ··················<html:code>netfs</html:code>54117 ··················<html:code>netfs</html:code>
54118 ··················service·can·be·disabled·with·the·following·command:54118 ··················service·can·be·disabled·with·the·following·command:
54119 ··················<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>54119 ··················<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>
54120 ················</xccdf-1.2:description>54120 ················</xccdf-1.2:description>
54121 ················<xccdf-1.2:rationale/>54121 ················<xccdf-1.2:rationale/>
 54122 ················<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services]
 54123 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix>
 54124 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs
  
 54125 class·disable_netfs·{
 54126 ··service·{'netfs':
 54127 ····enable·=&gt;·false,
 54128 ····ensure·=&gt;·'stopped',
 54129 ··}
 54130 }</xccdf-1.2:fix>
54122 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v154131 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v1
54123 kind:·MachineConfig54132 kind:·MachineConfig
54124 spec:54133 spec:
54125 ··config:54134 ··config:
54126 ····ignition:54135 ····ignition:
54127 ······version:·3.1.054136 ······version:·3.1.0
54128 ····systemd:54137 ····systemd:
54129 ······units:54138 ······units:
54130 ······-·name:·netfs.service54139 ······-·name:·netfs.service
54131 ········enabled:·false54140 ········enabled:·false
54132 ········mask:·true54141 ········mask:·true
54133 ······-·name:·netfs.socket54142 ······-·name:·netfs.socket
54134 ········enabled:·false54143 ········enabled:·false
54135 ········mask:·true</xccdf-1.2:fix>54144 ········mask:·true</xccdf-1.2:fix>
54136 ················<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services] 
54137 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix> 
54138 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs 
Max diff block lines reached; 700535/708604 bytes (98.86%) of diff not shown.
653 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
653 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
Ordering differences only
    
Offset 3, 2885 lines modifiedOffset 3, 2885 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
11 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>11 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
 23 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
29 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>29 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">
41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1"> 
47 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·TIPC·Support</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
59 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>59 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_name_format_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
65 ······<ocil:title>Set·hostname·as·computer·node·name·in·audit·logs</ocil:title>65 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_name_format_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Recovery·Booting</ocil:title>71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
77 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>77 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1"> 
83 ······<ocil:title>Disable·IA32·emulation</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
89 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">
95 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>95 ······<ocil:title>Kernel·panic·on·oops</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
101 ······<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-service_timesyncd_enabled_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>107 ······<ocil:title>Enable·systemd_timesyncd·Service</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-service_timesyncd_enabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 113 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
119 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
 119 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 655712/668118 bytes (98.14%) of diff not shown.
10.2 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
10.1 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
Ordering differences only
    
Offset 47, 92 lines modifiedOffset 47, 92 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="sudo">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="aarch64_arch">64 ····<cpe-lang:platform·id="login_defs">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
67 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="s390x_arch">69 ····<cpe-lang:platform·id="chrony">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
72 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="machine">74 ····<cpe-lang:platform·id="audit">
75 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
77 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
78 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
79 ····<cpe-lang:platform·id="chrony">79 ····<cpe-lang:platform·id="not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
82 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="grub2">84 ····<cpe-lang:platform·id="ntp">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="audit">89 ····<cpe-lang:platform·id="pam">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="postfix">94 ····<cpe-lang:platform·id="aarch64_arch">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="sssd">99 ····<cpe-lang:platform·id="postfix">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>101 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="gdm">104 ····<cpe-lang:platform·id="non-uefi">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>106 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="ntp">109 ····<cpe-lang:platform·id="uefi">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>111 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="non-uefi">114 ····<cpe-lang:platform·id="sudo">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>116 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_s390x_arch">119 ····<cpe-lang:platform·id="grub2">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>121 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
122 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="uefi">124 ····<cpe-lang:platform·id="s390x_arch">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>126 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
127 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="login_defs">129 ····<cpe-lang:platform·id="machine">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>131 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
132 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
134 ··</cpe-lang:platform-specification>134 ··</cpe-lang:platform-specification>
135 ··<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~"/>135 ··<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~"/>
136 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>136 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
137 ··<xccdf-1.2:metadata>137 ··<xccdf-1.2:metadata>
138 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>138 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 54018, 38 lines modifiedOffset 54018, 38 lines modified
  
54018 The54018 The
54019 ··············<html:code>netfs</html:code>54019 ··············<html:code>netfs</html:code>
54020 ··············service·can·be·disabled·with·the·following·command:54020 ··············service·can·be·disabled·with·the·following·command:
54021 ··············<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>54021 ··············<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>
54022 ············</xccdf-1.2:description>54022 ············</xccdf-1.2:description>
54023 ············<xccdf-1.2:rationale/>54023 ············<xccdf-1.2:rationale/>
 54024 ············<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services]
 54025 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix>
 54026 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs
  
 54027 class·disable_netfs·{
 54028 ··service·{'netfs':
 54029 ····enable·=&gt;·false,
 54030 ····ensure·=&gt;·'stopped',
 54031 ··}
 54032 }</xccdf-1.2:fix>
54024 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v154033 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v1
54025 kind:·MachineConfig54034 kind:·MachineConfig
54026 spec:54035 spec:
54027 ··config:54036 ··config:
54028 ····ignition:54037 ····ignition:
54029 ······version:·3.1.054038 ······version:·3.1.0
54030 ····systemd:54039 ····systemd:
54031 ······units:54040 ······units:
54032 ······-·name:·netfs.service54041 ······-·name:·netfs.service
54033 ········enabled:·false54042 ········enabled:·false
54034 ········mask:·true54043 ········mask:·true
54035 ······-·name:·netfs.socket54044 ······-·name:·netfs.socket
54036 ········enabled:·false54045 ········enabled:·false
54037 ········mask:·true</xccdf-1.2:fix>54046 ········mask:·true</xccdf-1.2:fix>
54038 ············<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services] 
54039 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix> 
54040 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs 
Max diff block lines reached; 2661/10200 bytes (26.09%) of diff not shown.
720 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds-1.2.xml
720 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds-1.2.xml
Ordering differences only
    
Offset 151, 104 lines modifiedOffset 151, 104 lines modified
151 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>151 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
152 ······</xccdf-1.2:front-matter>152 ······</xccdf-1.2:front-matter>
153 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered153 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
154 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other154 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
155 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their155 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
156 respective·companies.</xccdf-1.2:rear-matter>156 respective·companies.</xccdf-1.2:rear-matter>
157 ······<cpe-lang:platform-specification>157 ······<cpe-lang:platform-specification>
158 ········<cpe-lang:platform·id="pam">158 ········<cpe-lang:platform·id="sssd">
159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
160 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>160 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
161 ··········</cpe-lang:logical-test>161 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>162 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="machine_and_partition-var-tmp">163 ········<cpe-lang:platform·id="gdm">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
165 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>165 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
166 ············<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/> 
167 ··········</cpe-lang:logical-test>166 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>167 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="sudo">168 ········<cpe-lang:platform·id="login_defs">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
171 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>170 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
172 ··········</cpe-lang:logical-test>171 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>172 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="aarch64_arch">173 ········<cpe-lang:platform·id="chrony">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
176 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>175 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
177 ··········</cpe-lang:logical-test>176 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>177 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="s390x_arch">178 ········<cpe-lang:platform·id="audit">
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>180 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>
182 ··········</cpe-lang:logical-test>181 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>182 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="machine">183 ········<cpe-lang:platform·id="not_s390x_arch">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
186 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>185 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
187 ··········</cpe-lang:logical-test>186 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>187 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="chrony">188 ········<cpe-lang:platform·id="ntp">
190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
191 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>190 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
192 ··········</cpe-lang:logical-test>191 ··········</cpe-lang:logical-test>
193 ········</cpe-lang:platform>192 ········</cpe-lang:platform>
194 ········<cpe-lang:platform·id="grub2">193 ········<cpe-lang:platform·id="pam">
195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
196 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>195 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>
197 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
198 ········</cpe-lang:platform>197 ········</cpe-lang:platform>
199 ········<cpe-lang:platform·id="audit">198 ········<cpe-lang:platform·id="machine_and_partition-tmp">
200 ··········<cpe-lang:logical-test·operator="AND"·negate="false">199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
201 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>200 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 201 ············<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
202 ··········</cpe-lang:logical-test>202 ··········</cpe-lang:logical-test>
203 ········</cpe-lang:platform>203 ········</cpe-lang:platform>
204 ········<cpe-lang:platform·id="postfix">204 ········<cpe-lang:platform·id="machine_and_partition-var-tmp">
205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
206 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>206 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 207 ············<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
207 ··········</cpe-lang:logical-test>208 ··········</cpe-lang:logical-test>
208 ········</cpe-lang:platform>209 ········</cpe-lang:platform>
209 ········<cpe-lang:platform·id="sssd">210 ········<cpe-lang:platform·id="aarch64_arch">
210 ··········<cpe-lang:logical-test·operator="AND"·negate="false">211 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
211 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>212 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
212 ··········</cpe-lang:logical-test>213 ··········</cpe-lang:logical-test>
213 ········</cpe-lang:platform>214 ········</cpe-lang:platform>
214 ········<cpe-lang:platform·id="gdm">215 ········<cpe-lang:platform·id="postfix">
215 ··········<cpe-lang:logical-test·operator="AND"·negate="false">216 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
216 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>217 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
217 ··········</cpe-lang:logical-test>218 ··········</cpe-lang:logical-test>
218 ········</cpe-lang:platform>219 ········</cpe-lang:platform>
219 ········<cpe-lang:platform·id="ntp">220 ········<cpe-lang:platform·id="non-uefi">
220 ··········<cpe-lang:logical-test·operator="AND"·negate="false">221 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
221 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>222 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
222 ··········</cpe-lang:logical-test>223 ··········</cpe-lang:logical-test>
223 ········</cpe-lang:platform>224 ········</cpe-lang:platform>
224 ········<cpe-lang:platform·id="non-uefi">225 ········<cpe-lang:platform·id="uefi">
225 ··········<cpe-lang:logical-test·operator="AND"·negate="false">226 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
226 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>227 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
227 ··········</cpe-lang:logical-test>228 ··········</cpe-lang:logical-test>
228 ········</cpe-lang:platform>229 ········</cpe-lang:platform>
229 ········<cpe-lang:platform·id="not_s390x_arch">230 ········<cpe-lang:platform·id="sudo">
230 ··········<cpe-lang:logical-test·operator="AND"·negate="false">231 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
231 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>232 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
232 ··········</cpe-lang:logical-test>233 ··········</cpe-lang:logical-test>
233 ········</cpe-lang:platform>234 ········</cpe-lang:platform>
234 ········<cpe-lang:platform·id="machine_and_partition-tmp">235 ········<cpe-lang:platform·id="grub2">
235 ··········<cpe-lang:logical-test·operator="AND"·negate="false">236 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
236 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>237 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
237 ············<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/> 
238 ··········</cpe-lang:logical-test>238 ··········</cpe-lang:logical-test>
239 ········</cpe-lang:platform>239 ········</cpe-lang:platform>
240 ········<cpe-lang:platform·id="uefi">240 ········<cpe-lang:platform·id="s390x_arch">
241 ··········<cpe-lang:logical-test·operator="AND"·negate="false">241 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
242 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>242 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
243 ··········</cpe-lang:logical-test>243 ··········</cpe-lang:logical-test>
244 ········</cpe-lang:platform>244 ········</cpe-lang:platform>
245 ········<cpe-lang:platform·id="login_defs">245 ········<cpe-lang:platform·id="machine">
246 ··········<cpe-lang:logical-test·operator="AND"·negate="false">246 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
247 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>247 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
248 ··········</cpe-lang:logical-test>248 ··········</cpe-lang:logical-test>
249 ········</cpe-lang:platform>249 ········</cpe-lang:platform>
250 ······</cpe-lang:platform-specification>250 ······</cpe-lang:platform-specification>
251 ······<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~"/>251 ······<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~"/>
252 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>252 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
253 ······<xccdf-1.2:metadata>253 ······<xccdf-1.2:metadata>
254 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>254 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 57603, 38 lines modifiedOffset 57603, 38 lines modified
  
57603 The57603 The
57604 ··················<html:code>netfs</html:code>57604 ··················<html:code>netfs</html:code>
57605 ··················service·can·be·disabled·with·the·following·command:57605 ··················service·can·be·disabled·with·the·following·command:
57606 ··················<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>57606 ··················<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>
57607 ················</xccdf-1.2:description>57607 ················</xccdf-1.2:description>
57608 ················<xccdf-1.2:rationale/>57608 ················<xccdf-1.2:rationale/>
 57609 ················<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services]
 57610 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix>
 57611 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs
  
 57612 class·disable_netfs·{
 57613 ··service·{'netfs':
 57614 ····enable·=&gt;·false,
 57615 ····ensure·=&gt;·'stopped',
 57616 ··}
 57617 }</xccdf-1.2:fix>
57609 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v157618 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v1
57610 kind:·MachineConfig57619 kind:·MachineConfig
57611 spec:57620 spec:
Max diff block lines reached; 728993/737131 bytes (98.90%) of diff not shown.
720 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
720 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
Ordering differences only
    
Offset 151, 104 lines modifiedOffset 151, 104 lines modified
151 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>151 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
152 ······</xccdf-1.2:front-matter>152 ······</xccdf-1.2:front-matter>
153 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered153 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
154 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other154 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
155 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their155 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
156 respective·companies.</xccdf-1.2:rear-matter>156 respective·companies.</xccdf-1.2:rear-matter>
157 ······<cpe-lang:platform-specification>157 ······<cpe-lang:platform-specification>
158 ········<cpe-lang:platform·id="pam">158 ········<cpe-lang:platform·id="sssd">
159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">159 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
160 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>160 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
161 ··········</cpe-lang:logical-test>161 ··········</cpe-lang:logical-test>
162 ········</cpe-lang:platform>162 ········</cpe-lang:platform>
163 ········<cpe-lang:platform·id="machine_and_partition-var-tmp">163 ········<cpe-lang:platform·id="gdm">
164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">164 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
165 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>165 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
166 ············<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/> 
167 ··········</cpe-lang:logical-test>166 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>167 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="sudo">168 ········<cpe-lang:platform·id="login_defs">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">169 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
171 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>170 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
172 ··········</cpe-lang:logical-test>171 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>172 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="aarch64_arch">173 ········<cpe-lang:platform·id="chrony">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">174 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
176 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>175 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
177 ··········</cpe-lang:logical-test>176 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>177 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="s390x_arch">178 ········<cpe-lang:platform·id="audit">
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">179 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>180 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>
182 ··········</cpe-lang:logical-test>181 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>182 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="machine">183 ········<cpe-lang:platform·id="not_s390x_arch">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">184 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
186 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>185 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
187 ··········</cpe-lang:logical-test>186 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>187 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="chrony">188 ········<cpe-lang:platform·id="ntp">
190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">189 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
191 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>190 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
192 ··········</cpe-lang:logical-test>191 ··········</cpe-lang:logical-test>
193 ········</cpe-lang:platform>192 ········</cpe-lang:platform>
194 ········<cpe-lang:platform·id="grub2">193 ········<cpe-lang:platform·id="pam">
195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">194 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
196 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>195 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>
197 ··········</cpe-lang:logical-test>196 ··········</cpe-lang:logical-test>
198 ········</cpe-lang:platform>197 ········</cpe-lang:platform>
199 ········<cpe-lang:platform·id="audit">198 ········<cpe-lang:platform·id="machine_and_partition-tmp">
200 ··········<cpe-lang:logical-test·operator="AND"·negate="false">199 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
201 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>200 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 201 ············<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
202 ··········</cpe-lang:logical-test>202 ··········</cpe-lang:logical-test>
203 ········</cpe-lang:platform>203 ········</cpe-lang:platform>
204 ········<cpe-lang:platform·id="postfix">204 ········<cpe-lang:platform·id="machine_and_partition-var-tmp">
205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
206 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>206 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 207 ············<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
207 ··········</cpe-lang:logical-test>208 ··········</cpe-lang:logical-test>
208 ········</cpe-lang:platform>209 ········</cpe-lang:platform>
209 ········<cpe-lang:platform·id="sssd">210 ········<cpe-lang:platform·id="aarch64_arch">
210 ··········<cpe-lang:logical-test·operator="AND"·negate="false">211 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
211 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>212 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
212 ··········</cpe-lang:logical-test>213 ··········</cpe-lang:logical-test>
213 ········</cpe-lang:platform>214 ········</cpe-lang:platform>
214 ········<cpe-lang:platform·id="gdm">215 ········<cpe-lang:platform·id="postfix">
215 ··········<cpe-lang:logical-test·operator="AND"·negate="false">216 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
216 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>217 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
217 ··········</cpe-lang:logical-test>218 ··········</cpe-lang:logical-test>
218 ········</cpe-lang:platform>219 ········</cpe-lang:platform>
219 ········<cpe-lang:platform·id="ntp">220 ········<cpe-lang:platform·id="non-uefi">
220 ··········<cpe-lang:logical-test·operator="AND"·negate="false">221 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
221 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>222 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
222 ··········</cpe-lang:logical-test>223 ··········</cpe-lang:logical-test>
223 ········</cpe-lang:platform>224 ········</cpe-lang:platform>
224 ········<cpe-lang:platform·id="non-uefi">225 ········<cpe-lang:platform·id="uefi">
225 ··········<cpe-lang:logical-test·operator="AND"·negate="false">226 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
226 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>227 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
227 ··········</cpe-lang:logical-test>228 ··········</cpe-lang:logical-test>
228 ········</cpe-lang:platform>229 ········</cpe-lang:platform>
229 ········<cpe-lang:platform·id="not_s390x_arch">230 ········<cpe-lang:platform·id="sudo">
230 ··········<cpe-lang:logical-test·operator="AND"·negate="false">231 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
231 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>232 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
232 ··········</cpe-lang:logical-test>233 ··········</cpe-lang:logical-test>
233 ········</cpe-lang:platform>234 ········</cpe-lang:platform>
234 ········<cpe-lang:platform·id="machine_and_partition-tmp">235 ········<cpe-lang:platform·id="grub2">
235 ··········<cpe-lang:logical-test·operator="AND"·negate="false">236 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
236 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>237 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
237 ············<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/> 
238 ··········</cpe-lang:logical-test>238 ··········</cpe-lang:logical-test>
239 ········</cpe-lang:platform>239 ········</cpe-lang:platform>
240 ········<cpe-lang:platform·id="uefi">240 ········<cpe-lang:platform·id="s390x_arch">
241 ··········<cpe-lang:logical-test·operator="AND"·negate="false">241 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
242 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>242 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
243 ··········</cpe-lang:logical-test>243 ··········</cpe-lang:logical-test>
244 ········</cpe-lang:platform>244 ········</cpe-lang:platform>
245 ········<cpe-lang:platform·id="login_defs">245 ········<cpe-lang:platform·id="machine">
246 ··········<cpe-lang:logical-test·operator="AND"·negate="false">246 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
247 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>247 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
248 ··········</cpe-lang:logical-test>248 ··········</cpe-lang:logical-test>
249 ········</cpe-lang:platform>249 ········</cpe-lang:platform>
250 ······</cpe-lang:platform-specification>250 ······</cpe-lang:platform-specification>
251 ······<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~"/>251 ······<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~"/>
252 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>252 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
253 ······<xccdf-1.2:metadata>253 ······<xccdf-1.2:metadata>
254 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>254 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 57603, 38 lines modifiedOffset 57603, 38 lines modified
  
57603 The57603 The
57604 ··················<html:code>netfs</html:code>57604 ··················<html:code>netfs</html:code>
57605 ··················service·can·be·disabled·with·the·following·command:57605 ··················service·can·be·disabled·with·the·following·command:
57606 ··················<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>57606 ··················<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>
57607 ················</xccdf-1.2:description>57607 ················</xccdf-1.2:description>
57608 ················<xccdf-1.2:rationale/>57608 ················<xccdf-1.2:rationale/>
 57609 ················<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services]
 57610 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix>
 57611 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs
  
 57612 class·disable_netfs·{
 57613 ··service·{'netfs':
 57614 ····enable·=&gt;·false,
 57615 ····ensure·=&gt;·'stopped',
 57616 ··}
 57617 }</xccdf-1.2:fix>
57609 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v157618 ················<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v1
57610 kind:·MachineConfig57619 kind:·MachineConfig
57611 spec:57620 spec:
Max diff block lines reached; 728993/737131 bytes (98.90%) of diff not shown.
678 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
678 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
Ordering differences only
    
Offset 3, 2947 lines modifiedOffset 3, 2947 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
11 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>11 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
 23 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
29 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>29 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">
41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1"> 
47 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·TIPC·Support</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
59 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>59 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_name_format_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
65 ······<ocil:title>Set·hostname·as·computer·node·name·in·audit·logs</ocil:title>65 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_name_format_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Recovery·Booting</ocil:title>71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
77 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>77 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1"> 
83 ······<ocil:title>Disable·IA32·emulation</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
89 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">
95 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>95 ······<ocil:title>Kernel·panic·on·oops</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
101 ······<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-service_timesyncd_enabled_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>107 ······<ocil:title>Enable·systemd_timesyncd·Service</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-service_timesyncd_enabled_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 113 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
119 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
 119 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 681969/694375 bytes (98.21%) of diff not shown.
11.1 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
11.0 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
Ordering differences only
    
Offset 47, 104 lines modifiedOffset 47, 104 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/> 
63 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
64 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
65 ····<cpe-lang:platform·id="sudo">64 ····<cpe-lang:platform·id="login_defs">
66 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
67 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
68 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
69 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
70 ····<cpe-lang:platform·id="aarch64_arch">69 ····<cpe-lang:platform·id="chrony">
71 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
72 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
73 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
74 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
75 ····<cpe-lang:platform·id="s390x_arch">74 ····<cpe-lang:platform·id="audit">
76 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
77 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
78 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_s390x_arch">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
83 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="chrony">84 ····<cpe-lang:platform·id="ntp">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
88 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="grub2">89 ····<cpe-lang:platform·id="pam">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
93 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="audit">94 ····<cpe-lang:platform·id="machine_and_partition-tmp">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 97 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
98 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="postfix">100 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>102 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 103 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
103 ······</cpe-lang:logical-test>104 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>105 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="sssd">106 ····<cpe-lang:platform·id="aarch64_arch">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">107 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>108 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
108 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="gdm">111 ····<cpe-lang:platform·id="postfix">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>113 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
113 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="ntp">116 ····<cpe-lang:platform·id="non-uefi">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>118 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
118 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="non-uefi">121 ····<cpe-lang:platform·id="uefi">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>123 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
123 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="not_s390x_arch">126 ····<cpe-lang:platform·id="sudo">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>128 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
128 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="machine_and_partition-tmp">131 ····<cpe-lang:platform·id="grub2">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>133 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
133 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/> 
134 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="uefi">136 ····<cpe-lang:platform·id="s390x_arch">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>138 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
139 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="login_defs">141 ····<cpe-lang:platform·id="machine">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>143 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
144 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
146 ··</cpe-lang:platform-specification>146 ··</cpe-lang:platform-specification>
147 ··<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~"/>147 ··<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~"/>
148 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>148 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
149 ··<xccdf-1.2:metadata>149 ··<xccdf-1.2:metadata>
150 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>150 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 57499, 38 lines modifiedOffset 57499, 38 lines modified
  
57499 The57499 The
57500 ··············<html:code>netfs</html:code>57500 ··············<html:code>netfs</html:code>
57501 ··············service·can·be·disabled·with·the·following·command:57501 ··············service·can·be·disabled·with·the·following·command:
57502 ··············<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>57502 ··············<html:pre>$·sudo·systemctl·mask·--now·netfs.service</html:pre>
57503 ············</xccdf-1.2:description>57503 ············</xccdf-1.2:description>
57504 ············<xccdf-1.2:rationale/>57504 ············<xccdf-1.2:rationale/>
 57505 ············<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="service_netfs_disabled">[customizations.services]
 57506 disabled·=·[&quot;netfs&quot;]</xccdf-1.2:fix>
 57507 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="service_netfs_disabled"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·disable_netfs
  
 57508 class·disable_netfs·{
 57509 ··service·{'netfs':
 57510 ····enable·=&gt;·false,
 57511 ····ensure·=&gt;·'stopped',
 57512 ··}
 57513 }</xccdf-1.2:fix>
57505 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v157514 ············<xccdf-1.2:fix·system="urn:xccdf:fix:script:kubernetes"·id="service_netfs_disabled"·complexity="low"·disruption="medium"·reboot="true"·strategy="disable">apiVersion:·machineconfiguration.openshift.io/v1
57506 kind:·MachineConfig57515 kind:·MachineConfig
57507 spec:57516 spec:
Max diff block lines reached; 3572/11120 bytes (32.12%) of diff not shown.
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds-1.2.xml
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds-1.2.xml
Max HTML report size reached
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
Max HTML report size reached
1.17 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
1.17 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
Max HTML report size reached
337 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
337 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
    
Offset 47, 108 lines modifiedOffset 47, 108 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="wifi-iface">59 ····<cpe-lang:platform·id="chrony_or_ntp">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 61 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
61 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>62 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
62 ······</cpe-lang:logical-test>63 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>64 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="sudo">65 ····<cpe-lang:platform·id="gdm">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">66 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>67 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
67 ······</cpe-lang:logical-test>68 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>69 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="aarch64_arch">70 ····<cpe-lang:platform·id="login_defs">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">71 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>72 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
72 ······</cpe-lang:logical-test>73 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>74 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="chrony_or_ntp">75 ····<cpe-lang:platform·id="chrony">
75 ······<cpe-lang:logical-test·operator="OR"·negate="false">76 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>77 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
77 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/> 
78 ······</cpe-lang:logical-test>78 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>79 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="s390x_arch">80 ····<cpe-lang:platform·id="audit">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>82 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
83 ······</cpe-lang:logical-test>83 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>84 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="machine">85 ····<cpe-lang:platform·id="not_s390x_arch">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>87 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
88 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="chrony">90 ····<cpe-lang:platform·id="ntp">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>92 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
93 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="grub2">95 ····<cpe-lang:platform·id="pam">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>97 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
98 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="systemd">100 ····<cpe-lang:platform·id="systemd">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>102 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>
103 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="audit">105 ····<cpe-lang:platform·id="aarch64_arch">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
108 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="postfix">110 ····<cpe-lang:platform·id="postfix">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>112 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
113 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="sssd">115 ····<cpe-lang:platform·id="wifi-iface">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>117 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
118 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="gdm">120 ····<cpe-lang:platform·id="non-uefi">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>122 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
123 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="ntp">125 ····<cpe-lang:platform·id="uefi">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>127 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
128 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="non-uefi">130 ····<cpe-lang:platform·id="sudo">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>132 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
133 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="not_s390x_arch">135 ····<cpe-lang:platform·id="grub2">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>137 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
138 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="uefi">140 ····<cpe-lang:platform·id="s390x_arch">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>142 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
143 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="login_defs">145 ····<cpe-lang:platform·id="machine">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>147 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
148 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
150 ··</cpe-lang:platform-specification>150 ··</cpe-lang:platform-specification>
151 ··<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~"/>151 ··<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:20.04::~~lts~~~"/>
152 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>152 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
153 ··<xccdf-1.2:metadata>153 ··<xccdf-1.2:metadata>
154 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>154 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 16180, 16 lines modifiedOffset 16180, 16 lines modified
  
16180 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension16180 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
16181 ··find:16181 ··find:
16182 ····paths:·/etc/audit/rules.d/16182 ····paths:·/etc/audit/rules.d/
16183 ····patterns:·'*.rules'16183 ····patterns:·'*.rules'
16184 ··register:·find_rules_d16184 ··register:·find_rules_d
16185 ··when:16185 ··when:
16186 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
16187 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'16186 ··-·'&quot;auditd&quot;·in·ansible_facts.packages'
 16187 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
16188 ··tags:16188 ··tags:
16189 ··-·CJIS-5.4.1.116189 ··-·CJIS-5.4.1.1
16190 ··-·NIST-800-171-3.3.116190 ··-·NIST-800-171-3.3.1
16191 ··-·NIST-800-171-3.4.316191 ··-·NIST-800-171-3.4.3
16192 ··-·NIST-800-53-AC-6(9)16192 ··-·NIST-800-53-AC-6(9)
16193 ··-·NIST-800-53-CM-6(a)16193 ··-·NIST-800-53-CM-6(a)
16194 ··-·PCI-DSS-Req-10.5.216194 ··-·PCI-DSS-Req-10.5.2
Max diff block lines reached; 337860/345080 bytes (97.91%) of diff not shown.
1.24 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds-1.2.xml
1.24 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds-1.2.xml
Max HTML report size reached
1.24 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
1.24 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
Max HTML report size reached
1.17 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
1.17 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
Max HTML report size reached
26.9 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
26.7 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
    
Offset 47, 108 lines modifiedOffset 47, 108 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="wifi-iface">59 ····<cpe-lang:platform·id="chrony_or_ntp">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 61 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
61 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>62 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
62 ······</cpe-lang:logical-test>63 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>64 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="sudo">65 ····<cpe-lang:platform·id="gdm">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">66 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>67 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
67 ······</cpe-lang:logical-test>68 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>69 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="aarch64_arch">70 ····<cpe-lang:platform·id="login_defs">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">71 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>72 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
72 ······</cpe-lang:logical-test>73 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>74 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="chrony_or_ntp">75 ····<cpe-lang:platform·id="chrony">
75 ······<cpe-lang:logical-test·operator="OR"·negate="false">76 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>77 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
77 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/> 
78 ······</cpe-lang:logical-test>78 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>79 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="s390x_arch">80 ····<cpe-lang:platform·id="audit">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>82 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
83 ······</cpe-lang:logical-test>83 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>84 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="machine">85 ····<cpe-lang:platform·id="not_s390x_arch">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>87 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
88 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="chrony">90 ····<cpe-lang:platform·id="ntp">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>92 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
93 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="grub2">95 ····<cpe-lang:platform·id="pam">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>97 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
98 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="systemd">100 ····<cpe-lang:platform·id="systemd">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>102 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>
103 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="audit">105 ····<cpe-lang:platform·id="aarch64_arch">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
108 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="postfix">110 ····<cpe-lang:platform·id="postfix">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>112 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
113 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="sssd">115 ····<cpe-lang:platform·id="wifi-iface">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>117 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
118 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="gdm">120 ····<cpe-lang:platform·id="non-uefi">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>122 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
123 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="ntp">125 ····<cpe-lang:platform·id="uefi">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>127 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
128 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="non-uefi">130 ····<cpe-lang:platform·id="sudo">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>132 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
133 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="not_s390x_arch">135 ····<cpe-lang:platform·id="grub2">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>137 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
138 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="uefi">140 ····<cpe-lang:platform·id="s390x_arch">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>142 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
143 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="login_defs">145 ····<cpe-lang:platform·id="machine">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>147 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
148 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
150 ··</cpe-lang:platform-specification>150 ··</cpe-lang:platform-specification>
151 ··<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~"/>151 ··<xccdf-1.2:platform·idref="cpe:/o:canonical:ubuntu_linux:22.04::~~lts~~~"/>
152 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>152 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
153 ··<xccdf-1.2:metadata>153 ··<xccdf-1.2:metadata>
154 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>154 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 76421, 15 lines modifiedOffset 76421, 15 lines modified
76421 ··········<xccdf-1.2:reference·href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>76421 ··········<xccdf-1.2:reference·href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
76422 ··········<xccdf-1.2:reference·href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>76422 ··········<xccdf-1.2:reference·href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
76423 ··········<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>76423 ··········<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
76424 ··········<xccdf-1.2:reference·href="https://www.cisecurity.org/benchmark/ubuntu_linux/">1.5.2</xccdf-1.2:reference>76424 ··········<xccdf-1.2:reference·href="https://www.cisecurity.org/benchmark/ubuntu_linux/">1.5.2</xccdf-1.2:reference>
76425 ··········<xccdf-1.2:rationale>Only·root·should·be·able·to·modify·important·boot·parameters.</xccdf-1.2:rationale>76425 ··········<xccdf-1.2:rationale>Only·root·should·be·able·to·modify·important·boot·parameters.</xccdf-1.2:rationale>
76426 ··········<xccdf-1.2:platform·idref="#machine"/>76426 ··········<xccdf-1.2:platform·idref="#machine"/>
76427 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="file_owner_grub2_cfg"·complexity="low"·disruption="low"·reboot="false"·strategy="configure">#·Remediation·is·applicable·only·in·certain·platforms76427 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="file_owner_grub2_cfg"·complexity="low"·disruption="low"·reboot="false"·strategy="configure">#·Remediation·is·applicable·only·in·certain·platforms
76428 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2&gt;/dev/null·|·grep·-q·installed·&amp;&amp;·[·!·-f·/sys/firmware/efi·]·&amp;&amp;·{·[·!·-f·/.dockerenv·]·&amp;&amp;·[·!·-f·/run/.containerenv·];·};·then76428 if·[·!·-f·/sys/firmware/efi·]·&amp;&amp;·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2&gt;/dev/null·|·grep·-q·installed·&amp;&amp;·{·[·!·-f·/.dockerenv·]·&amp;&amp;·[·!·-f·/run/.containerenv·];·};·then
  
76429 chown·0·/boot/grub/grub.cfg76429 chown·0·/boot/grub/grub.cfg
  
76430 else76430 else
76431 ····&gt;&amp;2·echo·'Remediation·is·not·applicable,·nothing·was·done'76431 ····&gt;&amp;2·echo·'Remediation·is·not·applicable,·nothing·was·done'
76432 fi</xccdf-1.2:fix>76432 fi</xccdf-1.2:fix>
76433 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="file_owner_grub2_cfg"·complexity="low"·disruption="low"·reboot="false"·strategy="configure">-·name:·Gather·the·package·facts76433 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="file_owner_grub2_cfg"·complexity="low"·disruption="low"·reboot="false"·strategy="configure">-·name:·Gather·the·package·facts
Offset 76449, 16 lines modifiedOffset 76449, 16 lines modified
76449 ··-·no_reboot_needed76449 ··-·no_reboot_needed
Max diff block lines reached; 19017/27273 bytes (69.73%) of diff not shown.
4.36 MB
ssg-debian_0.1.65-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary
2 -rw-r--r--···0········0········0·····1820·2022-12-20·09:54:05.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1820·2022-12-20·09:54:05.000000·control.tar.xz
3 -rw-r--r--···0········0········0···829516·2022-12-20·09:54:05.000000·data.tar.xz3 -rw-r--r--···0········0········0···829496·2022-12-20·09:54:05.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
4.36 MB
data.tar.xz
4.36 MB
data.tar
782 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ds-1.2.xml
782 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ds-1.2.xml
Max HTML report size reached
782 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ds.xml
782 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ds.xml
Max HTML report size reached
690 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ocil.xml
690 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-ocil.xml
Ordering differences only
    
Offset 3, 6236 lines modifiedOffset 3, 6272 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>23 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
 29 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">
53 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
59 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
65 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>53 ······<ocil:title>Disable·TIPC·Support</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-auditd_name_format_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
71 ······<ocil:title>Set·hostname·as·computer·node·name·in·audit·logs</ocil:title>59 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-auditd_name_format_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
77 ······<ocil:title>Disable·Recovery·Booting</ocil:title>65 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1"> 
83 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
89 ······<ocil:title>Disable·IA32·emulation</ocil:title>77 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
95 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>83 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
101 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">
107 ······<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>95 ······<ocil:title>Kernel·panic·on·oops</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
Max diff block lines reached; 694360/706243 bytes (98.32%) of diff not shown.
61.2 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-xccdf.xml
61.0 KB
./usr/share/xml/scap/ssg/content/ssg-debian10-xccdf.xml
    
Offset 47, 97 lines modifiedOffset 47, 97 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="sudo">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="aarch64_arch">64 ····<cpe-lang:platform·id="login_defs">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
67 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="s390x_arch">69 ····<cpe-lang:platform·id="chrony">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
72 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="machine">74 ····<cpe-lang:platform·id="audit">
75 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
77 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
78 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
79 ····<cpe-lang:platform·id="net-snmp">79 ····<cpe-lang:platform·id="not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:fact-ref·name="cpe:/a:net-snmp"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
82 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="chrony">84 ····<cpe-lang:platform·id="ntp">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="grub2">89 ····<cpe-lang:platform·id="pam">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="audit">94 ····<cpe-lang:platform·id="net-snmp">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:net-snmp"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="postfix">99 ····<cpe-lang:platform·id="aarch64_arch">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>101 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="sssd">104 ····<cpe-lang:platform·id="postfix">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>106 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="gdm">109 ····<cpe-lang:platform·id="non-uefi">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>111 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="ntp">114 ····<cpe-lang:platform·id="uefi">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>116 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="non-uefi">119 ····<cpe-lang:platform·id="sudo">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>121 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
122 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="not_s390x_arch">124 ····<cpe-lang:platform·id="grub2">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>126 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
127 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="uefi">129 ····<cpe-lang:platform·id="s390x_arch">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>131 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
132 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="login_defs">134 ····<cpe-lang:platform·id="machine">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>136 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
137 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
139 ··</cpe-lang:platform-specification>139 ··</cpe-lang:platform-specification>
140 ··<xccdf-1.2:platform·idref="cpe:/o:debian:debian_linux:10"/>140 ··<xccdf-1.2:platform·idref="cpe:/o:debian:debian_linux:10"/>
141 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>141 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
142 ··<xccdf-1.2:metadata>142 ··<xccdf-1.2:metadata>
143 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>143 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 8229, 16 lines modifiedOffset 8229, 16 lines modified
  
8229 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension8229 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
8230 ··find:8230 ··find:
8231 ····paths:·/etc/audit/rules.d/8231 ····paths:·/etc/audit/rules.d/
8232 ····patterns:·'*.rules'8232 ····patterns:·'*.rules'
8233 ··register:·find_rules_d8233 ··register:·find_rules_d
8234 ··when:8234 ··when:
8235 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
8236 ··-·'&quot;audit&quot;·in·ansible_facts.packages'8235 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 8236 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
8237 ··tags:8237 ··tags:
8238 ··-·CJIS-5.4.1.18238 ··-·CJIS-5.4.1.1
8239 ··-·NIST-800-171-3.3.18239 ··-·NIST-800-171-3.3.1
8240 ··-·NIST-800-171-3.4.38240 ··-·NIST-800-171-3.4.3
8241 ··-·NIST-800-53-AC-6(9)8241 ··-·NIST-800-53-AC-6(9)
8242 ··-·NIST-800-53-CM-6(a)8242 ··-·NIST-800-53-CM-6(a)
8243 ··-·PCI-DSS-Req-10.5.28243 ··-·PCI-DSS-Req-10.5.2
Offset 8253, 16 lines modifiedOffset 8253, 16 lines modified
8253 ··lineinfile:8253 ··lineinfile:
8254 ····path:·'{{·item·}}'8254 ····path:·'{{·item·}}'
8255 ····regexp:·^\s*(?:-e)\s+.*$8255 ····regexp:·^\s*(?:-e)\s+.*$
8256 ····state:·absent8256 ····state:·absent
8257 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']8257 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
8258 ····}}'8258 ····}}'
8259 ··when:8259 ··when:
8260 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
8261 ··-·'&quot;audit&quot;·in·ansible_facts.packages'8260 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 8261 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
8262 ··tags:8262 ··tags:
Max diff block lines reached; 55247/62405 bytes (88.53%) of diff not shown.
727 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds-1.2.xml
727 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds-1.2.xml
Max HTML report size reached
727 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
727 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
Ordering differences only
    
Offset 147, 97 lines modifiedOffset 147, 97 lines modified
147 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>147 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
148 ······</xccdf-1.2:front-matter>148 ······</xccdf-1.2:front-matter>
149 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered149 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
150 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other150 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
151 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their151 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
152 respective·companies.</xccdf-1.2:rear-matter>152 respective·companies.</xccdf-1.2:rear-matter>
153 ······<cpe-lang:platform-specification>153 ······<cpe-lang:platform-specification>
154 ········<cpe-lang:platform·id="pam">154 ········<cpe-lang:platform·id="sssd">
155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">155 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
156 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>156 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
157 ··········</cpe-lang:logical-test>157 ··········</cpe-lang:logical-test>
158 ········</cpe-lang:platform>158 ········</cpe-lang:platform>
159 ········<cpe-lang:platform·id="sudo">159 ········<cpe-lang:platform·id="gdm">
160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">160 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
161 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>161 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
162 ··········</cpe-lang:logical-test>162 ··········</cpe-lang:logical-test>
163 ········</cpe-lang:platform>163 ········</cpe-lang:platform>
164 ········<cpe-lang:platform·id="aarch64_arch">164 ········<cpe-lang:platform·id="login_defs">
165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">165 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
166 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>166 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
167 ··········</cpe-lang:logical-test>167 ··········</cpe-lang:logical-test>
168 ········</cpe-lang:platform>168 ········</cpe-lang:platform>
169 ········<cpe-lang:platform·id="s390x_arch">169 ········<cpe-lang:platform·id="chrony">
170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">170 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
171 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>171 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
172 ··········</cpe-lang:logical-test>172 ··········</cpe-lang:logical-test>
173 ········</cpe-lang:platform>173 ········</cpe-lang:platform>
174 ········<cpe-lang:platform·id="machine">174 ········<cpe-lang:platform·id="audit">
175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">175 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
176 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>176 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>
177 ··········</cpe-lang:logical-test>177 ··········</cpe-lang:logical-test>
178 ········</cpe-lang:platform>178 ········</cpe-lang:platform>
179 ········<cpe-lang:platform·id="net-snmp">179 ········<cpe-lang:platform·id="not_s390x_arch">
180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">180 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
181 ············<cpe-lang:fact-ref·name="cpe:/a:net-snmp"/>181 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
182 ··········</cpe-lang:logical-test>182 ··········</cpe-lang:logical-test>
183 ········</cpe-lang:platform>183 ········</cpe-lang:platform>
184 ········<cpe-lang:platform·id="chrony">184 ········<cpe-lang:platform·id="ntp">
185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">185 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
186 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>186 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
187 ··········</cpe-lang:logical-test>187 ··········</cpe-lang:logical-test>
188 ········</cpe-lang:platform>188 ········</cpe-lang:platform>
189 ········<cpe-lang:platform·id="grub2">189 ········<cpe-lang:platform·id="pam">
190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">190 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
191 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>191 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>
192 ··········</cpe-lang:logical-test>192 ··········</cpe-lang:logical-test>
193 ········</cpe-lang:platform>193 ········</cpe-lang:platform>
194 ········<cpe-lang:platform·id="audit">194 ········<cpe-lang:platform·id="net-snmp">
195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">195 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
196 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>196 ············<cpe-lang:fact-ref·name="cpe:/a:net-snmp"/>
197 ··········</cpe-lang:logical-test>197 ··········</cpe-lang:logical-test>
198 ········</cpe-lang:platform>198 ········</cpe-lang:platform>
199 ········<cpe-lang:platform·id="postfix">199 ········<cpe-lang:platform·id="aarch64_arch">
200 ··········<cpe-lang:logical-test·operator="AND"·negate="false">200 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
201 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>201 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
202 ··········</cpe-lang:logical-test>202 ··········</cpe-lang:logical-test>
203 ········</cpe-lang:platform>203 ········</cpe-lang:platform>
204 ········<cpe-lang:platform·id="sssd">204 ········<cpe-lang:platform·id="postfix">
205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">205 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
206 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>206 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
207 ··········</cpe-lang:logical-test>207 ··········</cpe-lang:logical-test>
208 ········</cpe-lang:platform>208 ········</cpe-lang:platform>
209 ········<cpe-lang:platform·id="gdm">209 ········<cpe-lang:platform·id="non-uefi">
210 ··········<cpe-lang:logical-test·operator="AND"·negate="false">210 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
211 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>211 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
212 ··········</cpe-lang:logical-test>212 ··········</cpe-lang:logical-test>
213 ········</cpe-lang:platform>213 ········</cpe-lang:platform>
214 ········<cpe-lang:platform·id="ntp">214 ········<cpe-lang:platform·id="uefi">
215 ··········<cpe-lang:logical-test·operator="AND"·negate="false">215 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
216 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>216 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
217 ··········</cpe-lang:logical-test>217 ··········</cpe-lang:logical-test>
218 ········</cpe-lang:platform>218 ········</cpe-lang:platform>
219 ········<cpe-lang:platform·id="non-uefi">219 ········<cpe-lang:platform·id="sudo">
220 ··········<cpe-lang:logical-test·operator="AND"·negate="false">220 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
221 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>221 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
222 ··········</cpe-lang:logical-test>222 ··········</cpe-lang:logical-test>
223 ········</cpe-lang:platform>223 ········</cpe-lang:platform>
224 ········<cpe-lang:platform·id="not_s390x_arch">224 ········<cpe-lang:platform·id="grub2">
225 ··········<cpe-lang:logical-test·operator="AND"·negate="false">225 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
226 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>226 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
227 ··········</cpe-lang:logical-test>227 ··········</cpe-lang:logical-test>
228 ········</cpe-lang:platform>228 ········</cpe-lang:platform>
229 ········<cpe-lang:platform·id="uefi">229 ········<cpe-lang:platform·id="s390x_arch">
230 ··········<cpe-lang:logical-test·operator="AND"·negate="false">230 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
231 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>231 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
232 ··········</cpe-lang:logical-test>232 ··········</cpe-lang:logical-test>
233 ········</cpe-lang:platform>233 ········</cpe-lang:platform>
234 ········<cpe-lang:platform·id="login_defs">234 ········<cpe-lang:platform·id="machine">
235 ··········<cpe-lang:logical-test·operator="AND"·negate="false">235 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
236 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>236 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
237 ··········</cpe-lang:logical-test>237 ··········</cpe-lang:logical-test>
238 ········</cpe-lang:platform>238 ········</cpe-lang:platform>
239 ······</cpe-lang:platform-specification>239 ······</cpe-lang:platform-specification>
240 ······<xccdf-1.2:platform·idref="cpe:/o:debian:debian_linux:11"/>240 ······<xccdf-1.2:platform·idref="cpe:/o:debian:debian_linux:11"/>
241 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>241 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
242 ······<xccdf-1.2:metadata>242 ······<xccdf-1.2:metadata>
243 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>243 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 67944, 6236 lines modifiedOffset 67944, 6272 lines modified
67944 ······<ocil:generator>67944 ······<ocil:generator>
67945 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>67945 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
67946 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>67946 ········<ocil:product_version>ssg:·0.1.65</ocil:product_version>
67947 ········<ocil:schema_version>2.0</ocil:schema_version>67947 ········<ocil:schema_version>2.0</ocil:schema_version>
67948 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>67948 ········<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
67949 ······</ocil:generator>67949 ······</ocil:generator>
67950 ······<ocil:questionnaires>67950 ······<ocil:questionnaires>
67951 ········<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> 
67952 ··········<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title> 
67953 ··········<ocil:actions> 
67954 ············<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref> 
67955 ··········</ocil:actions> 
67956 ········</ocil:questionnaire> 
67957 ········<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">67951 ········<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
67958 ··········<ocil:title>Disable·SSH·Root·Login</ocil:title>67952 ··········<ocil:title>Disable·Host-Based·Authentication</ocil:title>
67959 ··········<ocil:actions> 
67960 ············<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref> 
67961 ··········</ocil:actions> 
67962 ········</ocil:questionnaire> 
67963 ········<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
67964 ··········<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> 
67965 ··········<ocil:actions>67953 ··········<ocil:actions>
67966 ············<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>67954 ············<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
67967 ··········</ocil:actions>67955 ··········</ocil:actions>
67968 ········</ocil:questionnaire>67956 ········</ocil:questionnaire>
67969 ········<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> 
67970 ··········<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>67957 ········<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 67958 ··········<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
67971 ··········<ocil:actions>67959 ··········<ocil:actions>
Max diff block lines reached; 735038/743916 bytes (98.81%) of diff not shown.
690 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
690 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
Ordering differences only
    
Offset 3, 6236 lines modifiedOffset 3, 6272 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
 11 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title> 
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>23 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
 29 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> 
47 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">
53 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>44 ······</ocil:actions>
57 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
59 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
60 ······<ocil:actions>48 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>50 ······</ocil:actions>
63 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
65 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>53 ······<ocil:title>Disable·TIPC·Support</ocil:title>
66 ······<ocil:actions>54 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>56 ······</ocil:actions>
69 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-auditd_name_format_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
71 ······<ocil:title>Set·hostname·as·computer·node·name·in·audit·logs</ocil:title>59 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
72 ······<ocil:actions>60 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-auditd_name_format_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>62 ······</ocil:actions>
75 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
77 ······<ocil:title>Disable·Recovery·Booting</ocil:title>65 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
78 ······<ocil:actions>66 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>68 ······</ocil:actions>
81 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1"> 
83 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
84 ······<ocil:actions>72 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>74 ······</ocil:actions>
87 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
89 ······<ocil:title>Disable·IA32·emulation</ocil:title>77 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
90 ······<ocil:actions>78 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>80 ······</ocil:actions>
93 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
95 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>83 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
96 ······<ocil:actions>84 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>86 ······</ocil:actions>
99 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
101 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
102 ······<ocil:actions>90 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>92 ······</ocil:actions>
105 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">
107 ······<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>95 ······<ocil:title>Kernel·panic·on·oops</ocil:title>
108 ······<ocil:actions>96 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>98 ······</ocil:actions>
111 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
113 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
114 ······<ocil:actions>102 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>104 ······</ocil:actions>
117 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
119 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
120 ······<ocil:actions>108 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>110 ······</ocil:actions>
Max diff block lines reached; 694339/706222 bytes (98.32%) of diff not shown.
5.99 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
5.88 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
Ordering differences only
    
Offset 47, 97 lines modifiedOffset 47, 97 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="sudo">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="aarch64_arch">64 ····<cpe-lang:platform·id="login_defs">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
67 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="s390x_arch">69 ····<cpe-lang:platform·id="chrony">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
72 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="machine">74 ····<cpe-lang:platform·id="audit">
75 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
77 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
78 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
79 ····<cpe-lang:platform·id="net-snmp">79 ····<cpe-lang:platform·id="not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:fact-ref·name="cpe:/a:net-snmp"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
82 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="chrony">84 ····<cpe-lang:platform·id="ntp">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="grub2">89 ····<cpe-lang:platform·id="pam">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="audit">94 ····<cpe-lang:platform·id="net-snmp">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:net-snmp"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="postfix">99 ····<cpe-lang:platform·id="aarch64_arch">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>101 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="sssd">104 ····<cpe-lang:platform·id="postfix">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>106 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="gdm">109 ····<cpe-lang:platform·id="non-uefi">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>111 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="ntp">114 ····<cpe-lang:platform·id="uefi">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>116 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="non-uefi">119 ····<cpe-lang:platform·id="sudo">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>121 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
122 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="not_s390x_arch">124 ····<cpe-lang:platform·id="grub2">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>126 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
127 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="uefi">129 ····<cpe-lang:platform·id="s390x_arch">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>131 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
132 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="login_defs">134 ····<cpe-lang:platform·id="machine">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>136 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
137 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
139 ··</cpe-lang:platform-specification>139 ··</cpe-lang:platform-specification>
140 ··<xccdf-1.2:platform·idref="cpe:/o:debian:debian_linux:11"/>140 ··<xccdf-1.2:platform·idref="cpe:/o:debian:debian_linux:11"/>
141 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>141 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
142 ··<xccdf-1.2:metadata>142 ··<xccdf-1.2:metadata>
143 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>143 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
326 MB
ssg-nondebian_0.1.65-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary1 -rw-r--r--···0········0········0········4·2022-12-20·09:54:05.000000·debian-binary
2 -rw-r--r--···0········0········0····15448·2022-12-20·09:54:05.000000·control.tar.xz2 -rw-r--r--···0········0········0····15444·2022-12-20·09:54:05.000000·control.tar.xz
3 -rw-r--r--···0········0········0·40433084·2022-12-20·09:54:05.000000·data.tar.xz3 -rw-r--r--···0········0········0·40430536·2022-12-20·09:54:05.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
326 MB
data.tar.xz
326 MB
data.tar
125 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-cis.html
    
Offset 55089, 21 lines modifiedOffset 55089, 21 lines modified
000d7300:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas000d7300:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
000d7310:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps000d7310:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
000d7320:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="000d7320:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
000d7330:·6964·6d31·3437·3033·223e·3c70·7265·3e3c··idm14703"><pre><000d7330:·6964·6d31·3437·3033·223e·3c70·7265·3e3c··idm14703"><pre><
000d7340:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati000d7340:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
000d7350:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable000d7350:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
000d7360:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain000d7360:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
000d7370:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp000d7370:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
000d7380:·6d20·2d2d·7175·6965·7420·2d71·2061·7564··m·--quiet·-q·aud 
000d7390:·6974·2026·616d·703b·2661·6d70·3b20·5b20··it·&amp;&amp;·[· 
000d73a0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv000d7380:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
000d73b0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·000d7390:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
000d73c0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta000d73a0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
000d73d0:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.000d73b0:·696e·6572·656e·7620·5d20·2661·6d70·3b26··inerenv·]·&amp;&
 000d73c0:·616d·703b·2072·706d·202d·2d71·7569·6574··amp;·rpm·--quiet
 000d73d0:·202d·7120·6175·6469·743b·2074·6865·6e0a···-q·audit;·then.
000d73e0:·0a23·2046·6972·7374·2070·6572·666f·726d··.#·First·perform000d73e0:·0a23·2046·6972·7374·2070·6572·666f·726d··.#·First·perform
000d73f0:·2074·6865·2072·656d·6564·6961·7469·6f6e···the·remediation000d73f0:·2074·6865·2072·656d·6564·6961·7469·6f6e···the·remediation
000d7400:·206f·6620·7468·6520·7379·7363·616c·6c20···of·the·syscall·000d7400:·206f·6620·7468·6520·7379·7363·616c·6c20···of·the·syscall·
000d7410:·7275·6c65·0a23·2052·6574·7269·6576·6520··rule.#·Retrieve·000d7410:·7275·6c65·0a23·2052·6574·7269·6576·6520··rule.#·Retrieve·
000d7420:·6861·7264·7761·7265·2061·7263·6869·7465··hardware·archite000d7420:·6861·7264·7761·7265·2061·7263·6869·7465··hardware·archite
000d7430:·6374·7572·6520·6f66·2074·6865·2075·6e64··cture·of·the·und000d7430:·6374·7572·6520·6f66·2074·6865·2075·6e64··cture·of·the·und
000d7440:·6572·6c79·696e·6720·7379·7374·656d·0a23··erlying·system.#000d7440:·6572·6c79·696e·6720·7379·7374·656d·0a23··erlying·system.#
Offset 56791, 20 lines modifiedOffset 56791, 20 lines modified
000ddd60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla000ddd60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
000ddd70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id000ddd70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
000ddd80:·3d22·6964·6d31·3530·3033·223e·3c70·7265··="idm15003"><pre000ddd80:·3d22·6964·6d31·3530·3033·223e·3c70·7265··="idm15003"><pre
000ddd90:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia000ddd90:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
000ddda0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab000ddda0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
000dddb0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa000dddb0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
000dddc0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·000dddc0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
000dddd0:·7270·6d20·2d2d·7175·6965·7420·2d71·2061··rpm·--quiet·-q·a 
000ddde0:·7564·6974·2026·616d·703b·2661·6d70·3b20··udit·&amp;&amp;· 
000dddf0:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere000dddd0:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
000dde00:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·000ddde0:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
000dde10:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con000dddf0:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
000dde20:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the000dde00:·7461·696e·6572·656e·7620·5d20·2661·6d70··tainerenv·]·&amp
 000dde10:·3b26·616d·703b·2072·706d·202d·2d71·7569··;&amp;·rpm·--qui
 000dde20:·6574·202d·7120·6175·6469·743b·2074·6865··et·-q·audit;·the
000dde30:·6e0a·0a23·2046·6972·7374·2070·6572·666f··n..#·First·perfo000dde30:·6e0a·0a23·2046·6972·7374·2070·6572·666f··n..#·First·perfo
000dde40:·726d·2074·6865·2072·656d·6564·6961·7469··rm·the·remediati000dde40:·726d·2074·6865·2072·656d·6564·6961·7469··rm·the·remediati
000dde50:·6f6e·206f·6620·7468·6520·7379·7363·616c··on·of·the·syscal000dde50:·6f6e·206f·6620·7468·6520·7379·7363·616c··on·of·the·syscal
000dde60:·6c20·7275·6c65·0a23·2052·6574·7269·6576··l·rule.#·Retriev000dde60:·6c20·7275·6c65·0a23·2052·6574·7269·6576··l·rule.#·Retriev
000dde70:·6520·6861·7264·7761·7265·2061·7263·6869··e·hardware·archi000dde70:·6520·6861·7264·7761·7265·2061·7263·6869··e·hardware·archi
000dde80:·7465·6374·7572·6520·6f66·2074·6865·2075··tecture·of·the·u000dde80:·7465·6374·7572·6520·6f66·2074·6865·2075··tecture·of·the·u
000dde90:·6e64·6572·6c79·696e·6720·7379·7374·656d··nderlying·system000dde90:·6e64·6572·6c79·696e·6720·7379·7374·656d··nderlying·system
Offset 61153, 23 lines modifiedOffset 61153, 23 lines modified
000eee00:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·000eee00:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·
000eee10:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra000eee10:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra
000eee20:·7465·6779·0a0a·2d20·6e61·6d65·3a20·5365··tegy..-·name:·Se000eee20:·7465·6779·0a0a·2d20·6e61·6d65·3a20·5365··tegy..-·name:·Se
000eee30:·7420·6172·6368·6974·6563·7475·7265·2066··t·architecture·f000eee30:·7420·6172·6368·6974·6563·7475·7265·2066··t·architecture·f
000eee40:·6f72·2061·7564·6974·2074·6173·6b73·0a20··or·audit·tasks.·000eee40:·6f72·2061·7564·6974·2074·6173·6b73·0a20··or·audit·tasks.·
000eee50:·2073·6574·5f66·6163·743a·0a20·2020·2061···set_fact:.····a000eee50:·2073·6574·5f66·6163·743a·0a20·2020·2061···set_fact:.····a
000eee60:·7564·6974·5f61·7263·683a·2062·3634·0a20··udit_arch:·b64.·000eee60:·7564·6974·5f61·7263·683a·2062·3634·0a20··udit_arch:·b64.·
000eee70:·2077·6865·6e3a·0a20·202d·2027·2261·7564···when:.··-·'"aud000eee70:·2077·6865·6e3a·0a20·202d·2061·6e73·6962···when:.··-·ansib
000eee80:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f 
000eee90:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
000eeea0:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu 
000eeeb0:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
000eeec0:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
000eeed0:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
000eeee0:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
000eeef0:·7461·696e·6572·225d·0a20·202d·2061·6e73··tainer"].··-·ans000eee80:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 000eee90:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 000eeea0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 000eeeb0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 000eeec0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
 000eeed0:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 000eeee0:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 000eeef0:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans
000eef00:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur000eef00:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
000eef10:·6520·3d3d·2022·6161·7263·6836·3422·206f··e·==·"aarch64"·o000eef10:·6520·3d3d·2022·6161·7263·6836·3422·206f··e·==·"aarch64"·o
000eef20:·7220·616e·7369·626c·655f·6172·6368·6974··r·ansible_archit000eef20:·7220·616e·7369·626c·655f·6172·6368·6974··r·ansible_archit
000eef30:·6563·7475·7265·203d·3d20·2270·7063·3634··ecture·==·"ppc64000eef30:·6563·7475·7265·203d·3d20·2270·7063·3634··ecture·==·"ppc64
000eef40:·2220·6f72·2061·6e73·6962·6c65·5f61·7263··"·or·ansible_arc000eef40:·2220·6f72·2061·6e73·6962·6c65·5f61·7263··"·or·ansible_arc
000eef50:·6869·7465·6374·7572·650a·2020·2020·3d3d··hitecture.····==000eef50:·6869·7465·6374·7572·650a·2020·2020·3d3d··hitecture.····==
000eef60:·2022·7070·6336·346c·6522·206f·7220·616e···"ppc64le"·or·an000eef60:·2022·7070·6336·346c·6522·206f·7220·616e···"ppc64le"·or·an
Offset 61465, 23 lines modifiedOffset 61465, 23 lines modified
000f0180:·6175·6469·745f·7469·6d65·5f72·756c·6573··audit_time_rules000f0180:·6175·6469·745f·7469·6d65·5f72·756c·6573··audit_time_rules
000f0190:·0a20·2020·2020·2063·7265·6174·653a·2074··.······create:·t000f0190:·0a20·2020·2020·2063·7265·6174·653a·2074··.······create:·t
000f01a0:·7275·650a·2020·2020·2020·6d6f·6465·3a20··rue.······mode:·000f01a0:·7275·650a·2020·2020·2020·6d6f·6465·3a20··rue.······mode:·
000f01b0:·6f2d·7277·780a·2020·2020·2020·7374·6174··o-rwx.······stat000f01b0:·6f2d·7277·780a·2020·2020·2020·7374·6174··o-rwx.······stat
000f01c0:·653a·2070·7265·7365·6e74·0a20·2020·2077··e:·present.····w000f01c0:·653a·2070·7265·7365·6e74·0a20·2020·2077··e:·present.····w
000f01d0:·6865·6e3a·2073·7973·6361·6c6c·735f·666f··hen:·syscalls_fo000f01d0:·6865·6e3a·2073·7973·6361·6c6c·735f·666f··hen:·syscalls_fo
000f01e0:·756e·6420·7c20·6c65·6e67·7468·203d·3d20··und·|·length·==·000f01e0:·756e·6420·7c20·6c65·6e67·7468·203d·3d20··und·|·length·==·
000f01f0:·300a·2020·7768·656e·3a0a·2020·2d20·2722··0.··when:.··-·'"000f01f0:·300a·2020·7768·656e·3a0a·2020·2d20·616e··0.··when:.··-·an
000f0200:·6175·6469·7422·2069·6e20·616e·7369·626c··audit"·in·ansibl 
000f0210:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages 
000f0220:·270a·2020·2d20·616e·7369·626c·655f·7669··'.··-·ansible_vi 
000f0230:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
000f0240:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
000f0250:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
000f0260:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
000f0270:·636f·6e74·6169·6e65·7222·5d0a·2020·7461··container"].··ta000f0200:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
 000f0210:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
 000f0220:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc
 000f0230:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po
 000f0240:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe
 000f0250:·7222·5d0a·2020·2d20·2722·6175·6469·7422··r"].··-·'"audit"
 000f0260:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 000f0270:·732e·7061·636b·6167·6573·270a·2020·7461··s.packages'.··ta
000f0280:·6773·3a0a·2020·2d20·434a·4953·2d35·2e34··gs:.··-·CJIS-5.4000f0280:·6773·3a0a·2020·2d20·434a·4953·2d35·2e34··gs:.··-·CJIS-5.4
000f0290:·2e31·2e31·0a20·202d·204e·4953·542d·3830··.1.1.··-·NIST-80000f0290:·2e31·2e31·0a20·202d·204e·4953·542d·3830··.1.1.··-·NIST-80
000f02a0:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·000f02a0:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·
000f02b0:·4e49·5354·2d38·3030·2d35·332d·4143·2d36··NIST-800-53-AC-6000f02b0:·4e49·5354·2d38·3030·2d35·332d·4143·2d36··NIST-800-53-AC-6
000f02c0:·2839·290a·2020·2d20·4e49·5354·2d38·3030··(9).··-·NIST-800000f02c0:·2839·290a·2020·2d20·4e49·5354·2d38·3030··(9).··-·NIST-800
000f02d0:·2d35·332d·4155·2d31·3228·6329·0a20·202d··-53-AU-12(c).··-000f02d0:·2d35·332d·4155·2d31·3228·6329·0a20·202d··-53-AU-12(c).··-
000f02e0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-000f02e0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
Offset 61765, 23 lines modifiedOffset 61765, 23 lines modified
000f1440:·745f·7469·6d65·5f72·756c·6573·0a20·2020··t_time_rules.···000f1440:·745f·7469·6d65·5f72·756c·6573·0a20·2020··t_time_rules.···
000f1450:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.000f1450:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.
000f1460:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw000f1460:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw
000f1470:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p000f1470:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p
000f1480:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:000f1480:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:
000f1490:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·000f1490:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·
000f14a0:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··000f14a0:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··
000f14b0:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi000f14b0:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
000f14c0:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
000f14d0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
000f14e0:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
000f14f0:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
000f1500:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
000f1510:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
000f1520:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont000f14c0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000f14d0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000f14e0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000f14f0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
Max diff block lines reached; 90000/100066 bytes (89.94%) of diff not shown.
27.6 KB
html2text {}
    
Offset 3169, 15 lines modifiedOffset 3169, 15 lines modified
3169 ············A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3169 ············A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-
3170 ············3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.2.7,·SRG-OS-000037-3170 ············3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.2.7,·SRG-OS-000037-
3171 ············GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-3171 ············GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-
3172 ············GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000471-GPOS-00216,·SRG-OS-000477-GPOS-00222,·SRG-OS-000477-VMM-3172 ············GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000471-GPOS-00216,·SRG-OS-000477-GPOS-00222,·SRG-OS-000477-VMM-
3173 ············001970,·4.1.173173 ············001970,·4.1.17
3174 Remediation_Shell_script_⇲3174 Remediation_Shell_script_⇲
3175 #·Remediation·is·applicable·only·in·certain·platforms3175 #·Remediation·is·applicable·only·in·certain·platforms
3176 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then3176 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
3177 #·First·perform·the·remediation·of·the·syscall·rule3177 #·First·perform·the·remediation·of·the·syscall·rule
3178 #·Retrieve·hardware·architecture·of·the·underlying·system3178 #·Retrieve·hardware·architecture·of·the·underlying·system
3179 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>3179 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>
3180 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence3180 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence
3181 #·······of·32-bit's·equivalent·of·the·corresponding·rule.3181 #·······of·32-bit's·equivalent·of·the·corresponding·rule.
3182 #·······(See·`man·7·audit.rules`·for·details·)3182 #·······(See·`man·7·audit.rules`·for·details·)
Offset 3535, 15 lines modifiedOffset 3535, 15 lines modified
3535 ············A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3535 ············A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-
3536 ············3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.2.7,·SRG-OS-000037-3536 ············3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.2.7,·SRG-OS-000037-
3537 ············GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-3537 ············GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-
3538 ············GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000471-GPOS-00216,·SRG-OS-000477-GPOS-00222,·SRG-OS-000477-VMM-3538 ············GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000471-GPOS-00216,·SRG-OS-000477-GPOS-00222,·SRG-OS-000477-VMM-
3539 ············001970,·4.1.173539 ············001970,·4.1.17
3540 Remediation_Shell_script_⇲3540 Remediation_Shell_script_⇲
3541 #·Remediation·is·applicable·only·in·certain·platforms3541 #·Remediation·is·applicable·only·in·certain·platforms
3542 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then3542 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
3543 #·First·perform·the·remediation·of·the·syscall·rule3543 #·First·perform·the·remediation·of·the·syscall·rule
3544 #·Retrieve·hardware·architecture·of·the·underlying·system3544 #·Retrieve·hardware·architecture·of·the·underlying·system
3545 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>3545 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>
3546 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence3546 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence
3547 #·······of·32-bit's·equivalent·of·the·corresponding·rule.3547 #·······of·32-bit's·equivalent·of·the·corresponding·rule.
3548 #·······(See·`man·7·audit.rules`·for·details·)3548 #·······(See·`man·7·audit.rules`·for·details·)
Offset 4062, 16 lines modifiedOffset 4062, 16 lines modified
4062 ··-·no_reboot_needed4062 ··-·no_reboot_needed
4063 ··-·restrict_strategy4063 ··-·restrict_strategy
  
4064 -·name:·Set·architecture·for·audit·tasks4064 -·name:·Set·architecture·for·audit·tasks
4065 ··set_fact:4065 ··set_fact:
4066 ····audit_arch:·b644066 ····audit_arch:·b64
4067 ··when:4067 ··when:
4068 ··-·'"audit"·in·ansible_facts.packages' 
4069 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4068 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4069 ··-·'"audit"·in·ansible_facts.packages'
4070 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4070 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4071 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4071 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4072 ··tags:4072 ··tags:
4073 ··-·CJIS-5.4.1.14073 ··-·CJIS-5.4.1.1
4074 ··-·NIST-800-171-3.1.74074 ··-·NIST-800-171-3.1.7
4075 ··-·NIST-800-53-AC-6(9)4075 ··-·NIST-800-53-AC-6(9)
4076 ··-·NIST-800-53-AU-12(c)4076 ··-·NIST-800-53-AU-12(c)
Offset 4204, 16 lines modifiedOffset 4204, 16 lines modified
4204 ······path:·'{{·audit_file·}}'4204 ······path:·'{{·audit_file·}}'
4205 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules4205 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
4206 ······create:·true4206 ······create:·true
4207 ······mode:·o-rwx4207 ······mode:·o-rwx
4208 ······state:·present4208 ······state:·present
4209 ····when:·syscalls_found·|·length·==·04209 ····when:·syscalls_found·|·length·==·0
4210 ··when:4210 ··when:
4211 ··-·'"audit"·in·ansible_facts.packages' 
4212 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4211 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4212 ··-·'"audit"·in·ansible_facts.packages'
4213 ··tags:4213 ··tags:
4214 ··-·CJIS-5.4.1.14214 ··-·CJIS-5.4.1.1
4215 ··-·NIST-800-171-3.1.74215 ··-·NIST-800-171-3.1.7
4216 ··-·NIST-800-53-AC-6(9)4216 ··-·NIST-800-53-AC-6(9)
4217 ··-·NIST-800-53-AU-12(c)4217 ··-·NIST-800-53-AU-12(c)
4218 ··-·NIST-800-53-AU-2(d)4218 ··-·NIST-800-53-AU-2(d)
4219 ··-·NIST-800-53-CM-6(a)4219 ··-·NIST-800-53-CM-6(a)
Offset 4343, 16 lines modifiedOffset 4343, 16 lines modified
4343 ······path:·'{{·audit_file·}}'4343 ······path:·'{{·audit_file·}}'
4344 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules4344 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
4345 ······create:·true4345 ······create:·true
4346 ······mode:·o-rwx4346 ······mode:·o-rwx
4347 ······state:·present4347 ······state:·present
4348 ····when:·syscalls_found·|·length·==·04348 ····when:·syscalls_found·|·length·==·0
4349 ··when:4349 ··when:
4350 ··-·'"audit"·in·ansible_facts.packages' 
4351 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4350 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4351 ··-·'"audit"·in·ansible_facts.packages'
4352 ··-·audit_arch·==·"b64"4352 ··-·audit_arch·==·"b64"
4353 ··tags:4353 ··tags:
4354 ··-·CJIS-5.4.1.14354 ··-·CJIS-5.4.1.1
4355 ··-·NIST-800-171-3.1.74355 ··-·NIST-800-171-3.1.7
4356 ··-·NIST-800-53-AC-6(9)4356 ··-·NIST-800-53-AC-6(9)
4357 ··-·NIST-800-53-AU-12(c)4357 ··-·NIST-800-53-AU-12(c)
4358 ··-·NIST-800-53-AU-2(d)4358 ··-·NIST-800-53-AU-2(d)
Offset 4417, 16 lines modifiedOffset 4417, 16 lines modified
4417 ··-·no_reboot_needed4417 ··-·no_reboot_needed
4418 ··-·restrict_strategy4418 ··-·restrict_strategy
  
4419 -·name:·Set·architecture·for·audit·tasks4419 -·name:·Set·architecture·for·audit·tasks
4420 ··set_fact:4420 ··set_fact:
4421 ····audit_arch:·b644421 ····audit_arch:·b64
4422 ··when:4422 ··when:
4423 ··-·'"audit"·in·ansible_facts.packages' 
4424 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4423 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4424 ··-·'"audit"·in·ansible_facts.packages'
4425 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4425 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4426 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4426 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4427 ··tags:4427 ··tags:
4428 ··-·CJIS-5.4.1.14428 ··-·CJIS-5.4.1.1
4429 ··-·NIST-800-171-3.1.74429 ··-·NIST-800-171-3.1.7
4430 ··-·NIST-800-53-AC-6(9)4430 ··-·NIST-800-53-AC-6(9)
4431 ··-·NIST-800-53-AU-12(c)4431 ··-·NIST-800-53-AU-12(c)
Offset 4559, 16 lines modifiedOffset 4559, 16 lines modified
4559 ······path:·'{{·audit_file·}}'4559 ······path:·'{{·audit_file·}}'
4560 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules4560 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
4561 ······create:·true4561 ······create:·true
4562 ······mode:·o-rwx4562 ······mode:·o-rwx
4563 ······state:·present4563 ······state:·present
4564 ····when:·syscalls_found·|·length·==·04564 ····when:·syscalls_found·|·length·==·0
4565 ··when:4565 ··when:
4566 ··-·'"audit"·in·ansible_facts.packages' 
4567 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4566 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4567 ··-·'"audit"·in·ansible_facts.packages'
4568 ··tags:4568 ··tags:
4569 ··-·CJIS-5.4.1.14569 ··-·CJIS-5.4.1.1
4570 ··-·NIST-800-171-3.1.74570 ··-·NIST-800-171-3.1.7
4571 ··-·NIST-800-53-AC-6(9)4571 ··-·NIST-800-53-AC-6(9)
4572 ··-·NIST-800-53-AU-12(c)4572 ··-·NIST-800-53-AU-12(c)
4573 ··-·NIST-800-53-AU-2(d)4573 ··-·NIST-800-53-AU-2(d)
4574 ··-·NIST-800-53-CM-6(a)4574 ··-·NIST-800-53-CM-6(a)
Offset 4699, 16 lines modifiedOffset 4699, 16 lines modified
4699 ······path:·'{{·audit_file·}}'4699 ······path:·'{{·audit_file·}}'
4700 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules4700 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
4701 ······create:·true4701 ······create:·true
4702 ······mode:·o-rwx4702 ······mode:·o-rwx
4703 ······state:·present4703 ······state:·present
Max diff block lines reached; 22658/28212 bytes (80.31%) of diff not shown.
34.8 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-cis_l1.html
    
Offset 38560, 18 lines modifiedOffset 38560, 18 lines modified
000969f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t000969f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00096a00:·643e·636f·6e66·6967·7572·653c·2f74·643e··d>configure</td>00096a00:·643e·636f·6e66·6967·7572·653c·2f74·643e··d>configure</td>
00096a10:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr00096a10:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
00096a20:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi00096a20:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
00096a30:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica00096a30:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
00096a40:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert00096a40:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
00096a50:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if00096a50:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 00096a60:·205b·202d·6620·2f73·7973·2f66·6972·6d77···[·-f·/sys/firmw
 00096a70:·6172·652f·6566·6920·5d20·2661·6d70·3b26··are/efi·]·&amp;&
00096a60:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·00096a80:·616d·703b·2072·706d·202d·2d71·7569·6574··amp;·rpm·--quiet
00096a70:·6772·7562·322d·636f·6d6d·6f6e·2026·616d··grub2-common·&am00096a90:·202d·7120·6772·7562·322d·636f·6d6d·6f6e···-q·grub2-common
00096a80:·703b·2661·6d70·3b20·5b20·2d66·202f·7379··p;&amp;·[·-f·/sy 
00096a90:·732f·6669·726d·7761·7265·2f65·6669·205d··s/firmware/efi·] 
00096aa0:·2026·616d·703b·2661·6d70·3b20·7b20·5b20···&amp;&amp;·{·[·00096aa0:·2026·616d·703b·2661·6d70·3b20·7b20·5b20···&amp;&amp;·{·[·
00096ab0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv00096ab0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
00096ac0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·00096ac0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
00096ad0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta00096ad0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
00096ae0:·696e·6572·656e·7620·5d3b·207d·3b20·7468··inerenv·];·};·th00096ae0:·696e·6572·656e·7620·5d3b·207d·3b20·7468··inerenv·];·};·th
00096af0:·656e·0a0a·6368·6772·7020·3020·2f62·6f6f··en..chgrp·0·/boo00096af0:·656e·0a0a·6368·6772·7020·3020·2f62·6f6f··en..chgrp·0·/boo
00096b00:·742f·6772·7562·322f·6772·7562·2e63·6667··t/grub2/grub.cfg00096b00:·742f·6772·7562·322f·6772·7562·2e63·6667··t/grub2/grub.cfg
Offset 38633, 22 lines modifiedOffset 38633, 22 lines modified
00096e80:·0a0a·2d20·6e61·6d65·3a20·5465·7374·2066··..-·name:·Test·f00096e80:·0a0a·2d20·6e61·6d65·3a20·5465·7374·2066··..-·name:·Test·f
00096e90:·6f72·2065·7869·7374·656e·6365·202f·626f··or·existence·/bo00096e90:·6f72·2065·7869·7374·656e·6365·202f·626f··or·existence·/bo
00096ea0:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf00096ea0:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf
00096eb0:·670a·2020·7374·6174·3a0a·2020·2020·7061··g.··stat:.····pa00096eb0:·670a·2020·7374·6174·3a0a·2020·2020·7061··g.··stat:.····pa
00096ec0:·7468·3a20·2f62·6f6f·742f·6772·7562·322f··th:·/boot/grub2/00096ec0:·7468·3a20·2f62·6f6f·742f·6772·7562·322f··th:·/boot/grub2/
00096ed0:·6772·7562·2e63·6667·0a20·2072·6567·6973··grub.cfg.··regis00096ed0:·6772·7562·2e63·6667·0a20·2072·6567·6973··grub.cfg.··regis
00096ee0:·7465·723a·2066·696c·655f·6578·6973·7473··ter:·file_exists00096ee0:·7465·723a·2066·696c·655f·6578·6973·7473··ter:·file_exists
00096ef0:·0a20·2077·6865·6e3a·0a20·202d·2027·2267··.··when:.··-·'"g00096ef0:·0a20·2077·6865·6e3a·0a20·202d·2027·222f··.··when:.··-·'"/
 00096f00:·626f·6f74·2f65·6669·2220·696e·2061·6e73··boot/efi"·in·ans
 00096f10:·6962·6c65·5f6d·6f75·6e74·7320·7c20·6d61··ible_mounts·|·ma
 00096f20:·7028·6174·7472·6962·7574·653d·226d·6f75··p(attribute="mou
 00096f30:·6e74·2229·207c·206c·6973·7427·0a20·202d··nt")·|·list'.··-
00096f00:·7275·6232·2d63·6f6d·6d6f·6e22·2069·6e20··rub2-common"·in·00096f40:·2027·2267·7275·6232·2d63·6f6d·6d6f·6e22···'"grub2-common"
00096f10:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa00096f50:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
00096f20:·636b·6167·6573·270a·2020·2d20·2722·2f62··ckages'.··-·'"/b00096f60:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·
00096f30:·6f6f·742f·6566·6922·2069·6e20·616e·7369··oot/efi"·in·ansi 
00096f40:·626c·655f·6d6f·756e·7473·207c·206d·6170··ble_mounts·|·map 
00096f50:·2861·7474·7269·6275·7465·3d22·6d6f·756e··(attribute="moun 
00096f60:·7422·2920·7c20·6c69·7374·270a·2020·2d20··t")·|·list'.··-· 
00096f70:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali00096f70:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
00096f80:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·00096f80:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
00096f90:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l00096f90:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
00096fa0:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"00096fa0:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
00096fb0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai00096fb0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
00096fc0:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··00096fc0:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··
00096fd0:·2d20·434a·4953·2d35·2e35·2e32·2e32·0a20··-·CJIS-5.5.2.2.·00096fd0:·2d20·434a·4953·2d35·2e35·2e32·2e32·0a20··-·CJIS-5.5.2.2.·
Offset 38669, 22 lines modifiedOffset 38669, 22 lines modified
000970c0:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur000970c0:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur
000970d0:·6520·6772·6f75·7020·6f77·6e65·7220·3020··e·group·owner·0·000970d0:·6520·6772·6f75·7020·6f77·6e65·7220·3020··e·group·owner·0·
000970e0:·6f6e·202f·626f·6f74·2f67·7275·6232·2f67··on·/boot/grub2/g000970e0:·6f6e·202f·626f·6f74·2f67·7275·6232·2f67··on·/boot/grub2/g
000970f0:·7275·622e·6366·670a·2020·6669·6c65·3a0a··rub.cfg.··file:.000970f0:·7275·622e·6366·670a·2020·6669·6c65·3a0a··rub.cfg.··file:.
00097100:·2020·2020·7061·7468·3a20·2f62·6f6f·742f······path:·/boot/00097100:·2020·2020·7061·7468·3a20·2f62·6f6f·742f······path:·/boot/
00097110:·6772·7562·322f·6772·7562·2e63·6667·0a20··grub2/grub.cfg.·00097110:·6772·7562·322f·6772·7562·2e63·6667·0a20··grub2/grub.cfg.·
00097120:·2020·2067·726f·7570·3a20·2730·270a·2020·····group:·'0'.··00097120:·2020·2067·726f·7570·3a20·2730·270a·2020·····group:·'0'.··
00097130:·7768·656e·3a0a·2020·2d20·2722·6772·7562··when:.··-·'"grub00097130:·7768·656e·3a0a·2020·2d20·2722·2f62·6f6f··when:.··-·'"/boo
 00097140:·742f·6566·6922·2069·6e20·616e·7369·626c··t/efi"·in·ansibl
 00097150:·655f·6d6f·756e·7473·207c·206d·6170·2861··e_mounts·|·map(a
 00097160:·7474·7269·6275·7465·3d22·6d6f·756e·7422··ttribute="mount"
 00097170:·2920·7c20·6c69·7374·270a·2020·2d20·2722··)·|·list'.··-·'"
00097140:·322d·636f·6d6d·6f6e·2220·696e·2061·6e73··2-common"·in·ans00097180:·6772·7562·322d·636f·6d6d·6f6e·2220·696e··grub2-common"·in
00097150:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa00097190:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 000971a0:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans
00097160:·6765·7327·0a20·202d·2027·222f·626f·6f74··ges'.··-·'"/boot 
00097170:·2f65·6669·2220·696e·2061·6e73·6962·6c65··/efi"·in·ansible 
00097180:·5f6d·6f75·6e74·7320·7c20·6d61·7028·6174··_mounts·|·map(at 
00097190:·7472·6962·7574·653d·226d·6f75·6e74·2229··tribute="mount") 
000971a0:·207c·206c·6973·7427·0a20·202d·2061·6e73···|·list'.··-·ans 
000971b0:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat000971b0:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
000971c0:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·000971c0:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
000971d0:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"000971d0:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
000971e0:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod000971e0:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
000971f0:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container000971f0:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
00097200:·225d·0a20·202d·2066·696c·655f·6578·6973··"].··-·file_exis00097200:·225d·0a20·202d·2066·696c·655f·6578·6973··"].··-·file_exis
00097210:·7473·2e73·7461·7420·6973·2064·6566·696e··ts.stat·is·defin00097210:·7473·2e73·7461·7420·6973·2064·6566·696e··ts.stat·is·defin
Offset 39052, 19 lines modifiedOffset 39052, 19 lines modified
000988b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St000988b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
000988c0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>000988c0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
000988d0:·636f·6e66·6967·7572·653c·2f74·643e·3c2f··configure</td></000988d0:·636f·6e66·6967·7572·653c·2f74·643e·3c2f··configure</td></
000988e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>000988e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
000988f0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat000988f0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
00098900:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl00098900:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
00098910:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai00098910:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
00098920:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r00098920:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 00098930:·202d·6620·2f73·7973·2f66·6972·6d77·6172···-f·/sys/firmwar
 00098940:·652f·6566·6920·5d20·2661·6d70·3b26·616d··e/efi·]·&amp;&am
00098930:·706d·202d·2d71·7569·6574·202d·7120·6772··pm·--quiet·-q·gr00098950:·703b·2072·706d·202d·2d71·7569·6574·202d··p;·rpm·--quiet·-
00098940:·7562·322d·636f·6d6d·6f6e·2026·616d·703b··ub2-common·&amp;00098960:·7120·6772·7562·322d·636f·6d6d·6f6e·2026··q·grub2-common·&
00098950:·2661·6d70·3b20·5b20·2d66·202f·7379·732f··&amp;·[·-f·/sys/ 
00098960:·6669·726d·7761·7265·2f65·6669·205d·2026··firmware/efi·]·& 
00098970:·616d·703b·2661·6d70·3b20·7b20·5b20·2120··amp;&amp;·{·[·!·00098970:·616d·703b·2661·6d70·3b20·7b20·5b20·2120··amp;&amp;·{·[·!·
00098980:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]00098980:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
00098990:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·00098990:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
000989a0:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain000989a0:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
000989b0:·6572·656e·7620·5d3b·207d·3b20·7468·656e··erenv·];·};·then000989b0:·6572·656e·7620·5d3b·207d·3b20·7468·656e··erenv·];·};·then
000989c0:·0a0a·6368·6f77·6e20·3020·2f62·6f6f·742f··..chown·0·/boot/000989c0:·0a0a·6368·6f77·6e20·3020·2f62·6f6f·742f··..chown·0·/boot/
000989d0:·6772·7562·322f·6772·7562·2e63·6667·0a0a··grub2/grub.cfg..000989d0:·6772·7562·322f·6772·7562·2e63·6667·0a0a··grub2/grub.cfg..
Offset 39126, 22 lines modifiedOffset 39126, 22 lines modified
00098d50:·653a·2054·6573·7420·666f·7220·6578·6973··e:·Test·for·exis00098d50:·653a·2054·6573·7420·666f·7220·6578·6973··e:·Test·for·exis
00098d60:·7465·6e63·6520·2f62·6f6f·742f·6772·7562··tence·/boot/grub00098d60:·7465·6e63·6520·2f62·6f6f·742f·6772·7562··tence·/boot/grub
00098d70:·322f·6772·7562·2e63·6667·0a20·2073·7461··2/grub.cfg.··sta00098d70:·322f·6772·7562·2e63·6667·0a20·2073·7461··2/grub.cfg.··sta
00098d80:·743a·0a20·2020·2070·6174·683a·202f·626f··t:.····path:·/bo00098d80:·743a·0a20·2020·2070·6174·683a·202f·626f··t:.····path:·/bo
00098d90:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf00098d90:·6f74·2f67·7275·6232·2f67·7275·622e·6366··ot/grub2/grub.cf
00098da0:·670a·2020·7265·6769·7374·6572·3a20·6669··g.··register:·fi00098da0:·670a·2020·7265·6769·7374·6572·3a20·6669··g.··register:·fi
00098db0:·6c65·5f65·7869·7374·730a·2020·7768·656e··le_exists.··when00098db0:·6c65·5f65·7869·7374·730a·2020·7768·656e··le_exists.··when
00098dc0:·3a0a·2020·2d20·2722·6772·7562·322d·636f··:.··-·'"grub2-co00098dc0:·3a0a·2020·2d20·2722·2f62·6f6f·742f·6566··:.··-·'"/boot/ef
 00098dd0:·6922·2069·6e20·616e·7369·626c·655f·6d6f··i"·in·ansible_mo
 00098de0:·756e·7473·207c·206d·6170·2861·7474·7269··unts·|·map(attri
 00098df0:·6275·7465·3d22·6d6f·756e·7422·2920·7c20··bute="mount")·|·
 00098e00:·6c69·7374·270a·2020·2d20·2722·6772·7562··list'.··-·'"grub
00098dd0:·6d6d·6f6e·2220·696e·2061·6e73·6962·6c65··mmon"·in·ansible00098e10:·322d·636f·6d6d·6f6e·2220·696e·2061·6e73··2-common"·in·ans
00098de0:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'00098e20:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
00098df0:·0a20·202d·2027·222f·626f·6f74·2f65·6669··.··-·'"/boot/efi 
00098e00:·2220·696e·2061·6e73·6962·6c65·5f6d·6f75··"·in·ansible_mou 
00098e10:·6e74·7320·7c20·6d61·7028·6174·7472·6962··nts·|·map(attrib 
00098e20:·7574·653d·226d·6f75·6e74·2229·207c·206c··ute="mount")·|·l 
00098e30:·6973·7427·0a20·202d·2061·6e73·6962·6c65··ist'.··-·ansible00098e30:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible
00098e40:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_00098e40:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_
00098e50:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do00098e50:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do
00098e60:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o00098e60:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o
00098e70:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"00098e70:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman"
00098e80:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·00098e80:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·
00098e90:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-00098e90:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-
00098ea0:·352e·352e·322e·320a·2020·2d20·4e49·5354··5.5.2.2.··-·NIST00098ea0:·352e·352e·322e·320a·2020·2d20·4e49·5354··5.5.2.2.··-·NIST
Offset 39161, 22 lines modifiedOffset 39161, 22 lines modified
00098f80:·6565·6465·640a·0a2d·206e·616d·653a·2045··eeded..-·name:·E00098f80:·6565·6465·640a·0a2d·206e·616d·653a·2045··eeded..-·name:·E
00098f90:·6e73·7572·6520·6f77·6e65·7220·3020·6f6e··nsure·owner·0·on00098f90:·6e73·7572·6520·6f77·6e65·7220·3020·6f6e··nsure·owner·0·on
Max diff block lines reached; 18667/28414 bytes (65.70%) of diff not shown.
6.98 KB
html2text {}
    
Offset 2662, 15 lines modifiedOffset 2662, 15 lines modified
2662 References··A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,2662 References··A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,
2663 ············A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.12663 ············A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.1
2664 Remediation_Shell_script_⇲2664 Remediation_Shell_script_⇲
2665 Complexity:·low2665 Complexity:·low
2666 Disruption:·low2666 Disruption:·low
2667 Strategy:···configure2667 Strategy:···configure
2668 #·Remediation·is·applicable·only·in·certain·platforms2668 #·Remediation·is·applicable·only·in·certain·platforms
2669 if·rpm·--quiet·-q·grub2-common·&&·[·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};2669 if·[·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};
2670 then2670 then
  
2671 chgrp·0·/boot/grub2/grub.cfg2671 chgrp·0·/boot/grub2/grub.cfg
  
2672 else2672 else
2673 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2673 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2674 fi2674 fi
Offset 2695, 16 lines modifiedOffset 2695, 16 lines modified
2695 ··-·no_reboot_needed2695 ··-·no_reboot_needed
  
2696 -·name:·Test·for·existence·/boot/grub2/grub.cfg2696 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2697 ··stat:2697 ··stat:
2698 ····path:·/boot/grub2/grub.cfg2698 ····path:·/boot/grub2/grub.cfg
2699 ··register:·file_exists2699 ··register:·file_exists
2700 ··when:2700 ··when:
2701 ··-·'"grub2-common"·in·ansible_facts.packages' 
2702 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'2701 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2702 ··-·'"grub2-common"·in·ansible_facts.packages'
2703 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2703 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2704 ··tags:2704 ··tags:
2705 ··-·CJIS-5.5.2.22705 ··-·CJIS-5.5.2.2
2706 ··-·NIST-800-171-3.4.52706 ··-·NIST-800-171-3.4.5
2707 ··-·NIST-800-53-AC-6(1)2707 ··-·NIST-800-53-AC-6(1)
2708 ··-·NIST-800-53-CM-6(a)2708 ··-·NIST-800-53-CM-6(a)
2709 ··-·PCI-DSS-Req-7.12709 ··-·PCI-DSS-Req-7.1
Offset 2716, 16 lines modifiedOffset 2716, 16 lines modified
2716 ··-·no_reboot_needed2716 ··-·no_reboot_needed
  
2717 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg2717 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
2718 ··file:2718 ··file:
2719 ····path:·/boot/grub2/grub.cfg2719 ····path:·/boot/grub2/grub.cfg
2720 ····group:·'0'2720 ····group:·'0'
2721 ··when:2721 ··when:
2722 ··-·'"grub2-common"·in·ansible_facts.packages' 
2723 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'2722 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2723 ··-·'"grub2-common"·in·ansible_facts.packages'
2724 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2724 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2725 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists2725 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
2726 ··tags:2726 ··tags:
2727 ··-·CJIS-5.5.2.22727 ··-·CJIS-5.5.2.2
2728 ··-·NIST-800-171-3.4.52728 ··-·NIST-800-171-3.4.5
2729 ··-·NIST-800-53-AC-6(1)2729 ··-·NIST-800-53-AC-6(1)
2730 ··-·NIST-800-53-CM-6(a)2730 ··-·NIST-800-53-CM-6(a)
Offset 2748, 15 lines modifiedOffset 2748, 15 lines modified
2748 References··A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,2748 References··A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,
2749 ············A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.12749 ············A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.1
2750 Remediation_Shell_script_⇲2750 Remediation_Shell_script_⇲
2751 Complexity:·low2751 Complexity:·low
2752 Disruption:·low2752 Disruption:·low
2753 Strategy:···configure2753 Strategy:···configure
2754 #·Remediation·is·applicable·only·in·certain·platforms2754 #·Remediation·is·applicable·only·in·certain·platforms
2755 if·rpm·--quiet·-q·grub2-common·&&·[·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};2755 if·[·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};
2756 then2756 then
  
2757 chown·0·/boot/grub2/grub.cfg2757 chown·0·/boot/grub2/grub.cfg
  
2758 else2758 else
2759 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2759 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2760 fi2760 fi
Offset 2781, 16 lines modifiedOffset 2781, 16 lines modified
2781 ··-·no_reboot_needed2781 ··-·no_reboot_needed
  
2782 -·name:·Test·for·existence·/boot/grub2/grub.cfg2782 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2783 ··stat:2783 ··stat:
2784 ····path:·/boot/grub2/grub.cfg2784 ····path:·/boot/grub2/grub.cfg
2785 ··register:·file_exists2785 ··register:·file_exists
2786 ··when:2786 ··when:
2787 ··-·'"grub2-common"·in·ansible_facts.packages' 
2788 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'2787 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2788 ··-·'"grub2-common"·in·ansible_facts.packages'
2789 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2789 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2790 ··tags:2790 ··tags:
2791 ··-·CJIS-5.5.2.22791 ··-·CJIS-5.5.2.2
2792 ··-·NIST-800-171-3.4.52792 ··-·NIST-800-171-3.4.5
2793 ··-·NIST-800-53-AC-6(1)2793 ··-·NIST-800-53-AC-6(1)
2794 ··-·NIST-800-53-CM-6(a)2794 ··-·NIST-800-53-CM-6(a)
2795 ··-·PCI-DSS-Req-7.12795 ··-·PCI-DSS-Req-7.1
Offset 2802, 16 lines modifiedOffset 2802, 16 lines modified
2802 ··-·no_reboot_needed2802 ··-·no_reboot_needed
  
2803 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg2803 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
2804 ··file:2804 ··file:
2805 ····path:·/boot/grub2/grub.cfg2805 ····path:·/boot/grub2/grub.cfg
2806 ····owner:·'0'2806 ····owner:·'0'
2807 ··when:2807 ··when:
2808 ··-·'"grub2-common"·in·ansible_facts.packages' 
2809 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'2808 ··-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 2809 ··-·'"grub2-common"·in·ansible_facts.packages'
2810 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2810 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2811 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists2811 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
2812 ··tags:2812 ··tags:
2813 ··-·CJIS-5.5.2.22813 ··-·CJIS-5.5.2.2
2814 ··-·NIST-800-171-3.4.52814 ··-·NIST-800-171-3.4.5
2815 ··-·NIST-800-53-AC-6(1)2815 ··-·NIST-800-53-AC-6(1)
2816 ··-·NIST-800-53-CM-6(a)2816 ··-·NIST-800-53-CM-6(a)
Offset 2834, 15 lines modifiedOffset 2834, 15 lines modified
2834 References··A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,2834 References··A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,
2835 ············A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·1.4.12835 ············A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·1.4.1
2836 Remediation_Shell_script_⇲2836 Remediation_Shell_script_⇲
2837 Complexity:·low2837 Complexity:·low
2838 Disruption:·low2838 Disruption:·low
2839 Strategy:···configure2839 Strategy:···configure
2840 #·Remediation·is·applicable·only·in·certain·platforms2840 #·Remediation·is·applicable·only·in·certain·platforms
2841 if·rpm·--quiet·-q·grub2-common·&&·[·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then2841 if·[·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
2842 chmod·u-s,g-xwrs,o-xwrt·/boot/grub2/grub.cfg2842 chmod·u-s,g-xwrs,o-xwrt·/boot/grub2/grub.cfg
  
2843 else2843 else
2844 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2844 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2845 fi2845 fi
2846 Remediation_Ansible_snippet_⇲2846 Remediation_Ansible_snippet_⇲
Offset 2864, 16 lines modifiedOffset 2864, 16 lines modified
2864 ··-·no_reboot_needed2864 ··-·no_reboot_needed
  
2865 -·name:·Test·for·existence·/boot/grub2/grub.cfg2865 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2866 ··stat:2866 ··stat:
2867 ····path:·/boot/grub2/grub.cfg2867 ····path:·/boot/grub2/grub.cfg
2868 ··register:·file_exists2868 ··register:·file_exists
2869 ··when:2869 ··when:
Max diff block lines reached; 2328/7120 bytes (32.70%) of diff not shown.
3.12 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-standard.html
    
Offset 23175, 21 lines modifiedOffset 23175, 21 lines modified
0005a860:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0005a860:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0005a870:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0005a870:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0005a880:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0005a880:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0005a890:·646d·3134·3535·3422·3e3c·7072·653e·3c63··dm14554"><pre><c0005a890:·646d·3134·3535·3422·3e3c·7072·653e·3c63··dm14554"><pre><c
0005a8a0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio0005a8a0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
0005a8b0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·0005a8b0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
0005a8c0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·0005a8c0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
0005a8d0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm0005a8d0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
0005a8e0:·202d·2d71·7569·6574·202d·7120·6175·6469···--quiet·-q·audi 
0005a8f0:·7420·2661·6d70·3b26·616d·703b·205b·2021··t·&amp;&amp;·[·! 
0005a900:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·0005a8e0:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
0005a910:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!0005a8f0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
0005a920:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai0005a900:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
0005a930:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..0005a910:·6e65·7265·6e76·205d·2026·616d·703b·2661··nerenv·]·&amp;&a
 0005a920:·6d70·3b20·7270·6d20·2d2d·7175·6965·7420··mp;·rpm·--quiet·
 0005a930:·2d71·2061·7564·6974·3b20·7468·656e·0a0a··-q·audit;·then..
0005a940:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·0005a940:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·
0005a950:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·0005a950:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·
0005a960:·6f66·2074·6865·2073·7973·6361·6c6c·2072··of·the·syscall·r0005a960:·6f66·2074·6865·2073·7973·6361·6c6c·2072··of·the·syscall·r
0005a970:·756c·650a·2320·5265·7472·6965·7665·2068··ule.#·Retrieve·h0005a970:·756c·650a·2320·5265·7472·6965·7665·2068··ule.#·Retrieve·h
0005a980:·6172·6477·6172·6520·6172·6368·6974·6563··ardware·architec0005a980:·6172·6477·6172·6520·6172·6368·6974·6563··ardware·architec
0005a990:·7475·7265·206f·6620·7468·6520·756e·6465··ture·of·the·unde0005a990:·7475·7265·206f·6620·7468·6520·756e·6465··ture·of·the·unde
0005a9a0:·726c·7969·6e67·2073·7973·7465·6d0a·2320··rlying·system.#·0005a9a0:·726c·7969·6e67·2073·7973·7465·6d0a·2320··rlying·system.#·
1.09 KB
html2text {}
    
Offset 996, 15 lines modifiedOffset 996, 15 lines modified
996 ············4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,996 ············4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,
997 ············A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,997 ············A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,
998 ············A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),998 ············A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),
999 ············AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,999 ············AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,
1000 ············PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·Req-10.2.71000 ············PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·Req-10.2.7
1001 Remediation_Shell_script_⇲1001 Remediation_Shell_script_⇲
1002 #·Remediation·is·applicable·only·in·certain·platforms1002 #·Remediation·is·applicable·only·in·certain·platforms
1003 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1003 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1004 #·First·perform·the·remediation·of·the·syscall·rule1004 #·First·perform·the·remediation·of·the·syscall·rule
1005 #·Retrieve·hardware·architecture·of·the·underlying·system1005 #·Retrieve·hardware·architecture·of·the·underlying·system
1006 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>1006 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>
1007 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence1007 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence
1008 #·······of·32-bit's·equivalent·of·the·corresponding·rule.1008 #·······of·32-bit's·equivalent·of·the·corresponding·rule.
1009 #·······(See·`man·7·audit.rules`·for·details·)1009 #·······(See·`man·7·audit.rules`·for·details·)
142 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-cis.html
    
Offset 41914, 22 lines modifiedOffset 41914, 22 lines modified
000a3b90:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr000a3b90:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr
000a3ba0:·6963·745f·7374·7261·7465·6779·0a0a·2d20··ict_strategy..-·000a3ba0:·6963·745f·7374·7261·7465·6779·0a0a·2d20··ict_strategy..-·
000a3bb0:·6e61·6d65·3a20·5365·7420·6172·6368·6974··name:·Set·archit000a3bb0:·6e61·6d65·3a20·5365·7420·6172·6368·6974··name:·Set·archit
000a3bc0:·6563·7475·7265·2066·6f72·2061·7564·6974··ecture·for·audit000a3bc0:·6563·7475·7265·2066·6f72·2061·7564·6974··ecture·for·audit
000a3bd0:·2074·6173·6b73·0a20·2073·6574·5f66·6163···tasks.··set_fac000a3bd0:·2074·6173·6b73·0a20·2073·6574·5f66·6163···tasks.··set_fac
000a3be0:·743a·0a20·2020·2061·7564·6974·5f61·7263··t:.····audit_arc000a3be0:·743a·0a20·2020·2061·7564·6974·5f61·7263··t:.····audit_arc
000a3bf0:·683a·2062·3634·0a20·2077·6865·6e3a·0a20··h:·b64.··when:.·000a3bf0:·683a·2062·3634·0a20·2077·6865·6e3a·0a20··h:·b64.··when:.·
000a3c00:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a 
000a3c10:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
000a3c20:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib 
000a3c30:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
000a3c40:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
000a3c50:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
000a3c60:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
000a3c70:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]000a3c00:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu
 000a3c10:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 000a3c20:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 000a3c30:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 000a3c40:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 000a3c50:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a
 000a3c60:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible
 000a3c70:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
000a3c80:·0a20·202d·2061·6e73·6962·6c65·5f61·7263··.··-·ansible_arc000a3c80:·0a20·202d·2061·6e73·6962·6c65·5f61·7263··.··-·ansible_arc
000a3c90:·6869·7465·6374·7572·6520·3d3d·2022·6161··hitecture·==·"aa000a3c90:·6869·7465·6374·7572·6520·3d3d·2022·6161··hitecture·==·"aa
000a3ca0:·7263·6836·3422·206f·7220·616e·7369·626c··rch64"·or·ansibl000a3ca0:·7263·6836·3422·206f·7220·616e·7369·626c··rch64"·or·ansibl
000a3cb0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=000a3cb0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=
000a3cc0:·3d20·2270·7063·3634·2220·6f72·2061·6e73··=·"ppc64"·or·ans000a3cc0:·3d20·2270·7063·3634·2220·6f72·2061·6e73··=·"ppc64"·or·ans
000a3cd0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur000a3cd0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
000a3ce0:·650a·2020·2020·3d3d·2022·7070·6336·346c··e.····==·"ppc64l000a3ce0:·650a·2020·2020·3d3d·2022·7070·6336·346c··e.····==·"ppc64l
Offset 42226, 23 lines modifiedOffset 42226, 23 lines modified
000a4f10:·6d65·5f72·756c·6573·0a20·2020·2020·2063··me_rules.······c000a4f10:·6d65·5f72·756c·6573·0a20·2020·2020·2063··me_rules.······c
000a4f20:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····000a4f20:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····
000a4f30:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··000a4f30:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··
000a4f40:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese000a4f40:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese
000a4f50:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys000a4f50:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys
000a4f60:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le000a4f60:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le
000a4f70:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when000a4f70:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when
000a4f80:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i 
000a4f90:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
000a4fa0:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an 
000a4fb0:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
000a4fc0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
000a4fd0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
000a4fe0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
000a4ff0:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe000a4f80:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi
 000a4f90:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 000a4fa0:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 000a4fb0:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 000a4fc0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 000a4fd0:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·
 000a4fe0:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi
 000a4ff0:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
000a5000:·7222·5d0a·2020·7461·6773·3a0a·2020·2d20··r"].··tags:.··-·000a5000:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·
000a5010:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-000a5010:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-
000a5020:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000a5020:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
000a5030:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800000a5030:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
000a5040:·2d35·332d·4143·2d36·2839·290a·2020·2d20··-53-AC-6(9).··-·000a5040:·2d35·332d·4143·2d36·2839·290a·2020·2d20··-53-AC-6(9).··-·
000a5050:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1000a5050:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1
000a5060:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80000a5060:·3228·6329·0a20·202d·204e·4953·542d·3830··2(c).··-·NIST-80
000a5070:·302d·3533·2d41·552d·3228·6429·0a20·202d··0-53-AU-2(d).··-000a5070:·302d·3533·2d41·552d·3228·6429·0a20·202d··0-53-AU-2(d).··-
Offset 42526, 22 lines modifiedOffset 42526, 22 lines modified
000a61d0:·756c·6573·0a20·2020·2020·2063·7265·6174··ules.······creat000a61d0:·756c·6573·0a20·2020·2020·2063·7265·6174··ules.······creat
000a61e0:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo000a61e0:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo
000a61f0:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······000a61f0:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······
000a6200:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·000a6200:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
000a6210:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall000a6210:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall
000a6220:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length000a6220:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length
000a6230:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··000a6230:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··
000a6240:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an 
000a6250:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
000a6260:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl 
000a6270:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
000a6280:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
000a6290:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
000a62a0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
000a62b0:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].000a6240:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
 000a6250:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
 000a6260:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
 000a6270:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
 000a6280:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
 000a6290:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au
 000a62a0:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_
 000a62b0:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.
000a62c0:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=000a62c0:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=
000a62d0:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.000a62d0:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.
000a62e0:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1000a62e0:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1
000a62f0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17000a62f0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
000a6300:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST000a6300:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST
000a6310:·2d38·3030·2d35·332d·4143·2d36·2839·290a··-800-53-AC-6(9).000a6310:·2d38·3030·2d35·332d·4143·2d36·2839·290a··-800-53-AC-6(9).
000a6320:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-000a6320:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
Offset 43403, 22 lines modifiedOffset 43403, 22 lines modified
000a98a0:·6565·6465·640a·2020·2d20·7265·7374·7269··eeded.··-·restri000a98a0:·6565·6465·640a·2020·2d20·7265·7374·7269··eeded.··-·restri
000a98b0:·6374·5f73·7472·6174·6567·790a·0a2d·206e··ct_strategy..-·n000a98b0:·6374·5f73·7472·6174·6567·790a·0a2d·206e··ct_strategy..-·n
000a98c0:·616d·653a·2053·6574·2061·7263·6869·7465··ame:·Set·archite000a98c0:·616d·653a·2053·6574·2061·7263·6869·7465··ame:·Set·archite
000a98d0:·6374·7572·6520·666f·7220·6175·6469·7420··cture·for·audit·000a98d0:·6374·7572·6520·666f·7220·6175·6469·7420··cture·for·audit·
000a98e0:·7461·736b·730a·2020·7365·745f·6661·6374··tasks.··set_fact000a98e0:·7461·736b·730a·2020·7365·745f·6661·6374··tasks.··set_fact
000a98f0:·3a0a·2020·2020·6175·6469·745f·6172·6368··:.····audit_arch000a98f0:·3a0a·2020·2020·6175·6469·745f·6172·6368··:.····audit_arch
000a9900:·3a20·6236·340a·2020·7768·656e·3a0a·2020··:·b64.··when:.··000a9900:·3a20·6236·340a·2020·7768·656e·3a0a·2020··:·b64.··when:.··
000a9910:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an 
000a9920:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
000a9930:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl 
000a9940:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization 
000a9950:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d 
000a9960:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·" 
000a9970:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman 
000a9980:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].000a9910:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua
 000a9920:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no
 000a9930:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",·
 000a9940:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz",
 000a9950:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont
 000a9960:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au
 000a9970:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_
 000a9980:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.
000a9990:·2020·2d20·616e·7369·626c·655f·6172·6368····-·ansible_arch000a9990:·2020·2d20·616e·7369·626c·655f·6172·6368····-·ansible_arch
000a99a0:·6974·6563·7475·7265·203d·3d20·2261·6172··itecture·==·"aar000a99a0:·6974·6563·7475·7265·203d·3d20·2261·6172··itecture·==·"aar
000a99b0:·6368·3634·2220·6f72·2061·6e73·6962·6c65··ch64"·or·ansible000a99b0:·6368·3634·2220·6f72·2061·6e73·6962·6c65··ch64"·or·ansible
000a99c0:·5f61·7263·6869·7465·6374·7572·6520·3d3d··_architecture·==000a99c0:·5f61·7263·6869·7465·6374·7572·6520·3d3d··_architecture·==
000a99d0:·2022·7070·6336·3422·206f·7220·616e·7369···"ppc64"·or·ansi000a99d0:·2022·7070·6336·3422·206f·7220·616e·7369···"ppc64"·or·ansi
000a99e0:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture000a99e0:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
000a99f0:·0a20·2020·203d·3d20·2270·7063·3634·6c65··.····==·"ppc64le000a99f0:·0a20·2020·203d·3d20·2270·7063·3634·6c65··.····==·"ppc64le
Offset 43714, 23 lines modifiedOffset 43714, 23 lines modified
000aac10:·7469·6d65·2d63·6861·6e67·650a·2020·2020··time-change.····000aac10:·7469·6d65·2d63·6861·6e67·650a·2020·2020··time-change.····
000aac20:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·000aac20:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·
000aac30:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx000aac30:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx
000aac40:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr000aac40:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr
000aac50:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·000aac50:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·
000aac60:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|000aac60:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|
Max diff block lines reached; 104879/113910 bytes (92.07%) of diff not shown.
30.5 KB
html2text {}
    
Offset 3024, 16 lines modifiedOffset 3024, 16 lines modified
3024 ··-·no_reboot_needed3024 ··-·no_reboot_needed
3025 ··-·restrict_strategy3025 ··-·restrict_strategy
  
3026 -·name:·Set·architecture·for·audit·tasks3026 -·name:·Set·architecture·for·audit·tasks
3027 ··set_fact:3027 ··set_fact:
3028 ····audit_arch:·b643028 ····audit_arch:·b64
3029 ··when:3029 ··when:
3030 ··-·'"audit"·in·ansible_facts.packages' 
3031 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3030 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3031 ··-·'"audit"·in·ansible_facts.packages'
3032 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3032 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3033 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3033 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3034 ··tags:3034 ··tags:
3035 ··-·CJIS-5.4.1.13035 ··-·CJIS-5.4.1.1
3036 ··-·NIST-800-171-3.1.73036 ··-·NIST-800-171-3.1.7
3037 ··-·NIST-800-53-AC-6(9)3037 ··-·NIST-800-53-AC-6(9)
3038 ··-·NIST-800-53-AU-12(c)3038 ··-·NIST-800-53-AU-12(c)
Offset 3166, 16 lines modifiedOffset 3166, 16 lines modified
3166 ······path:·'{{·audit_file·}}'3166 ······path:·'{{·audit_file·}}'
3167 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules3167 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
3168 ······create:·true3168 ······create:·true
3169 ······mode:·o-rwx3169 ······mode:·o-rwx
3170 ······state:·present3170 ······state:·present
3171 ····when:·syscalls_found·|·length·==·03171 ····when:·syscalls_found·|·length·==·0
3172 ··when:3172 ··when:
3173 ··-·'"audit"·in·ansible_facts.packages' 
3174 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3173 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3174 ··-·'"audit"·in·ansible_facts.packages'
3175 ··tags:3175 ··tags:
3176 ··-·CJIS-5.4.1.13176 ··-·CJIS-5.4.1.1
3177 ··-·NIST-800-171-3.1.73177 ··-·NIST-800-171-3.1.7
3178 ··-·NIST-800-53-AC-6(9)3178 ··-·NIST-800-53-AC-6(9)
3179 ··-·NIST-800-53-AU-12(c)3179 ··-·NIST-800-53-AU-12(c)
3180 ··-·NIST-800-53-AU-2(d)3180 ··-·NIST-800-53-AU-2(d)
3181 ··-·NIST-800-53-CM-6(a)3181 ··-·NIST-800-53-CM-6(a)
Offset 3305, 16 lines modifiedOffset 3305, 16 lines modified
3305 ······path:·'{{·audit_file·}}'3305 ······path:·'{{·audit_file·}}'
3306 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules3306 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
3307 ······create:·true3307 ······create:·true
3308 ······mode:·o-rwx3308 ······mode:·o-rwx
3309 ······state:·present3309 ······state:·present
3310 ····when:·syscalls_found·|·length·==·03310 ····when:·syscalls_found·|·length·==·0
3311 ··when:3311 ··when:
3312 ··-·'"audit"·in·ansible_facts.packages' 
3313 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3312 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3313 ··-·'"audit"·in·ansible_facts.packages'
3314 ··-·audit_arch·==·"b64"3314 ··-·audit_arch·==·"b64"
3315 ··tags:3315 ··tags:
3316 ··-·CJIS-5.4.1.13316 ··-·CJIS-5.4.1.1
3317 ··-·NIST-800-171-3.1.73317 ··-·NIST-800-171-3.1.7
3318 ··-·NIST-800-53-AC-6(9)3318 ··-·NIST-800-53-AC-6(9)
3319 ··-·NIST-800-53-AU-12(c)3319 ··-·NIST-800-53-AU-12(c)
3320 ··-·NIST-800-53-AU-2(d)3320 ··-·NIST-800-53-AU-2(d)
Offset 3380, 16 lines modifiedOffset 3380, 16 lines modified
3380 ··-·no_reboot_needed3380 ··-·no_reboot_needed
3381 ··-·restrict_strategy3381 ··-·restrict_strategy
  
3382 -·name:·Set·architecture·for·audit·tasks3382 -·name:·Set·architecture·for·audit·tasks
3383 ··set_fact:3383 ··set_fact:
3384 ····audit_arch:·b643384 ····audit_arch:·b64
3385 ··when:3385 ··when:
3386 ··-·'"audit"·in·ansible_facts.packages' 
3387 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3386 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3387 ··-·'"audit"·in·ansible_facts.packages'
3388 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3388 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3389 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3389 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3390 ··tags:3390 ··tags:
3391 ··-·CJIS-5.4.1.13391 ··-·CJIS-5.4.1.1
3392 ··-·NIST-800-171-3.1.73392 ··-·NIST-800-171-3.1.7
3393 ··-·NIST-800-53-AC-6(9)3393 ··-·NIST-800-53-AC-6(9)
3394 ··-·NIST-800-53-AU-12(c)3394 ··-·NIST-800-53-AU-12(c)
Offset 3518, 16 lines modifiedOffset 3518, 16 lines modified
3518 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a0=0x0·-F3518 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a0=0x0·-F
3519 ········key=time-change3519 ········key=time-change
3520 ······create:·true3520 ······create:·true
3521 ······mode:·o-rwx3521 ······mode:·o-rwx
3522 ······state:·present3522 ······state:·present
3523 ····when:·syscalls_found·|·length·==·03523 ····when:·syscalls_found·|·length·==·0
3524 ··when:3524 ··when:
3525 ··-·'"audit"·in·ansible_facts.packages' 
3526 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3525 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3526 ··-·'"audit"·in·ansible_facts.packages'
3527 ··tags:3527 ··tags:
3528 ··-·CJIS-5.4.1.13528 ··-·CJIS-5.4.1.1
3529 ··-·NIST-800-171-3.1.73529 ··-·NIST-800-171-3.1.7
3530 ··-·NIST-800-53-AC-6(9)3530 ··-·NIST-800-53-AC-6(9)
3531 ··-·NIST-800-53-AU-12(c)3531 ··-·NIST-800-53-AU-12(c)
3532 ··-·NIST-800-53-AU-2(d)3532 ··-·NIST-800-53-AU-2(d)
3533 ··-·NIST-800-53-CM-6(a)3533 ··-·NIST-800-53-CM-6(a)
Offset 3654, 16 lines modifiedOffset 3654, 16 lines modified
3654 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·a0=0x0·-F3654 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·a0=0x0·-F
3655 ········key=time-change3655 ········key=time-change
3656 ······create:·true3656 ······create:·true
3657 ······mode:·o-rwx3657 ······mode:·o-rwx
3658 ······state:·present3658 ······state:·present
3659 ····when:·syscalls_found·|·length·==·03659 ····when:·syscalls_found·|·length·==·0
3660 ··when:3660 ··when:
3661 ··-·'"audit"·in·ansible_facts.packages' 
3662 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3661 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3662 ··-·'"audit"·in·ansible_facts.packages'
3663 ··-·audit_arch·==·"b64"3663 ··-·audit_arch·==·"b64"
3664 ··tags:3664 ··tags:
3665 ··-·CJIS-5.4.1.13665 ··-·CJIS-5.4.1.1
3666 ··-·NIST-800-171-3.1.73666 ··-·NIST-800-171-3.1.7
3667 ··-·NIST-800-53-AC-6(9)3667 ··-·NIST-800-53-AC-6(9)
3668 ··-·NIST-800-53-AU-12(c)3668 ··-·NIST-800-53-AU-12(c)
3669 ··-·NIST-800-53-AU-2(d)3669 ··-·NIST-800-53-AU-2(d)
Offset 3851, 16 lines modifiedOffset 3851, 16 lines modified
3851 ······path:·'{{·audit_file·}}'3851 ······path:·'{{·audit_file·}}'
3852 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules3852 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_time_rules
3853 ······create:·true3853 ······create:·true
3854 ······mode:·o-rwx3854 ······mode:·o-rwx
3855 ······state:·present3855 ······state:·present
3856 ····when:·syscalls_found·|·length·==·03856 ····when:·syscalls_found·|·length·==·0
3857 ··when:3857 ··when:
3858 ··-·'"audit"·in·ansible_facts.packages' 
3859 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3858 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3859 ··-·'"audit"·in·ansible_facts.packages'
3860 ··tags:3860 ··tags:
3861 ··-·CJIS-5.4.1.13861 ··-·CJIS-5.4.1.1
3862 ··-·NIST-800-171-3.1.73862 ··-·NIST-800-171-3.1.7
3863 ··-·NIST-800-53-AC-6(9)3863 ··-·NIST-800-53-AC-6(9)
3864 ··-·NIST-800-53-AU-12(c)3864 ··-·NIST-800-53-AU-12(c)
3865 ··-·NIST-800-53-AU-2(d)3865 ··-·NIST-800-53-AU-2(d)
3866 ··-·NIST-800-53-CM-6(a)3866 ··-·NIST-800-53-CM-6(a)
Offset 3922, 16 lines modifiedOffset 3922, 16 lines modified
3922 -·name:·Check·if·watch·rule·for·/etc/localtime·already·exists·in·/etc/audit/rules.d/3922 -·name:·Check·if·watch·rule·for·/etc/localtime·already·exists·in·/etc/audit/rules.d/
Max diff block lines reached; 26925/31169 bytes (86.38%) of diff not shown.
57.2 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-cis_l1.html
    
Offset 37724, 19 lines modifiedOffset 37724, 19 lines modified
000935b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy000935b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
000935c0:·3a3c·2f74·683e·3c74·643e·636f·6e66·6967··:</th><td>config000935c0:·3a3c·2f74·683e·3c74·643e·636f·6e66·6967··:</th><td>config
000935d0:·7572·653c·2f74·643e·3c2f·7472·3e3c·2f74··ure</td></tr></t000935d0:·7572·653c·2f74·643e·3c2f·7472·3e3c·2f74··ure</td></tr></t
000935e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>000935e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
000935f0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is000935f0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
00093600:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only00093600:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
00093610:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat00093610:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
00093620:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·00093620:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
00093630:·2f73·7973·2f66·6972·6d77·6172·652f·6566··/sys/firmware/ef 
00093640:·6920·5d20·2661·6d70·3b26·616d·703b·2072··i·]·&amp;&amp;·r 
00093650:·706d·202d·2d71·7569·6574·202d·7120·6772··pm·--quiet·-q·gr 
00093660:·7562·322d·636f·6d6d·6f6e·2026·616d·703b··ub2-common·&amp;00093630:·7569·6574·202d·7120·6772·7562·322d·636f··uiet·-q·grub2-co
 00093640:·6d6d·6f6e·2026·616d·703b·2661·6d70·3b20··mmon·&amp;&amp;·
 00093650:·5b20·2120·2d66·202f·7379·732f·6669·726d··[·!·-f·/sys/firm
 00093660:·7761·7265·2f65·6669·205d·2026·616d·703b··ware/efi·]·&amp;
00093670:·2661·6d70·3b20·7b20·5b20·2120·2d66·202f··&amp;·{·[·!·-f·/00093670:·2661·6d70·3b20·7b20·5b20·2120·2d66·202f··&amp;·{·[·!·-f·/
00093680:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am00093680:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
00093690:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/00093690:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
000936a0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren000936a0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
000936b0:·7620·5d3b·207d·3b20·7468·656e·0a0a·6368··v·];·};·then..ch000936b0:·7620·5d3b·207d·3b20·7468·656e·0a0a·6368··v·];·};·then..ch
000936c0:·6772·7020·3020·2f62·6f6f·742f·6772·7562··grp·0·/boot/grub000936c0:·6772·7020·3020·2f62·6f6f·742f·6772·7562··grp·0·/boot/grub
000936d0:·322f·6772·7562·2e63·6667·0a0a·656c·7365··2/grub.cfg..else000936d0:·322f·6772·7562·2e63·6667·0a0a·656c·7365··2/grub.cfg..else
Offset 37798, 22 lines modifiedOffset 37798, 22 lines modified
00093a50:·5465·7374·2066·6f72·2065·7869·7374·656e··Test·for·existen00093a50:·5465·7374·2066·6f72·2065·7869·7374·656e··Test·for·existen
00093a60:·6365·202f·626f·6f74·2f67·7275·6232·2f67··ce·/boot/grub2/g00093a60:·6365·202f·626f·6f74·2f67·7275·6232·2f67··ce·/boot/grub2/g
00093a70:·7275·622e·6366·670a·2020·7374·6174·3a0a··rub.cfg.··stat:.00093a70:·7275·622e·6366·670a·2020·7374·6174·3a0a··rub.cfg.··stat:.
00093a80:·2020·2020·7061·7468·3a20·2f62·6f6f·742f······path:·/boot/00093a80:·2020·2020·7061·7468·3a20·2f62·6f6f·742f······path:·/boot/
00093a90:·6772·7562·322f·6772·7562·2e63·6667·0a20··grub2/grub.cfg.·00093a90:·6772·7562·322f·6772·7562·2e63·6667·0a20··grub2/grub.cfg.·
00093aa0:·2072·6567·6973·7465·723a·2066·696c·655f···register:·file_00093aa0:·2072·6567·6973·7465·723a·2066·696c·655f···register:·file_
00093ab0:·6578·6973·7473·0a20·2077·6865·6e3a·0a20··exists.··when:.·00093ab0:·6578·6973·7473·0a20·2077·6865·6e3a·0a20··exists.··when:.·
00093ac0:·202d·2027·222f·626f·6f74·2f65·6669·2220···-·'"/boot/efi"· 
00093ad0:·6e6f·7420·696e·2061·6e73·6962·6c65·5f6d··not·in·ansible_m 
00093ae0:·6f75·6e74·7320·7c20·6d61·7028·6174·7472··ounts·|·map(attr 
00093af0:·6962·7574·653d·226d·6f75·6e74·2229·207c··ibute="mount")·| 
00093b00:·206c·6973·7427·0a20·202d·2027·2267·7275···list'.··-·'"gru 
00093b10:·6232·2d63·6f6d·6d6f·6e22·2069·6e20·616e··b2-common"·in·an 
00093b20:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack00093ac0:·202d·2027·2267·7275·6232·2d63·6f6d·6d6f···-·'"grub2-commo
 00093ad0:·6e22·2069·6e20·616e·7369·626c·655f·6661··n"·in·ansible_fa
 00093ae0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
 00093af0:·2d20·2722·2f62·6f6f·742f·6566·6922·206e··-·'"/boot/efi"·n
 00093b00:·6f74·2069·6e20·616e·7369·626c·655f·6d6f··ot·in·ansible_mo
 00093b10:·756e·7473·207c·206d·6170·2861·7474·7269··unts·|·map(attri
 00093b20:·6275·7465·3d22·6d6f·756e·7422·2920·7c20··bute="mount")·|·
00093b30:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl00093b30:·6c69·7374·270a·2020·2d20·616e·7369·626c··list'.··-·ansibl
00093b40:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization00093b40:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
00093b50:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d00093b50:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
00093b60:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"00093b60:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
00093b70:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman00093b70:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
00093b80:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].00093b80:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
00093b90:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS00093b90:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS
00093ba0:·2d35·2e35·2e32·2e32·0a20·202d·204e·4953··-5.5.2.2.··-·NIS00093ba0:·2d35·2e35·2e32·2e32·0a20·202d·204e·4953··-5.5.2.2.··-·NIS
Offset 37834, 22 lines modifiedOffset 37834, 22 lines modified
00093c90:·2045·6e73·7572·6520·6772·6f75·7020·6f77···Ensure·group·ow00093c90:·2045·6e73·7572·6520·6772·6f75·7020·6f77···Ensure·group·ow
00093ca0:·6e65·7220·3020·6f6e·202f·626f·6f74·2f67··ner·0·on·/boot/g00093ca0:·6e65·7220·3020·6f6e·202f·626f·6f74·2f67··ner·0·on·/boot/g
00093cb0:·7275·6232·2f67·7275·622e·6366·670a·2020··rub2/grub.cfg.··00093cb0:·7275·6232·2f67·7275·622e·6366·670a·2020··rub2/grub.cfg.··
00093cc0:·6669·6c65·3a0a·2020·2020·7061·7468·3a20··file:.····path:·00093cc0:·6669·6c65·3a0a·2020·2020·7061·7468·3a20··file:.····path:·
00093cd0:·2f62·6f6f·742f·6772·7562·322f·6772·7562··/boot/grub2/grub00093cd0:·2f62·6f6f·742f·6772·7562·322f·6772·7562··/boot/grub2/grub
00093ce0:·2e63·6667·0a20·2020·2067·726f·7570·3a20··.cfg.····group:·00093ce0:·2e63·6667·0a20·2020·2067·726f·7570·3a20··.cfg.····group:·
00093cf0:·2730·270a·2020·7768·656e·3a0a·2020·2d20··'0'.··when:.··-·00093cf0:·2730·270a·2020·7768·656e·3a0a·2020·2d20··'0'.··when:.··-·
00093d00:·2722·2f62·6f6f·742f·6566·6922·206e·6f74··'"/boot/efi"·not 
00093d10:·2069·6e20·616e·7369·626c·655f·6d6f·756e···in·ansible_moun 
00093d20:·7473·207c·206d·6170·2861·7474·7269·6275··ts·|·map(attribu 
00093d30:·7465·3d22·6d6f·756e·7422·2920·7c20·6c69··te="mount")·|·li 
00093d40:·7374·270a·2020·2d20·2722·6772·7562·322d··st'.··-·'"grub2- 
00093d50:·636f·6d6d·6f6e·2220·696e·2061·6e73·6962··common"·in·ansib 
00093d60:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package00093d00:·2722·6772·7562·322d·636f·6d6d·6f6e·2220··'"grub2-common"·
 00093d10:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 00093d20:·2e70·6163·6b61·6765·7327·0a20·202d·2027··.packages'.··-·'
 00093d30:·222f·626f·6f74·2f65·6669·2220·6e6f·7420··"/boot/efi"·not·
 00093d40:·696e·2061·6e73·6962·6c65·5f6d·6f75·6e74··in·ansible_mount
 00093d50:·7320·7c20·6d61·7028·6174·7472·6962·7574··s·|·map(attribut
 00093d60:·653d·226d·6f75·6e74·2229·207c·206c·6973··e="mount")·|·lis
00093d70:·7327·0a20·202d·2061·6e73·6962·6c65·5f76··s'.··-·ansible_v00093d70:·7427·0a20·202d·2061·6e73·6962·6c65·5f76··t'.··-·ansible_v
00093d80:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty00093d80:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
00093d90:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock00093d90:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
00093da0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope00093da0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
00093db0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·00093db0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
00093dc0:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-00093dc0:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-
00093dd0:·2066·696c·655f·6578·6973·7473·2e73·7461···file_exists.sta00093dd0:·2066·696c·655f·6578·6973·7473·2e73·7461···file_exists.sta
00093de0:·7420·6973·2064·6566·696e·6564·2061·6e64··t·is·defined·and00093de0:·7420·6973·2064·6566·696e·6564·2061·6e64··t·is·defined·and
Offset 38304, 19 lines modifiedOffset 38304, 19 lines modified
000959f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><000959f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00095a00:·7464·3e63·6f6e·6669·6775·7265·3c2f·7464··td>configure</td00095a00:·7464·3e63·6f6e·6669·6775·7265·3c2f·7464··td>configure</td
00095a10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p00095a10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
00095a20:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed00095a20:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
00095a30:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic00095a30:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
00095a40:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer00095a40:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
00095a50:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i00095a50:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
00095a60:·6620·5b20·2120·2d66·202f·7379·732f·6669··f·[·!·-f·/sys/fi 
00095a70:·726d·7761·7265·2f65·6669·205d·2026·616d··rmware/efi·]·&am 
00095a80:·703b·2661·6d70·3b20·7270·6d20·2d2d·7175··p;&amp;·rpm·--qu 
00095a90:·6965·7420·2d71·2067·7275·6232·2d63·6f6d··iet·-q·grub2-com00095a60:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q
 00095a70:·2067·7275·6232·2d63·6f6d·6d6f·6e20·2661···grub2-common·&a
 00095a80:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 00095a90:·2f73·7973·2f66·6972·6d77·6172·652f·6566··/sys/firmware/ef
00095aa0:·6d6f·6e20·2661·6d70·3b26·616d·703b·207b··mon·&amp;&amp;·{00095aa0:·6920·5d20·2661·6d70·3b26·616d·703b·207b··i·]·&amp;&amp;·{
00095ab0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker00095ab0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
00095ac0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;00095ac0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
00095ad0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co00095ad0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
00095ae0:·6e74·6169·6e65·7265·6e76·205d·3b20·7d3b··ntainerenv·];·};00095ae0:·6e74·6169·6e65·7265·6e76·205d·3b20·7d3b··ntainerenv·];·};
00095af0:·2074·6865·6e0a·0a63·686f·776e·2030·202f···then..chown·0·/00095af0:·2074·6865·6e0a·0a63·686f·776e·2030·202f···then..chown·0·/
00095b00:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.00095b00:·626f·6f74·2f67·7275·6232·2f67·7275·622e··boot/grub2/grub.
00095b10:·6366·670a·0a65·6c73·650a·2020·2020·2667··cfg..else.····&g00095b10:·6366·670a·0a65·6c73·650a·2020·2020·2667··cfg..else.····&g
Offset 38377, 22 lines modifiedOffset 38377, 22 lines modified
00095e80:·6d65·3a20·5465·7374·2066·6f72·2065·7869··me:·Test·for·exi00095e80:·6d65·3a20·5465·7374·2066·6f72·2065·7869··me:·Test·for·exi
00095e90:·7374·656e·6365·202f·626f·6f74·2f67·7275··stence·/boot/gru00095e90:·7374·656e·6365·202f·626f·6f74·2f67·7275··stence·/boot/gru
00095ea0:·6232·2f67·7275·622e·6366·670a·2020·7374··b2/grub.cfg.··st00095ea0:·6232·2f67·7275·622e·6366·670a·2020·7374··b2/grub.cfg.··st
00095eb0:·6174·3a0a·2020·2020·7061·7468·3a20·2f62··at:.····path:·/b00095eb0:·6174·3a0a·2020·2020·7061·7468·3a20·2f62··at:.····path:·/b
00095ec0:·6f6f·742f·6772·7562·322f·6772·7562·2e63··oot/grub2/grub.c00095ec0:·6f6f·742f·6772·7562·322f·6772·7562·2e63··oot/grub2/grub.c
00095ed0:·6667·0a20·2072·6567·6973·7465·723a·2066··fg.··register:·f00095ed0:·6667·0a20·2072·6567·6973·7465·723a·2066··fg.··register:·f
00095ee0:·696c·655f·6578·6973·7473·0a20·2077·6865··ile_exists.··whe00095ee0:·696c·655f·6578·6973·7473·0a20·2077·6865··ile_exists.··whe
00095ef0:·6e3a·0a20·202d·2027·222f·626f·6f74·2f65··n:.··-·'"/boot/e00095ef0:·6e3a·0a20·202d·2027·2267·7275·6232·2d63··n:.··-·'"grub2-c
00095f00:·6669·2220·6e6f·7420·696e·2061·6e73·6962··fi"·not·in·ansib 
00095f10:·6c65·5f6d·6f75·6e74·7320·7c20·6d61·7028··le_mounts·|·map( 
00095f20:·6174·7472·6962·7574·653d·226d·6f75·6e74··attribute="mount 
00095f30:·2229·207c·206c·6973·7427·0a20·202d·2027··")·|·list'.··-·' 
00095f40:·2267·7275·6232·2d63·6f6d·6d6f·6e22·2069··"grub2-common"·i 
00095f50:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
00095f60:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an00095f00:·6f6d·6d6f·6e22·2069·6e20·616e·7369·626c··ommon"·in·ansibl
 00095f10:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 00095f20:·270a·2020·2d20·2722·2f62·6f6f·742f·6566··'.··-·'"/boot/ef
 00095f30:·6922·206e·6f74·2069·6e20·616e·7369·626c··i"·not·in·ansibl
 00095f40:·655f·6d6f·756e·7473·207c·206d·6170·2861··e_mounts·|·map(a
 00095f50:·7474·7269·6275·7465·3d22·6d6f·756e·7422··ttribute="mount"
 00095f60:·2920·7c20·6c69·7374·270a·2020·2d20·616e··)·|·list'.··-·an
00095f70:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza00095f70:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
00095f80:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in00095f80:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
Max diff block lines reached; 36522/45898 bytes (79.57%) of diff not shown.
12.3 KB
html2text {}
    
Offset 2764, 15 lines modifiedOffset 2764, 15 lines modified
2764 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,2764 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,
2765 ············Req-7.1,·SRG-OS-000480-GPOS-00227,·1.5.22765 ············Req-7.1,·SRG-OS-000480-GPOS-00227,·1.5.2
2766 Remediation_Shell_script_⇲2766 Remediation_Shell_script_⇲
2767 Complexity:·low2767 Complexity:·low
2768 Disruption:·low2768 Disruption:·low
2769 Strategy:···configure2769 Strategy:···configure
2770 #·Remediation·is·applicable·only·in·certain·platforms2770 #·Remediation·is·applicable·only·in·certain·platforms
2771 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/2771 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/
2772 run/.containerenv·];·};·then2772 run/.containerenv·];·};·then
  
2773 chgrp·0·/boot/grub2/grub.cfg2773 chgrp·0·/boot/grub2/grub.cfg
  
2774 else2774 else
2775 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2775 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2776 fi2776 fi
Offset 2797, 16 lines modifiedOffset 2797, 16 lines modified
2797 ··-·no_reboot_needed2797 ··-·no_reboot_needed
  
2798 -·name:·Test·for·existence·/boot/grub2/grub.cfg2798 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2799 ··stat:2799 ··stat:
2800 ····path:·/boot/grub2/grub.cfg2800 ····path:·/boot/grub2/grub.cfg
2801 ··register:·file_exists2801 ··register:·file_exists
2802 ··when:2802 ··when:
2803 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2804 ··-·'"grub2-common"·in·ansible_facts.packages'2803 ··-·'"grub2-common"·in·ansible_facts.packages'
 2804 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2805 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2805 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2806 ··tags:2806 ··tags:
2807 ··-·CJIS-5.5.2.22807 ··-·CJIS-5.5.2.2
2808 ··-·NIST-800-171-3.4.52808 ··-·NIST-800-171-3.4.5
2809 ··-·NIST-800-53-AC-6(1)2809 ··-·NIST-800-53-AC-6(1)
2810 ··-·NIST-800-53-CM-6(a)2810 ··-·NIST-800-53-CM-6(a)
2811 ··-·PCI-DSS-Req-7.12811 ··-·PCI-DSS-Req-7.1
Offset 2818, 16 lines modifiedOffset 2818, 16 lines modified
2818 ··-·no_reboot_needed2818 ··-·no_reboot_needed
  
2819 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg2819 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
2820 ··file:2820 ··file:
2821 ····path:·/boot/grub2/grub.cfg2821 ····path:·/boot/grub2/grub.cfg
2822 ····group:·'0'2822 ····group:·'0'
2823 ··when:2823 ··when:
2824 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2825 ··-·'"grub2-common"·in·ansible_facts.packages'2824 ··-·'"grub2-common"·in·ansible_facts.packages'
 2825 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2826 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2826 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2827 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists2827 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
2828 ··tags:2828 ··tags:
2829 ··-·CJIS-5.5.2.22829 ··-·CJIS-5.5.2.2
2830 ··-·NIST-800-171-3.4.52830 ··-·NIST-800-171-3.4.5
2831 ··-·NIST-800-53-AC-6(1)2831 ··-·NIST-800-53-AC-6(1)
2832 ··-·NIST-800-53-CM-6(a)2832 ··-·NIST-800-53-CM-6(a)
Offset 2853, 15 lines modifiedOffset 2853, 15 lines modified
2853 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,2853 ············A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,
2854 ············Req-7.1,·1.5.22854 ············Req-7.1,·1.5.2
2855 Remediation_Shell_script_⇲2855 Remediation_Shell_script_⇲
2856 Complexity:·low2856 Complexity:·low
2857 Disruption:·low2857 Disruption:·low
2858 Strategy:···configure2858 Strategy:···configure
2859 #·Remediation·is·applicable·only·in·certain·platforms2859 #·Remediation·is·applicable·only·in·certain·platforms
2860 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/2860 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/
2861 run/.containerenv·];·};·then2861 run/.containerenv·];·};·then
  
2862 chown·0·/boot/grub2/grub.cfg2862 chown·0·/boot/grub2/grub.cfg
  
2863 else2863 else
2864 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2864 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2865 fi2865 fi
Offset 2886, 16 lines modifiedOffset 2886, 16 lines modified
2886 ··-·no_reboot_needed2886 ··-·no_reboot_needed
  
2887 -·name:·Test·for·existence·/boot/grub2/grub.cfg2887 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2888 ··stat:2888 ··stat:
2889 ····path:·/boot/grub2/grub.cfg2889 ····path:·/boot/grub2/grub.cfg
2890 ··register:·file_exists2890 ··register:·file_exists
2891 ··when:2891 ··when:
2892 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2893 ··-·'"grub2-common"·in·ansible_facts.packages'2892 ··-·'"grub2-common"·in·ansible_facts.packages'
 2893 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2894 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2894 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2895 ··tags:2895 ··tags:
2896 ··-·CJIS-5.5.2.22896 ··-·CJIS-5.5.2.2
2897 ··-·NIST-800-171-3.4.52897 ··-·NIST-800-171-3.4.5
2898 ··-·NIST-800-53-AC-6(1)2898 ··-·NIST-800-53-AC-6(1)
2899 ··-·NIST-800-53-CM-6(a)2899 ··-·NIST-800-53-CM-6(a)
2900 ··-·PCI-DSS-Req-7.12900 ··-·PCI-DSS-Req-7.1
Offset 2907, 16 lines modifiedOffset 2907, 16 lines modified
2907 ··-·no_reboot_needed2907 ··-·no_reboot_needed
  
2908 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg2908 -·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
2909 ··file:2909 ··file:
2910 ····path:·/boot/grub2/grub.cfg2910 ····path:·/boot/grub2/grub.cfg
2911 ····owner:·'0'2911 ····owner:·'0'
2912 ··when:2912 ··when:
2913 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2914 ··-·'"grub2-common"·in·ansible_facts.packages'2913 ··-·'"grub2-common"·in·ansible_facts.packages'
 2914 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2915 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2915 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2916 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists2916 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
2917 ··tags:2917 ··tags:
2918 ··-·CJIS-5.5.2.22918 ··-·CJIS-5.5.2.2
2919 ··-·NIST-800-171-3.4.52919 ··-·NIST-800-171-3.4.5
2920 ··-·NIST-800-53-AC-6(1)2920 ··-·NIST-800-53-AC-6(1)
2921 ··-·NIST-800-53-CM-6(a)2921 ··-·NIST-800-53-CM-6(a)
Offset 2942, 15 lines modifiedOffset 2942, 15 lines modified
2942 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),2942 ············A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),
2943 ············PR.AC-4,·PR.DS-5,·1.5.22943 ············PR.AC-4,·PR.DS-5,·1.5.2
2944 Remediation_Shell_script_⇲2944 Remediation_Shell_script_⇲
2945 Complexity:·low2945 Complexity:·low
2946 Disruption:·low2946 Disruption:·low
2947 Strategy:···configure2947 Strategy:···configure
2948 #·Remediation·is·applicable·only·in·certain·platforms2948 #·Remediation·is·applicable·only·in·certain·platforms
2949 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/2949 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/
2950 run/.containerenv·];·};·then2950 run/.containerenv·];·};·then
  
2951 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub2/grub.cfg2951 chmod·u-xs,g-xwrs,o-xwrt·/boot/grub2/grub.cfg
  
2952 else2952 else
2953 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2953 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2954 fi2954 fi
Offset 2973, 16 lines modifiedOffset 2973, 16 lines modified
2973 ··-·no_reboot_needed2973 ··-·no_reboot_needed
  
2974 -·name:·Test·for·existence·/boot/grub2/grub.cfg2974 -·name:·Test·for·existence·/boot/grub2/grub.cfg
2975 ··stat:2975 ··stat:
2976 ····path:·/boot/grub2/grub.cfg2976 ····path:·/boot/grub2/grub.cfg
2977 ··register:·file_exists2977 ··register:·file_exists
2978 ··when:2978 ··when:
Max diff block lines reached; 7877/12521 bytes (62.91%) of diff not shown.
2.99 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-standard.html
    
Offset 22916, 20 lines modifiedOffset 22916, 20 lines modified
00059830:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00059830:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00059840:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00059840:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00059850:·643d·2269·646d·3134·3333·3722·3e3c·7072··d="idm14337"><pr00059850:·643d·2269·646d·3134·3333·3722·3e3c·7072··d="idm14337"><pr
00059860:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi00059860:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
00059870:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica00059870:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
00059880:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert00059880:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
00059890:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if00059890:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
000598a0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
000598b0:·6175·6469·7420·2661·6d70·3b26·616d·703b··audit·&amp;&amp; 
000598c0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker000598a0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
000598d0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;000598b0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
000598e0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co000598c0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
000598f0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th000598d0:·6e74·6169·6e65·7265·6e76·205d·2026·616d··ntainerenv·]·&am
 000598e0:·703b·2661·6d70·3b20·7270·6d20·2d2d·7175··p;&amp;·rpm·--qu
 000598f0:·6965·7420·2d71·2061·7564·6974·3b20·7468··iet·-q·audit;·th
00059900:·656e·0a0a·2320·4669·7273·7420·7065·7266··en..#·First·perf00059900:·656e·0a0a·2320·4669·7273·7420·7065·7266··en..#·First·perf
00059910:·6f72·6d20·7468·6520·7265·6d65·6469·6174··orm·the·remediat00059910:·6f72·6d20·7468·6520·7265·6d65·6469·6174··orm·the·remediat
00059920:·696f·6e20·6f66·2074·6865·2073·7973·6361··ion·of·the·sysca00059920:·696f·6e20·6f66·2074·6865·2073·7973·6361··ion·of·the·sysca
00059930:·6c6c·2072·756c·650a·2320·5265·7472·6965··ll·rule.#·Retrie00059930:·6c6c·2072·756c·650a·2320·5265·7472·6965··ll·rule.#·Retrie
00059940:·7665·2068·6172·6477·6172·6520·6172·6368··ve·hardware·arch00059940:·7665·2068·6172·6477·6172·6520·6172·6368··ve·hardware·arch
00059950:·6974·6563·7475·7265·206f·6620·7468·6520··itecture·of·the·00059950:·6974·6563·7475·7265·206f·6620·7468·6520··itecture·of·the·
00059960:·756e·6465·726c·7969·6e67·2073·7973·7465··underlying·syste00059960:·756e·6465·726c·7969·6e67·2073·7973·7465··underlying·syste
1.09 KB
html2text {}
    
Offset 943, 15 lines modifiedOffset 943, 15 lines modified
943 ············4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,943 ············4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,
944 ············A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,944 ············A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,
945 ············A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),945 ············A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),
946 ············AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,946 ············AU-12(c),·AC-6(9),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,
947 ············PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·Req-10.2.7947 ············PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·Req-10.2.7
948 Remediation_Shell_script_⇲948 Remediation_Shell_script_⇲
949 #·Remediation·is·applicable·only·in·certain·platforms949 #·Remediation·is·applicable·only·in·certain·platforms
950 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then950 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
951 #·First·perform·the·remediation·of·the·syscall·rule951 #·First·perform·the·remediation·of·the·syscall·rule
952 #·Retrieve·hardware·architecture·of·the·underlying·system952 #·Retrieve·hardware·architecture·of·the·underlying·system
953 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>953 #·Note:·32-bit·and·64-bit·kernel·syscall·numbers·not·always·line·up·=>
954 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence954 #·······it's·required·on·a·64-bit·system·to·check·also·for·the·presence
955 #·······of·32-bit's·equivalent·of·the·corresponding·rule.955 #·······of·32-bit's·equivalent·of·the·corresponding·rule.
956 #·······(See·`man·7·audit.rules`·for·details·)956 #·······(See·`man·7·audit.rules`·for·details·)
683 KB
./usr/share/doc/ssg-nondebian/ssg-centos7-guide-pci-dss.html
    
Offset 17292, 116 lines modifiedOffset 17292, 116 lines modified
000438b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="000438b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
000438c0:·2369·646d·3135·3139·2220·7461·6269·6e64··#idm1519"·tabind000438c0:·2369·646d·3135·3139·2220·7461·6269·6e64··#idm1519"·tabind
000438d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but000438d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
000438e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand000438e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
000438f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title000438f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00043900:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00043900:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00043910:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00043910:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00043920:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac00043920:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
00043930:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...00043930:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
00043940:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00043940:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
00043950:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00043950:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
00043960:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00043960:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
00043970:·2269·646d·3135·3139·223e·3c74·6162·6c65··"idm1519"><table00043970:·646d·3135·3139·223e·3c74·6162·6c65·2063··dm1519"><table·c
00043980:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00043980:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
00043990:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00043990:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
000439a0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table000439a0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
000439b0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>000439b0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
000439c0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<000439c0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
000439d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>000439d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
000439e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis000439e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
000439f0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td000439f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
00043a00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00043a00:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00043a10:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<00043a10:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00043a20:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</00043a20:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
00043a30:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>00043a30:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
00043a40:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
00043a50:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<00043a40:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 00043a50:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 00043a60:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 00043a70:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 00043a80:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 00043a90:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 00043aa0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 00043ab0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 00043ac0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 00043ad0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 00043ae0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 00043af0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 00043b00:·646d·3135·3230·2220·7461·6269·6e64·6578··dm1520"·tabindex
 00043b10:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 00043b20:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 00043b30:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 00043b40:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 00043b50:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00043b60:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 00043b70:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 00043b80:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00043b90:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00043ba0:·6c61·7073·6522·2069·643d·2269·646d·3135··lapse"·id="idm15
 00043bb0:·3230·223e·3c74·6162·6c65·2063·6c61·7373··20"><table·class
 00043bc0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00043bd0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00043be0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00043bf0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00043c00:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 00043c10:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00043c20:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00043c30:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 00043c40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00043c50:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 00043c60:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 00043c70:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00043c80:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 00043c90:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 00043ca0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 00043cb0:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
 00043cc0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
 00043cd0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
 00043ce0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
 00043cf0:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.
 00043d00:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 00043d10:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 00043d20:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta
 00043d30:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 00043d40:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 00043d50:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 00043d60:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 00043d70:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 00043d80:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
00043a60:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di00043d90:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
00043a70:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·00043da0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
00043a80:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat00043db0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
00043a90:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap00043dc0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
00043aa0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00043dd0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00043ab0:·2223·6964·6d31·3532·3022·2074·6162·696e··"#idm1520"·tabin00043de0:·2223·6964·6d31·3532·3122·2074·6162·696e··"#idm1521"·tabin
00043ac0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00043df0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00043ad0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00043e00:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00043ae0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00043e10:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00043af0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00043e20:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00043b00:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00043e30:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00043b10:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup00043e40:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
00043b20:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<00043e50:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
00043b30:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00043e60:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
00043b40:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00043e70:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
00043b50:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00043e80:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
00043b60:·6964·6d31·3532·3022·3e3c·7461·626c·6520··idm1520"><table·00043e90:·3d22·6964·6d31·3532·3122·3e3c·7461·626c··="idm1521"><tabl
00043b70:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab00043ea0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
00043b80:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00043eb0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
00043b90:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00043ec0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
00043ba0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00043ed0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
00043bb0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00043ee0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00043bc0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00043ef0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00043bd0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00043f00:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
00043be0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00043f10:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
00043bf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00043f20:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00043c00:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</00043f30:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
00043c10:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t00043f40:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
00043c20:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><00043f50:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00043f60:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 00043f70:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
00043c30:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ 
00043c40:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
00043c50:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
00043c60:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
00043c70:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
00043c80:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
00043c90:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
00043ca0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00043cb0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00043cc0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00043cd0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00043ce0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00043cf0:·6964·6d31·3532·3122·2074·6162·696e·6465··idm1521"·tabinde 
00043d00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00043d10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00043d20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00043d30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
Max diff block lines reached; 490046/504702 bytes (97.10%) of diff not shown.
190 KB
html2text {}
    
Offset 408, 20 lines modifiedOffset 408, 14 lines modified
408 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed408 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
409 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251705r861078_rule409 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251705r861078_rule
410 Remediation_OSBuild_Blueprint_snippet_⇲410 Remediation_OSBuild_Blueprint_snippet_⇲
  
411 [[packages]]411 [[packages]]
412 name·=·"aide"412 name·=·"aide"
413 version·=·"*"413 version·=·"*"
414 Remediation_Anaconda_snippet_⇲ 
415 Complexity:·low 
416 Disruption:·low 
417 Strategy:···enable 
  
418 package·--add=aide 
419 Remediation_Puppet_snippet_⇲414 Remediation_Puppet_snippet_⇲
420 Complexity:·low415 Complexity:·low
421 Disruption:·low416 Disruption:·low
422 Strategy:···enable417 Strategy:···enable
423 include·install_aide418 include·install_aide
  
424 class·install_aide·{419 class·install_aide·{
Offset 439, 14 lines modifiedOffset 433, 20 lines modified
439 if·!·rpm·-q·--quiet·"aide"·;·then433 if·!·rpm·-q·--quiet·"aide"·;·then
440 ····yum·install·-y·"aide"434 ····yum·install·-y·"aide"
441 fi435 fi
  
442 else436 else
443 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'437 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
444 fi438 fi
 439 Remediation_Anaconda_snippet_⇲
 440 Complexity:·low
 441 Disruption:·low
 442 Strategy:···enable
  
 443 package·--add=aide
445 Remediation_Ansible_snippet_⇲444 Remediation_Ansible_snippet_⇲
446 Complexity:·low445 Complexity:·low
447 Disruption:·low446 Disruption:·low
448 Strategy:···enable447 Strategy:···enable
449 -·name:·Ensure·aide·is·installed448 -·name:·Ensure·aide·is·installed
450 ··package:449 ··package:
451 ····name:·aide450 ····name:·aide
Offset 5676, 17 lines modifiedOffset 5676, 14 lines modified
5676 ····*·https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/system-level_authentication_guide/smartcards#authconfig-smartcards5676 ····*·https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/system-level_authentication_guide/smartcards#authconfig-smartcards
5677 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:5677 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:
5678 ····*·https://access.redhat.com/solutions/822735678 ····*·https://access.redhat.com/solutions/82273
5679 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.5679 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.
5680 Severity: ················medium5680 Severity: ················medium
5681 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth5681 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth
5682 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·SV-204441r818813_rule5682 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·SV-204441r818813_rule
5683 Remediation_Anaconda_snippet_⇲ 
  
5684 package·--add=pam_pkcs11·--add=esc 
5685 Remediation_Shell_script_⇲5683 Remediation_Shell_script_⇲
5686 #·Remediation·is·applicable·only·in·certain·platforms5684 #·Remediation·is·applicable·only·in·certain·platforms
5687 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·!·grep·-q·s390x·/proc/sys/kernel/osrelease;·};·then5685 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·!·grep·-q·s390x·/proc/sys/kernel/osrelease;·};·then
  
5688 #·Install·required·packages5686 #·Install·required·packages
5689 if·!·rpm·-q·--quiet·"esc"·;·then5687 if·!·rpm·-q·--quiet·"esc"·;·then
5690 ····yum·install·-y·"esc"5688 ····yum·install·-y·"esc"
Offset 5791, 14 lines modifiedOffset 5788, 17 lines modified
5791 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,5788 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,
5792 #·which·does·not·contain·it·yet5789 #·which·does·not·contain·it·yet
5793 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"5790 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"
  
5794 else5791 else
5795 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5792 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5796 fi5793 fi
 5794 Remediation_Anaconda_snippet_⇲
  
 5795 package·--add=pam_pkcs11·--add=esc
5797 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules5796 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules
5798 [ref]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.5797 [ref]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.
5799 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules5798 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules
5800 [ref]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:5799 [ref]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:
5801 $·sudo·chage·-I·NUM_DAYS·USER5800 $·sudo·chage·-I·NUM_DAYS·USER
5802 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.5801 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.
5803 Warning: ·This·will·only·apply·to·newly·created·accounts5802 Warning: ·This·will·only·apply·to·newly·created·accounts
Offset 6262, 15 lines modifiedOffset 6262, 15 lines modified
6262 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.6262 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
6263 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.6263 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
6264 Severity: ················medium6264 Severity: ················medium
6265 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod6265 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
6266 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204521r809772_rule6266 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204521r809772_rule
6267 Remediation_Shell_script_⇲6267 Remediation_Shell_script_⇲
6268 #·Remediation·is·applicable·only·in·certain·platforms6268 #·Remediation·is·applicable·only·in·certain·platforms
6269 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then6269 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
6270 #·First·perform·the·remediation·of·the·syscall·rule6270 #·First·perform·the·remediation·of·the·syscall·rule
6271 #·Retrieve·hardware·architecture·of·the·underlying·system6271 #·Retrieve·hardware·architecture·of·the·underlying·system
6272 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6272 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6273 for·ARCH·in·"${RULE_ARCHS[@]}"6273 for·ARCH·in·"${RULE_ARCHS[@]}"
6274 do6274 do
Offset 6617, 16 lines modifiedOffset 6617, 16 lines modified
6617 ··-·reboot_required6617 ··-·reboot_required
6618 ··-·restrict_strategy6618 ··-·restrict_strategy
  
6619 -·name:·Set·architecture·for·audit·chmod·tasks6619 -·name:·Set·architecture·for·audit·chmod·tasks
6620 ··set_fact:6620 ··set_fact:
6621 ····audit_arch:·b646621 ····audit_arch:·b64
6622 ··when:6622 ··when:
6623 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6624 ··-·'"audit"·in·ansible_facts.packages'6623 ··-·'"audit"·in·ansible_facts.packages'
 6624 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6625 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6625 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6626 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6626 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6627 ··tags:6627 ··tags:
6628 ··-·CJIS-5.4.1.16628 ··-·CJIS-5.4.1.1
6629 ··-·DISA-STIG-RHEL-07-0304106629 ··-·DISA-STIG-RHEL-07-030410
6630 ··-·NIST-800-171-3.1.76630 ··-·NIST-800-171-3.1.7
6631 ··-·NIST-800-53-AU-12(c)6631 ··-·NIST-800-53-AU-12(c)
Offset 6763, 16 lines modifiedOffset 6763, 16 lines modified
6763 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006763 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6764 ········-F·auid!=unset·-F·key=perm_mod6764 ········-F·auid!=unset·-F·key=perm_mod
6765 ······create:·true6765 ······create:·true
6766 ······mode:·o-rwx6766 ······mode:·o-rwx
6767 ······state:·present6767 ······state:·present
6768 ····when:·syscalls_found·|·length·==·06768 ····when:·syscalls_found·|·length·==·0
6769 ··when:6769 ··when:
6770 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6771 ··-·'"audit"·in·ansible_facts.packages'6770 ··-·'"audit"·in·ansible_facts.packages'
 6771 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6772 ··tags:6772 ··tags:
6773 ··-·CJIS-5.4.1.16773 ··-·CJIS-5.4.1.1
6774 ··-·DISA-STIG-RHEL-07-0304106774 ··-·DISA-STIG-RHEL-07-030410
6775 ··-·NIST-800-171-3.1.76775 ··-·NIST-800-171-3.1.7
6776 ··-·NIST-800-53-AU-12(c)6776 ··-·NIST-800-53-AU-12(c)
Max diff block lines reached; 184702/194301 bytes (95.06%) of diff not shown.
570 KB
./usr/share/doc/ssg-nondebian/ssg-centos7-guide-standard.html
    
Offset 23921, 21 lines modifiedOffset 23921, 21 lines modified
0005d700:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0005d700:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0005d710:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0005d710:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0005d720:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10005d720:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
0005d730:·3731·3332·223e·3c70·7265·3e3c·636f·6465··7132"><pre><code0005d730:·3731·3332·223e·3c70·7265·3e3c·636f·6465··7132"><pre><code
0005d740:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i0005d740:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
0005d750:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl0005d750:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
0005d760:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla0005d760:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
0005d770:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f0005d770:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
0005d780:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&0005d780:·7175·6965·7420·2d71·2061·7564·6974·2026··quiet·-q·audit·&
0005d790:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f0005d790:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 0005d7a0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 0005d7b0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
0005d7a0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container0005d7c0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
0005d7b0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0005d7c0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0005d7d0:·6175·6469·743b·2074·6865·6e0a·0a23·2046··audit;·then..#·F0005d7d0:·656e·7620·5d3b·2074·6865·6e0a·0a23·2046··env·];·then..#·F
0005d7e0:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the0005d7e0:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the
0005d7f0:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·0005d7f0:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·
0005d800:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule0005d800:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule
0005d810:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard0005d810:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard
0005d820:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur0005d820:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur
0005d830:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly0005d830:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly
0005d840:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(0005d840:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(
Offset 24815, 23 lines modifiedOffset 24815, 23 lines modified
00060ee0:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_00060ee0:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
00060ef0:·7374·7261·7465·6779·0a0a·2d20·6e61·6d65··strategy..-·name00060ef0:·7374·7261·7465·6779·0a0a·2d20·6e61·6d65··strategy..-·name
00060f00:·3a20·5365·7420·6172·6368·6974·6563·7475··:·Set·architectu00060f00:·3a20·5365·7420·6172·6368·6974·6563·7475··:·Set·architectu
00060f10:·7265·2066·6f72·2061·7564·6974·2063·686d··re·for·audit·chm00060f10:·7265·2066·6f72·2061·7564·6974·2063·686d··re·for·audit·chm
00060f20:·6f64·2074·6173·6b73·0a20·2073·6574·5f66··od·tasks.··set_f00060f20:·6f64·2074·6173·6b73·0a20·2073·6574·5f66··od·tasks.··set_f
00060f30:·6163·743a·0a20·2020·2061·7564·6974·5f61··act:.····audit_a00060f30:·6163·743a·0a20·2020·2061·7564·6974·5f61··act:.····audit_a
00060f40:·7263·683a·2062·3634·0a20·2077·6865·6e3a··rch:·b64.··when:00060f40:·7263·683a·2062·3634·0a20·2077·6865·6e3a··rch:·b64.··when:
00060f50:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
00060f60:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
00060f70:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
00060f80:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
00060f90:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
00060fa0:·6f6e·7461·696e·6572·225d·0a20·202d·2027··ontainer"].··-·' 
00060fb0:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib 
00060fc0:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package00060f50:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 00060f60:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 00060f70:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans
 00060f80:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 00060f90:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 00060fa0:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 00060fb0:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 00060fc0:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
00060fd0:·7327·0a20·202d·2061·6e73·6962·6c65·5f61··s'.··-·ansible_a00060fd0:·225d·0a20·202d·2061·6e73·6962·6c65·5f61··"].··-·ansible_a
00060fe0:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"00060fe0:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"
00060ff0:·6161·7263·6836·3422·206f·7220·616e·7369··aarch64"·or·ansi00060ff0:·6161·7263·6836·3422·206f·7220·616e·7369··aarch64"·or·ansi
00061000:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture00061000:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
00061010:·203d·3d20·2270·7063·3634·2220·6f72·2061···==·"ppc64"·or·a00061010:·203d·3d20·2270·7063·3634·2220·6f72·2061···==·"ppc64"·or·a
00061020:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect00061020:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
00061030:·7572·650a·2020·2020·3d3d·2022·7070·6336··ure.····==·"ppc600061030:·7572·650a·2020·2020·3d3d·2022·7070·6336··ure.····==·"ppc6
00061040:·346c·6522·206f·7220·616e·7369·626c·655f··4le"·or·ansible_00061040:·346c·6522·206f·7220·616e·7369·626c·655f··4le"·or·ansible_
Offset 25138, 23 lines modifiedOffset 25138, 23 lines modified
00062310:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····00062310:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····
00062320:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··00062320:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··
00062330:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.00062330:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.
00062340:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre00062340:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre
00062350:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s00062350:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s
00062360:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·00062360:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·
00062370:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh00062370:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh
00062380:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_ 
00062390:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
000623a0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
000623b0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
000623c0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
000623d0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].·· 
000623e0:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an 
000623f0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack00062380:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit"
 00062390:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 000623a0:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·
 000623b0:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 000623c0:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 000623d0:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 000623e0:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 000623f0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
00062400:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··00062400:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··
00062410:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·00062410:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
00062420:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE00062420:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE
00062430:·4c2d·3037·2d30·3330·3431·300a·2020·2d20··L-07-030410.··-·00062430:·4c2d·3037·2d30·3330·3431·300a·2020·2d20··L-07-030410.··-·
00062440:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.100062440:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
00062450:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-00062450:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-
00062460:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·00062460:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·
00062470:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-200062470:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-2
Offset 25450, 22 lines modifiedOffset 25450, 22 lines modified
00063690:·5f6d·6f64·0a20·2020·2020·2063·7265·6174··_mod.······creat00063690:·5f6d·6f64·0a20·2020·2020·2063·7265·6174··_mod.······creat
000636a0:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo000636a0:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo
000636b0:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······000636b0:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······
000636c0:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·000636c0:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
000636d0:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall000636d0:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall
000636e0:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length000636e0:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length
000636f0:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··000636f0:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··
00063700:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
00063710:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
00063720:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
00063730:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
00063740:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont 
00063750:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au 
00063760:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
00063770:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.00063700:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 00063710:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 00063720:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
 00063730:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 00063740:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 00063750:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 00063760:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 00063770:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
00063780:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=00063780:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=
00063790:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.00063790:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.
000637a0:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1000637a0:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1
000637b0:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R000637b0:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R
000637c0:·4845·4c2d·3037·2d30·3330·3431·300a·2020··HEL-07-030410.··000637c0:·4845·4c2d·3037·2d30·3330·3431·300a·2020··HEL-07-030410.··
000637d0:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3000637d0:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
000637e0:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80000637e0:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80
Offset 26415, 21 lines modifiedOffset 26415, 21 lines modified
000672e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel000672e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
000672f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap000672f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00067300:·7365·2220·6964·3d22·6964·6d31·3732·3930··se"·id="idm1729000067300:·7365·2220·6964·3d22·6964·6d31·3732·3930··se"·id="idm17290
00067310:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R00067310:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R
00067320:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap00067320:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
00067330:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in00067330:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
00067340:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor00067340:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 00067350:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 00067360:·7420·2d71·2061·7564·6974·2026·616d·703b··t·-q·audit·&amp;
00067350:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d00067370:·2661·6d70·3b20·5b20·2120·2d66·202f·2e64··&amp;·[·!·-f·/.d
00067360:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;00067380:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;
Max diff block lines reached; 415343/425340 bytes (97.65%) of diff not shown.
155 KB
html2text {}
    
Offset 1075, 15 lines modifiedOffset 1075, 15 lines modified
1075 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1075 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1076 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1076 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1077 Severity: ················medium1077 Severity: ················medium
1078 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1078 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1079 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204521r809772_rule1079 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204521r809772_rule
1080 Remediation_Shell_script_⇲1080 Remediation_Shell_script_⇲
1081 #·Remediation·is·applicable·only·in·certain·platforms1081 #·Remediation·is·applicable·only·in·certain·platforms
1082 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1082 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1083 #·First·perform·the·remediation·of·the·syscall·rule1083 #·First·perform·the·remediation·of·the·syscall·rule
1084 #·Retrieve·hardware·architecture·of·the·underlying·system1084 #·Retrieve·hardware·architecture·of·the·underlying·system
1085 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1085 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1086 for·ARCH·in·"${RULE_ARCHS[@]}"1086 for·ARCH·in·"${RULE_ARCHS[@]}"
1087 do1087 do
Offset 1430, 16 lines modifiedOffset 1430, 16 lines modified
1430 ··-·reboot_required1430 ··-·reboot_required
1431 ··-·restrict_strategy1431 ··-·restrict_strategy
  
1432 -·name:·Set·architecture·for·audit·chmod·tasks1432 -·name:·Set·architecture·for·audit·chmod·tasks
1433 ··set_fact:1433 ··set_fact:
1434 ····audit_arch:·b641434 ····audit_arch:·b64
1435 ··when:1435 ··when:
1436 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1437 ··-·'"audit"·in·ansible_facts.packages'1436 ··-·'"audit"·in·ansible_facts.packages'
 1437 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1438 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1438 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1439 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1439 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1440 ··tags:1440 ··tags:
1441 ··-·CJIS-5.4.1.11441 ··-·CJIS-5.4.1.1
1442 ··-·DISA-STIG-RHEL-07-0304101442 ··-·DISA-STIG-RHEL-07-030410
1443 ··-·NIST-800-171-3.1.71443 ··-·NIST-800-171-3.1.7
1444 ··-·NIST-800-53-AU-12(c)1444 ··-·NIST-800-53-AU-12(c)
Offset 1576, 16 lines modifiedOffset 1576, 16 lines modified
1576 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001576 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1577 ········-F·auid!=unset·-F·key=perm_mod1577 ········-F·auid!=unset·-F·key=perm_mod
1578 ······create:·true1578 ······create:·true
1579 ······mode:·o-rwx1579 ······mode:·o-rwx
1580 ······state:·present1580 ······state:·present
1581 ····when:·syscalls_found·|·length·==·01581 ····when:·syscalls_found·|·length·==·0
1582 ··when:1582 ··when:
1583 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1584 ··-·'"audit"·in·ansible_facts.packages'1583 ··-·'"audit"·in·ansible_facts.packages'
 1584 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1585 ··tags:1585 ··tags:
1586 ··-·CJIS-5.4.1.11586 ··-·CJIS-5.4.1.1
1587 ··-·DISA-STIG-RHEL-07-0304101587 ··-·DISA-STIG-RHEL-07-030410
1588 ··-·NIST-800-171-3.1.71588 ··-·NIST-800-171-3.1.7
1589 ··-·NIST-800-53-AU-12(c)1589 ··-·NIST-800-53-AU-12(c)
1590 ··-·NIST-800-53-AU-2(d)1590 ··-·NIST-800-53-AU-2(d)
1591 ··-·NIST-800-53-CM-6(a)1591 ··-·NIST-800-53-CM-6(a)
Offset 1720, 16 lines modifiedOffset 1720, 16 lines modified
1720 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001720 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1721 ········-F·auid!=unset·-F·key=perm_mod1721 ········-F·auid!=unset·-F·key=perm_mod
1722 ······create:·true1722 ······create:·true
1723 ······mode:·o-rwx1723 ······mode:·o-rwx
1724 ······state:·present1724 ······state:·present
1725 ····when:·syscalls_found·|·length·==·01725 ····when:·syscalls_found·|·length·==·0
1726 ··when:1726 ··when:
1727 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1728 ··-·'"audit"·in·ansible_facts.packages'1727 ··-·'"audit"·in·ansible_facts.packages'
 1728 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1729 ··-·audit_arch·==·"b64"1729 ··-·audit_arch·==·"b64"
1730 ··tags:1730 ··tags:
1731 ··-·CJIS-5.4.1.11731 ··-·CJIS-5.4.1.1
1732 ··-·DISA-STIG-RHEL-07-0304101732 ··-·DISA-STIG-RHEL-07-030410
1733 ··-·NIST-800-171-3.1.71733 ··-·NIST-800-171-3.1.7
1734 ··-·NIST-800-53-AU-12(c)1734 ··-·NIST-800-53-AU-12(c)
1735 ··-·NIST-800-53-AU-2(d)1735 ··-·NIST-800-53-AU-2(d)
Offset 1753, 15 lines modifiedOffset 1753, 15 lines modified
1753 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1753 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1754 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1754 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1755 Severity: ················medium1755 Severity: ················medium
1756 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown1756 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
1757 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204517r809570_rule1757 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204517r809570_rule
1758 Remediation_Shell_script_⇲1758 Remediation_Shell_script_⇲
1759 #·Remediation·is·applicable·only·in·certain·platforms1759 #·Remediation·is·applicable·only·in·certain·platforms
1760 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1760 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1761 #·First·perform·the·remediation·of·the·syscall·rule1761 #·First·perform·the·remediation·of·the·syscall·rule
1762 #·Retrieve·hardware·architecture·of·the·underlying·system1762 #·Retrieve·hardware·architecture·of·the·underlying·system
1763 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1763 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1764 for·ARCH·in·"${RULE_ARCHS[@]}"1764 for·ARCH·in·"${RULE_ARCHS[@]}"
1765 do1765 do
Offset 2108, 16 lines modifiedOffset 2108, 16 lines modified
2108 ··-·reboot_required2108 ··-·reboot_required
2109 ··-·restrict_strategy2109 ··-·restrict_strategy
  
2110 -·name:·Set·architecture·for·audit·chown·tasks2110 -·name:·Set·architecture·for·audit·chown·tasks
2111 ··set_fact:2111 ··set_fact:
2112 ····audit_arch:·b642112 ····audit_arch:·b64
2113 ··when:2113 ··when:
2114 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2115 ··-·'"audit"·in·ansible_facts.packages'2114 ··-·'"audit"·in·ansible_facts.packages'
 2115 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2116 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2116 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2117 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2117 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2118 ··tags:2118 ··tags:
2119 ··-·CJIS-5.4.1.12119 ··-·CJIS-5.4.1.1
2120 ··-·DISA-STIG-RHEL-07-0303702120 ··-·DISA-STIG-RHEL-07-030370
2121 ··-·NIST-800-171-3.1.72121 ··-·NIST-800-171-3.1.7
2122 ··-·NIST-800-53-AU-12(c)2122 ··-·NIST-800-53-AU-12(c)
Offset 2256, 16 lines modifiedOffset 2256, 16 lines modified
2256 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002256 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2257 ········-F·auid!=unset·-F·key=perm_mod2257 ········-F·auid!=unset·-F·key=perm_mod
2258 ······create:·true2258 ······create:·true
2259 ······mode:·o-rwx2259 ······mode:·o-rwx
2260 ······state:·present2260 ······state:·present
2261 ····when:·syscalls_found·|·length·==·02261 ····when:·syscalls_found·|·length·==·0
2262 ··when:2262 ··when:
2263 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2264 ··-·'"audit"·in·ansible_facts.packages'2263 ··-·'"audit"·in·ansible_facts.packages'
 2264 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2265 ··tags:2265 ··tags:
2266 ··-·CJIS-5.4.1.12266 ··-·CJIS-5.4.1.1
2267 ··-·DISA-STIG-RHEL-07-0303702267 ··-·DISA-STIG-RHEL-07-030370
2268 ··-·NIST-800-171-3.1.72268 ··-·NIST-800-171-3.1.7
2269 ··-·NIST-800-53-AU-12(c)2269 ··-·NIST-800-53-AU-12(c)
2270 ··-·NIST-800-53-AU-2(d)2270 ··-·NIST-800-53-AU-2(d)
2271 ··-·NIST-800-53-CM-6(a)2271 ··-·NIST-800-53-CM-6(a)
Offset 2402, 16 lines modifiedOffset 2402, 16 lines modified
2402 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002402 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2403 ········-F·auid!=unset·-F·key=perm_mod2403 ········-F·auid!=unset·-F·key=perm_mod
2404 ······create:·true2404 ······create:·true
2405 ······mode:·o-rwx2405 ······mode:·o-rwx
2406 ······state:·present2406 ······state:·present
Max diff block lines reached; 149334/158313 bytes (94.33%) of diff not shown.
655 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_enhanced.html
    
Offset 15494, 116 lines modifiedOffset 15494, 116 lines modified
0003c850:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003c850:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003c860:·3534·3122·2074·6162·696e·6465·783d·2230··541"·tabindex="00003c860:·3534·3122·2074·6162·696e·6465·783d·2230··541"·tabindex="0
0003c870:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c870:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c880:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c880:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c890:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c890:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c8a0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c8a0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c8b0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c8b0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c8c0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003c8c0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003c8d0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003c8d0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003c8e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003c8e0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003c8f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003c8f0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003c900:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003c900:·6170·7365·2220·6964·3d22·6964·6d38·3534··apse"·id="idm854
0003c910:·3534·3122·3e3c·7461·626c·6520·636c·6173··541"><table·clas0003c910:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=
0003c920:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003c920:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c930:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003c930:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c940:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003c940:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c950:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003c950:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c960:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003c960:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c970:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c970:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c980:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c980:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c990:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c990:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c9a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c9a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c9b0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c9b0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c9c0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c9c0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003c9d0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c9d0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003c9e0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003c9f0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003c9e0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003c9f0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003ca00:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003ca10:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003ca20:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003ca30:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003ca40:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003ca50:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003ca60:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003ca70:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003ca80:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003ca90:·2d74·6172·6765·743d·2223·6964·6d38·3534··-target="#idm854
 0003caa0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
 0003cab0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003cac0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003cad0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003cae0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003caf0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003cb00:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003cb10:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003cb20:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003cb30:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003cb40:·2220·6964·3d22·6964·6d38·3534·3222·3e3c··"·id="idm8542"><
 0003cb50:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003cb60:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003cb70:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003cb80:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003cb90:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003cba0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003cbb0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003cbc0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003cbd0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003cbe0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003cbf0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003cc00:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003cc10:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003cc20:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003cc30:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003cc40:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003cc50:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003cc60:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003cc70:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003cc80:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003cc90:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003cca0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003ccb0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003ccc0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 0003ccd0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003cce0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003ccf0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003cd00:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003cd10:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003cd20:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003ca00:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003cd30:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003ca10:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003cd40:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003ca20:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003cd50:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003ca30:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003cd60:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003ca40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003cd70:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003ca50:·3835·3432·2220·7461·6269·6e64·6578·3d22··8542"·tabindex="0003cd80:·3835·3433·2220·7461·6269·6e64·6578·3d22··8543"·tabindex="
0003ca60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003cd90:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003ca70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003cda0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003ca80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003cdb0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003ca90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003cdc0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003caa0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003cdd0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003cab0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003cde0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003cac0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003cdf0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003cad0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003ce00:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003cae0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003ce10:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003caf0:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm850003ce20:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003cb00:·3432·223e·3c74·6162·6c65·2063·6c61·7373··42"><table·class0003ce30:·3835·3433·223e·3c74·6162·6c65·2063·6c61··8543"><table·cla
0003cb10:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003ce40:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003cb20:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003ce50:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003cb30:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003ce60:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003cb40:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003ce70:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003cb50:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003ce80:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003cb60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003ce90:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003cb70:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003cea0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003cb80:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003ceb0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003cb90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003cec0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003cba0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003ced0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003cbb0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003cee0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003cbc0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003cef0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003cf00:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003cf10:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003cbd0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003cbe0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003cbf0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003cc00:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003cc10:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003cc20:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003cc30:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003cc40:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003cc50:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003cc60:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003cc70:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003cc80:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm85 
0003cc90:·3433·2220·7461·6269·6e64·6578·3d22·3022··43"·tabindex="0" 
0003cca0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003ccb0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003ccc0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003ccd0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 598053/612709 bytes (97.61%) of diff not shown.
56.7 KB
html2text {}
    
Offset 118, 20 lines modifiedOffset 118, 14 lines modified
118 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule118 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
119 References119 References
120 Remediation_OSBuild_Blueprint_snippet_⇲120 Remediation_OSBuild_Blueprint_snippet_⇲
  
121 [[packages]]121 [[packages]]
122 name·=·"aide"122 name·=·"aide"
123 version·=·"*"123 version·=·"*"
124 Remediation_Anaconda_snippet_⇲ 
125 Complexity:·low 
126 Disruption:·low 
127 Strategy:···enable 
  
128 package·--add=aide 
129 Remediation_Puppet_snippet_⇲124 Remediation_Puppet_snippet_⇲
130 Complexity:·low125 Complexity:·low
131 Disruption:·low126 Disruption:·low
132 Strategy:···enable127 Strategy:···enable
133 include·install_aide128 include·install_aide
  
134 class·install_aide·{129 class·install_aide·{
Offset 149, 14 lines modifiedOffset 143, 20 lines modified
149 if·!·rpm·-q·--quiet·"aide"·;·then143 if·!·rpm·-q·--quiet·"aide"·;·then
150 ····yum·install·-y·"aide"144 ····yum·install·-y·"aide"
151 fi145 fi
  
152 else146 else
153 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'147 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
154 fi148 fi
 149 Remediation_Anaconda_snippet_⇲
 150 Complexity:·low
 151 Disruption:·low
 152 Strategy:···enable
  
 153 package·--add=aide
155 Remediation_Ansible_snippet_⇲154 Remediation_Ansible_snippet_⇲
156 Complexity:·low155 Complexity:·low
157 Disruption:·low156 Disruption:·low
158 Strategy:···enable157 Strategy:···enable
159 -·name:·Ensure·aide·is·installed158 -·name:·Ensure·aide·is·installed
160 ··package:159 ··package:
161 ····name:·aide160 ····name:·aide
Offset 463, 20 lines modifiedOffset 463, 14 lines modified
463 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed463 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
464 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1464 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
465 Remediation_OSBuild_Blueprint_snippet_⇲465 Remediation_OSBuild_Blueprint_snippet_⇲
  
466 [[packages]]466 [[packages]]
467 name·=·"sudo"467 name·=·"sudo"
468 version·=·"*"468 version·=·"*"
469 Remediation_Anaconda_snippet_⇲ 
470 Complexity:·low 
471 Disruption:·low 
472 Strategy:···enable 
  
473 package·--add=sudo 
474 Remediation_Puppet_snippet_⇲469 Remediation_Puppet_snippet_⇲
475 Complexity:·low470 Complexity:·low
476 Disruption:·low471 Disruption:·low
477 Strategy:···enable472 Strategy:···enable
478 include·install_sudo473 include·install_sudo
  
479 class·install_sudo·{474 class·install_sudo·{
Offset 494, 14 lines modifiedOffset 488, 20 lines modified
494 if·!·rpm·-q·--quiet·"sudo"·;·then488 if·!·rpm·-q·--quiet·"sudo"·;·then
495 ····yum·install·-y·"sudo"489 ····yum·install·-y·"sudo"
496 fi490 fi
  
497 else491 else
498 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'492 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
499 fi493 fi
 494 Remediation_Anaconda_snippet_⇲
 495 Complexity:·low
 496 Disruption:·low
 497 Strategy:···enable
  
 498 package·--add=sudo
500 Remediation_Ansible_snippet_⇲499 Remediation_Ansible_snippet_⇲
501 Complexity:·low500 Complexity:·low
502 Disruption:·low501 Disruption:·low
503 Strategy:···enable502 Strategy:···enable
504 -·name:·Ensure·sudo·is·installed503 -·name:·Ensure·sudo·is·installed
505 ··package:504 ··package:
506 ····name:·sudo505 ····name:·sudo
Offset 1097, 20 lines modifiedOffset 1097, 14 lines modified
1097 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1097 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1098 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000801098 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1099 Remediation_OSBuild_Blueprint_snippet_⇲1099 Remediation_OSBuild_Blueprint_snippet_⇲
  
1100 [[packages]]1100 [[packages]]
1101 name·=·"dnf-automatic"1101 name·=·"dnf-automatic"
1102 version·=·"*"1102 version·=·"*"
1103 Remediation_Anaconda_snippet_⇲ 
1104 Complexity:·low 
1105 Disruption:·low 
1106 Strategy:···enable 
  
1107 package·--add=dnf-automatic 
1108 Remediation_Puppet_snippet_⇲1103 Remediation_Puppet_snippet_⇲
1109 Complexity:·low1104 Complexity:·low
1110 Disruption:·low1105 Disruption:·low
1111 Strategy:···enable1106 Strategy:···enable
1112 include·install_dnf-automatic1107 include·install_dnf-automatic
  
1113 class·install_dnf-automatic·{1108 class·install_dnf-automatic·{
Offset 1122, 14 lines modifiedOffset 1116, 20 lines modified
1122 Complexity:·low1116 Complexity:·low
1123 Disruption:·low1117 Disruption:·low
1124 Strategy:···enable1118 Strategy:···enable
  
1125 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1119 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1126 ····yum·install·-y·"dnf-automatic"1120 ····yum·install·-y·"dnf-automatic"
1127 fi1121 fi
 1122 Remediation_Anaconda_snippet_⇲
 1123 Complexity:·low
 1124 Disruption:·low
 1125 Strategy:···enable
  
 1126 package·--add=dnf-automatic
1128 Remediation_Ansible_snippet_⇲1127 Remediation_Ansible_snippet_⇲
1129 Complexity:·low1128 Complexity:·low
1130 Disruption:·low1129 Disruption:·low
1131 Strategy:···enable1130 Strategy:···enable
1132 -·name:·Ensure·dnf-automatic·is·installed1131 -·name:·Ensure·dnf-automatic·is·installed
1133 ··package:1132 ··package:
1134 ····name:·dnf-automatic1133 ····name:·dnf-automatic
Offset 8019, 15 lines modifiedOffset 8019, 15 lines modified
8019 Severity: ·medium8019 Severity: ·medium
Max diff block lines reached; 54973/58065 bytes (94.67%) of diff not shown.
712 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_high.html
    
Offset 15493, 116 lines modifiedOffset 15493, 116 lines modified
0003c840:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003c840:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003c850:·3534·3122·2074·6162·696e·6465·783d·2230··541"·tabindex="00003c850:·3534·3122·2074·6162·696e·6465·783d·2230··541"·tabindex="0
0003c860:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c860:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c870:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c870:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c880:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c880:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c890:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c890:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c8a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c8a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c8b0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003c8b0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003c8c0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003c8c0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003c8d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003c8d0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003c8e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003c8e0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003c8f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003c8f0:·6170·7365·2220·6964·3d22·6964·6d38·3534··apse"·id="idm854
0003c900:·3534·3122·3e3c·7461·626c·6520·636c·6173··541"><table·clas0003c900:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=
0003c910:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003c910:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c920:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003c920:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c930:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003c930:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c940:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003c940:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c950:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003c950:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c960:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c960:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c970:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c970:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c980:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c980:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c990:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c990:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c9a0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c9a0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c9b0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c9b0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003c9c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c9c0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003c9d0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003c9e0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003c9d0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003c9e0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003c9f0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003ca00:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003ca10:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003ca20:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003ca30:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003ca40:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003ca50:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003ca60:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003ca70:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003ca80:·2d74·6172·6765·743d·2223·6964·6d38·3534··-target="#idm854
 0003ca90:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
 0003caa0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003cab0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003cac0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003cad0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003cae0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003caf0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003cb00:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003cb10:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003cb20:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003cb30:·2220·6964·3d22·6964·6d38·3534·3222·3e3c··"·id="idm8542"><
 0003cb40:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003cb50:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003cb60:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003cb70:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003cb80:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003cb90:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003cba0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003cbb0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003cbc0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003cbd0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003cbe0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003cbf0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003cc00:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003cc10:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003cc20:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003cc30:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003cc40:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003cc50:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003cc60:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003cc70:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003cc80:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003cc90:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003cca0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003ccb0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 0003ccc0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003ccd0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003cce0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003ccf0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003cd00:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003cd10:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003c9f0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003cd20:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003ca00:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003cd30:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003ca10:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003cd40:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003ca20:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003cd50:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003ca30:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003cd60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003ca40:·3835·3432·2220·7461·6269·6e64·6578·3d22··8542"·tabindex="0003cd70:·3835·3433·2220·7461·6269·6e64·6578·3d22··8543"·tabindex="
0003ca50:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003cd80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003ca60:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003cd90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003ca70:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003cda0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003ca80:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003cdb0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003ca90:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003cdc0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003caa0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003cdd0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003cab0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003cde0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003cac0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003cdf0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003cad0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003ce00:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003cae0:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm850003ce10:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003caf0:·3432·223e·3c74·6162·6c65·2063·6c61·7373··42"><table·class0003ce20:·3835·3433·223e·3c74·6162·6c65·2063·6c61··8543"><table·cla
0003cb00:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003ce30:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003cb10:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003ce40:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003cb20:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003ce50:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003cb30:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003ce60:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003cb40:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003ce70:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003cb50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003ce80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003cb60:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003ce90:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003cb70:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003cea0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003cb80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003ceb0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003cb90:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003cec0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003cba0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003ced0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003cbb0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003cee0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003cef0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003cf00:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003cbc0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003cbd0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003cbe0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003cbf0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003cc00:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003cc10:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003cc20:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003cc30:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003cc40:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003cc50:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003cc60:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003cc70:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm85 
0003cc80:·3433·2220·7461·6269·6e64·6578·3d22·3022··43"·tabindex="0" 
0003cc90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003cca0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003ccb0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003ccc0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 652314/666970 bytes (97.80%) of diff not shown.
60.9 KB
html2text {}
    
Offset 118, 20 lines modifiedOffset 118, 14 lines modified
118 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule118 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
119 References119 References
120 Remediation_OSBuild_Blueprint_snippet_⇲120 Remediation_OSBuild_Blueprint_snippet_⇲
  
121 [[packages]]121 [[packages]]
122 name·=·"aide"122 name·=·"aide"
123 version·=·"*"123 version·=·"*"
124 Remediation_Anaconda_snippet_⇲ 
125 Complexity:·low 
126 Disruption:·low 
127 Strategy:···enable 
  
128 package·--add=aide 
129 Remediation_Puppet_snippet_⇲124 Remediation_Puppet_snippet_⇲
130 Complexity:·low125 Complexity:·low
131 Disruption:·low126 Disruption:·low
132 Strategy:···enable127 Strategy:···enable
133 include·install_aide128 include·install_aide
  
134 class·install_aide·{129 class·install_aide·{
Offset 149, 14 lines modifiedOffset 143, 20 lines modified
149 if·!·rpm·-q·--quiet·"aide"·;·then143 if·!·rpm·-q·--quiet·"aide"·;·then
150 ····yum·install·-y·"aide"144 ····yum·install·-y·"aide"
151 fi145 fi
  
152 else146 else
153 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'147 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
154 fi148 fi
 149 Remediation_Anaconda_snippet_⇲
 150 Complexity:·low
 151 Disruption:·low
 152 Strategy:···enable
  
 153 package·--add=aide
155 Remediation_Ansible_snippet_⇲154 Remediation_Ansible_snippet_⇲
156 Complexity:·low155 Complexity:·low
157 Disruption:·low156 Disruption:·low
158 Strategy:···enable157 Strategy:···enable
159 -·name:·Ensure·aide·is·installed158 -·name:·Ensure·aide·is·installed
160 ··package:159 ··package:
161 ····name:·aide160 ····name:·aide
Offset 765, 20 lines modifiedOffset 765, 14 lines modified
765 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed765 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
766 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1766 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
767 Remediation_OSBuild_Blueprint_snippet_⇲767 Remediation_OSBuild_Blueprint_snippet_⇲
  
768 [[packages]]768 [[packages]]
769 name·=·"sudo"769 name·=·"sudo"
770 version·=·"*"770 version·=·"*"
771 Remediation_Anaconda_snippet_⇲ 
772 Complexity:·low 
773 Disruption:·low 
774 Strategy:···enable 
  
775 package·--add=sudo 
776 Remediation_Puppet_snippet_⇲771 Remediation_Puppet_snippet_⇲
777 Complexity:·low772 Complexity:·low
778 Disruption:·low773 Disruption:·low
779 Strategy:···enable774 Strategy:···enable
780 include·install_sudo775 include·install_sudo
  
781 class·install_sudo·{776 class·install_sudo·{
Offset 796, 14 lines modifiedOffset 790, 20 lines modified
796 if·!·rpm·-q·--quiet·"sudo"·;·then790 if·!·rpm·-q·--quiet·"sudo"·;·then
797 ····yum·install·-y·"sudo"791 ····yum·install·-y·"sudo"
798 fi792 fi
  
799 else793 else
800 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'794 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
801 fi795 fi
 796 Remediation_Anaconda_snippet_⇲
 797 Complexity:·low
 798 Disruption:·low
 799 Strategy:···enable
  
 800 package·--add=sudo
802 Remediation_Ansible_snippet_⇲801 Remediation_Ansible_snippet_⇲
803 Complexity:·low802 Complexity:·low
804 Disruption:·low803 Disruption:·low
805 Strategy:···enable804 Strategy:···enable
806 -·name:·Ensure·sudo·is·installed805 -·name:·Ensure·sudo·is·installed
807 ··package:806 ··package:
808 ····name:·sudo807 ····name:·sudo
Offset 1399, 20 lines modifiedOffset 1399, 14 lines modified
1399 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1399 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1400 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000801400 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1401 Remediation_OSBuild_Blueprint_snippet_⇲1401 Remediation_OSBuild_Blueprint_snippet_⇲
  
1402 [[packages]]1402 [[packages]]
1403 name·=·"dnf-automatic"1403 name·=·"dnf-automatic"
1404 version·=·"*"1404 version·=·"*"
1405 Remediation_Anaconda_snippet_⇲ 
1406 Complexity:·low 
1407 Disruption:·low 
1408 Strategy:···enable 
  
1409 package·--add=dnf-automatic 
1410 Remediation_Puppet_snippet_⇲1405 Remediation_Puppet_snippet_⇲
1411 Complexity:·low1406 Complexity:·low
1412 Disruption:·low1407 Disruption:·low
1413 Strategy:···enable1408 Strategy:···enable
1414 include·install_dnf-automatic1409 include·install_dnf-automatic
  
1415 class·install_dnf-automatic·{1410 class·install_dnf-automatic·{
Offset 1424, 14 lines modifiedOffset 1418, 20 lines modified
1424 Complexity:·low1418 Complexity:·low
1425 Disruption:·low1419 Disruption:·low
1426 Strategy:···enable1420 Strategy:···enable
  
1427 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1421 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1428 ····yum·install·-y·"dnf-automatic"1422 ····yum·install·-y·"dnf-automatic"
1429 fi1423 fi
 1424 Remediation_Anaconda_snippet_⇲
 1425 Complexity:·low
 1426 Disruption:·low
 1427 Strategy:···enable
  
 1428 package·--add=dnf-automatic
1430 Remediation_Ansible_snippet_⇲1429 Remediation_Ansible_snippet_⇲
1431 Complexity:·low1430 Complexity:·low
1432 Disruption:·low1431 Disruption:·low
1433 Strategy:···enable1432 Strategy:···enable
1434 -·name:·Ensure·dnf-automatic·is·installed1433 -·name:·Ensure·dnf-automatic·is·installed
1435 ··package:1434 ··package:
1436 ····name:·dnf-automatic1435 ····name:·dnf-automatic
Offset 8321, 15 lines modifiedOffset 8321, 15 lines modified
8321 Severity: ·medium8321 Severity: ·medium
Max diff block lines reached; 59267/62359 bytes (95.04%) of diff not shown.
655 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_intermediary.html
    
Offset 15488, 116 lines modifiedOffset 15488, 116 lines modified
0003c7f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003c7f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c800:·2223·6964·6d38·3534·3122·2074·6162·696e··"#idm8541"·tabin0003c800:·2223·6964·6d38·3534·3122·2074·6162·696e··"#idm8541"·tabin
0003c810:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003c810:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c820:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003c820:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c830:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003c830:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c840:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003c840:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c850:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003c850:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c860:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003c860:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
0003c870:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003c870:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
0003c880:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c880:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003c890:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003c890:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003c8a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003c8a0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003c8b0:·3d22·6964·6d38·3534·3122·3e3c·7461·626c··="idm8541"><tabl0003c8b0:·6964·6d38·3534·3122·3e3c·7461·626c·6520··idm8541"><table·
0003c8c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003c8c0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003c8d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003c8d0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003c8e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003c8e0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003c8f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003c8f0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003c900:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003c900:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003c910:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c910:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003c920:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003c920:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003c930:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003c930:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003c940:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c940:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c950:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003c950:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003c960:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c960:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003c970:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003c970:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003c980:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac0003c980:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
0003c990:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.0003c990:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003c9a0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003c9b0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003c9c0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003c9d0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003c9e0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003c9f0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003ca00:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003ca10:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003ca20:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003ca30:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003ca40:·6964·6d38·3534·3222·2074·6162·696e·6465··idm8542"·tabinde
 0003ca50:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003ca60:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003ca70:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003ca80:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003ca90:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003caa0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003cab0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003cac0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003cad0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003cae0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 0003caf0:·3534·3222·3e3c·7461·626c·6520·636c·6173··542"><table·clas
 0003cb00:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003cb10:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003cb20:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003cb30:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003cb40:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003cb50:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003cb60:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003cb70:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003cb80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003cb90:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003cba0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003cbb0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003cbc0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003cbd0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003cbe0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003cbf0:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 0003cc00:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
 0003cc10:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
 0003cc20:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
 0003cc30:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
 0003cc40:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003cc50:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003cc60:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 0003cc70:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003cc80:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003cc90:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003cca0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003ccb0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003ccc0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
0003c9a0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003ccd0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003c9b0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003cce0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003c9c0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003ccf0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003c9d0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003cd00:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003c9e0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003cd10:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003c9f0:·3d22·2369·646d·3835·3432·2220·7461·6269··="#idm8542"·tabi0003cd20:·3d22·2369·646d·3835·3433·2220·7461·6269··="#idm8543"·tabi
0003ca00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003cd30:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003ca10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003cd40:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003ca20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003cd50:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003ca30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003cd60:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003ca40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003cd70:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003ca50:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003cd80:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003ca60:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003cd90:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003ca70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003cda0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003ca80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003cdb0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003ca90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003cdc0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003caa0:·2269·646d·3835·3432·223e·3c74·6162·6c65··"idm8542"><table0003cdd0:·643d·2269·646d·3835·3433·223e·3c74·6162··d="idm8543"><tab
0003cab0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003cde0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003cac0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003cdf0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003cad0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003ce00:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003cae0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003ce10:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003caf0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003ce20:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003cb00:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003ce30:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003cb10:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003ce40:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003cb20:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003ce50:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003cb30:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003ce60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003cb40:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003ce70:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003cb50:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003ce80:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003cb60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003ce90:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003cea0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003ceb0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
0003cb70:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003cb80:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003cb90:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003cba0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003cbb0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003cbc0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003cbd0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003cbe0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003cbf0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003cc00:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003cc10:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003cc20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003cc30:·2369·646d·3835·3433·2220·7461·6269·6e64··#idm8543"·tabind 
0003cc40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003cc50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003cc60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003cc70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003cc80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
Max diff block lines reached; 598114/612770 bytes (97.61%) of diff not shown.
56.7 KB
html2text {}
    
Offset 117, 20 lines modifiedOffset 117, 14 lines modified
117 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule117 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
118 References118 References
119 Remediation_OSBuild_Blueprint_snippet_⇲119 Remediation_OSBuild_Blueprint_snippet_⇲
  
120 [[packages]]120 [[packages]]
121 name·=·"aide"121 name·=·"aide"
122 version·=·"*"122 version·=·"*"
123 Remediation_Anaconda_snippet_⇲ 
124 Complexity:·low 
125 Disruption:·low 
126 Strategy:···enable 
  
127 package·--add=aide 
128 Remediation_Puppet_snippet_⇲123 Remediation_Puppet_snippet_⇲
129 Complexity:·low124 Complexity:·low
130 Disruption:·low125 Disruption:·low
131 Strategy:···enable126 Strategy:···enable
132 include·install_aide127 include·install_aide
  
133 class·install_aide·{128 class·install_aide·{
Offset 148, 14 lines modifiedOffset 142, 20 lines modified
148 if·!·rpm·-q·--quiet·"aide"·;·then142 if·!·rpm·-q·--quiet·"aide"·;·then
149 ····yum·install·-y·"aide"143 ····yum·install·-y·"aide"
150 fi144 fi
  
151 else145 else
152 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'146 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
153 fi147 fi
 148 Remediation_Anaconda_snippet_⇲
 149 Complexity:·low
 150 Disruption:·low
 151 Strategy:···enable
  
 152 package·--add=aide
154 Remediation_Ansible_snippet_⇲153 Remediation_Ansible_snippet_⇲
155 Complexity:·low154 Complexity:·low
156 Disruption:·low155 Disruption:·low
157 Strategy:···enable156 Strategy:···enable
158 -·name:·Ensure·aide·is·installed157 -·name:·Ensure·aide·is·installed
159 ··package:158 ··package:
160 ····name:·aide159 ····name:·aide
Offset 462, 20 lines modifiedOffset 462, 14 lines modified
462 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed462 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
463 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1463 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
464 Remediation_OSBuild_Blueprint_snippet_⇲464 Remediation_OSBuild_Blueprint_snippet_⇲
  
465 [[packages]]465 [[packages]]
466 name·=·"sudo"466 name·=·"sudo"
467 version·=·"*"467 version·=·"*"
468 Remediation_Anaconda_snippet_⇲ 
469 Complexity:·low 
470 Disruption:·low 
471 Strategy:···enable 
  
472 package·--add=sudo 
473 Remediation_Puppet_snippet_⇲468 Remediation_Puppet_snippet_⇲
474 Complexity:·low469 Complexity:·low
475 Disruption:·low470 Disruption:·low
476 Strategy:···enable471 Strategy:···enable
477 include·install_sudo472 include·install_sudo
  
478 class·install_sudo·{473 class·install_sudo·{
Offset 493, 14 lines modifiedOffset 487, 20 lines modified
493 if·!·rpm·-q·--quiet·"sudo"·;·then487 if·!·rpm·-q·--quiet·"sudo"·;·then
494 ····yum·install·-y·"sudo"488 ····yum·install·-y·"sudo"
495 fi489 fi
  
496 else490 else
497 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'491 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
498 fi492 fi
 493 Remediation_Anaconda_snippet_⇲
 494 Complexity:·low
 495 Disruption:·low
 496 Strategy:···enable
  
 497 package·--add=sudo
499 Remediation_Ansible_snippet_⇲498 Remediation_Ansible_snippet_⇲
500 Complexity:·low499 Complexity:·low
501 Disruption:·low500 Disruption:·low
502 Strategy:···enable501 Strategy:···enable
503 -·name:·Ensure·sudo·is·installed502 -·name:·Ensure·sudo·is·installed
504 ··package:503 ··package:
505 ····name:·sudo504 ····name:·sudo
Offset 1096, 20 lines modifiedOffset 1096, 14 lines modified
1096 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1096 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1097 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000801097 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1098 Remediation_OSBuild_Blueprint_snippet_⇲1098 Remediation_OSBuild_Blueprint_snippet_⇲
  
1099 [[packages]]1099 [[packages]]
1100 name·=·"dnf-automatic"1100 name·=·"dnf-automatic"
1101 version·=·"*"1101 version·=·"*"
1102 Remediation_Anaconda_snippet_⇲ 
1103 Complexity:·low 
1104 Disruption:·low 
1105 Strategy:···enable 
  
1106 package·--add=dnf-automatic 
1107 Remediation_Puppet_snippet_⇲1102 Remediation_Puppet_snippet_⇲
1108 Complexity:·low1103 Complexity:·low
1109 Disruption:·low1104 Disruption:·low
1110 Strategy:···enable1105 Strategy:···enable
1111 include·install_dnf-automatic1106 include·install_dnf-automatic
  
1112 class·install_dnf-automatic·{1107 class·install_dnf-automatic·{
Offset 1121, 14 lines modifiedOffset 1115, 20 lines modified
1121 Complexity:·low1115 Complexity:·low
1122 Disruption:·low1116 Disruption:·low
1123 Strategy:···enable1117 Strategy:···enable
  
1124 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1118 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1125 ····yum·install·-y·"dnf-automatic"1119 ····yum·install·-y·"dnf-automatic"
1126 fi1120 fi
 1121 Remediation_Anaconda_snippet_⇲
 1122 Complexity:·low
 1123 Disruption:·low
 1124 Strategy:···enable
  
 1125 package·--add=dnf-automatic
1127 Remediation_Ansible_snippet_⇲1126 Remediation_Ansible_snippet_⇲
1128 Complexity:·low1127 Complexity:·low
1129 Disruption:·low1128 Disruption:·low
1130 Strategy:···enable1129 Strategy:···enable
1131 -·name:·Ensure·dnf-automatic·is·installed1130 -·name:·Ensure·dnf-automatic·is·installed
1132 ··package:1131 ··package:
1133 ····name:·dnf-automatic1132 ····name:·dnf-automatic
Offset 7606, 15 lines modifiedOffset 7606, 15 lines modified
7606 Severity: ·medium7606 Severity: ·medium
Max diff block lines reached; 54973/58065 bytes (94.67%) of diff not shown.
245 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_minimal.html
    
Offset 16166, 107 lines modifiedOffset 16166, 107 lines modified
0003f250:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm10003f250:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
0003f260:·3335·3831·2220·7461·6269·6e64·6578·3d22··3581"·tabindex="0003f260:·3335·3831·2220·7461·6269·6e64·6578·3d22··3581"·tabindex="
0003f270:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003f270:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003f280:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003f280:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003f290:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003f290:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003f2a0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003f2a0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003f2b0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003f2b0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003f2c0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003f2c0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003f2d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003f2d0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003f2e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003f2e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003f2f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003f2f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003f300:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003f300:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13
0003f310:·3133·3538·3122·3e3c·7461·626c·6520·636c··13581"><table·cl0003f310:·3538·3122·3e3c·7461·626c·6520·636c·6173··581"><table·clas
0003f320:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003f320:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003f330:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003f330:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003f340:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003f340:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003f350:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003f350:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003f360:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003f360:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003f370:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003f380:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003f390:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003f3a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003f3b0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003f3c0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003f3d0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003f3e0:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003f3f0:·7374·616c·6c5f·646e·662d·6175·746f·6d61··stall_dnf-automa
 0003f400:·7469·630a·0a63·6c61·7373·2069·6e73·7461··tic..class·insta
 0003f410:·6c6c·5f64·6e66·2d61·7574·6f6d·6174·6963··ll_dnf-automatic
 0003f420:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003f430:·646e·662d·6175·746f·6d61·7469·6327·3a0a··dnf-automatic':.
 0003f440:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 0003f450:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 0003f460:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 0003f470:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003f480:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003f490:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003f4a0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003f4b0:·7267·6574·3d22·2369·646d·3133·3538·3222··rget="#idm13582"
 0003f4c0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003f4d0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003f4e0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003f4f0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003f500:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003f510:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003f520:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003f530:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003f540:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003f550:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003f560:·6964·3d22·6964·6d31·3335·3832·223e·3c74··id="idm13582"><t
 0003f570:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003f580:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003f590:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003f5a0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003f5b0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003f5c0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003f5d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003f5e0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003f370:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003f5f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003f380:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003f390:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003f3a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003f3b0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003f3c0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003f3d0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003f3e0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
0003f3f0:·202d·2d61·6464·3d64·6e66·2d61·7574·6f6d···--add=dnf-autom0003f600:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003f610:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003f620:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003f630:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003f640:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003f650:·6965·7420·2264·6e66·2d61·7574·6f6d·6174··iet·"dnf-automat
 0003f660:·6963·2220·3b20·7468·656e·0a20·2020·2079··ic"·;·then.····y
 0003f670:·756d·2069·6e73·7461·6c6c·202d·7920·2264··um·install·-y·"d
 0003f680:·6e66·2d61·7574·6f6d·6174·6963·220a·6669··nf-automatic".fi
0003f400:·6174·6963·0a3c·2f63·6f64·653e·3c2f·7072··atic.</code></pr0003f690:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003f410:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003f6a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003f420:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003f6b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003f430:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003f6c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003f440:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003f6d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003f450:·6172·6765·743d·2223·6964·6d31·3335·3832··arget="#idm135820003f6e0:·743d·2223·6964·6d31·3335·3833·2220·7461··t="#idm13583"·ta
0003f460:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003f6f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003f470:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003f700:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003f480:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003f710:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003f490:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003f720:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003f4a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003f730:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003f4b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003f740:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003f4c0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003f750:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003f4d0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003f760:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003f4e0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003f770:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003f4f0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003f780:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003f500:·6522·2069·643d·2269·646d·3133·3538·3222··e"·id="idm13582"0003f790:·2069·643d·2269·646d·3133·3538·3322·3e3c···id="idm13583"><
0003f510:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003f7a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003f520:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003f7b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003f530:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003f7c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003f540:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003f7d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003f550:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003f7e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003f560:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003f7f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003f570:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003f800:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003f580:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003f810:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003f590:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003f820:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003f5a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003f830:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003f5b0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003f840:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003f5c0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003f850:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003f5d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003f860:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003f870:·0a70·6163·6b61·6765·202d·2d61·6464·3d64··.package·--add=d
0003f5e0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003f5f0:·6c5f·646e·662d·6175·746f·6d61·7469·630a··l_dnf-automatic. 
0003f600:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f64··.class·install_d 
0003f610:·6e66·2d61·7574·6f6d·6174·6963·207b·0a20··nf-automatic·{.·0003f880:·6e66·2d61·7574·6f6d·6174·6963·0a3c·2f63··nf-automatic.</c
0003f620:·2070·6163·6b61·6765·207b·2027·646e·662d···package·{·'dnf- 
0003f630:·6175·746f·6d61·7469·6327·3a0a·2020·2020··automatic':.···· 
0003f640:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003f650:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003f660:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003f670:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003f680:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003f690:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003f6a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003f6b0:·3d22·2369·646d·3133·3538·3322·2074·6162··="#idm13583"·tab 
0003f6c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003f6d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003f6e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003f6f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003f700:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003f710:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003f720:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
Max diff block lines reached; 219536/232950 bytes (94.24%) of diff not shown.
17.4 KB
html2text {}
    
Offset 276, 20 lines modifiedOffset 276, 14 lines modified
276 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed276 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
277 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080277 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
278 Remediation_OSBuild_Blueprint_snippet_⇲278 Remediation_OSBuild_Blueprint_snippet_⇲
  
279 [[packages]]279 [[packages]]
280 name·=·"dnf-automatic"280 name·=·"dnf-automatic"
281 version·=·"*"281 version·=·"*"
282 Remediation_Anaconda_snippet_⇲ 
283 Complexity:·low 
284 Disruption:·low 
285 Strategy:···enable 
  
286 package·--add=dnf-automatic 
287 Remediation_Puppet_snippet_⇲282 Remediation_Puppet_snippet_⇲
288 Complexity:·low283 Complexity:·low
289 Disruption:·low284 Disruption:·low
290 Strategy:···enable285 Strategy:···enable
291 include·install_dnf-automatic286 include·install_dnf-automatic
  
292 class·install_dnf-automatic·{287 class·install_dnf-automatic·{
Offset 301, 14 lines modifiedOffset 295, 20 lines modified
301 Complexity:·low295 Complexity:·low
302 Disruption:·low296 Disruption:·low
303 Strategy:···enable297 Strategy:···enable
  
304 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then298 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
305 ····yum·install·-y·"dnf-automatic"299 ····yum·install·-y·"dnf-automatic"
306 fi300 fi
 301 Remediation_Anaconda_snippet_⇲
 302 Complexity:·low
 303 Disruption:·low
 304 Strategy:···enable
  
 305 package·--add=dnf-automatic
307 Remediation_Ansible_snippet_⇲306 Remediation_Ansible_snippet_⇲
308 Complexity:·low307 Complexity:·low
309 Disruption:·low308 Disruption:·low
310 Strategy:···enable309 Strategy:···enable
311 -·name:·Ensure·dnf-automatic·is·installed310 -·name:·Ensure·dnf-automatic·is·installed
312 ··package:311 ··package:
313 ····name:·dnf-automatic312 ····name:·dnf-automatic
Offset 6974, 20 lines modifiedOffset 6974, 14 lines modified
6974 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-6974 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
6975 ············00227,·4.2.1.1,·SV-230477r627750_rule6975 ············00227,·4.2.1.1,·SV-230477r627750_rule
6976 Remediation_OSBuild_Blueprint_snippet_⇲6976 Remediation_OSBuild_Blueprint_snippet_⇲
  
6977 [[packages]]6977 [[packages]]
6978 name·=·"rsyslog"6978 name·=·"rsyslog"
6979 version·=·"*"6979 version·=·"*"
6980 Remediation_Anaconda_snippet_⇲ 
6981 Complexity:·low 
6982 Disruption:·low 
6983 Strategy:···enable 
  
6984 package·--add=rsyslog 
6985 Remediation_Puppet_snippet_⇲6980 Remediation_Puppet_snippet_⇲
6986 Complexity:·low6981 Complexity:·low
6987 Disruption:·low6982 Disruption:·low
6988 Strategy:···enable6983 Strategy:···enable
6989 include·install_rsyslog6984 include·install_rsyslog
  
6990 class·install_rsyslog·{6985 class·install_rsyslog·{
Offset 7005, 14 lines modifiedOffset 6999, 20 lines modified
7005 if·!·rpm·-q·--quiet·"rsyslog"·;·then6999 if·!·rpm·-q·--quiet·"rsyslog"·;·then
7006 ····yum·install·-y·"rsyslog"7000 ····yum·install·-y·"rsyslog"
7007 fi7001 fi
  
7008 else7002 else
7009 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7003 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7010 fi7004 fi
 7005 Remediation_Anaconda_snippet_⇲
 7006 Complexity:·low
 7007 Disruption:·low
 7008 Strategy:···enable
  
 7009 package·--add=rsyslog
7011 Remediation_Ansible_snippet_⇲7010 Remediation_Ansible_snippet_⇲
7012 Complexity:·low7011 Complexity:·low
7013 Disruption:·low7012 Disruption:·low
7014 Strategy:···enable7013 Strategy:···enable
7015 -·name:·Ensure·rsyslog·is·installed7014 -·name:·Ensure·rsyslog·is·installed
7016 ··package:7015 ··package:
7017 ····name:·rsyslog7016 ····name:·rsyslog
Offset 7199, 20 lines modifiedOffset 7199, 14 lines modified
7199 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,7199 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,
7200 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7200 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
7201 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,7201 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
7202 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR7202 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
7203 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR7203 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
7204 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,7204 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
7205 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-37205 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3
7206 Remediation_Anaconda_snippet_⇲ 
7207 Complexity:·low 
7208 Disruption:·low 
7209 Strategy:···disable 
  
7210 package·--remove=dhcp-server 
7211 Remediation_Puppet_snippet_⇲7206 Remediation_Puppet_snippet_⇲
7212 Complexity:·low7207 Complexity:·low
7213 Disruption:·low7208 Disruption:·low
7214 Strategy:···disable7209 Strategy:···disable
7215 include·remove_dhcp-server7210 include·remove_dhcp-server
  
7216 class·remove_dhcp-server·{7211 class·remove_dhcp-server·{
Offset 7232, 14 lines modifiedOffset 7226, 20 lines modified
7232 #»      ···system!7226 #»      ···system!
  
7233 if·rpm·-q·--quiet·"dhcp-server"·;·then7227 if·rpm·-q·--quiet·"dhcp-server"·;·then
  
7234 ····yum·remove·-y·"dhcp-server"7228 ····yum·remove·-y·"dhcp-server"
  
7235 fi7229 fi
 7230 Remediation_Anaconda_snippet_⇲
 7231 Complexity:·low
 7232 Disruption:·low
 7233 Strategy:···disable
  
 7234 package·--remove=dhcp-server
7236 Remediation_Ansible_snippet_⇲7235 Remediation_Ansible_snippet_⇲
7237 Complexity:·low7236 Complexity:·low
7238 Disruption:·low7237 Disruption:·low
7239 Strategy:···disable7238 Strategy:···disable
7240 -·name:·Ensure·dhcp-server·is·removed7239 -·name:·Ensure·dhcp-server·is·removed
7241 ··package:7240 ··package:
7242 ····name:·dhcp-server7241 ····name:·dhcp-server
Offset 7286, 20 lines modifiedOffset 7286, 14 lines modified
7286 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7286 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
Max diff block lines reached; 14299/17819 bytes (80.25%) of diff not shown.
1.75 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis.html
    
Offset 15534, 116 lines modifiedOffset 15534, 116 lines modified
0003cad0:·7267·6574·3d22·2369·646d·3835·3431·2220··rget="#idm8541"·0003cad0:·7267·6574·3d22·2369·646d·3835·3431·2220··rget="#idm8541"·
0003cae0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003cae0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003caf0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003caf0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003cb00:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003cb00:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003cb10:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003cb10:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003cb20:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003cb20:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003cb30:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003cb30:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003cb40:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp0003cb40:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003cb50:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003cb50:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003cb60:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003cb60:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003cb70:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003cb70:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003cb80:·6522·2069·643d·2269·646d·3835·3431·223e··e"·id="idm8541">0003cb80:·2069·643d·2269·646d·3835·3431·223e·3c74···id="idm8541"><t
0003cb90:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003cb90:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003cba0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003cba0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003cbb0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003cbb0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003cbc0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003cbc0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003cbd0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003cbd0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003cbe0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003cbe0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003cbf0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003cbf0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003cc00:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003cc00:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003cc10:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003cc10:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003cc20:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003cc20:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003cc30:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003cc30:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003cc40:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003cc40:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003cc50:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003cc50:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
0003cc60:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=0003cc60:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003cc70:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003cc80:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003cc90:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003cca0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003ccb0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003ccc0:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003ccd0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003cce0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003ccf0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003cd00:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003cd10:·6574·3d22·2369·646d·3835·3432·2220·7461··et="#idm8542"·ta
 0003cd20:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003cd30:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003cd40:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003cd50:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003cd60:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003cd70:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003cd80:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003cd90:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003cda0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003cdb0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003cdc0:·2269·646d·3835·3432·223e·3c74·6162·6c65··"idm8542"><table
 0003cdd0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003cde0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003cdf0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003ce00:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003ce10:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003ce20:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003ce30:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003ce40:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003ce50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003ce60:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003ce70:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003ce80:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003ce90:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003cea0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003ceb0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003cec0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003ced0:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0003cee0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0003cef0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0003cf00:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0003cf10:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003cf20:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 0003cf30:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
 0003cf40:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003cf50:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 0003cf60:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003cf70:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003cf80:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003cf90:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
0003cc70:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003cfa0:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003cc80:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003cfb0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003cc90:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003cfc0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003cca0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003cfd0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003ccb0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003cfe0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003ccc0:·6172·6765·743d·2223·6964·6d38·3534·3222··arget="#idm8542"0003cff0:·6172·6765·743d·2223·6964·6d38·3534·3322··arget="#idm8543"
0003ccd0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003d000:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003cce0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003d010:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003ccf0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003d020:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003cd00:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003d030:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003cd10:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003d040:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003cd20:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003d050:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003cd30:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003d060:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003cd40:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003d070:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003cd50:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003d080:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003cd60:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003d090:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003cd70:·2220·6964·3d22·6964·6d38·3534·3222·3e3c··"·id="idm8542"><0003d0a0:·7365·2220·6964·3d22·6964·6d38·3534·3322··se"·id="idm8543"
0003cd80:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003d0b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003cd90:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003d0c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003cda0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003d0d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003cdb0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003d0e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003cdc0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003d0f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003cdd0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003d100:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003cde0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003d110:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003cdf0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003d120:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003ce00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003d130:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003ce10:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003d140:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003ce20:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003d150:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003ce30:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003d160:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003ce40:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003d170:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003d180:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
0003ce50:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003ce60:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003ce70:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003ce80:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003ce90:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003cea0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003ceb0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003cec0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003ced0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003cee0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003cef0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003cf00:·6765·743d·2223·6964·6d38·3534·3322·2074··get="#idm8543"·t 
0003cf10:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003cf20:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003cf30:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003cf40:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003cf50:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003cf60:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003cf70:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 1468899/1483555 bytes (99.01%) of diff not shown.
338 KB
html2text {}
    
Offset 122, 20 lines modifiedOffset 122, 14 lines modified
122 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed122 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
123 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule123 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
124 Remediation_OSBuild_Blueprint_snippet_⇲124 Remediation_OSBuild_Blueprint_snippet_⇲
  
125 [[packages]]125 [[packages]]
126 name·=·"aide"126 name·=·"aide"
127 version·=·"*"127 version·=·"*"
128 Remediation_Anaconda_snippet_⇲ 
129 Complexity:·low 
130 Disruption:·low 
131 Strategy:···enable 
  
132 package·--add=aide 
133 Remediation_Puppet_snippet_⇲128 Remediation_Puppet_snippet_⇲
134 Complexity:·low129 Complexity:·low
135 Disruption:·low130 Disruption:·low
136 Strategy:···enable131 Strategy:···enable
137 include·install_aide132 include·install_aide
  
138 class·install_aide·{133 class·install_aide·{
Offset 153, 14 lines modifiedOffset 147, 20 lines modified
153 if·!·rpm·-q·--quiet·"aide"·;·then147 if·!·rpm·-q·--quiet·"aide"·;·then
154 ····yum·install·-y·"aide"148 ····yum·install·-y·"aide"
155 fi149 fi
  
156 else150 else
157 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'151 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
158 fi152 fi
 153 Remediation_Anaconda_snippet_⇲
 154 Complexity:·low
 155 Disruption:·low
 156 Strategy:···enable
  
 157 package·--add=aide
159 Remediation_Ansible_snippet_⇲158 Remediation_Ansible_snippet_⇲
160 Complexity:·low159 Complexity:·low
161 Disruption:·low160 Disruption:·low
162 Strategy:···enable161 Strategy:···enable
163 -·name:·Ensure·aide·is·installed162 -·name:·Ensure·aide·is·installed
164 ··package:163 ··package:
165 ····name:·aide164 ····name:·aide
Offset 1220, 20 lines modifiedOffset 1220, 14 lines modified
1220 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1220 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1221 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11221 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1222 Remediation_OSBuild_Blueprint_snippet_⇲1222 Remediation_OSBuild_Blueprint_snippet_⇲
  
1223 [[packages]]1223 [[packages]]
1224 name·=·"sudo"1224 name·=·"sudo"
1225 version·=·"*"1225 version·=·"*"
1226 Remediation_Anaconda_snippet_⇲ 
1227 Complexity:·low 
1228 Disruption:·low 
1229 Strategy:···enable 
  
1230 package·--add=sudo 
1231 Remediation_Puppet_snippet_⇲1226 Remediation_Puppet_snippet_⇲
1232 Complexity:·low1227 Complexity:·low
1233 Disruption:·low1228 Disruption:·low
1234 Strategy:···enable1229 Strategy:···enable
1235 include·install_sudo1230 include·install_sudo
  
1236 class·install_sudo·{1231 class·install_sudo·{
Offset 1251, 14 lines modifiedOffset 1245, 20 lines modified
1251 if·!·rpm·-q·--quiet·"sudo"·;·then1245 if·!·rpm·-q·--quiet·"sudo"·;·then
1252 ····yum·install·-y·"sudo"1246 ····yum·install·-y·"sudo"
1253 fi1247 fi
  
1254 else1248 else
1255 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1249 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1256 fi1250 fi
 1251 Remediation_Anaconda_snippet_⇲
 1252 Complexity:·low
 1253 Disruption:·low
 1254 Strategy:···enable
  
 1255 package·--add=sudo
1257 Remediation_Ansible_snippet_⇲1256 Remediation_Ansible_snippet_⇲
1258 Complexity:·low1257 Complexity:·low
1259 Disruption:·low1258 Disruption:·low
1260 Strategy:···enable1259 Strategy:···enable
1261 -·name:·Ensure·sudo·is·installed1260 -·name:·Ensure·sudo·is·installed
1262 ··package:1261 ··package:
1263 ····name:·sudo1262 ····name:·sudo
Offset 8241, 15 lines modifiedOffset 8241, 15 lines modified
8241 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.8241 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
8242 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.8242 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
8243 Severity: ················medium8243 Severity: ················medium
8244 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod8244 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
8245 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule8245 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule
8246 Remediation_Shell_script_⇲8246 Remediation_Shell_script_⇲
8247 #·Remediation·is·applicable·only·in·certain·platforms8247 #·Remediation·is·applicable·only·in·certain·platforms
8248 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8248 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8249 #·First·perform·the·remediation·of·the·syscall·rule8249 #·First·perform·the·remediation·of·the·syscall·rule
8250 #·Retrieve·hardware·architecture·of·the·underlying·system8250 #·Retrieve·hardware·architecture·of·the·underlying·system
8251 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8251 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8252 for·ARCH·in·"${RULE_ARCHS[@]}"8252 for·ARCH·in·"${RULE_ARCHS[@]}"
8253 do8253 do
Offset 8596, 16 lines modifiedOffset 8596, 16 lines modified
8596 ··-·reboot_required8596 ··-·reboot_required
8597 ··-·restrict_strategy8597 ··-·restrict_strategy
  
8598 -·name:·Set·architecture·for·audit·chmod·tasks8598 -·name:·Set·architecture·for·audit·chmod·tasks
8599 ··set_fact:8599 ··set_fact:
8600 ····audit_arch:·b648600 ····audit_arch:·b64
8601 ··when:8601 ··when:
8602 ··-·'"audit"·in·ansible_facts.packages' 
8603 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8602 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8603 ··-·'"audit"·in·ansible_facts.packages'
8604 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8604 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8605 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8605 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8606 ··tags:8606 ··tags:
8607 ··-·CJIS-5.4.1.18607 ··-·CJIS-5.4.1.1
8608 ··-·DISA-STIG-RHEL-08-0304908608 ··-·DISA-STIG-RHEL-08-030490
8609 ··-·NIST-800-171-3.1.78609 ··-·NIST-800-171-3.1.7
8610 ··-·NIST-800-53-AU-12(c)8610 ··-·NIST-800-53-AU-12(c)
Offset 8742, 16 lines modifiedOffset 8742, 16 lines modified
8742 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008742 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8743 ········-F·auid!=unset·-F·key=perm_mod8743 ········-F·auid!=unset·-F·key=perm_mod
8744 ······create:·true8744 ······create:·true
8745 ······mode:·o-rwx8745 ······mode:·o-rwx
8746 ······state:·present8746 ······state:·present
8747 ····when:·syscalls_found·|·length·==·08747 ····when:·syscalls_found·|·length·==·0
8748 ··when:8748 ··when:
8749 ··-·'"audit"·in·ansible_facts.packages' 
8750 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8749 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
Max diff block lines reached; 339732/346103 bytes (98.16%) of diff not shown.
887 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_server_l1.html
    
Offset 15524, 116 lines modifiedOffset 15524, 116 lines modified
0003ca30:·6574·3d22·2369·646d·3835·3431·2220·7461··et="#idm8541"·ta0003ca30:·6574·3d22·2369·646d·3835·3431·2220·7461··et="#idm8541"·ta
0003ca40:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003ca40:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003ca50:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003ca50:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003ca60:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003ca60:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003ca70:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003ca70:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003ca80:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003ca80:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003ca90:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003ca90:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003caa0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet0003caa0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
0003cab0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003cab0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003cac0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003cac0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003cad0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003cad0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003cae0:·2069·643d·2269·646d·3835·3431·223e·3c74···id="idm8541"><t0003cae0:·643d·2269·646d·3835·3431·223e·3c74·6162··d="idm8541"><tab
0003caf0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003caf0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003cb00:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003cb00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003cb10:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003cb10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003cb20:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003cb20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003cb30:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003cb30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003cb40:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003cb40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003cb50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003cb50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003cb60:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003cb60:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003cb70:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003cb70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003cb80:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003cb80:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003cb90:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003cb90:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003cba0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003cba0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003cbb0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.0003cbb0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
0003cbc0:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai0003cbc0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003cbd0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003cbe0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003cbf0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003cc00:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003cc10:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003cc20:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003cc30:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003cc40:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003cc50:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003cc60:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003cc70:·3d22·2369·646d·3835·3432·2220·7461·6269··="#idm8542"·tabi
 0003cc80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003cc90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003cca0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003ccb0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003ccc0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003ccd0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003cce0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003ccf0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003cd00:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003cd10:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003cd20:·646d·3835·3432·223e·3c74·6162·6c65·2063··dm8542"><table·c
 0003cd30:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003cd40:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003cd50:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003cd60:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003cd70:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003cd80:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003cd90:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003cda0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003cdb0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003cdc0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003cdd0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003cde0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003cdf0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 0003ce00:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 0003ce10:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 0003ce20:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 0003ce30:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
 0003ce40:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
 0003ce50:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
 0003ce60:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t
 0003ce70:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 0003ce80:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"·
 0003ce90:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 0003cea0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 0003ceb0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 0003cec0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 0003ced0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 0003cee0:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 0003cef0:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
0003cbd0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>0003cf00:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
0003cbe0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003cf10:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003cbf0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003cf20:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003cc00:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003cf30:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003cc10:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003cf40:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003cc20:·6765·743d·2223·6964·6d38·3534·3222·2074··get="#idm8542"·t0003cf50:·6765·743d·2223·6964·6d38·3534·3322·2074··get="#idm8543"·t
0003cc30:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003cf60:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003cc40:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003cf70:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003cc50:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003cf80:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003cc60:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003cf90:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003cc70:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003cfa0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003cc80:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003cfb0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003cc90:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·0003cfc0:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
0003cca0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003cfd0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003ccb0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003cfe0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003ccc0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003cff0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003ccd0:·6964·3d22·6964·6d38·3534·3222·3e3c·7461··id="idm8542"><ta0003d000:·2220·6964·3d22·6964·6d38·3534·3322·3e3c··"·id="idm8543"><
0003cce0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003d010:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003ccf0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003d020:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003cd00:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003d030:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003cd10:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003d040:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003cd20:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003d050:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003cd30:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003d060:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003cd40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003d070:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003cd50:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003d080:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003cd60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003d090:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003cd70:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003d0a0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003cd80:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003d0b0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003cd90:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003d0c0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003cda0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in0003d0d0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003d0e0:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a
0003cdb0:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai 
0003cdc0:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal 
0003cdd0:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa 
0003cde0:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.··· 
0003cdf0:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
0003ce00:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
0003ce10:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003ce20:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003ce30:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003ce40:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003ce50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003ce60:·743d·2223·6964·6d38·3534·3322·2074·6162··t="#idm8543"·tab 
0003ce70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003ce80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003ce90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003cea0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003ceb0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003cec0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003ced0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
Max diff block lines reached; 801952/816608 bytes (98.21%) of diff not shown.
89.0 KB
html2text {}
    
Offset 120, 20 lines modifiedOffset 120, 14 lines modified
120 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed120 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
121 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule121 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
122 Remediation_OSBuild_Blueprint_snippet_⇲122 Remediation_OSBuild_Blueprint_snippet_⇲
  
123 [[packages]]123 [[packages]]
124 name·=·"aide"124 name·=·"aide"
125 version·=·"*"125 version·=·"*"
126 Remediation_Anaconda_snippet_⇲ 
127 Complexity:·low 
128 Disruption:·low 
129 Strategy:···enable 
  
130 package·--add=aide 
131 Remediation_Puppet_snippet_⇲126 Remediation_Puppet_snippet_⇲
132 Complexity:·low127 Complexity:·low
133 Disruption:·low128 Disruption:·low
134 Strategy:···enable129 Strategy:···enable
135 include·install_aide130 include·install_aide
  
136 class·install_aide·{131 class·install_aide·{
Offset 151, 14 lines modifiedOffset 145, 20 lines modified
151 if·!·rpm·-q·--quiet·"aide"·;·then145 if·!·rpm·-q·--quiet·"aide"·;·then
152 ····yum·install·-y·"aide"146 ····yum·install·-y·"aide"
153 fi147 fi
  
154 else148 else
155 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
156 fi150 fi
 151 Remediation_Anaconda_snippet_⇲
 152 Complexity:·low
 153 Disruption:·low
 154 Strategy:···enable
  
 155 package·--add=aide
157 Remediation_Ansible_snippet_⇲156 Remediation_Ansible_snippet_⇲
158 Complexity:·low157 Complexity:·low
159 Disruption:·low158 Disruption:·low
160 Strategy:···enable159 Strategy:···enable
161 -·name:·Ensure·aide·is·installed160 -·name:·Ensure·aide·is·installed
162 ··package:161 ··package:
163 ····name:·aide162 ····name:·aide
Offset 1133, 20 lines modifiedOffset 1133, 14 lines modified
1133 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1133 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1134 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11134 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1135 Remediation_OSBuild_Blueprint_snippet_⇲1135 Remediation_OSBuild_Blueprint_snippet_⇲
  
1136 [[packages]]1136 [[packages]]
1137 name·=·"sudo"1137 name·=·"sudo"
1138 version·=·"*"1138 version·=·"*"
1139 Remediation_Anaconda_snippet_⇲ 
1140 Complexity:·low 
1141 Disruption:·low 
1142 Strategy:···enable 
  
1143 package·--add=sudo 
1144 Remediation_Puppet_snippet_⇲1139 Remediation_Puppet_snippet_⇲
1145 Complexity:·low1140 Complexity:·low
1146 Disruption:·low1141 Disruption:·low
1147 Strategy:···enable1142 Strategy:···enable
1148 include·install_sudo1143 include·install_sudo
  
1149 class·install_sudo·{1144 class·install_sudo·{
Offset 1164, 14 lines modifiedOffset 1158, 20 lines modified
1164 if·!·rpm·-q·--quiet·"sudo"·;·then1158 if·!·rpm·-q·--quiet·"sudo"·;·then
1165 ····yum·install·-y·"sudo"1159 ····yum·install·-y·"sudo"
1166 fi1160 fi
  
1167 else1161 else
1168 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1162 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1169 fi1163 fi
 1164 Remediation_Anaconda_snippet_⇲
 1165 Complexity:·low
 1166 Disruption:·low
 1167 Strategy:···enable
  
 1168 package·--add=sudo
1170 Remediation_Ansible_snippet_⇲1169 Remediation_Ansible_snippet_⇲
1171 Complexity:·low1170 Complexity:·low
1172 Disruption:·low1171 Disruption:·low
1173 Strategy:···enable1172 Strategy:···enable
1174 -·name:·Ensure·sudo·is·installed1173 -·name:·Ensure·sudo·is·installed
1175 ··package:1174 ··package:
1176 ····name:·sudo1175 ····name:·sudo
Offset 8098, 15 lines modifiedOffset 8098, 15 lines modified
8098 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg8098 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg
8099 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.28099 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
8100 Remediation_Shell_script_⇲8100 Remediation_Shell_script_⇲
8101 Complexity:·low8101 Complexity:·low
8102 Disruption:·low8102 Disruption:·low
8103 Strategy:···configure8103 Strategy:···configure
8104 #·Remediation·is·applicable·only·in·certain·platforms8104 #·Remediation·is·applicable·only·in·certain·platforms
8105 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then8105 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
8106 chgrp·0·/boot/grub2/grub.cfg8106 chgrp·0·/boot/grub2/grub.cfg
  
8107 else8107 else
8108 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8108 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8109 fi8109 fi
8110 Remediation_Ansible_snippet_⇲8110 Remediation_Ansible_snippet_⇲
Offset 8130, 16 lines modifiedOffset 8130, 16 lines modified
8130 ··-·no_reboot_needed8130 ··-·no_reboot_needed
  
8131 -·name:·Test·for·existence·/boot/grub2/grub.cfg8131 -·name:·Test·for·existence·/boot/grub2/grub.cfg
8132 ··stat:8132 ··stat:
8133 ····path:·/boot/grub2/grub.cfg8133 ····path:·/boot/grub2/grub.cfg
8134 ··register:·file_exists8134 ··register:·file_exists
8135 ··when:8135 ··when:
8136 ··-·'"grub2-common"·in·ansible_facts.packages' 
8137 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8136 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8137 ··-·'"grub2-common"·in·ansible_facts.packages'
8138 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8138 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8139 ··tags:8139 ··tags:
8140 ··-·CJIS-5.5.2.28140 ··-·CJIS-5.5.2.2
8141 ··-·NIST-800-171-3.4.58141 ··-·NIST-800-171-3.4.5
8142 ··-·NIST-800-53-AC-6(1)8142 ··-·NIST-800-53-AC-6(1)
8143 ··-·NIST-800-53-CM-6(a)8143 ··-·NIST-800-53-CM-6(a)
8144 ··-·PCI-DSS-Req-7.18144 ··-·PCI-DSS-Req-7.1
Offset 8151, 16 lines modifiedOffset 8151, 16 lines modified
8151 ··-·no_reboot_needed8151 ··-·no_reboot_needed
  
8152 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg8152 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
8153 ··file:8153 ··file:
8154 ····path:·/boot/grub2/grub.cfg8154 ····path:·/boot/grub2/grub.cfg
8155 ····group:·'0'8155 ····group:·'0'
8156 ··when:8156 ··when:
8157 ··-·'"grub2-common"·in·ansible_facts.packages' 
8158 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8157 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
Max diff block lines reached; 86207/91074 bytes (94.66%) of diff not shown.
855 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l1.html
    
Offset 15520, 116 lines modifiedOffset 15520, 116 lines modified
0003c9f0:·6765·743d·2223·6964·6d38·3534·3122·2074··get="#idm8541"·t0003c9f0:·6765·743d·2223·6964·6d38·3534·3122·2074··get="#idm8541"·t
0003ca00:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003ca00:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003ca10:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003ca10:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003ca20:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003ca20:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003ca30:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003ca30:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003ca40:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003ca40:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003ca50:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003ca50:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003ca60:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe0003ca60:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
0003ca70:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003ca70:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003ca80:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003ca80:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003ca90:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003ca90:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003caa0:·2220·6964·3d22·6964·6d38·3534·3122·3e3c··"·id="idm8541"><0003caa0:·6964·3d22·6964·6d38·3534·3122·3e3c·7461··id="idm8541"><ta
0003cab0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003cab0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003cac0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003cac0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003cad0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003cad0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003cae0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003cae0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003caf0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003caf0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003cb00:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003cb00:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003cb10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003cb10:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003cb20:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003cb20:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003cb30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003cb30:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003cb40:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003cb40:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003cb50:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003cb50:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003cb60:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003cb60:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003cb70:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003cb70:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
0003cb80:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a0003cb80:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai
 0003cb90:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal
 0003cba0:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa
 0003cbb0:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.···
 0003cbc0:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i
 0003cbd0:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.}
 0003cbe0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003cbf0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003cc00:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003cc10:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003cc20:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003cc30:·743d·2223·6964·6d38·3534·3222·2074·6162··t="#idm8542"·tab
 0003cc40:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003cc50:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003cc60:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003cc70:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003cc80:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003cc90:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 0003cca0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0003ccb0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003ccc0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003ccd0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003cce0:·6964·6d38·3534·3222·3e3c·7461·626c·6520··idm8542"><table·
 0003ccf0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003cd00:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003cd10:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003cd20:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003cd30:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003cd40:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003cd50:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003cd60:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003cd70:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003cd80:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003cd90:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003cda0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003cdb0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 0003cdc0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003cdd0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003cde0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003cdf0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
 0003ce00:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
 0003ce10:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
 0003ce20:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·
 0003ce30:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 0003ce40:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 0003ce50:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
 0003ce60:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003ce70:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 0003ce80:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003ce90:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003cea0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003ceb0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
0003cb90:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre0003cec0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
0003cba0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003ced0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
0003cbb0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003cee0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
0003cbc0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003cef0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
0003cbd0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003cf00:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
0003cbe0:·7267·6574·3d22·2369·646d·3835·3432·2220··rget="#idm8542"·0003cf10:·7267·6574·3d22·2369·646d·3835·3433·2220··rget="#idm8543"·
0003cbf0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003cf20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003cc00:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003cf30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003cc10:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003cf40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003cc20:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003cf50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003cc30:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003cf60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003cc40:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003cf70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003cc50:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet0003cf80:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
0003cc60:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003cf90:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003cc70:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003cfa0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003cc80:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003cfb0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003cc90:·2069·643d·2269·646d·3835·3432·223e·3c74···id="idm8542"><t0003cfc0:·6522·2069·643d·2269·646d·3835·3433·223e··e"·id="idm8543">
0003cca0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003cfd0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003ccb0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003cfe0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003ccc0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003cff0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003ccd0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003d000:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003cce0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003d010:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003ccf0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003d020:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003cd00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003d030:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003cd10:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003d040:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003cd20:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003d050:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003cd30:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003d060:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003cd40:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003d070:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003cd50:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003d080:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003cd60:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i0003d090:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003d0a0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=
0003cd70:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a 
0003cd80:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta 
0003cd90:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack 
0003cda0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.·· 
0003cdb0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003cdc0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003cdd0:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003cde0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003cdf0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003ce00:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003ce10:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003ce20:·6574·3d22·2369·646d·3835·3433·2220·7461··et="#idm8543"·ta 
0003ce30:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003ce40:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003ce50:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003ce60:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003ce70:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003ce80:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003ce90:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
Max diff block lines reached; 773604/788260 bytes (98.14%) of diff not shown.
84.7 KB
html2text {}
    
Offset 120, 20 lines modifiedOffset 120, 14 lines modified
120 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed120 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
121 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule121 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
122 Remediation_OSBuild_Blueprint_snippet_⇲122 Remediation_OSBuild_Blueprint_snippet_⇲
  
123 [[packages]]123 [[packages]]
124 name·=·"aide"124 name·=·"aide"
125 version·=·"*"125 version·=·"*"
126 Remediation_Anaconda_snippet_⇲ 
127 Complexity:·low 
128 Disruption:·low 
129 Strategy:···enable 
  
130 package·--add=aide 
131 Remediation_Puppet_snippet_⇲126 Remediation_Puppet_snippet_⇲
132 Complexity:·low127 Complexity:·low
133 Disruption:·low128 Disruption:·low
134 Strategy:···enable129 Strategy:···enable
135 include·install_aide130 include·install_aide
  
136 class·install_aide·{131 class·install_aide·{
Offset 151, 14 lines modifiedOffset 145, 20 lines modified
151 if·!·rpm·-q·--quiet·"aide"·;·then145 if·!·rpm·-q·--quiet·"aide"·;·then
152 ····yum·install·-y·"aide"146 ····yum·install·-y·"aide"
153 fi147 fi
  
154 else148 else
155 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
156 fi150 fi
 151 Remediation_Anaconda_snippet_⇲
 152 Complexity:·low
 153 Disruption:·low
 154 Strategy:···enable
  
 155 package·--add=aide
157 Remediation_Ansible_snippet_⇲156 Remediation_Ansible_snippet_⇲
158 Complexity:·low157 Complexity:·low
159 Disruption:·low158 Disruption:·low
160 Strategy:···enable159 Strategy:···enable
161 -·name:·Ensure·aide·is·installed160 -·name:·Ensure·aide·is·installed
162 ··package:161 ··package:
163 ····name:·aide162 ····name:·aide
Offset 1133, 20 lines modifiedOffset 1133, 14 lines modified
1133 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1133 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1134 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11134 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1135 Remediation_OSBuild_Blueprint_snippet_⇲1135 Remediation_OSBuild_Blueprint_snippet_⇲
  
1136 [[packages]]1136 [[packages]]
1137 name·=·"sudo"1137 name·=·"sudo"
1138 version·=·"*"1138 version·=·"*"
1139 Remediation_Anaconda_snippet_⇲ 
1140 Complexity:·low 
1141 Disruption:·low 
1142 Strategy:···enable 
  
1143 package·--add=sudo 
1144 Remediation_Puppet_snippet_⇲1139 Remediation_Puppet_snippet_⇲
1145 Complexity:·low1140 Complexity:·low
1146 Disruption:·low1141 Disruption:·low
1147 Strategy:···enable1142 Strategy:···enable
1148 include·install_sudo1143 include·install_sudo
  
1149 class·install_sudo·{1144 class·install_sudo·{
Offset 1164, 14 lines modifiedOffset 1158, 20 lines modified
1164 if·!·rpm·-q·--quiet·"sudo"·;·then1158 if·!·rpm·-q·--quiet·"sudo"·;·then
1165 ····yum·install·-y·"sudo"1159 ····yum·install·-y·"sudo"
1166 fi1160 fi
  
1167 else1161 else
1168 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1162 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1169 fi1163 fi
 1164 Remediation_Anaconda_snippet_⇲
 1165 Complexity:·low
 1166 Disruption:·low
 1167 Strategy:···enable
  
 1168 package·--add=sudo
1170 Remediation_Ansible_snippet_⇲1169 Remediation_Ansible_snippet_⇲
1171 Complexity:·low1170 Complexity:·low
1172 Disruption:·low1171 Disruption:·low
1173 Strategy:···enable1172 Strategy:···enable
1174 -·name:·Ensure·sudo·is·installed1173 -·name:·Ensure·sudo·is·installed
1175 ··package:1174 ··package:
1176 ····name:·sudo1175 ····name:·sudo
Offset 8098, 15 lines modifiedOffset 8098, 15 lines modified
8098 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg8098 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg
8099 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.28099 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
8100 Remediation_Shell_script_⇲8100 Remediation_Shell_script_⇲
8101 Complexity:·low8101 Complexity:·low
8102 Disruption:·low8102 Disruption:·low
8103 Strategy:···configure8103 Strategy:···configure
8104 #·Remediation·is·applicable·only·in·certain·platforms8104 #·Remediation·is·applicable·only·in·certain·platforms
8105 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then8105 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
8106 chgrp·0·/boot/grub2/grub.cfg8106 chgrp·0·/boot/grub2/grub.cfg
  
8107 else8107 else
8108 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8108 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8109 fi8109 fi
8110 Remediation_Ansible_snippet_⇲8110 Remediation_Ansible_snippet_⇲
Offset 8130, 16 lines modifiedOffset 8130, 16 lines modified
8130 ··-·no_reboot_needed8130 ··-·no_reboot_needed
  
8131 -·name:·Test·for·existence·/boot/grub2/grub.cfg8131 -·name:·Test·for·existence·/boot/grub2/grub.cfg
8132 ··stat:8132 ··stat:
8133 ····path:·/boot/grub2/grub.cfg8133 ····path:·/boot/grub2/grub.cfg
8134 ··register:·file_exists8134 ··register:·file_exists
8135 ··when:8135 ··when:
8136 ··-·'"grub2-common"·in·ansible_facts.packages' 
8137 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8136 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8137 ··-·'"grub2-common"·in·ansible_facts.packages'
8138 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8138 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8139 ··tags:8139 ··tags:
8140 ··-·CJIS-5.5.2.28140 ··-·CJIS-5.5.2.2
8141 ··-·NIST-800-171-3.4.58141 ··-·NIST-800-171-3.4.5
8142 ··-·NIST-800-53-AC-6(1)8142 ··-·NIST-800-53-AC-6(1)
8143 ··-·NIST-800-53-CM-6(a)8143 ··-·NIST-800-53-CM-6(a)
8144 ··-·PCI-DSS-Req-7.18144 ··-·PCI-DSS-Req-7.1
Offset 8151, 16 lines modifiedOffset 8151, 16 lines modified
8151 ··-·no_reboot_needed8151 ··-·no_reboot_needed
  
8152 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg8152 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
8153 ··file:8153 ··file:
8154 ····path:·/boot/grub2/grub.cfg8154 ····path:·/boot/grub2/grub.cfg
8155 ····group:·'0'8155 ····group:·'0'
8156 ··when:8156 ··when:
8157 ··-·'"grub2-common"·in·ansible_facts.packages' 
8158 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8157 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
Max diff block lines reached; 81791/86658 bytes (94.38%) of diff not shown.
1.71 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l2.html
    
Offset 15530, 116 lines modifiedOffset 15530, 116 lines modified
0003ca90:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003ca90:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003caa0:·2369·646d·3835·3431·2220·7461·6269·6e64··#idm8541"·tabind0003caa0:·2369·646d·3835·3431·2220·7461·6269·6e64··#idm8541"·tabind
0003cab0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003cab0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003cac0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003cac0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003cad0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003cad0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003cae0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003cae0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003caf0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003caf0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003cb00:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003cb00:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003cb10:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003cb10:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003cb20:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003cb20:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003cb30:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003cb30:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003cb40:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003cb40:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003cb50:·2269·646d·3835·3431·223e·3c74·6162·6c65··"idm8541"><table0003cb50:·646d·3835·3431·223e·3c74·6162·6c65·2063··dm8541"><table·c
0003cb60:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003cb60:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003cb70:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003cb70:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003cb80:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003cb80:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003cb90:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003cb90:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003cba0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003cba0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003cbb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003cbb0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003cbc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003cbc0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003cbd0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003cbd0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003cbe0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003cbe0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003cbf0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003cbf0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003cc00:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003cc00:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003cc10:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003cc10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0003cc20:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
0003cc30:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<0003cc20:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 0003cc30:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 0003cc40:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 0003cc50:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 0003cc60:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 0003cc70:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 0003cc80:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 0003cc90:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003cca0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003ccb0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003ccc0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003ccd0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003cce0:·646d·3835·3432·2220·7461·6269·6e64·6578··dm8542"·tabindex
 0003ccf0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003cd00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003cd10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003cd20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003cd30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003cd40:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 0003cd50:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003cd60:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003cd70:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003cd80:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm85
 0003cd90:·3432·223e·3c74·6162·6c65·2063·6c61·7373··42"><table·class
 0003cda0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003cdb0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003cdc0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003cdd0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003cde0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003cdf0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003ce00:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003ce10:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003ce20:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003ce30:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003ce40:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003ce50:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003ce60:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0003ce70:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0003ce80:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0003ce90:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
 0003cea0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
 0003ceb0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
 0003cec0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
 0003ced0:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.
 0003cee0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 0003cef0:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 0003cf00:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta
 0003cf10:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 0003cf20:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 0003cf30:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 0003cf40:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 0003cf50:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 0003cf60:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
0003cc40:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003cf70:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003cc50:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003cf80:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003cc60:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003cf90:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003cc70:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003cfa0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003cc80:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003cfb0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003cc90:·2223·6964·6d38·3534·3222·2074·6162·696e··"#idm8542"·tabin0003cfc0:·2223·6964·6d38·3534·3322·2074·6162·696e··"#idm8543"·tabin
0003cca0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003cfd0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003ccb0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003cfe0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003ccc0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003cff0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003ccd0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003d000:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003cce0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003d010:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003ccf0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup0003d020:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
0003cd00:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<0003d030:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
0003cd10:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003d040:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003cd20:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003d050:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003cd30:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003d060:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003cd40:·6964·6d38·3534·3222·3e3c·7461·626c·6520··idm8542"><table·0003d070:·3d22·6964·6d38·3534·3322·3e3c·7461·626c··="idm8543"><tabl
0003cd50:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003d080:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003cd60:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003d090:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003cd70:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003d0a0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003cd80:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003d0b0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003cd90:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003d0c0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003cda0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003d0d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003cdb0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003d0e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003cdc0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003d0f0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003cdd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003d100:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003cde0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003d110:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003cdf0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003d120:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003ce00:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003d130:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003d140:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003d150:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
0003ce10:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ 
0003ce20:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003ce30:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003ce40:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003ce50:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003ce60:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003ce70:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003ce80:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003ce90:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003cea0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003ceb0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003cec0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003ced0:·6964·6d38·3534·3322·2074·6162·696e·6465··idm8543"·tabinde 
0003cee0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003cef0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003cf00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003cf10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
Max diff block lines reached; 1435305/1449961 bytes (98.99%) of diff not shown.
335 KB
html2text {}
    
Offset 122, 20 lines modifiedOffset 122, 14 lines modified
122 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed122 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
123 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule123 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
124 Remediation_OSBuild_Blueprint_snippet_⇲124 Remediation_OSBuild_Blueprint_snippet_⇲
  
125 [[packages]]125 [[packages]]
126 name·=·"aide"126 name·=·"aide"
127 version·=·"*"127 version·=·"*"
128 Remediation_Anaconda_snippet_⇲ 
129 Complexity:·low 
130 Disruption:·low 
131 Strategy:···enable 
  
132 package·--add=aide 
133 Remediation_Puppet_snippet_⇲128 Remediation_Puppet_snippet_⇲
134 Complexity:·low129 Complexity:·low
135 Disruption:·low130 Disruption:·low
136 Strategy:···enable131 Strategy:···enable
137 include·install_aide132 include·install_aide
  
138 class·install_aide·{133 class·install_aide·{
Offset 153, 14 lines modifiedOffset 147, 20 lines modified
153 if·!·rpm·-q·--quiet·"aide"·;·then147 if·!·rpm·-q·--quiet·"aide"·;·then
154 ····yum·install·-y·"aide"148 ····yum·install·-y·"aide"
155 fi149 fi
  
156 else150 else
157 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'151 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
158 fi152 fi
 153 Remediation_Anaconda_snippet_⇲
 154 Complexity:·low
 155 Disruption:·low
 156 Strategy:···enable
  
 157 package·--add=aide
159 Remediation_Ansible_snippet_⇲158 Remediation_Ansible_snippet_⇲
160 Complexity:·low159 Complexity:·low
161 Disruption:·low160 Disruption:·low
162 Strategy:···enable161 Strategy:···enable
163 -·name:·Ensure·aide·is·installed162 -·name:·Ensure·aide·is·installed
164 ··package:163 ··package:
165 ····name:·aide164 ····name:·aide
Offset 1220, 20 lines modifiedOffset 1220, 14 lines modified
1220 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1220 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1221 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11221 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1222 Remediation_OSBuild_Blueprint_snippet_⇲1222 Remediation_OSBuild_Blueprint_snippet_⇲
  
1223 [[packages]]1223 [[packages]]
1224 name·=·"sudo"1224 name·=·"sudo"
1225 version·=·"*"1225 version·=·"*"
1226 Remediation_Anaconda_snippet_⇲ 
1227 Complexity:·low 
1228 Disruption:·low 
1229 Strategy:···enable 
  
1230 package·--add=sudo 
1231 Remediation_Puppet_snippet_⇲1226 Remediation_Puppet_snippet_⇲
1232 Complexity:·low1227 Complexity:·low
1233 Disruption:·low1228 Disruption:·low
1234 Strategy:···enable1229 Strategy:···enable
1235 include·install_sudo1230 include·install_sudo
  
1236 class·install_sudo·{1231 class·install_sudo·{
Offset 1251, 14 lines modifiedOffset 1245, 20 lines modified
1251 if·!·rpm·-q·--quiet·"sudo"·;·then1245 if·!·rpm·-q·--quiet·"sudo"·;·then
1252 ····yum·install·-y·"sudo"1246 ····yum·install·-y·"sudo"
1253 fi1247 fi
  
1254 else1248 else
1255 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1249 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1256 fi1250 fi
 1251 Remediation_Anaconda_snippet_⇲
 1252 Complexity:·low
 1253 Disruption:·low
 1254 Strategy:···enable
  
 1255 package·--add=sudo
1257 Remediation_Ansible_snippet_⇲1256 Remediation_Ansible_snippet_⇲
1258 Complexity:·low1257 Complexity:·low
1259 Disruption:·low1258 Disruption:·low
1260 Strategy:···enable1259 Strategy:···enable
1261 -·name:·Ensure·sudo·is·installed1260 -·name:·Ensure·sudo·is·installed
1262 ··package:1261 ··package:
1263 ····name:·sudo1262 ····name:·sudo
Offset 8241, 15 lines modifiedOffset 8241, 15 lines modified
8241 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.8241 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
8242 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.8242 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
8243 Severity: ················medium8243 Severity: ················medium
8244 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod8244 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
8245 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule8245 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule
8246 Remediation_Shell_script_⇲8246 Remediation_Shell_script_⇲
8247 #·Remediation·is·applicable·only·in·certain·platforms8247 #·Remediation·is·applicable·only·in·certain·platforms
8248 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8248 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8249 #·First·perform·the·remediation·of·the·syscall·rule8249 #·First·perform·the·remediation·of·the·syscall·rule
8250 #·Retrieve·hardware·architecture·of·the·underlying·system8250 #·Retrieve·hardware·architecture·of·the·underlying·system
8251 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8251 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8252 for·ARCH·in·"${RULE_ARCHS[@]}"8252 for·ARCH·in·"${RULE_ARCHS[@]}"
8253 do8253 do
Offset 8596, 16 lines modifiedOffset 8596, 16 lines modified
8596 ··-·reboot_required8596 ··-·reboot_required
8597 ··-·restrict_strategy8597 ··-·restrict_strategy
  
8598 -·name:·Set·architecture·for·audit·chmod·tasks8598 -·name:·Set·architecture·for·audit·chmod·tasks
8599 ··set_fact:8599 ··set_fact:
8600 ····audit_arch:·b648600 ····audit_arch:·b64
8601 ··when:8601 ··when:
8602 ··-·'"audit"·in·ansible_facts.packages' 
8603 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8602 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8603 ··-·'"audit"·in·ansible_facts.packages'
8604 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8604 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8605 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8605 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8606 ··tags:8606 ··tags:
8607 ··-·CJIS-5.4.1.18607 ··-·CJIS-5.4.1.1
8608 ··-·DISA-STIG-RHEL-08-0304908608 ··-·DISA-STIG-RHEL-08-030490
8609 ··-·NIST-800-171-3.1.78609 ··-·NIST-800-171-3.1.7
8610 ··-·NIST-800-53-AU-12(c)8610 ··-·NIST-800-53-AU-12(c)
Offset 8742, 16 lines modifiedOffset 8742, 16 lines modified
8742 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008742 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8743 ········-F·auid!=unset·-F·key=perm_mod8743 ········-F·auid!=unset·-F·key=perm_mod
8744 ······create:·true8744 ······create:·true
8745 ······mode:·o-rwx8745 ······mode:·o-rwx
8746 ······state:·present8746 ······state:·present
8747 ····when:·syscalls_found·|·length·==·08747 ····when:·syscalls_found·|·length·==·0
8748 ··when:8748 ··when:
8749 ··-·'"audit"·in·ansible_facts.packages' 
8750 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8749 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
Max diff block lines reached; 336266/342637 bytes (98.14%) of diff not shown.
609 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cjis.html
    
Offset 17345, 117 lines modifiedOffset 17345, 117 lines modified
00043c00:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00043c00:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00043c10:·3d22·2369·646d·3835·3431·2220·7461·6269··="#idm8541"·tabi00043c10:·3d22·2369·646d·3835·3431·2220·7461·6269··="#idm8541"·tabi
00043c20:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00043c20:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00043c30:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00043c30:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00043c40:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00043c40:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00043c50:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00043c50:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00043c60:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00043c60:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00043c70:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An00043c70:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
00043c80:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.00043c80:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
00043c90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00043c90:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
00043ca0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00043ca0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00043cb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00043cb0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
00043cc0:·643d·2269·646d·3835·3431·223e·3c74·6162··d="idm8541"><tab00043cc0:·2269·646d·3835·3431·223e·3c74·6162·6c65··"idm8541"><table
00043cd0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00043cd0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
00043ce0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00043ce0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00043cf0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00043cf0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00043d00:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00043d00:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
00043d10:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00043d10:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00043d20:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00043d20:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00043d30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00043d30:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
00043d40:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00043d40:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00043d50:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00043d50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00043d60:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy00043d60:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
00043d70:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable00043d70:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
00043d80:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl00043d80:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
00043d90:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa00043d90:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
00043da0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide00043da0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 00043db0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 00043dc0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 00043dd0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 00043de0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 00043df0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 00043e00:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 00043e10:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 00043e20:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 00043e30:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 00043e40:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 00043e50:·2369·646d·3835·3432·2220·7461·6269·6e64··#idm8542"·tabind
 00043e60:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 00043e70:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 00043e80:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 00043e90:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 00043ea0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 00043eb0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 00043ec0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 00043ed0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00043ee0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00043ef0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00043f00:·3835·3432·223e·3c74·6162·6c65·2063·6c61··8542"><table·cla
 00043f10:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 00043f20:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 00043f30:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 00043f40:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 00043f50:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 00043f60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00043f70:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 00043f80:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 00043f90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00043fa0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 00043fb0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 00043fc0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 00043fd0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 00043fe0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 00043ff0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 00044000:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 00044010:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
 00044020:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 00044030:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
 00044040:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the
 00044050:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 00044060:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 00044070:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 00044080:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 00044090:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 000440a0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 000440b0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 000440c0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 000440d0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
00043db0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></000440e0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
00043dc0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt000440f0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
00043dd0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d00044100:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
00043de0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll00044110:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
00043df0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00044120:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00043e00:·743d·2223·6964·6d38·3534·3222·2074·6162··t="#idm8542"·tab00044130:·743d·2223·6964·6d38·3534·3322·2074·6162··t="#idm8543"·tab
00043e10:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00044140:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00043e20:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00044150:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00043e30:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00044160:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00043e40:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00044170:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00043e50:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00044180:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00043e60:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P00044190:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
00043e70:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..000441a0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
00043e80:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl000441b0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00043e90:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla000441c0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00043ea0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id000441d0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00043eb0:·3d22·6964·6d38·3534·3222·3e3c·7461·626c··="idm8542"><tabl000441e0:·6964·3d22·6964·6d38·3534·3322·3e3c·7461··id="idm8543"><ta
00043ec0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t000441f0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
00043ed0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00044200:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
00043ee0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00044210:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
00043ef0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00044220:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
00043f00:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00044230:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
00043f10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00044240:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
00043f20:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00044250:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00043f30:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00044260:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
00043f40:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00044270:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
00043f50:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00044280:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
00043f60:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<00044290:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
00043f70:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table000442a0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
00043f80:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl000442b0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 000442c0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
00043f90:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
00043fa0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
00043fb0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
00043fc0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
00043fd0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
00043fe0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
00043ff0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00044000:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
00044010:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
00044020:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00044030:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00044040:·2223·6964·6d38·3534·3322·2074·6162·696e··"#idm8543"·tabin 
00044050:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00044060:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00044070:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00044080:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00044090:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
000440a0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
Max diff block lines reached; 427687/442481 bytes (96.66%) of diff not shown.
177 KB
html2text {}
    
Offset 407, 20 lines modifiedOffset 407, 14 lines modified
407 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed407 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
408 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule408 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
409 Remediation_OSBuild_Blueprint_snippet_⇲409 Remediation_OSBuild_Blueprint_snippet_⇲
  
410 [[packages]]410 [[packages]]
411 name·=·"aide"411 name·=·"aide"
412 version·=·"*"412 version·=·"*"
413 Remediation_Anaconda_snippet_⇲ 
414 Complexity:·low 
415 Disruption:·low 
416 Strategy:···enable 
  
417 package·--add=aide 
418 Remediation_Puppet_snippet_⇲413 Remediation_Puppet_snippet_⇲
419 Complexity:·low414 Complexity:·low
420 Disruption:·low415 Disruption:·low
421 Strategy:···enable416 Strategy:···enable
422 include·install_aide417 include·install_aide
  
423 class·install_aide·{418 class·install_aide·{
Offset 438, 14 lines modifiedOffset 432, 20 lines modified
438 if·!·rpm·-q·--quiet·"aide"·;·then432 if·!·rpm·-q·--quiet·"aide"·;·then
439 ····yum·install·-y·"aide"433 ····yum·install·-y·"aide"
440 fi434 fi
  
441 else435 else
442 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'436 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
443 fi437 fi
 438 Remediation_Anaconda_snippet_⇲
 439 Complexity:·low
 440 Disruption:·low
 441 Strategy:···enable
  
 442 package·--add=aide
444 Remediation_Ansible_snippet_⇲443 Remediation_Ansible_snippet_⇲
445 Complexity:·low444 Complexity:·low
446 Disruption:·low445 Disruption:·low
447 Strategy:···enable446 Strategy:···enable
448 -·name:·Ensure·aide·is·installed447 -·name:·Ensure·aide·is·installed
449 ··package:448 ··package:
450 ····name:·aide449 ····name:·aide
Offset 4397, 15 lines modifiedOffset 4397, 15 lines modified
4397 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.4397 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
4398 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.4398 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
4399 Severity: ················medium4399 Severity: ················medium
4400 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod4400 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
4401 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule4401 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule
4402 Remediation_Shell_script_⇲4402 Remediation_Shell_script_⇲
4403 #·Remediation·is·applicable·only·in·certain·platforms4403 #·Remediation·is·applicable·only·in·certain·platforms
4404 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then4404 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
4405 #·First·perform·the·remediation·of·the·syscall·rule4405 #·First·perform·the·remediation·of·the·syscall·rule
4406 #·Retrieve·hardware·architecture·of·the·underlying·system4406 #·Retrieve·hardware·architecture·of·the·underlying·system
4407 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4407 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4408 for·ARCH·in·"${RULE_ARCHS[@]}"4408 for·ARCH·in·"${RULE_ARCHS[@]}"
4409 do4409 do
Offset 4752, 16 lines modifiedOffset 4752, 16 lines modified
4752 ··-·reboot_required4752 ··-·reboot_required
4753 ··-·restrict_strategy4753 ··-·restrict_strategy
  
4754 -·name:·Set·architecture·for·audit·chmod·tasks4754 -·name:·Set·architecture·for·audit·chmod·tasks
4755 ··set_fact:4755 ··set_fact:
4756 ····audit_arch:·b644756 ····audit_arch:·b64
4757 ··when:4757 ··when:
4758 ··-·'"audit"·in·ansible_facts.packages' 
4759 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4758 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4759 ··-·'"audit"·in·ansible_facts.packages'
4760 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4760 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4761 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4761 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4762 ··tags:4762 ··tags:
4763 ··-·CJIS-5.4.1.14763 ··-·CJIS-5.4.1.1
4764 ··-·DISA-STIG-RHEL-08-0304904764 ··-·DISA-STIG-RHEL-08-030490
4765 ··-·NIST-800-171-3.1.74765 ··-·NIST-800-171-3.1.7
4766 ··-·NIST-800-53-AU-12(c)4766 ··-·NIST-800-53-AU-12(c)
Offset 4898, 16 lines modifiedOffset 4898, 16 lines modified
4898 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004898 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4899 ········-F·auid!=unset·-F·key=perm_mod4899 ········-F·auid!=unset·-F·key=perm_mod
4900 ······create:·true4900 ······create:·true
4901 ······mode:·o-rwx4901 ······mode:·o-rwx
4902 ······state:·present4902 ······state:·present
4903 ····when:·syscalls_found·|·length·==·04903 ····when:·syscalls_found·|·length·==·0
4904 ··when:4904 ··when:
4905 ··-·'"audit"·in·ansible_facts.packages' 
4906 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4905 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4906 ··-·'"audit"·in·ansible_facts.packages'
4907 ··tags:4907 ··tags:
4908 ··-·CJIS-5.4.1.14908 ··-·CJIS-5.4.1.1
4909 ··-·DISA-STIG-RHEL-08-0304904909 ··-·DISA-STIG-RHEL-08-030490
4910 ··-·NIST-800-171-3.1.74910 ··-·NIST-800-171-3.1.7
4911 ··-·NIST-800-53-AU-12(c)4911 ··-·NIST-800-53-AU-12(c)
4912 ··-·NIST-800-53-AU-2(d)4912 ··-·NIST-800-53-AU-2(d)
4913 ··-·NIST-800-53-CM-6(a)4913 ··-·NIST-800-53-CM-6(a)
Offset 5042, 16 lines modifiedOffset 5042, 16 lines modified
5042 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005042 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
5043 ········-F·auid!=unset·-F·key=perm_mod5043 ········-F·auid!=unset·-F·key=perm_mod
5044 ······create:·true5044 ······create:·true
5045 ······mode:·o-rwx5045 ······mode:·o-rwx
5046 ······state:·present5046 ······state:·present
5047 ····when:·syscalls_found·|·length·==·05047 ····when:·syscalls_found·|·length·==·0
5048 ··when:5048 ··when:
5049 ··-·'"audit"·in·ansible_facts.packages' 
5050 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5049 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5050 ··-·'"audit"·in·ansible_facts.packages'
5051 ··-·audit_arch·==·"b64"5051 ··-·audit_arch·==·"b64"
5052 ··tags:5052 ··tags:
5053 ··-·CJIS-5.4.1.15053 ··-·CJIS-5.4.1.1
5054 ··-·DISA-STIG-RHEL-08-0304905054 ··-·DISA-STIG-RHEL-08-030490
5055 ··-·NIST-800-171-3.1.75055 ··-·NIST-800-171-3.1.7
5056 ··-·NIST-800-53-AU-12(c)5056 ··-·NIST-800-53-AU-12(c)
5057 ··-·NIST-800-53-AU-2(d)5057 ··-·NIST-800-53-AU-2(d)
Offset 5075, 15 lines modifiedOffset 5075, 15 lines modified
5075 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.5075 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
5076 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.5076 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
5077 Severity: ················medium5077 Severity: ················medium
5078 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown5078 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
5079 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230455r810459_rule5079 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230455r810459_rule
5080 Remediation_Shell_script_⇲5080 Remediation_Shell_script_⇲
5081 #·Remediation·is·applicable·only·in·certain·platforms5081 #·Remediation·is·applicable·only·in·certain·platforms
5082 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then5082 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
5083 #·First·perform·the·remediation·of·the·syscall·rule5083 #·First·perform·the·remediation·of·the·syscall·rule
5084 #·Retrieve·hardware·architecture·of·the·underlying·system5084 #·Retrieve·hardware·architecture·of·the·underlying·system
5085 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")5085 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
5086 for·ARCH·in·"${RULE_ARCHS[@]}"5086 for·ARCH·in·"${RULE_ARCHS[@]}"
5087 do5087 do
Max diff block lines reached; 172181/181062 bytes (95.10%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cui.html
    
Offset 15545, 116 lines modifiedOffset 15545, 116 lines modified
0003cb80:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003cb80:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003cb90:·3534·3122·2074·6162·696e·6465·783d·2230··541"·tabindex="00003cb90:·3534·3122·2074·6162·696e·6465·783d·2230··541"·tabindex="0
0003cba0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003cba0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003cbb0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003cbb0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003cbc0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003cbc0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003cbd0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003cbd0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003cbe0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003cbe0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003cbf0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003cbf0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003cc00:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003cc00:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003cc10:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003cc10:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003cc20:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003cc20:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003cc30:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003cc30:·6170·7365·2220·6964·3d22·6964·6d38·3534··apse"·id="idm854
0003cc40:·3534·3122·3e3c·7461·626c·6520·636c·6173··541"><table·clas0003cc40:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=
0003cc50:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003cc50:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003cc60:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003cc60:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003cc70:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003cc70:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003cc80:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003cc80:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003cc90:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003cc90:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003cca0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003cca0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003ccb0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003ccb0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003ccc0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003ccc0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003ccd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003ccd0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003cce0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003cce0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003ccf0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003ccf0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003cd00:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003cd00:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003cd10:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003cd20:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003cd10:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003cd20:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003cd30:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003cd40:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003cd50:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003cd60:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003cd70:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003cd80:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003cd90:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003cda0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003cdb0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003cdc0:·2d74·6172·6765·743d·2223·6964·6d38·3534··-target="#idm854
 0003cdd0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
 0003cde0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003cdf0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003ce00:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003ce10:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003ce20:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003ce30:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003ce40:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003ce50:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003ce60:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003ce70:·2220·6964·3d22·6964·6d38·3534·3222·3e3c··"·id="idm8542"><
 0003ce80:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003ce90:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003cea0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003ceb0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003cec0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003ced0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003cee0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003cef0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003cf00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003cf10:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003cf20:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003cf30:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003cf40:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003cf50:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003cf60:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003cf70:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003cf80:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003cf90:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003cfa0:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003cfb0:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003cfc0:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003cfd0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003cfe0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003cff0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 0003d000:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003d010:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003d020:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003d030:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003d040:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003d050:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003cd30:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003d060:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003cd40:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003d070:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003cd50:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003d080:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003cd60:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003d090:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003cd70:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003d0a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003cd80:·3835·3432·2220·7461·6269·6e64·6578·3d22··8542"·tabindex="0003d0b0:·3835·3433·2220·7461·6269·6e64·6578·3d22··8543"·tabindex="
0003cd90:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003d0c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003cda0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003d0d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003cdb0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003d0e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003cdc0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003d0f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003cdd0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003d100:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003cde0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003d110:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003cdf0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003d120:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003ce00:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003d130:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003ce10:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003d140:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003ce20:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm850003d150:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003ce30:·3432·223e·3c74·6162·6c65·2063·6c61·7373··42"><table·class0003d160:·3835·3433·223e·3c74·6162·6c65·2063·6c61··8543"><table·cla
0003ce40:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003d170:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003ce50:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003d180:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003ce60:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003d190:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003ce70:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003d1a0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003ce80:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003d1b0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003ce90:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003d1c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003cea0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003d1d0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003ceb0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003d1e0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003cec0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003d1f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003ced0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003d200:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003cee0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003d210:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003cef0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003d220:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003d230:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003d240:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003cf00:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003cf10:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003cf20:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003cf30:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003cf40:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003cf50:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003cf60:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003cf70:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003cf80:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003cf90:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003cfa0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003cfb0:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm85 
0003cfc0:·3433·2220·7461·6269·6e64·6578·3d22·3022··43"·tabindex="0" 
0003cfd0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003cfe0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003cff0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003d000:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 974062/988718 bytes (98.52%) of diff not shown.
96.1 KB
html2text {}
    
Offset 126, 20 lines modifiedOffset 126, 14 lines modified
126 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed126 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
127 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule127 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
128 Remediation_OSBuild_Blueprint_snippet_⇲128 Remediation_OSBuild_Blueprint_snippet_⇲
  
129 [[packages]]129 [[packages]]
130 name·=·"aide"130 name·=·"aide"
131 version·=·"*"131 version·=·"*"
132 Remediation_Anaconda_snippet_⇲ 
133 Complexity:·low 
134 Disruption:·low 
135 Strategy:···enable 
  
136 package·--add=aide 
137 Remediation_Puppet_snippet_⇲132 Remediation_Puppet_snippet_⇲
138 Complexity:·low133 Complexity:·low
139 Disruption:·low134 Disruption:·low
140 Strategy:···enable135 Strategy:···enable
141 include·install_aide136 include·install_aide
  
142 class·install_aide·{137 class·install_aide·{
Offset 157, 14 lines modifiedOffset 151, 20 lines modified
157 if·!·rpm·-q·--quiet·"aide"·;·then151 if·!·rpm·-q·--quiet·"aide"·;·then
158 ····yum·install·-y·"aide"152 ····yum·install·-y·"aide"
159 fi153 fi
  
160 else154 else
161 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'155 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
162 fi156 fi
 157 Remediation_Anaconda_snippet_⇲
 158 Complexity:·low
 159 Disruption:·low
 160 Strategy:···enable
  
 161 package·--add=aide
163 Remediation_Ansible_snippet_⇲162 Remediation_Ansible_snippet_⇲
164 Complexity:·low163 Complexity:·low
165 Disruption:·low164 Disruption:·low
166 Strategy:···enable165 Strategy:···enable
167 -·name:·Ensure·aide·is·installed166 -·name:·Ensure·aide·is·installed
168 ··package:167 ··package:
169 ····name:·aide168 ····name:·aide
Offset 429, 20 lines modifiedOffset 429, 14 lines modified
429 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed429 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
430 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174430 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
431 Remediation_OSBuild_Blueprint_snippet_⇲431 Remediation_OSBuild_Blueprint_snippet_⇲
  
432 [[packages]]432 [[packages]]
433 name·=·"crypto-policies"433 name·=·"crypto-policies"
434 version·=·"*"434 version·=·"*"
435 Remediation_Anaconda_snippet_⇲ 
436 Complexity:·low 
437 Disruption:·low 
438 Strategy:···enable 
  
439 package·--add=crypto-policies 
440 Remediation_Puppet_snippet_⇲435 Remediation_Puppet_snippet_⇲
441 Complexity:·low436 Complexity:·low
442 Disruption:·low437 Disruption:·low
443 Strategy:···enable438 Strategy:···enable
444 include·install_crypto-policies439 include·install_crypto-policies
  
445 class·install_crypto-policies·{440 class·install_crypto-policies·{
Offset 454, 14 lines modifiedOffset 448, 20 lines modified
454 Complexity:·low448 Complexity:·low
455 Disruption:·low449 Disruption:·low
456 Strategy:···enable450 Strategy:···enable
  
457 if·!·rpm·-q·--quiet·"crypto-policies"·;·then451 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
458 ····yum·install·-y·"crypto-policies"452 ····yum·install·-y·"crypto-policies"
459 fi453 fi
 454 Remediation_Anaconda_snippet_⇲
 455 Complexity:·low
 456 Disruption:·low
 457 Strategy:···enable
  
 458 package·--add=crypto-policies
460 Remediation_Ansible_snippet_⇲459 Remediation_Ansible_snippet_⇲
461 Complexity:·low460 Complexity:·low
462 Disruption:·low461 Disruption:·low
463 Strategy:···enable462 Strategy:···enable
464 -·name:·Ensure·crypto-policies·is·installed463 -·name:·Ensure·crypto-policies·is·installed
465 ··package:464 ··package:
466 ····name:·crypto-policies465 ····name:·crypto-policies
Offset 1031, 20 lines modifiedOffset 1031, 14 lines modified
1031 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1031 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1032 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11032 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1033 Remediation_OSBuild_Blueprint_snippet_⇲1033 Remediation_OSBuild_Blueprint_snippet_⇲
  
1034 [[packages]]1034 [[packages]]
1035 name·=·"sudo"1035 name·=·"sudo"
1036 version·=·"*"1036 version·=·"*"
1037 Remediation_Anaconda_snippet_⇲ 
1038 Complexity:·low 
1039 Disruption:·low 
1040 Strategy:···enable 
  
1041 package·--add=sudo 
1042 Remediation_Puppet_snippet_⇲1037 Remediation_Puppet_snippet_⇲
1043 Complexity:·low1038 Complexity:·low
1044 Disruption:·low1039 Disruption:·low
1045 Strategy:···enable1040 Strategy:···enable
1046 include·install_sudo1041 include·install_sudo
  
1047 class·install_sudo·{1042 class·install_sudo·{
Offset 1062, 14 lines modifiedOffset 1056, 20 lines modified
1062 if·!·rpm·-q·--quiet·"sudo"·;·then1056 if·!·rpm·-q·--quiet·"sudo"·;·then
1063 ····yum·install·-y·"sudo"1057 ····yum·install·-y·"sudo"
1064 fi1058 fi
  
1065 else1059 else
1066 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1060 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1067 fi1061 fi
 1062 Remediation_Anaconda_snippet_⇲
 1063 Complexity:·low
 1064 Disruption:·low
 1065 Strategy:···enable
  
 1066 package·--add=sudo
1068 Remediation_Ansible_snippet_⇲1067 Remediation_Ansible_snippet_⇲
1069 Complexity:·low1068 Complexity:·low
1070 Disruption:·low1069 Disruption:·low
1071 Strategy:···enable1070 Strategy:···enable
1072 -·name:·Ensure·sudo·is·installed1071 -·name:·Ensure·sudo·is·installed
1073 ··package:1072 ··package:
1074 ····name:·sudo1073 ····name:·sudo
Offset 1094, 20 lines modifiedOffset 1094, 14 lines modified
1094 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed1094 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed
Max diff block lines reached; 94318/98335 bytes (95.91%) of diff not shown.
707 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-e8.html
    
Offset 20842, 104 lines modifiedOffset 20842, 104 lines modified
00051690:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm100051690:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
000516a0:·3331·3536·2220·7461·6269·6e64·6578·3d22··3156"·tabindex="000516a0:·3331·3536·2220·7461·6269·6e64·6578·3d22··3156"·tabindex="
000516b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"000516b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
000516c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="000516c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
000516d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac000516d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
000516e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal000516e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
000516f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme000516f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00051700:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda00051700:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
00051710:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>00051710:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00051720:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00051720:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00051730:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c00051730:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00051740:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm00051740:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13
00051750:·3133·3135·3622·3e3c·7461·626c·6520·636c··13156"><table·cl00051750:·3135·3622·3e3c·7461·626c·6520·636c·6173··156"><table·clas
00051760:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table00051760:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
00051770:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b00051770:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
00051780:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co00051780:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00051790:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th00051790:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
000517a0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th000517a0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
000517b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t000517b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
000517c0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup000517c0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
000517d0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo000517d0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
000517e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><000517e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
000517f0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th000517f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00051800:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>00051800:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
00051810:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr00051810:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
00051820:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
00051830:·202d·2d61·6464·3d72·6561·720a·3c2f·636f···--add=rear.</co 
00051840:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00051850:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00051860:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00051870:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
00051880:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
00051890:·646d·3133·3135·3722·2074·6162·696e·6465··dm13157"·tabinde 
000518a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
000518b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
000518c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
000518d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
000518e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
000518f0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe 
00051900:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a00051820:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 00051830:·7374·616c·6c5f·7265·6172·0a0a·636c·6173··stall_rear..clas
 00051840:·7320·696e·7374·616c·6c5f·7265·6172·207b··s·install_rear·{
 00051850:·0a20·2070·6163·6b61·6765·207b·2027·7265··.··package·{·'re
 00051860:·6172·273a·0a20·2020·2065·6e73·7572·6520··ar':.····ensure·
 00051870:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 00051880:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 00051890:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 000518a0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 000518b0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 000518c0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 000518d0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
 000518e0:·3331·3537·2220·7461·6269·6e64·6578·3d22··3157"·tabindex="
 000518f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 00051900:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 00051910:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 00051920:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 00051930:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00051940:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 00051950:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 00051960:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00051970:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00051980:·7073·6522·2069·643d·2269·646d·3133·3135··pse"·id="idm1315
00051910:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=00051990:·3722·3e3c·7461·626c·6520·636c·6173·733d··7"><table·class=
 000519a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 000519b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 000519c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 000519d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 000519e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
00051920:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00051930:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00051940:·6d31·3331·3537·223e·3c74·6162·6c65·2063··m13157"><table·c 
00051950:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00051960:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
00051970:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
00051980:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
00051990:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
000519a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
000519b0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
000519c0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
000519d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>000519f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
000519e0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
000519f0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
00051a00:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
00051a10:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
00051a20:·2069·6e73·7461·6c6c·5f72·6561·720a·0a63···install_rear..c 
00051a30:·6c61·7373·2069·6e73·7461·6c6c·5f72·6561··lass·install_rea 
00051a40:·7220·7b0a·2020·7061·636b·6167·6520·7b20··r·{.··package·{· 
00051a50:·2772·6561·7227·3a0a·2020·2020·656e·7375··'rear':.····ensu 
00051a60:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
00051a70:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
00051a80:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00051a90:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00051aa0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00051ab0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
00051ac0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
00051ad0:·646d·3133·3135·3822·2074·6162·696e·6465··dm13158"·tabinde 
00051ae0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00051af0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00051b00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00051b10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
00051b20:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
00051b30:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
00051b40:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><00051a00:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 00051a10:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00051a20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00051a30:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00051a40:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00051a50:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00051a60:·6f64·653e·0a69·6620·2120·7270·6d20·2d71··ode>.if·!·rpm·-q
 00051a70:·202d·2d71·7569·6574·2022·7265·6172·2220···--quiet·"rear"·
 00051a80:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 00051a90:·6e73·7461·6c6c·202d·7920·2272·6561·7222··nstall·-y·"rear"
 00051aa0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
 00051ab0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 00051ac0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 00051ad0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 00051ae0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 00051af0:·7267·6574·3d22·2369·646d·3133·3135·3822··rget="#idm13158"
 00051b00:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00051b10:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00051b20:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00051b30:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00051b40:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00051b50:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00051b60:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
 00051b70:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
00051b50:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p00051b80:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
Max diff block lines reached; 567215/580215 bytes (97.76%) of diff not shown.
140 KB
html2text {}
    
Offset 927, 20 lines modifiedOffset 927, 14 lines modified
927 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed927 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
928 Identifiers·and·References928 Identifiers·and·References
929 Remediation_OSBuild_Blueprint_snippet_⇲929 Remediation_OSBuild_Blueprint_snippet_⇲
  
930 [[packages]]930 [[packages]]
931 name·=·"rear"931 name·=·"rear"
932 version·=·"*"932 version·=·"*"
933 Remediation_Anaconda_snippet_⇲ 
934 Complexity:·low 
935 Disruption:·low 
936 Strategy:···enable 
  
937 package·--add=rear 
938 Remediation_Puppet_snippet_⇲933 Remediation_Puppet_snippet_⇲
939 Complexity:·low934 Complexity:·low
940 Disruption:·low935 Disruption:·low
941 Strategy:···enable936 Strategy:···enable
942 include·install_rear937 include·install_rear
  
943 class·install_rear·{938 class·install_rear·{
Offset 952, 14 lines modifiedOffset 946, 20 lines modified
952 Complexity:·low946 Complexity:·low
953 Disruption:·low947 Disruption:·low
954 Strategy:···enable948 Strategy:···enable
  
955 if·!·rpm·-q·--quiet·"rear"·;·then949 if·!·rpm·-q·--quiet·"rear"·;·then
956 ····yum·install·-y·"rear"950 ····yum·install·-y·"rear"
957 fi951 fi
 952 Remediation_Anaconda_snippet_⇲
 953 Complexity:·low
 954 Disruption:·low
 955 Strategy:···enable
  
 956 package·--add=rear
958 Remediation_Ansible_snippet_⇲957 Remediation_Ansible_snippet_⇲
959 Complexity:·low958 Complexity:·low
960 Disruption:·low959 Disruption:·low
961 Strategy:···enable960 Strategy:···enable
962 -·name:·Ensure·rear·is·installed961 -·name:·Ensure·rear·is·installed
963 ··package:962 ··package:
964 ····name:·rear963 ····name:·rear
Offset 1864, 15 lines modifiedOffset 1864, 15 lines modified
1864 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1864 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1865 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1865 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1866 Severity: ················medium1866 Severity: ················medium
1867 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1867 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1868 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule1868 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule
1869 Remediation_Shell_script_⇲1869 Remediation_Shell_script_⇲
1870 #·Remediation·is·applicable·only·in·certain·platforms1870 #·Remediation·is·applicable·only·in·certain·platforms
1871 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1871 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1872 #·First·perform·the·remediation·of·the·syscall·rule1872 #·First·perform·the·remediation·of·the·syscall·rule
1873 #·Retrieve·hardware·architecture·of·the·underlying·system1873 #·Retrieve·hardware·architecture·of·the·underlying·system
1874 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1874 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1875 for·ARCH·in·"${RULE_ARCHS[@]}"1875 for·ARCH·in·"${RULE_ARCHS[@]}"
1876 do1876 do
Offset 2219, 16 lines modifiedOffset 2219, 16 lines modified
2219 ··-·reboot_required2219 ··-·reboot_required
2220 ··-·restrict_strategy2220 ··-·restrict_strategy
  
2221 -·name:·Set·architecture·for·audit·chmod·tasks2221 -·name:·Set·architecture·for·audit·chmod·tasks
2222 ··set_fact:2222 ··set_fact:
2223 ····audit_arch:·b642223 ····audit_arch:·b64
2224 ··when:2224 ··when:
2225 ··-·'"audit"·in·ansible_facts.packages' 
2226 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2225 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2226 ··-·'"audit"·in·ansible_facts.packages'
2227 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2227 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2228 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2228 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2229 ··tags:2229 ··tags:
2230 ··-·CJIS-5.4.1.12230 ··-·CJIS-5.4.1.1
2231 ··-·DISA-STIG-RHEL-08-0304902231 ··-·DISA-STIG-RHEL-08-030490
2232 ··-·NIST-800-171-3.1.72232 ··-·NIST-800-171-3.1.7
2233 ··-·NIST-800-53-AU-12(c)2233 ··-·NIST-800-53-AU-12(c)
Offset 2365, 16 lines modifiedOffset 2365, 16 lines modified
2365 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002365 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2366 ········-F·auid!=unset·-F·key=perm_mod2366 ········-F·auid!=unset·-F·key=perm_mod
2367 ······create:·true2367 ······create:·true
2368 ······mode:·o-rwx2368 ······mode:·o-rwx
2369 ······state:·present2369 ······state:·present
2370 ····when:·syscalls_found·|·length·==·02370 ····when:·syscalls_found·|·length·==·0
2371 ··when:2371 ··when:
2372 ··-·'"audit"·in·ansible_facts.packages' 
2373 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2372 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2373 ··-·'"audit"·in·ansible_facts.packages'
2374 ··tags:2374 ··tags:
2375 ··-·CJIS-5.4.1.12375 ··-·CJIS-5.4.1.1
2376 ··-·DISA-STIG-RHEL-08-0304902376 ··-·DISA-STIG-RHEL-08-030490
2377 ··-·NIST-800-171-3.1.72377 ··-·NIST-800-171-3.1.7
2378 ··-·NIST-800-53-AU-12(c)2378 ··-·NIST-800-53-AU-12(c)
2379 ··-·NIST-800-53-AU-2(d)2379 ··-·NIST-800-53-AU-2(d)
2380 ··-·NIST-800-53-CM-6(a)2380 ··-·NIST-800-53-CM-6(a)
Offset 2509, 16 lines modifiedOffset 2509, 16 lines modified
2509 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002509 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2510 ········-F·auid!=unset·-F·key=perm_mod2510 ········-F·auid!=unset·-F·key=perm_mod
2511 ······create:·true2511 ······create:·true
2512 ······mode:·o-rwx2512 ······mode:·o-rwx
2513 ······state:·present2513 ······state:·present
2514 ····when:·syscalls_found·|·length·==·02514 ····when:·syscalls_found·|·length·==·0
2515 ··when:2515 ··when:
2516 ··-·'"audit"·in·ansible_facts.packages' 
2517 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2516 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2517 ··-·'"audit"·in·ansible_facts.packages'
2518 ··-·audit_arch·==·"b64"2518 ··-·audit_arch·==·"b64"
2519 ··tags:2519 ··tags:
2520 ··-·CJIS-5.4.1.12520 ··-·CJIS-5.4.1.1
2521 ··-·DISA-STIG-RHEL-08-0304902521 ··-·DISA-STIG-RHEL-08-030490
2522 ··-·NIST-800-171-3.1.72522 ··-·NIST-800-171-3.1.7
2523 ··-·NIST-800-53-AU-12(c)2523 ··-·NIST-800-53-AU-12(c)
2524 ··-·NIST-800-53-AU-2(d)2524 ··-·NIST-800-53-AU-2(d)
Offset 2542, 15 lines modifiedOffset 2542, 15 lines modified
2542 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2542 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2543 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2543 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2544 Severity: ················medium2544 Severity: ················medium
2545 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2545 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2546 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230455r810459_rule2546 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230455r810459_rule
2547 Remediation_Shell_script_⇲2547 Remediation_Shell_script_⇲
2548 #·Remediation·is·applicable·only·in·certain·platforms2548 #·Remediation·is·applicable·only·in·certain·platforms
2549 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2549 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2550 #·First·perform·the·remediation·of·the·syscall·rule2550 #·First·perform·the·remediation·of·the·syscall·rule
2551 #·Retrieve·hardware·architecture·of·the·underlying·system2551 #·Retrieve·hardware·architecture·of·the·underlying·system
2552 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2552 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2553 for·ARCH·in·"${RULE_ARCHS[@]}"2553 for·ARCH·in·"${RULE_ARCHS[@]}"
2554 do2554 do
Max diff block lines reached; 135559/143710 bytes (94.33%) of diff not shown.
1.25 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-hipaa.html
    
Offset 23335, 94 lines modifiedOffset 23335, 94 lines modified
0005b260:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0005b260:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0005b270:·2369·646d·3137·3033·3722·2074·6162·696e··#idm17037"·tabin0005b270:·2369·646d·3137·3033·3722·2074·6162·696e··#idm17037"·tabin
0005b280:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0005b280:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0005b290:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0005b290:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0005b2a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0005b2a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0005b2b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0005b2b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0005b2c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0005b2c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0005b2d0:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub0005b2d0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0005b2e0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0005b2f0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0005b300:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0005b310:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0005b320:·6c61·7073·6522·2069·643d·2269·646d·3137··lapse"·id="idm17
 0005b330:·3033·3722·3e3c·7072·653e·3c63·6f64·653e··037"><pre><code>
 0005b340:·0a5b·6375·7374·6f6d·697a·6174·696f·6e73··.[customizations
 0005b350:·2e73·6572·7669·6365·735d·0a64·6973·6162··.services].disab
 0005b360:·6c65·6420·3d20·5b22·6465·6275·672d·7368··led·=·["debug-sh
 0005b370:·656c·6c22·5d0a·3c2f·636f·6465·3e3c·2f70··ell"].</code></p
0005b2e0:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet· 
0005b2f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0005b300:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0005b310:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0005b320:·6964·3d22·6964·6d31·3730·3337·223e·3c70··id="idm17037"><p 
0005b330:·7265·3e3c·636f·6465·3e2d·2d2d·0a61·7069··re><code>---.api 
0005b340:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine 
0005b350:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op 
0005b360:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki 
0005b370:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi 
0005b380:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config 
0005b390:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:. 
0005b3a0:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3 
0005b3b0:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd 
0005b3c0:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.· 
0005b3d0:·2020·2020·202d·2065·6e61·626c·6564·3a20·······-·enabled:· 
0005b3e0:·6661·6c73·650a·2020·2020·2020·2020·6e61··false.········na 
0005b3f0:·6d65·3a20·6465·6275·672d·7368·656c·6c2e··me:·debug-shell. 
0005b400:·7365·7276·6963·650a·3c2f·636f·6465·3e3c··service.</code>< 
0005b410:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0005b380:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0005b420:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0005b390:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0005b430:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0005b3a0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0005b440:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0005b3b0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0005b450:·612d·7461·7267·6574·3d22·2369·646d·3137··a-target="#idm170005b3c0:·7461·7267·6574·3d22·2369·646d·3137·3033··target="#idm1703
0005b460:·3033·3822·2074·6162·696e·6465·783d·2230··038"·tabindex="00005b3d0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0005b470:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0005b3e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0005b480:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0005b3f0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0005b490:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0005b400:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0005b4a0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0005b410:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0005b4b0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0005b420:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0005b4c0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
0005b4d0:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
0005b4e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0005b4f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0005b500:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0005b510:·2069·643d·2269·646d·3137·3033·3822·3e3c···id="idm17038">< 
0005b520:·7072·653e·3c63·6f64·653e·0a5b·6375·7374··pre><code>.[cust 
0005b530:·6f6d·697a·6174·696f·6e73·2e73·6572·7669··omizations.servi 
0005b540:·6365·735d·0a64·6973·6162·6c65·6420·3d20··ces].disabled·=· 
0005b550:·5b22·6465·6275·672d·7368·656c·6c22·5d0a··["debug-shell"].0005b430:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
 0005b440:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0005b450:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0005b460:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0005b470:·7365·2220·6964·3d22·6964·6d31·3730·3338··se"·id="idm17038
 0005b480:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0005b490:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0005b4a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0005b4b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0005b4c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0005b4d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0005b4e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0005b4f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0005b500:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0005b510:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0005b520:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0005b530:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0005b540:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0005b550:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab
 0005b560:·6c65·5f64·6562·7567·2d73·6865·6c6c·0a0a··le_debug-shell..
 0005b570:·636c·6173·7320·6469·7361·626c·655f·6465··class·disable_de
 0005b580:·6275·672d·7368·656c·6c20·7b0a·2020·7365··bug-shell·{.··se
 0005b590:·7276·6963·6520·7b27·6465·6275·672d·7368··rvice·{'debug-sh
 0005b5a0:·656c·6c27·3a0a·2020·2020·656e·6162·6c65··ell':.····enable
 0005b5b0:·203d·2667·743b·2066·616c·7365·2c0a·2020···=&gt;·false,.··
 0005b5c0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0005b5d0:·7374·6f70·7065·6427·2c0a·2020·7d0a·7d0a··stopped',.··}.}.
0005b560:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0005b5e0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0005b570:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0005b5f0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0005b580:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0005b600:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0005b590:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0005b610:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0005b5a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0005b620:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0005b5b0:·3d22·2369·646d·3137·3033·3922·2074·6162··="#idm17039"·tab0005b630:·3d22·2369·646d·3137·3033·3922·2074·6162··="#idm17039"·tab
0005b5c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0005b640:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0005b5d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0005b650:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0005b5e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0005b660:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0005b5f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0005b670:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0005b600:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0005b680:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0005b610:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0005b690:·2122·3e52·656d·6564·6961·7469·6f6e·204b··!">Remediation·K
0005b620:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0005b6a0:·7562·6572·6e65·7465·7320·736e·6970·7065··ubernetes·snippe
0005b630:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0005b6b0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0005b640:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0005b6c0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0005b650:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0005b6d0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0005b660:·3d22·6964·6d31·3730·3339·223e·3c74·6162··="idm17039"><tab0005b6e0:·2220·6964·3d22·6964·6d31·3730·3339·223e··"·id="idm17039">
 0005b6f0:·3c70·7265·3e3c·636f·6465·3e2d·2d2d·0a61··<pre><code>---.a
 0005b700:·7069·5665·7273·696f·6e3a·206d·6163·6869··piVersion:·machi
 0005b710:·6e65·636f·6e66·6967·7572·6174·696f·6e2e··neconfiguration.
 0005b720:·6f70·656e·7368·6966·742e·696f·2f76·310a··openshift.io/v1.
 0005b730:·6b69·6e64·3a20·4d61·6368·696e·6543·6f6e··kind:·MachineCon
 0005b740:·6669·670a·7370·6563·3a0a·2020·636f·6e66··fig.spec:.··conf
 0005b750:·6967·3a0a·2020·2020·6967·6e69·7469·6f6e··ig:.····ignition
 0005b760:·3a0a·2020·2020·2020·7665·7273·696f·6e3a··:.······version:
 0005b770:·2033·2e31·2e30·0a20·2020·2073·7973·7465···3.1.0.····syste
 0005b780:·6d64·3a0a·2020·2020·2020·756e·6974·733a··md:.······units:
 0005b790:·0a20·2020·2020·202d·2065·6e61·626c·6564··.······-·enabled
 0005b7a0:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
 0005b7b0:·6e61·6d65·3a20·6465·6275·672d·7368·656c··name:·debug-shel
 0005b7c0:·6c2e·7365·7276·6963·650a·3c2f·636f·6465··l.service.</code
0005b670:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0005b680:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0005b690:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0005b6a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0005b6b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0005b6c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0005b6d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0005b6e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0005b6f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0005b700:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0005b710:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0005b720:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
Max diff block lines reached; 947567/959185 bytes (98.79%) of diff not shown.
346 KB
html2text {}
    
Offset 1336, 26 lines modifiedOffset 1336, 14 lines modified
  
1336 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:1336 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
1337 $·sudo·systemctl·mask·--now·debug-shell.service1337 $·sudo·systemctl·mask·--now·debug-shell.service
1338 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.1338 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
1339 Severity: ················medium1339 Severity: ················medium
1340 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1340 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1341 Identifiers·and·References·References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227,·SV-230532r627750_rule1341 Identifiers·and·References·References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227,·SV-230532r627750_rule
1342 Remediation_Kubernetes_snippet_⇲ 
1343 --- 
1344 apiVersion:·machineconfiguration.openshift.io/v1 
1345 kind:·MachineConfig 
1346 spec: 
1347 ··config: 
1348 ····ignition: 
1349 ······version:·3.1.0 
1350 ····systemd: 
1351 ······units: 
1352 ······-·enabled:·false 
1353 ········name:·debug-shell.service 
1354 Remediation_OSBuild_Blueprint_snippet_⇲1342 Remediation_OSBuild_Blueprint_snippet_⇲
  
1355 [customizations.services]1343 [customizations.services]
1356 disabled·=·["debug-shell"]1344 disabled·=·["debug-shell"]
1357 Remediation_Puppet_snippet_⇲1345 Remediation_Puppet_snippet_⇲
1358 Complexity:·low1346 Complexity:·low
1359 Disruption:·low1347 Disruption:·low
Offset 1364, 14 lines modifiedOffset 1352, 26 lines modified
  
1364 class·disable_debug-shell·{1352 class·disable_debug-shell·{
1365 ··service·{'debug-shell':1353 ··service·{'debug-shell':
1366 ····enable·=>·false,1354 ····enable·=>·false,
1367 ····ensure·=>·'stopped',1355 ····ensure·=>·'stopped',
1368 ··}1356 ··}
1369 }1357 }
 1358 Remediation_Kubernetes_snippet_⇲
 1359 ---
 1360 apiVersion:·machineconfiguration.openshift.io/v1
 1361 kind:·MachineConfig
 1362 spec:
 1363 ··config:
 1364 ····ignition:
 1365 ······version:·3.1.0
 1366 ····systemd:
 1367 ······units:
 1368 ······-·enabled:·false
 1369 ········name:·debug-shell.service
1370 Remediation_Shell_script_⇲1370 Remediation_Shell_script_⇲
1371 Complexity:·low1371 Complexity:·low
1372 Disruption:·low1372 Disruption:·low
1373 Strategy:···disable1373 Strategy:···disable
1374 #·Remediation·is·applicable·only·in·certain·platforms1374 #·Remediation·is·applicable·only·in·certain·platforms
1375 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1375 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
Offset 2273, 15 lines modifiedOffset 2273, 15 lines modified
2273 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2273 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2274 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2274 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2275 Severity: ················medium2275 Severity: ················medium
2276 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod2276 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
2277 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule2277 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule
2278 Remediation_Shell_script_⇲2278 Remediation_Shell_script_⇲
2279 #·Remediation·is·applicable·only·in·certain·platforms2279 #·Remediation·is·applicable·only·in·certain·platforms
2280 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2280 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2281 #·First·perform·the·remediation·of·the·syscall·rule2281 #·First·perform·the·remediation·of·the·syscall·rule
2282 #·Retrieve·hardware·architecture·of·the·underlying·system2282 #·Retrieve·hardware·architecture·of·the·underlying·system
2283 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2283 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2284 for·ARCH·in·"${RULE_ARCHS[@]}"2284 for·ARCH·in·"${RULE_ARCHS[@]}"
2285 do2285 do
Offset 2628, 16 lines modifiedOffset 2628, 16 lines modified
2628 ··-·reboot_required2628 ··-·reboot_required
2629 ··-·restrict_strategy2629 ··-·restrict_strategy
  
2630 -·name:·Set·architecture·for·audit·chmod·tasks2630 -·name:·Set·architecture·for·audit·chmod·tasks
2631 ··set_fact:2631 ··set_fact:
2632 ····audit_arch:·b642632 ····audit_arch:·b64
2633 ··when:2633 ··when:
2634 ··-·'"audit"·in·ansible_facts.packages' 
2635 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2634 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2635 ··-·'"audit"·in·ansible_facts.packages'
2636 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2636 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2637 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2637 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2638 ··tags:2638 ··tags:
2639 ··-·CJIS-5.4.1.12639 ··-·CJIS-5.4.1.1
2640 ··-·DISA-STIG-RHEL-08-0304902640 ··-·DISA-STIG-RHEL-08-030490
2641 ··-·NIST-800-171-3.1.72641 ··-·NIST-800-171-3.1.7
2642 ··-·NIST-800-53-AU-12(c)2642 ··-·NIST-800-53-AU-12(c)
Offset 2774, 16 lines modifiedOffset 2774, 16 lines modified
2774 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002774 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2775 ········-F·auid!=unset·-F·key=perm_mod2775 ········-F·auid!=unset·-F·key=perm_mod
2776 ······create:·true2776 ······create:·true
2777 ······mode:·o-rwx2777 ······mode:·o-rwx
2778 ······state:·present2778 ······state:·present
2779 ····when:·syscalls_found·|·length·==·02779 ····when:·syscalls_found·|·length·==·0
2780 ··when:2780 ··when:
2781 ··-·'"audit"·in·ansible_facts.packages' 
2782 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2781 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2782 ··-·'"audit"·in·ansible_facts.packages'
2783 ··tags:2783 ··tags:
2784 ··-·CJIS-5.4.1.12784 ··-·CJIS-5.4.1.1
2785 ··-·DISA-STIG-RHEL-08-0304902785 ··-·DISA-STIG-RHEL-08-030490
2786 ··-·NIST-800-171-3.1.72786 ··-·NIST-800-171-3.1.7
2787 ··-·NIST-800-53-AU-12(c)2787 ··-·NIST-800-53-AU-12(c)
2788 ··-·NIST-800-53-AU-2(d)2788 ··-·NIST-800-53-AU-2(d)
2789 ··-·NIST-800-53-CM-6(a)2789 ··-·NIST-800-53-CM-6(a)
Offset 2918, 16 lines modifiedOffset 2918, 16 lines modified
2918 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002918 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2919 ········-F·auid!=unset·-F·key=perm_mod2919 ········-F·auid!=unset·-F·key=perm_mod
2920 ······create:·true2920 ······create:·true
2921 ······mode:·o-rwx2921 ······mode:·o-rwx
2922 ······state:·present2922 ······state:·present
2923 ····when:·syscalls_found·|·length·==·02923 ····when:·syscalls_found·|·length·==·0
2924 ··when:2924 ··when:
2925 ··-·'"audit"·in·ansible_facts.packages' 
2926 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2925 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2926 ··-·'"audit"·in·ansible_facts.packages'
2927 ··-·audit_arch·==·"b64"2927 ··-·audit_arch·==·"b64"
2928 ··tags:2928 ··tags:
2929 ··-·CJIS-5.4.1.12929 ··-·CJIS-5.4.1.1
2930 ··-·DISA-STIG-RHEL-08-0304902930 ··-·DISA-STIG-RHEL-08-030490
2931 ··-·NIST-800-171-3.1.72931 ··-·NIST-800-171-3.1.7
2932 ··-·NIST-800-53-AU-12(c)2932 ··-·NIST-800-53-AU-12(c)
2933 ··-·NIST-800-53-AU-2(d)2933 ··-·NIST-800-53-AU-2(d)
Offset 2951, 15 lines modifiedOffset 2951, 15 lines modified
2951 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2951 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2952 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2952 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2953 Severity: ················medium2953 Severity: ················medium
Max diff block lines reached; 347062/354223 bytes (97.98%) of diff not shown.
890 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ism_o.html
    
Offset 18355, 116 lines modifiedOffset 18355, 116 lines modified
00047b20:·6765·743d·2223·6964·6d38·3534·3122·2074··get="#idm8541"·t00047b20:·6765·743d·2223·6964·6d38·3534·3122·2074··get="#idm8541"·t
00047b30:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00047b30:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00047b40:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00047b40:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00047b50:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00047b50:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00047b60:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00047b60:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00047b70:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00047b70:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00047b80:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00047b80:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00047b90:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe00047b90:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
00047ba0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00047ba0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00047bb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00047bb0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00047bc0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00047bc0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00047bd0:·2220·6964·3d22·6964·6d38·3534·3122·3e3c··"·id="idm8541"><00047bd0:·6964·3d22·6964·6d38·3534·3122·3e3c·7461··id="idm8541"><ta
00047be0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00047be0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
00047bf0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00047bf0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
00047c00:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00047c00:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
00047c10:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00047c10:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
00047c20:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00047c20:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
00047c30:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low00047c30:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
00047c40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00047c40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00047c50:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t00047c50:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
00047c60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00047c60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
00047c70:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat00047c70:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
00047c80:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena00047c80:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
00047c90:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t00047c90:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
00047ca0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00047ca0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
00047cb0:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a00047cb0:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai
 00047cc0:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal
 00047cd0:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa
 00047ce0:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.···
 00047cf0:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i
 00047d00:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.}
 00047d10:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00047d20:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00047d30:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00047d40:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 00047d50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 00047d60:·743d·2223·6964·6d38·3534·3222·2074·6162··t="#idm8542"·tab
 00047d70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00047d80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00047d90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00047da0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 00047db0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 00047dc0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 00047dd0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 00047de0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00047df0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00047e00:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00047e10:·6964·6d38·3534·3222·3e3c·7461·626c·6520··idm8542"><table·
 00047e20:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00047e30:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00047e40:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00047e50:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00047e60:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 00047e70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00047e80:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 00047e90:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 00047ea0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00047eb0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00047ec0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00047ed0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00047ee0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 00047ef0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00047f00:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00047f10:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00047f20:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
 00047f30:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
 00047f40:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
 00047f50:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·
 00047f60:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 00047f70:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 00047f80:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
 00047f90:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 00047fa0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 00047fb0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 00047fc0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 00047fd0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 00047fe0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
00047cc0:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre00047ff0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
00047cd0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=00048000:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
00047ce0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success00048010:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
00047cf0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c00048020:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
00047d00:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta00048030:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
00047d10:·7267·6574·3d22·2369·646d·3835·3432·2220··rget="#idm8542"·00048040:·7267·6574·3d22·2369·646d·3835·3433·2220··rget="#idm8543"·
00047d20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00048050:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00047d30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00048060:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
00047d40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00048070:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
00047d50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00048080:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
00047d60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00048090:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
00047d70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio000480a0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
00047d80:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet000480b0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
00047d90:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div000480c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
00047da0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000480d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
00047db0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"000480e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
00047dc0:·2069·643d·2269·646d·3835·3432·223e·3c74···id="idm8542"><t000480f0:·6522·2069·643d·2269·646d·3835·3433·223e··e"·id="idm8543">
00047dd0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00048100:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
00047de0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00048110:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
00047df0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00048120:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
00047e00:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00048130:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
00047e10:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00048140:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
00047e20:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<00048150:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
00047e30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00048160:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
00047e40:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th00048170:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
00047e50:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t00048180:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00047e60:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate00048190:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
00047e70:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab000481a0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
00047e80:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta000481b0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
00047e90:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i000481c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 000481d0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=
00047ea0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a 
00047eb0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta 
00047ec0:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack 
00047ed0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.·· 
00047ee0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
00047ef0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
00047f00:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
00047f10:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00047f20:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00047f30:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00047f40:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00047f50:·6574·3d22·2369·646d·3835·3433·2220·7461··et="#idm8543"·ta 
00047f60:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00047f70:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00047f80:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00047f90:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00047fa0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00047fb0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00047fc0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
Max diff block lines reached; 722952/737608 bytes (98.01%) of diff not shown.
170 KB
html2text {}
    
Offset 535, 20 lines modifiedOffset 535, 14 lines modified
535 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed535 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
536 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule536 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
537 Remediation_OSBuild_Blueprint_snippet_⇲537 Remediation_OSBuild_Blueprint_snippet_⇲
  
538 [[packages]]538 [[packages]]
539 name·=·"aide"539 name·=·"aide"
540 version·=·"*"540 version·=·"*"
541 Remediation_Anaconda_snippet_⇲ 
542 Complexity:·low 
543 Disruption:·low 
544 Strategy:···enable 
  
545 package·--add=aide 
546 Remediation_Puppet_snippet_⇲541 Remediation_Puppet_snippet_⇲
547 Complexity:·low542 Complexity:·low
548 Disruption:·low543 Disruption:·low
549 Strategy:···enable544 Strategy:···enable
550 include·install_aide545 include·install_aide
  
551 class·install_aide·{546 class·install_aide·{
Offset 566, 14 lines modifiedOffset 560, 20 lines modified
566 if·!·rpm·-q·--quiet·"aide"·;·then560 if·!·rpm·-q·--quiet·"aide"·;·then
567 ····yum·install·-y·"aide"561 ····yum·install·-y·"aide"
568 fi562 fi
  
569 else563 else
570 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'564 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
571 fi565 fi
 566 Remediation_Anaconda_snippet_⇲
 567 Complexity:·low
 568 Disruption:·low
 569 Strategy:···enable
  
 570 package·--add=aide
572 Remediation_Ansible_snippet_⇲571 Remediation_Ansible_snippet_⇲
573 Complexity:·low572 Complexity:·low
574 Disruption:·low573 Disruption:·low
575 Strategy:···enable574 Strategy:···enable
576 -·name:·Ensure·aide·is·installed575 -·name:·Ensure·aide·is·installed
577 ··package:576 ··package:
578 ····name:·aide577 ····name:·aide
Offset 1002, 20 lines modifiedOffset 1002, 14 lines modified
1002 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1002 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1003 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11003 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1004 Remediation_OSBuild_Blueprint_snippet_⇲1004 Remediation_OSBuild_Blueprint_snippet_⇲
  
1005 [[packages]]1005 [[packages]]
1006 name·=·"sudo"1006 name·=·"sudo"
1007 version·=·"*"1007 version·=·"*"
1008 Remediation_Anaconda_snippet_⇲ 
1009 Complexity:·low 
1010 Disruption:·low 
1011 Strategy:···enable 
  
1012 package·--add=sudo 
1013 Remediation_Puppet_snippet_⇲1008 Remediation_Puppet_snippet_⇲
1014 Complexity:·low1009 Complexity:·low
1015 Disruption:·low1010 Disruption:·low
1016 Strategy:···enable1011 Strategy:···enable
1017 include·install_sudo1012 include·install_sudo
  
1018 class·install_sudo·{1013 class·install_sudo·{
Offset 1033, 14 lines modifiedOffset 1027, 20 lines modified
1033 if·!·rpm·-q·--quiet·"sudo"·;·then1027 if·!·rpm·-q·--quiet·"sudo"·;·then
1034 ····yum·install·-y·"sudo"1028 ····yum·install·-y·"sudo"
1035 fi1029 fi
  
1036 else1030 else
1037 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1031 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1038 fi1032 fi
 1033 Remediation_Anaconda_snippet_⇲
 1034 Complexity:·low
 1035 Disruption:·low
 1036 Strategy:···enable
  
 1037 package·--add=sudo
1039 Remediation_Ansible_snippet_⇲1038 Remediation_Ansible_snippet_⇲
1040 Complexity:·low1039 Complexity:·low
1041 Disruption:·low1040 Disruption:·low
1042 Strategy:···enable1041 Strategy:···enable
1043 -·name:·Ensure·sudo·is·installed1042 -·name:·Ensure·sudo·is·installed
1044 ··package:1043 ··package:
1045 ····name:·sudo1044 ····name:·sudo
Offset 1311, 20 lines modifiedOffset 1311, 14 lines modified
1311 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed1311 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
1312 Identifiers·and·References1312 Identifiers·and·References
1313 Remediation_OSBuild_Blueprint_snippet_⇲1313 Remediation_OSBuild_Blueprint_snippet_⇲
  
1314 [[packages]]1314 [[packages]]
1315 name·=·"rear"1315 name·=·"rear"
1316 version·=·"*"1316 version·=·"*"
1317 Remediation_Anaconda_snippet_⇲ 
1318 Complexity:·low 
1319 Disruption:·low 
1320 Strategy:···enable 
  
1321 package·--add=rear 
1322 Remediation_Puppet_snippet_⇲1317 Remediation_Puppet_snippet_⇲
1323 Complexity:·low1318 Complexity:·low
1324 Disruption:·low1319 Disruption:·low
1325 Strategy:···enable1320 Strategy:···enable
1326 include·install_rear1321 include·install_rear
  
1327 class·install_rear·{1322 class·install_rear·{
Offset 1336, 14 lines modifiedOffset 1330, 20 lines modified
1336 Complexity:·low1330 Complexity:·low
1337 Disruption:·low1331 Disruption:·low
1338 Strategy:···enable1332 Strategy:···enable
  
1339 if·!·rpm·-q·--quiet·"rear"·;·then1333 if·!·rpm·-q·--quiet·"rear"·;·then
1340 ····yum·install·-y·"rear"1334 ····yum·install·-y·"rear"
1341 fi1335 fi
 1336 Remediation_Anaconda_snippet_⇲
 1337 Complexity:·low
 1338 Disruption:·low
 1339 Strategy:···enable
  
 1340 package·--add=rear
1342 Remediation_Ansible_snippet_⇲1341 Remediation_Ansible_snippet_⇲
1343 Complexity:·low1342 Complexity:·low
1344 Disruption:·low1343 Disruption:·low
1345 Strategy:···enable1344 Strategy:···enable
1346 -·name:·Ensure·rear·is·installed1345 -·name:·Ensure·rear·is·installed
1347 ··package:1346 ··package:
1348 ····name:·rear1347 ····name:·rear
Offset 6376, 15 lines modifiedOffset 6376, 15 lines modified
6376 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.6376 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
Max diff block lines reached; 169965/174015 bytes (97.67%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ospp.html
    
Offset 15518, 116 lines modifiedOffset 15518, 116 lines modified
0003c9d0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003c9d0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003c9e0:·6964·6d38·3534·3122·2074·6162·696e·6465··idm8541"·tabinde0003c9e0:·6964·6d38·3534·3122·2074·6162·696e·6465··idm8541"·tabinde
0003c9f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003c9f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003ca00:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003ca00:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003ca10:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003ca10:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003ca20:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003ca20:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003ca30:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003ca30:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003ca40:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003ca40:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
0003ca50:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003ca50:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003ca60:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003ca60:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003ca70:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003ca70:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003ca80:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003ca80:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003ca90:·6964·6d38·3534·3122·3e3c·7461·626c·6520··idm8541"><table·0003ca90:·6d38·3534·3122·3e3c·7461·626c·6520·636c··m8541"><table·cl
0003caa0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003caa0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003cab0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003cab0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003cac0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003cac0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003cad0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003cad0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003cae0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003cae0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003caf0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003caf0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003cb00:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003cb00:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003cb10:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003cb10:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003cb20:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003cb20:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003cb30:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003cb30:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003cb40:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003cb40:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003cb50:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003cb50:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003cb60:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003cb70:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</0003cb60:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003cb70:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003cb80:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003cb90:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003cba0:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003cbb0:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003cbc0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003cbd0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003cbe0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003cbf0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003cc00:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003cc10:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003cc20:·6d38·3534·3222·2074·6162·696e·6465·783d··m8542"·tabindex=
 0003cc30:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003cc40:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003cc50:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003cc60:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003cc70:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003cc80:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003cc90:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003cca0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003ccb0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003ccc0:·6170·7365·2220·6964·3d22·6964·6d38·3534··apse"·id="idm854
 0003ccd0:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 0003cce0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003ccf0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003cd00:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003cd10:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003cd20:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003cd30:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003cd40:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003cd50:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003cd60:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003cd70:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003cd80:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003cd90:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003cda0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 0003cdb0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 0003cdc0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 0003cdd0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
 0003cde0:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
 0003cdf0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
 0003ce00:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 0003ce10:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
 0003ce20:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003ce30:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003ce40:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 0003ce50:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003ce60:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003ce70:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003ce80:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003ce90:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003cea0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
0003cb80:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003ceb0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003cb90:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003cec0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003cba0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003ced0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003cbb0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003cee0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003cbc0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003cef0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003cbd0:·2369·646d·3835·3432·2220·7461·6269·6e64··#idm8542"·tabind0003cf00:·2369·646d·3835·3433·2220·7461·6269·6e64··#idm8543"·tabind
0003cbe0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003cf10:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003cbf0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003cf20:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003cc00:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003cf30:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003cc10:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003cf40:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003cc20:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003cf50:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003cc30:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003cf60:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003cc40:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003cf70:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003cc50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003cf80:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003cc60:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003cf90:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003cc70:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003cfa0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003cc80:·646d·3835·3432·223e·3c74·6162·6c65·2063··dm8542"><table·c0003cfb0:·2269·646d·3835·3433·223e·3c74·6162·6c65··"idm8543"><table
0003cc90:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003cfc0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003cca0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003cfd0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003ccb0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003cfe0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003ccc0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003cff0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003ccd0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003d000:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003cce0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003d010:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003ccf0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003d020:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003cd00:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003d030:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003cd10:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003d040:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003cd20:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003d050:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003cd30:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003d060:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003cd40:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003d070:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003d080:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003d090:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
0003cd50:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003cd60:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003cd70:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003cd80:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003cd90:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003cda0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003cdb0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003cdc0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003cdd0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003cde0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003cdf0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003ce00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003ce10:·646d·3835·3433·2220·7461·6269·6e64·6578··dm8543"·tabindex 
0003ce20:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003ce30:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003ce40:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003ce50:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
Max diff block lines reached; 973234/987890 bytes (98.52%) of diff not shown.
96.1 KB
html2text {}
    
Offset 118, 20 lines modifiedOffset 118, 14 lines modified
118 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed118 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
119 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule119 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
120 Remediation_OSBuild_Blueprint_snippet_⇲120 Remediation_OSBuild_Blueprint_snippet_⇲
  
121 [[packages]]121 [[packages]]
122 name·=·"aide"122 name·=·"aide"
123 version·=·"*"123 version·=·"*"
124 Remediation_Anaconda_snippet_⇲ 
125 Complexity:·low 
126 Disruption:·low 
127 Strategy:···enable 
  
128 package·--add=aide 
129 Remediation_Puppet_snippet_⇲124 Remediation_Puppet_snippet_⇲
130 Complexity:·low125 Complexity:·low
131 Disruption:·low126 Disruption:·low
132 Strategy:···enable127 Strategy:···enable
133 include·install_aide128 include·install_aide
  
134 class·install_aide·{129 class·install_aide·{
Offset 149, 14 lines modifiedOffset 143, 20 lines modified
149 if·!·rpm·-q·--quiet·"aide"·;·then143 if·!·rpm·-q·--quiet·"aide"·;·then
150 ····yum·install·-y·"aide"144 ····yum·install·-y·"aide"
151 fi145 fi
  
152 else146 else
153 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'147 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
154 fi148 fi
 149 Remediation_Anaconda_snippet_⇲
 150 Complexity:·low
 151 Disruption:·low
 152 Strategy:···enable
  
 153 package·--add=aide
155 Remediation_Ansible_snippet_⇲154 Remediation_Ansible_snippet_⇲
156 Complexity:·low155 Complexity:·low
157 Disruption:·low156 Disruption:·low
158 Strategy:···enable157 Strategy:···enable
159 -·name:·Ensure·aide·is·installed158 -·name:·Ensure·aide·is·installed
160 ··package:159 ··package:
161 ····name:·aide160 ····name:·aide
Offset 421, 20 lines modifiedOffset 421, 14 lines modified
421 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed421 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
422 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174422 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
423 Remediation_OSBuild_Blueprint_snippet_⇲423 Remediation_OSBuild_Blueprint_snippet_⇲
  
424 [[packages]]424 [[packages]]
425 name·=·"crypto-policies"425 name·=·"crypto-policies"
426 version·=·"*"426 version·=·"*"
427 Remediation_Anaconda_snippet_⇲ 
428 Complexity:·low 
429 Disruption:·low 
430 Strategy:···enable 
  
431 package·--add=crypto-policies 
432 Remediation_Puppet_snippet_⇲427 Remediation_Puppet_snippet_⇲
433 Complexity:·low428 Complexity:·low
434 Disruption:·low429 Disruption:·low
435 Strategy:···enable430 Strategy:···enable
436 include·install_crypto-policies431 include·install_crypto-policies
  
437 class·install_crypto-policies·{432 class·install_crypto-policies·{
Offset 446, 14 lines modifiedOffset 440, 20 lines modified
446 Complexity:·low440 Complexity:·low
447 Disruption:·low441 Disruption:·low
448 Strategy:···enable442 Strategy:···enable
  
449 if·!·rpm·-q·--quiet·"crypto-policies"·;·then443 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
450 ····yum·install·-y·"crypto-policies"444 ····yum·install·-y·"crypto-policies"
451 fi445 fi
 446 Remediation_Anaconda_snippet_⇲
 447 Complexity:·low
 448 Disruption:·low
 449 Strategy:···enable
  
 450 package·--add=crypto-policies
452 Remediation_Ansible_snippet_⇲451 Remediation_Ansible_snippet_⇲
453 Complexity:·low452 Complexity:·low
454 Disruption:·low453 Disruption:·low
455 Strategy:···enable454 Strategy:···enable
456 -·name:·Ensure·crypto-policies·is·installed455 -·name:·Ensure·crypto-policies·is·installed
457 ··package:456 ··package:
458 ····name:·crypto-policies457 ····name:·crypto-policies
Offset 1023, 20 lines modifiedOffset 1023, 14 lines modified
1023 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1023 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1024 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11024 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1025 Remediation_OSBuild_Blueprint_snippet_⇲1025 Remediation_OSBuild_Blueprint_snippet_⇲
  
1026 [[packages]]1026 [[packages]]
1027 name·=·"sudo"1027 name·=·"sudo"
1028 version·=·"*"1028 version·=·"*"
1029 Remediation_Anaconda_snippet_⇲ 
1030 Complexity:·low 
1031 Disruption:·low 
1032 Strategy:···enable 
  
1033 package·--add=sudo 
1034 Remediation_Puppet_snippet_⇲1029 Remediation_Puppet_snippet_⇲
1035 Complexity:·low1030 Complexity:·low
1036 Disruption:·low1031 Disruption:·low
1037 Strategy:···enable1032 Strategy:···enable
1038 include·install_sudo1033 include·install_sudo
  
1039 class·install_sudo·{1034 class·install_sudo·{
Offset 1054, 14 lines modifiedOffset 1048, 20 lines modified
1054 if·!·rpm·-q·--quiet·"sudo"·;·then1048 if·!·rpm·-q·--quiet·"sudo"·;·then
1055 ····yum·install·-y·"sudo"1049 ····yum·install·-y·"sudo"
1056 fi1050 fi
  
1057 else1051 else
1058 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1052 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1059 fi1053 fi
 1054 Remediation_Anaconda_snippet_⇲
 1055 Complexity:·low
 1056 Disruption:·low
 1057 Strategy:···enable
  
 1058 package·--add=sudo
1060 Remediation_Ansible_snippet_⇲1059 Remediation_Ansible_snippet_⇲
1061 Complexity:·low1060 Complexity:·low
1062 Disruption:·low1061 Disruption:·low
1063 Strategy:···enable1062 Strategy:···enable
1064 -·name:·Ensure·sudo·is·installed1063 -·name:·Ensure·sudo·is·installed
1065 ··package:1064 ··package:
1066 ····name:·sudo1065 ····name:·sudo
Offset 1086, 20 lines modifiedOffset 1086, 14 lines modified
1086 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed1086 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed
Max diff block lines reached; 94318/98335 bytes (95.91%) of diff not shown.
978 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-pci-dss.html
    
Offset 17353, 116 lines modifiedOffset 17353, 116 lines modified
00043c80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00043c80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00043c90:·6964·6d38·3534·3122·2074·6162·696e·6465··idm8541"·tabinde00043c90:·6964·6d38·3534·3122·2074·6162·696e·6465··idm8541"·tabinde
00043ca0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00043ca0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
00043cb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00043cb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
00043cc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00043cc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
00043cd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00043cd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
00043ce0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00043ce0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
00043cf0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco00043cf0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
00043d00:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<00043d00:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
00043d10:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00043d10:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
00043d20:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00043d20:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
00043d30:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00043d30:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
00043d40:·6964·6d38·3534·3122·3e3c·7461·626c·6520··idm8541"><table·00043d40:·6d38·3534·3122·3e3c·7461·626c·6520·636c··m8541"><table·cl
00043d50:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab00043d50:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
00043d60:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00043d60:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
00043d70:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00043d70:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
00043d80:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00043d80:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
00043d90:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00043d90:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
00043da0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00043da0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00043db0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00043db0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
00043dc0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00043dc0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
00043dd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00043dd0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
00043de0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</00043de0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
00043df0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t00043df0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
00043e00:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><00043e00:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
00043e10:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
00043e20:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</00043e10:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 00043e20:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 00043e30:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 00043e40:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 00043e50:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 00043e60:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 00043e70:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 00043e80:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00043e90:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00043ea0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 00043eb0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 00043ec0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00043ed0:·6d38·3534·3222·2074·6162·696e·6465·783d··m8542"·tabindex=
 00043ee0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00043ef0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00043f00:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00043f10:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00043f20:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00043f30:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 00043f40:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 00043f50:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00043f60:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00043f70:·6170·7365·2220·6964·3d22·6964·6d38·3534··apse"·id="idm854
 00043f80:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 00043f90:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 00043fa0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 00043fb0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 00043fc0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 00043fd0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 00043fe0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00043ff0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 00044000:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00044010:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00044020:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00044030:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00044040:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00044050:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 00044060:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 00044070:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 00044080:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
 00044090:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
 000440a0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
 000440b0:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 000440c0:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
 000440d0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 000440e0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 000440f0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 00044100:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 00044110:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 00044120:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 00044130:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 00044140:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 00044150:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
00043e30:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div00044160:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
00043e40:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b00044170:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
00043e50:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data00044180:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
00043e60:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps00044190:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
00043e70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="000441a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00043e80:·2369·646d·3835·3432·2220·7461·6269·6e64··#idm8542"·tabind000441b0:·2369·646d·3835·3433·2220·7461·6269·6e64··#idm8543"·tabind
00043e90:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but000441c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00043ea0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand000441d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
00043eb0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title000441e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00043ec0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re000441f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00043ed0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00044200:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00043ee0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp00044210:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
00043ef0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</00044220:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
00043f00:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class00044230:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
00043f10:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse00044240:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00043f20:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i00044250:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
00043f30:·646d·3835·3432·223e·3c74·6162·6c65·2063··dm8542"><table·c00044260:·2269·646d·3835·3433·223e·3c74·6162·6c65··"idm8543"><table
00043f40:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl00044270:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
00043f50:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-00044280:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00043f60:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c00044290:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00043f70:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t000442a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
00043f80:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t000442b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00043f90:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></000442c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00043fa0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru000442d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
00043fb0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l000442e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00043fc0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>000442f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00043fd0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t00044300:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
00043fe0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td00044310:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
00043ff0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p00044320:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00044330:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 00044340:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
00044000:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
00044010:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
00044020:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
00044030:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
00044040:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
00044050:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
00044060:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
00044070:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00044080:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00044090:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
000440a0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
000440b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
000440c0:·646d·3835·3433·2220·7461·6269·6e64·6578··dm8543"·tabindex 
000440d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
000440e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
000440f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00044100:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
Max diff block lines reached; 706592/721248 bytes (97.97%) of diff not shown.
273 KB
html2text {}
    
Offset 407, 20 lines modifiedOffset 407, 14 lines modified
407 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed407 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
408 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule408 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
409 Remediation_OSBuild_Blueprint_snippet_⇲409 Remediation_OSBuild_Blueprint_snippet_⇲
  
410 [[packages]]410 [[packages]]
411 name·=·"aide"411 name·=·"aide"
412 version·=·"*"412 version·=·"*"
413 Remediation_Anaconda_snippet_⇲ 
414 Complexity:·low 
415 Disruption:·low 
416 Strategy:···enable 
  
417 package·--add=aide 
418 Remediation_Puppet_snippet_⇲413 Remediation_Puppet_snippet_⇲
419 Complexity:·low414 Complexity:·low
420 Disruption:·low415 Disruption:·low
421 Strategy:···enable416 Strategy:···enable
422 include·install_aide417 include·install_aide
  
423 class·install_aide·{418 class·install_aide·{
Offset 438, 14 lines modifiedOffset 432, 20 lines modified
438 if·!·rpm·-q·--quiet·"aide"·;·then432 if·!·rpm·-q·--quiet·"aide"·;·then
439 ····yum·install·-y·"aide"433 ····yum·install·-y·"aide"
440 fi434 fi
  
441 else435 else
442 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'436 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
443 fi437 fi
 438 Remediation_Anaconda_snippet_⇲
 439 Complexity:·low
 440 Disruption:·low
 441 Strategy:···enable
  
 442 package·--add=aide
444 Remediation_Ansible_snippet_⇲443 Remediation_Ansible_snippet_⇲
445 Complexity:·low444 Complexity:·low
446 Disruption:·low445 Disruption:·low
447 Strategy:···enable446 Strategy:···enable
448 -·name:·Ensure·aide·is·installed447 -·name:·Ensure·aide·is·installed
449 ··package:448 ··package:
450 ····name:·aide449 ····name:·aide
Offset 6414, 20 lines modifiedOffset 6414, 14 lines modified
6414 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed6414 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed
6415 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520,·SV-230275r854030_rule6415 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520,·SV-230275r854030_rule
6416 Remediation_OSBuild_Blueprint_snippet_⇲6416 Remediation_OSBuild_Blueprint_snippet_⇲
  
6417 [[packages]]6417 [[packages]]
6418 name·=·"opensc"6418 name·=·"opensc"
6419 version·=·"*"6419 version·=·"*"
6420 Remediation_Anaconda_snippet_⇲ 
6421 Complexity:·low 
6422 Disruption:·low 
6423 Strategy:···enable 
  
6424 package·--add=opensc 
6425 Remediation_Puppet_snippet_⇲6420 Remediation_Puppet_snippet_⇲
6426 Complexity:·low6421 Complexity:·low
6427 Disruption:·low6422 Disruption:·low
6428 Strategy:···enable6423 Strategy:···enable
6429 include·install_opensc6424 include·install_opensc
  
6430 class·install_opensc·{6425 class·install_opensc·{
Offset 6445, 14 lines modifiedOffset 6439, 20 lines modified
6445 if·!·rpm·-q·--quiet·"opensc"·;·then6439 if·!·rpm·-q·--quiet·"opensc"·;·then
6446 ····yum·install·-y·"opensc"6440 ····yum·install·-y·"opensc"
6447 fi6441 fi
  
6448 else6442 else
6449 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6443 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6450 fi6444 fi
 6445 Remediation_Anaconda_snippet_⇲
 6446 Complexity:·low
 6447 Disruption:·low
 6448 Strategy:···enable
  
 6449 package·--add=opensc
6451 Remediation_Ansible_snippet_⇲6450 Remediation_Ansible_snippet_⇲
6452 Complexity:·low6451 Complexity:·low
6453 Disruption:·low6452 Disruption:·low
6454 Strategy:···enable6453 Strategy:···enable
6455 -·name:·Ensure·opensc·is·installed6454 -·name:·Ensure·opensc·is·installed
6456 ··package:6455 ··package:
6457 ····name:·opensc6456 ····name:·opensc
Offset 6475, 20 lines modifiedOffset 6475, 14 lines modified
6475 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed6475 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
6476 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015306476 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
6477 Remediation_OSBuild_Blueprint_snippet_⇲6477 Remediation_OSBuild_Blueprint_snippet_⇲
  
6478 [[packages]]6478 [[packages]]
6479 name·=·"pcsc-lite"6479 name·=·"pcsc-lite"
6480 version·=·"*"6480 version·=·"*"
6481 Remediation_Anaconda_snippet_⇲ 
6482 Complexity:·low 
6483 Disruption:·low 
6484 Strategy:···enable 
  
6485 package·--add=pcsc-lite 
6486 Remediation_Puppet_snippet_⇲6481 Remediation_Puppet_snippet_⇲
6487 Complexity:·low6482 Complexity:·low
6488 Disruption:·low6483 Disruption:·low
6489 Strategy:···enable6484 Strategy:···enable
6490 include·install_pcsc-lite6485 include·install_pcsc-lite
  
6491 class·install_pcsc-lite·{6486 class·install_pcsc-lite·{
Offset 6506, 14 lines modifiedOffset 6500, 20 lines modified
6506 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then6500 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
6507 ····yum·install·-y·"pcsc-lite"6501 ····yum·install·-y·"pcsc-lite"
6508 fi6502 fi
  
6509 else6503 else
6510 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6504 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6511 fi6505 fi
 6506 Remediation_Anaconda_snippet_⇲
 6507 Complexity:·low
 6508 Disruption:·low
 6509 Strategy:···enable
  
 6510 package·--add=pcsc-lite
6512 Remediation_Ansible_snippet_⇲6511 Remediation_Ansible_snippet_⇲
6513 Complexity:·low6512 Complexity:·low
6514 Disruption:·low6513 Disruption:·low
6515 Strategy:···enable6514 Strategy:···enable
6516 -·name:·Ensure·pcsc-lite·is·installed6515 -·name:·Ensure·pcsc-lite·is·installed
6517 ··package:6516 ··package:
6518 ····name:·pcsc-lite6517 ····name:·pcsc-lite
Offset 7350, 15 lines modifiedOffset 7350, 15 lines modified
7350 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.7350 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
Max diff block lines reached; 275363/279658 bytes (98.46%) of diff not shown.
113 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-rht-ccp.html
    
Offset 15465, 116 lines modifiedOffset 15465, 116 lines modified
0003c680:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003c680:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003c690:·646d·3835·3431·2220·7461·6269·6e64·6578··dm8541"·tabindex0003c690:·646d·3835·3431·2220·7461·6269·6e64·6578··dm8541"·tabindex
0003c6a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003c6a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003c6b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003c6b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003c6c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003c6c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003c6d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003c6d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003c6e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003c6e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003c6f0:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon0003c6f0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
0003c700:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</0003c700:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003c710:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c710:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003c720:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c720:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003c730:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003c730:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003c740:·646d·3835·3431·223e·3c74·6162·6c65·2063··dm8541"><table·c0003c740:·3835·3431·223e·3c74·6162·6c65·2063·6c61··8541"><table·cla
0003c750:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003c750:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003c760:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003c760:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c770:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003c770:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003c780:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003c780:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003c790:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003c790:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003c7a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c7a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c7b0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003c7b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003c7c0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003c7c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003c7d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c7d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c7e0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003c7e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003c7f0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003c7f0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003c800:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003c800:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
0003c810:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
0003c820:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c0003c810:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i
 0003c820:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla
 0003c830:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide·
 0003c840:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a
 0003c850:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure
 0003c860:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 0003c870:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 0003c880:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003c890:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003c8a0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003c8b0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003c8c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003c8d0:·3835·3432·2220·7461·6269·6e64·6578·3d22··8542"·tabindex="
 0003c8e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003c8f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003c900:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003c910:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003c920:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003c930:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 0003c940:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003c950:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003c960:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003c970:·7073·6522·2069·643d·2269·646d·3835·3432··pse"·id="idm8542
 0003c980:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003c990:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003c9a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003c9b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003c9c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003c9d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003c9e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003c9f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003ca00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003ca10:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003ca20:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003ca30:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003ca40:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003ca50:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003ca60:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003ca70:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003ca80:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
 0003ca90:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
 0003caa0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
 0003cab0:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
 0003cac0:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i
 0003cad0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 0003cae0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then
 0003caf0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install
 0003cb00:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e
 0003cb10:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp
 0003cb20:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia
 0003cb30:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl
 0003cb40:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·
 0003cb50:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c
0003c830:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003cb60:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003c840:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003cb70:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003c850:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003cb80:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003c860:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003cb90:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003c870:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003cba0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003c880:·6964·6d38·3534·3222·2074·6162·696e·6465··idm8542"·tabinde0003cbb0:·6964·6d38·3534·3322·2074·6162·696e·6465··idm8543"·tabinde
0003c890:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003cbc0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003c8a0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003cbd0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003c8b0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003cbe0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003c8c0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003cbf0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003c8d0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003cc00:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003c8e0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe0003cc10:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco
0003c8f0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a0003cc20:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<
0003c900:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003cc30:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003c910:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003cc40:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003c920:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003cc50:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003c930:·6d38·3534·3222·3e3c·7461·626c·6520·636c··m8542"><table·cl0003cc60:·6964·6d38·3534·3322·3e3c·7461·626c·6520··idm8543"><table·
0003c940:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003cc70:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003c950:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003cc80:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003c960:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003cc90:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003c970:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003cca0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003c980:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003ccb0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003c990:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003ccc0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003c9a0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003ccd0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003c9b0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003cce0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003c9c0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003ccf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c9d0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003cd00:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003c9e0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003cd10:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003c9f0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003cd20:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003cd30:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003cd40:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</
0003ca00:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
0003ca10:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl 
0003ca20:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide 
0003ca30:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
0003ca40:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur 
0003ca50:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
0003ca60:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
0003ca70:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003ca80:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ca90:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003caa0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003cab0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003cac0:·6d38·3534·3322·2074·6162·696e·6465·783d··m8543"·tabindex= 
0003cad0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003cae0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003caf0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003cb00:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
Max diff block lines reached; 80136/94792 bytes (84.54%) of diff not shown.
20.4 KB
html2text {}
    
Offset 108, 20 lines modifiedOffset 108, 14 lines modified
108 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed108 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
109 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule109 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
110 Remediation_OSBuild_Blueprint_snippet_⇲110 Remediation_OSBuild_Blueprint_snippet_⇲
  
111 [[packages]]111 [[packages]]
112 name·=·"aide"112 name·=·"aide"
113 version·=·"*"113 version·=·"*"
114 Remediation_Anaconda_snippet_⇲ 
115 Complexity:·low 
116 Disruption:·low 
117 Strategy:···enable 
  
118 package·--add=aide 
119 Remediation_Puppet_snippet_⇲114 Remediation_Puppet_snippet_⇲
120 Complexity:·low115 Complexity:·low
121 Disruption:·low116 Disruption:·low
122 Strategy:···enable117 Strategy:···enable
123 include·install_aide118 include·install_aide
  
124 class·install_aide·{119 class·install_aide·{
Offset 139, 14 lines modifiedOffset 133, 20 lines modified
139 if·!·rpm·-q·--quiet·"aide"·;·then133 if·!·rpm·-q·--quiet·"aide"·;·then
140 ····yum·install·-y·"aide"134 ····yum·install·-y·"aide"
141 fi135 fi
  
142 else136 else
143 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'137 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
144 fi138 fi
 139 Remediation_Anaconda_snippet_⇲
 140 Complexity:·low
 141 Disruption:·low
 142 Strategy:···enable
  
 143 package·--add=aide
145 Remediation_Ansible_snippet_⇲144 Remediation_Ansible_snippet_⇲
146 Complexity:·low145 Complexity:·low
147 Disruption:·low146 Disruption:·low
148 Strategy:···enable147 Strategy:···enable
149 -·name:·Ensure·aide·is·installed148 -·name:·Ensure·aide·is·installed
150 ··package:149 ··package:
151 ····name:·aide150 ····name:·aide
Offset 4766, 15 lines modifiedOffset 4766, 15 lines modified
4766 By·default,·audit_log_file·is·"/var/log/audit/audit.log".4766 By·default,·audit_log_file·is·"/var/log/audit/audit.log".
4767 Rationale:·················If·users·can·write·to·audit·logs,·audit·trails·can·be·modified·or·destroyed.4767 Rationale:·················If·users·can·write·to·audit·logs,·audit·trails·can·be·modified·or·destroyed.
4768 Severity: ················medium4768 Severity: ················medium
4769 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit4769 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit
4770 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·18,·19,·3,·4,·5,·6,·7,·8,·5.4.1.1,·APO01.06,·APO11.04,·APO12.06,·BAI03.05,·BAI08.02,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS05.04,·DSS05.07,·DSS06.02,·MEA02.01,·3.3.1,·CCI-000162,·CCI-000163,·CCI-000164,·CCI-001314,·4.2.3.10,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.7.3,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.1,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_5.2,·SR_6.1,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CIP-003-8_R5.1.1,·CIP-003-8_R5.3,·CIP-004-6_R2.3,·CIP-007-3_R2.1,·CIP-007-3_R2.2,·CIP-007-3_R2.3,·CIP-007-3_R5.1,·CIP-007-3_R5.1.1,·CIP-007-3_R5.1.2,·CM-6(a),·AC-6(1),·AU-9(4),·DE.AE-3,·DE.AE-5,·PR.AC-4,·PR.DS-5,·PR.PT-1,·RS.AN-1,·RS.AN-4,·Req-10.5,·SRG-OS-000057-GPOS-00027,·SRG-OS-000058-GPOS-00028,·SRG-OS-000059-GPOS-00029,·SRG-OS-000206-GPOS-00084,·SV-230396r627750_rule4770 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·18,·19,·3,·4,·5,·6,·7,·8,·5.4.1.1,·APO01.06,·APO11.04,·APO12.06,·BAI03.05,·BAI08.02,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS05.04,·DSS05.07,·DSS06.02,·MEA02.01,·3.3.1,·CCI-000162,·CCI-000163,·CCI-000164,·CCI-001314,·4.2.3.10,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.7.3,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.1,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_5.2,·SR_6.1,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CIP-003-8_R5.1.1,·CIP-003-8_R5.3,·CIP-004-6_R2.3,·CIP-007-3_R2.1,·CIP-007-3_R2.2,·CIP-007-3_R2.3,·CIP-007-3_R5.1,·CIP-007-3_R5.1.1,·CIP-007-3_R5.1.2,·CM-6(a),·AC-6(1),·AU-9(4),·DE.AE-3,·DE.AE-5,·PR.AC-4,·PR.DS-5,·PR.PT-1,·RS.AN-1,·RS.AN-4,·Req-10.5,·SRG-OS-000057-GPOS-00027,·SRG-OS-000058-GPOS-00028,·SRG-OS-000059-GPOS-00029,·SRG-OS-000206-GPOS-00084,·SV-230396r627750_rule
4771 Remediation_Shell_script_⇲4771 Remediation_Shell_script_⇲
4772 #·Remediation·is·applicable·only·in·certain·platforms4772 #·Remediation·is·applicable·only·in·certain·platforms
4773 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then4773 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
4774 if·LC_ALL=C·grep·-iw·^log_file·/etc/audit/auditd.conf;·then4774 if·LC_ALL=C·grep·-iw·^log_file·/etc/audit/auditd.conf;·then
4775 ····FILE=$(awk·-F·"="·'/^log_file/·{print·$2}'·/etc/audit/auditd.conf·|·tr·-d·'·')4775 ····FILE=$(awk·-F·"="·'/^log_file/·{print·$2}'·/etc/audit/auditd.conf·|·tr·-d·'·')
4776 else4776 else
4777 ····FILE="/var/log/audit/audit.log"4777 ····FILE="/var/log/audit/audit.log"
4778 fi4778 fi
  
Offset 4796, 15 lines modifiedOffset 4796, 15 lines modified
4796 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg4796 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg
4797 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.24797 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
4798 Remediation_Shell_script_⇲4798 Remediation_Shell_script_⇲
4799 Complexity:·low4799 Complexity:·low
4800 Disruption:·low4800 Disruption:·low
4801 Strategy:···configure4801 Strategy:···configure
4802 #·Remediation·is·applicable·only·in·certain·platforms4802 #·Remediation·is·applicable·only·in·certain·platforms
4803 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then4803 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
4804 chgrp·0·/boot/grub2/grub.cfg4804 chgrp·0·/boot/grub2/grub.cfg
  
4805 else4805 else
4806 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4806 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4807 fi4807 fi
4808 Remediation_Ansible_snippet_⇲4808 Remediation_Ansible_snippet_⇲
Offset 4828, 16 lines modifiedOffset 4828, 16 lines modified
4828 ··-·no_reboot_needed4828 ··-·no_reboot_needed
  
4829 -·name:·Test·for·existence·/boot/grub2/grub.cfg4829 -·name:·Test·for·existence·/boot/grub2/grub.cfg
4830 ··stat:4830 ··stat:
4831 ····path:·/boot/grub2/grub.cfg4831 ····path:·/boot/grub2/grub.cfg
4832 ··register:·file_exists4832 ··register:·file_exists
4833 ··when:4833 ··when:
4834 ··-·'"grub2-common"·in·ansible_facts.packages' 
4835 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'4834 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 4835 ··-·'"grub2-common"·in·ansible_facts.packages'
4836 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4836 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4837 ··tags:4837 ··tags:
4838 ··-·CJIS-5.5.2.24838 ··-·CJIS-5.5.2.2
4839 ··-·NIST-800-171-3.4.54839 ··-·NIST-800-171-3.4.5
4840 ··-·NIST-800-53-AC-6(1)4840 ··-·NIST-800-53-AC-6(1)
4841 ··-·NIST-800-53-CM-6(a)4841 ··-·NIST-800-53-CM-6(a)
4842 ··-·PCI-DSS-Req-7.14842 ··-·PCI-DSS-Req-7.1
Offset 4849, 16 lines modifiedOffset 4849, 16 lines modified
4849 ··-·no_reboot_needed4849 ··-·no_reboot_needed
  
4850 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg4850 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
4851 ··file:4851 ··file:
4852 ····path:·/boot/grub2/grub.cfg4852 ····path:·/boot/grub2/grub.cfg
4853 ····group:·'0'4853 ····group:·'0'
4854 ··when:4854 ··when:
4855 ··-·'"grub2-common"·in·ansible_facts.packages' 
4856 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'4855 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 4856 ··-·'"grub2-common"·in·ansible_facts.packages'
4857 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4857 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4858 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists4858 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
4859 ··tags:4859 ··tags:
4860 ··-·CJIS-5.5.2.24860 ··-·CJIS-5.5.2.2
4861 ··-·NIST-800-171-3.4.54861 ··-·NIST-800-171-3.4.5
4862 ··-·NIST-800-53-AC-6(1)4862 ··-·NIST-800-53-AC-6(1)
4863 ··-·NIST-800-53-CM-6(a)4863 ··-·NIST-800-53-CM-6(a)
Offset 4877, 15 lines modifiedOffset 4877, 15 lines modified
4877 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg4877 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg
4878 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.24878 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.2
4879 Remediation_Shell_script_⇲4879 Remediation_Shell_script_⇲
4880 Complexity:·low4880 Complexity:·low
4881 Disruption:·low4881 Disruption:·low
4882 Strategy:···configure4882 Strategy:···configure
4883 #·Remediation·is·applicable·only·in·certain·platforms4883 #·Remediation·is·applicable·only·in·certain·platforms
4884 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then4884 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
4885 chown·0·/boot/grub2/grub.cfg4885 chown·0·/boot/grub2/grub.cfg
  
4886 else4886 else
4887 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4887 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4888 fi4888 fi
4889 Remediation_Ansible_snippet_⇲4889 Remediation_Ansible_snippet_⇲
Offset 4909, 16 lines modifiedOffset 4909, 16 lines modified
4909 ··-·no_reboot_needed4909 ··-·no_reboot_needed
Max diff block lines reached; 13624/20885 bytes (65.23%) of diff not shown.
566 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-standard.html
    
Offset 26405, 21 lines modifiedOffset 26405, 21 lines modified
00067240:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00067240:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00067250:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00067250:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00067260:·6c61·7073·6522·2069·643d·2269·646d·3235··lapse"·id="idm2500067260:·6c61·7073·6522·2069·643d·2269·646d·3235··lapse"·id="idm25
00067270:·3338·3922·3e3c·7072·653e·3c63·6f64·653e··389"><pre><code>00067270:·3338·3922·3e3c·7072·653e·3c63·6f64·653e··389"><pre><code>
00067280:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is00067280:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
00067290:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only00067290:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
000672a0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat000672a0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
000672b0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q000672b0:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
000672c0:·7569·6574·202d·7120·6175·6469·7420·2661··uiet·-q·audit·&a000672c0:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
000672d0:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·000672d0:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
000672e0:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a 
000672f0:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f· 
00067300:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere000672e0:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 000672f0:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 00067300:·7270·6d20·2d2d·7175·6965·7420·2d71·2061··rpm·--quiet·-q·a
00067310:·6e76·205d·3b20·7468·656e·0a0a·2320·4669··nv·];·then..#·Fi00067310:·7564·6974·3b20·7468·656e·0a0a·2320·4669··udit;·then..#·Fi
00067320:·7273·7420·7065·7266·6f72·6d20·7468·6520··rst·perform·the·00067320:·7273·7420·7065·7266·6f72·6d20·7468·6520··rst·perform·the·
00067330:·7265·6d65·6469·6174·696f·6e20·6f66·2074··remediation·of·t00067330:·7265·6d65·6469·6174·696f·6e20·6f66·2074··remediation·of·t
00067340:·6865·2073·7973·6361·6c6c·2072·756c·650a··he·syscall·rule.00067340:·6865·2073·7973·6361·6c6c·2072·756c·650a··he·syscall·rule.
00067350:·2320·5265·7472·6965·7665·2068·6172·6477··#·Retrieve·hardw00067350:·2320·5265·7472·6965·7665·2068·6172·6477··#·Retrieve·hardw
00067360:·6172·6520·6172·6368·6974·6563·7475·7265··are·architecture00067360:·6172·6520·6172·6368·6974·6563·7475·7265··are·architecture
00067370:·206f·6620·7468·6520·756e·6465·726c·7969···of·the·underlyi00067370:·206f·6620·7468·6520·756e·6465·726c·7969···of·the·underlyi
00067380:·6e67·2073·7973·7465·6d0a·5b20·2224·2867··ng·system.[·"$(g00067380:·6e67·2073·7973·7465·6d0a·5b20·2224·2867··ng·system.[·"$(g
Offset 27299, 23 lines modifiedOffset 27299, 23 lines modified
0006aa20:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s0006aa20:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s
0006aa30:·7472·6174·6567·790a·0a2d·206e·616d·653a··trategy..-·name:0006aa30:·7472·6174·6567·790a·0a2d·206e·616d·653a··trategy..-·name:
0006aa40:·2053·6574·2061·7263·6869·7465·6374·7572···Set·architectur0006aa40:·2053·6574·2061·7263·6869·7465·6374·7572···Set·architectur
0006aa50:·6520·666f·7220·6175·6469·7420·6368·6d6f··e·for·audit·chmo0006aa50:·6520·666f·7220·6175·6469·7420·6368·6d6f··e·for·audit·chmo
0006aa60:·6420·7461·736b·730a·2020·7365·745f·6661··d·tasks.··set_fa0006aa60:·6420·7461·736b·730a·2020·7365·745f·6661··d·tasks.··set_fa
0006aa70:·6374·3a0a·2020·2020·6175·6469·745f·6172··ct:.····audit_ar0006aa70:·6374·3a0a·2020·2020·6175·6469·745f·6172··ct:.····audit_ar
0006aa80:·6368·3a20·6236·340a·2020·7768·656e·3a0a··ch:·b64.··when:.0006aa80:·6368·3a20·6236·340a·2020·7768·656e·3a0a··ch:·b64.··when:.
0006aa90:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in· 
0006aaa0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
0006aab0:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi 
0006aac0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
0006aad0:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
0006aae0:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
0006aaf0:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
0006ab00:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"0006aa90:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt
 0006aaa0:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
 0006aab0:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
 0006aac0:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
 0006aad0:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
 0006aae0:·6e74·6169·6e65·7222·5d0a·2020·2d20·2722··ntainer"].··-·'"
 0006aaf0:·6175·6469·7422·2069·6e20·616e·7369·626c··audit"·in·ansibl
 0006ab00:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
0006ab10:·5d0a·2020·2d20·616e·7369·626c·655f·6172··].··-·ansible_ar0006ab10:·270a·2020·2d20·616e·7369·626c·655f·6172··'.··-·ansible_ar
0006ab20:·6368·6974·6563·7475·7265·203d·3d20·2261··chitecture·==·"a0006ab20:·6368·6974·6563·7475·7265·203d·3d20·2261··chitecture·==·"a
0006ab30:·6172·6368·3634·2220·6f72·2061·6e73·6962··arch64"·or·ansib0006ab30:·6172·6368·3634·2220·6f72·2061·6e73·6962··arch64"·or·ansib
0006ab40:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·0006ab40:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·
0006ab50:·3d3d·2022·7070·6336·3422·206f·7220·616e··==·"ppc64"·or·an0006ab50:·3d3d·2022·7070·6336·3422·206f·7220·616e··==·"ppc64"·or·an
0006ab60:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu0006ab60:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu
0006ab70:·7265·0a20·2020·203d·3d20·2270·7063·3634··re.····==·"ppc640006ab70:·7265·0a20·2020·203d·3d20·2270·7063·3634··re.····==·"ppc64
0006ab80:·6c65·2220·6f72·2061·6e73·6962·6c65·5f61··le"·or·ansible_a0006ab80:·6c65·2220·6f72·2061·6e73·6962·6c65·5f61··le"·or·ansible_a
Offset 27622, 23 lines modifiedOffset 27622, 23 lines modified
0006be50:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······0006be50:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······
0006be60:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···0006be60:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···
0006be70:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·0006be70:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·
0006be80:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres0006be80:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres
0006be90:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy0006be90:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy
0006bea0:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l0006bea0:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l
0006beb0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe0006beb0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe
0006bec0:·6e3a·0a20·202d·2027·2261·7564·6974·2220··n:.··-·'"audit"· 
0006bed0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
0006bee0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a 
0006bef0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
0006bf00:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
0006bf10:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
0006bf20:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
0006bf30:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain0006bec0:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v
 0006bed0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 0006bee0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 0006bef0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 0006bf00:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 0006bf10:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-
 0006bf20:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans
 0006bf30:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
0006bf40:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-0006bf40:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
0006bf50:·2043·4a49·532d·352e·342e·312e·310a·2020···CJIS-5.4.1.1.··0006bf50:·2043·4a49·532d·352e·342e·312e·310a·2020···CJIS-5.4.1.1.··
0006bf60:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL0006bf60:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL
0006bf70:·2d30·382d·3033·3034·3930·0a20·202d·204e··-08-030490.··-·N0006bf70:·2d30·382d·3033·3034·3930·0a20·202d·204e··-08-030490.··-·N
0006bf80:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.0006bf80:·4953·542d·3830·302d·3137·312d·332e·312e··IST-800-171-3.1.
0006bf90:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-50006bf90:·370a·2020·2d20·4e49·5354·2d38·3030·2d35··7.··-·NIST-800-5
0006bfa0:·332d·4155·2d31·3228·6329·0a20·202d·204e··3-AU-12(c).··-·N0006bfa0:·332d·4155·2d31·3228·6329·0a20·202d·204e··3-AU-12(c).··-·N
0006bfb0:·4953·542d·3830·302d·3533·2d41·552d·3228··IST-800-53-AU-2(0006bfb0:·4953·542d·3830·302d·3533·2d41·552d·3228··IST-800-53-AU-2(
Offset 27934, 22 lines modifiedOffset 27934, 22 lines modified
0006d1d0:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create0006d1d0:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create
0006d1e0:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod0006d1e0:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod
0006d1f0:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s0006d1f0:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s
0006d200:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··0006d200:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
0006d210:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls0006d210:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls
0006d220:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·0006d220:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·
0006d230:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-0006d230:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-
0006d240:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans 
0006d250:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
0006d260:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible 
0006d270:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
0006d280:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
0006d290:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
0006d2a0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
0006d2b0:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·0006d240:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
 0006d250:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
 0006d260:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
 0006d270:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
 0006d280:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
 0006d290:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud
 0006d2a0:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f
 0006d2b0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·
0006d2c0:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==0006d2c0:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==
0006d2d0:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·0006d2d0:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·
0006d2e0:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.0006d2e0:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.
0006d2f0:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH0006d2f0:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH
0006d300:·454c·2d30·382d·3033·3034·3930·0a20·202d··EL-08-030490.··-0006d300:·454c·2d30·382d·3033·3034·3930·0a20·202d··EL-08-030490.··-
0006d310:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0006d310:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
0006d320:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-8000006d320:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
Offset 28899, 21 lines modifiedOffset 28899, 21 lines modified
00070e20:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane00070e20:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00070e30:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00070e30:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00070e40:·7073·6522·2069·643d·2269·646d·3235·3534··pse"·id="idm255400070e40:·7073·6522·2069·643d·2269·646d·3235·3534··pse"·id="idm2554
00070e50:·3722·3e3c·7072·653e·3c63·6f64·653e·2320··7"><pre><code>#·00070e50:·3722·3e3c·7072·653e·3c63·6f64·653e·2320··7"><pre><code>#·
00070e60:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a00070e60:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
00070e70:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i00070e70:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
00070e80:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo00070e80:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
00070e90:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui 
00070ea0:·6574·202d·7120·6175·6469·7420·2661·6d70··et·-q·audit·&amp 
00070eb0:·3b26·616d·703b·205b·2021·202d·6620·2f2e··;&amp;·[·!·-f·/.00070e90:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
00070ec0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp00070ea0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
Max diff block lines reached; 417492/427489 bytes (97.66%) of diff not shown.
149 KB
html2text {}
    
Offset 1429, 15 lines modifiedOffset 1429, 15 lines modified
1429 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1429 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1430 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1430 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1431 Severity: ················medium1431 Severity: ················medium
1432 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1432 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1433 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule1433 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230456r810462_rule
1434 Remediation_Shell_script_⇲1434 Remediation_Shell_script_⇲
1435 #·Remediation·is·applicable·only·in·certain·platforms1435 #·Remediation·is·applicable·only·in·certain·platforms
1436 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1436 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1437 #·First·perform·the·remediation·of·the·syscall·rule1437 #·First·perform·the·remediation·of·the·syscall·rule
1438 #·Retrieve·hardware·architecture·of·the·underlying·system1438 #·Retrieve·hardware·architecture·of·the·underlying·system
1439 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1439 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1440 for·ARCH·in·"${RULE_ARCHS[@]}"1440 for·ARCH·in·"${RULE_ARCHS[@]}"
1441 do1441 do
Offset 1784, 16 lines modifiedOffset 1784, 16 lines modified
1784 ··-·reboot_required1784 ··-·reboot_required
1785 ··-·restrict_strategy1785 ··-·restrict_strategy
  
1786 -·name:·Set·architecture·for·audit·chmod·tasks1786 -·name:·Set·architecture·for·audit·chmod·tasks
1787 ··set_fact:1787 ··set_fact:
1788 ····audit_arch:·b641788 ····audit_arch:·b64
1789 ··when:1789 ··when:
1790 ··-·'"audit"·in·ansible_facts.packages' 
1791 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1790 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1791 ··-·'"audit"·in·ansible_facts.packages'
1792 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1792 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1793 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1793 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1794 ··tags:1794 ··tags:
1795 ··-·CJIS-5.4.1.11795 ··-·CJIS-5.4.1.1
1796 ··-·DISA-STIG-RHEL-08-0304901796 ··-·DISA-STIG-RHEL-08-030490
1797 ··-·NIST-800-171-3.1.71797 ··-·NIST-800-171-3.1.7
1798 ··-·NIST-800-53-AU-12(c)1798 ··-·NIST-800-53-AU-12(c)
Offset 1930, 16 lines modifiedOffset 1930, 16 lines modified
1930 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001930 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1931 ········-F·auid!=unset·-F·key=perm_mod1931 ········-F·auid!=unset·-F·key=perm_mod
1932 ······create:·true1932 ······create:·true
1933 ······mode:·o-rwx1933 ······mode:·o-rwx
1934 ······state:·present1934 ······state:·present
1935 ····when:·syscalls_found·|·length·==·01935 ····when:·syscalls_found·|·length·==·0
1936 ··when:1936 ··when:
1937 ··-·'"audit"·in·ansible_facts.packages' 
1938 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1937 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1938 ··-·'"audit"·in·ansible_facts.packages'
1939 ··tags:1939 ··tags:
1940 ··-·CJIS-5.4.1.11940 ··-·CJIS-5.4.1.1
1941 ··-·DISA-STIG-RHEL-08-0304901941 ··-·DISA-STIG-RHEL-08-030490
1942 ··-·NIST-800-171-3.1.71942 ··-·NIST-800-171-3.1.7
1943 ··-·NIST-800-53-AU-12(c)1943 ··-·NIST-800-53-AU-12(c)
1944 ··-·NIST-800-53-AU-2(d)1944 ··-·NIST-800-53-AU-2(d)
1945 ··-·NIST-800-53-CM-6(a)1945 ··-·NIST-800-53-CM-6(a)
Offset 2074, 16 lines modifiedOffset 2074, 16 lines modified
2074 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002074 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2075 ········-F·auid!=unset·-F·key=perm_mod2075 ········-F·auid!=unset·-F·key=perm_mod
2076 ······create:·true2076 ······create:·true
2077 ······mode:·o-rwx2077 ······mode:·o-rwx
2078 ······state:·present2078 ······state:·present
2079 ····when:·syscalls_found·|·length·==·02079 ····when:·syscalls_found·|·length·==·0
2080 ··when:2080 ··when:
2081 ··-·'"audit"·in·ansible_facts.packages' 
2082 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2081 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2082 ··-·'"audit"·in·ansible_facts.packages'
2083 ··-·audit_arch·==·"b64"2083 ··-·audit_arch·==·"b64"
2084 ··tags:2084 ··tags:
2085 ··-·CJIS-5.4.1.12085 ··-·CJIS-5.4.1.1
2086 ··-·DISA-STIG-RHEL-08-0304902086 ··-·DISA-STIG-RHEL-08-030490
2087 ··-·NIST-800-171-3.1.72087 ··-·NIST-800-171-3.1.7
2088 ··-·NIST-800-53-AU-12(c)2088 ··-·NIST-800-53-AU-12(c)
2089 ··-·NIST-800-53-AU-2(d)2089 ··-·NIST-800-53-AU-2(d)
Offset 2107, 15 lines modifiedOffset 2107, 15 lines modified
2107 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2107 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2108 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2108 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2109 Severity: ················medium2109 Severity: ················medium
2110 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2110 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2111 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230455r810459_rule2111 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.3.9,·SV-230455r810459_rule
2112 Remediation_Shell_script_⇲2112 Remediation_Shell_script_⇲
2113 #·Remediation·is·applicable·only·in·certain·platforms2113 #·Remediation·is·applicable·only·in·certain·platforms
2114 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2114 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2115 #·First·perform·the·remediation·of·the·syscall·rule2115 #·First·perform·the·remediation·of·the·syscall·rule
2116 #·Retrieve·hardware·architecture·of·the·underlying·system2116 #·Retrieve·hardware·architecture·of·the·underlying·system
2117 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2117 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2118 for·ARCH·in·"${RULE_ARCHS[@]}"2118 for·ARCH·in·"${RULE_ARCHS[@]}"
2119 do2119 do
Offset 2462, 16 lines modifiedOffset 2462, 16 lines modified
2462 ··-·reboot_required2462 ··-·reboot_required
2463 ··-·restrict_strategy2463 ··-·restrict_strategy
  
2464 -·name:·Set·architecture·for·audit·chown·tasks2464 -·name:·Set·architecture·for·audit·chown·tasks
2465 ··set_fact:2465 ··set_fact:
2466 ····audit_arch:·b642466 ····audit_arch:·b64
2467 ··when:2467 ··when:
2468 ··-·'"audit"·in·ansible_facts.packages' 
2469 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2468 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2469 ··-·'"audit"·in·ansible_facts.packages'
2470 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2470 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2471 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2471 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2472 ··tags:2472 ··tags:
2473 ··-·CJIS-5.4.1.12473 ··-·CJIS-5.4.1.1
2474 ··-·DISA-STIG-RHEL-08-0304802474 ··-·DISA-STIG-RHEL-08-030480
2475 ··-·NIST-800-171-3.1.72475 ··-·NIST-800-171-3.1.7
2476 ··-·NIST-800-53-AU-12(c)2476 ··-·NIST-800-53-AU-12(c)
Offset 2610, 16 lines modifiedOffset 2610, 16 lines modified
2610 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002610 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2611 ········-F·auid!=unset·-F·key=perm_mod2611 ········-F·auid!=unset·-F·key=perm_mod
2612 ······create:·true2612 ······create:·true
2613 ······mode:·o-rwx2613 ······mode:·o-rwx
2614 ······state:·present2614 ······state:·present
2615 ····when:·syscalls_found·|·length·==·02615 ····when:·syscalls_found·|·length·==·0
2616 ··when:2616 ··when:
2617 ··-·'"audit"·in·ansible_facts.packages' 
2618 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2617 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2618 ··-·'"audit"·in·ansible_facts.packages'
2619 ··tags:2619 ··tags:
2620 ··-·CJIS-5.4.1.12620 ··-·CJIS-5.4.1.1
2621 ··-·DISA-STIG-RHEL-08-0304802621 ··-·DISA-STIG-RHEL-08-030480
2622 ··-·NIST-800-171-3.1.72622 ··-·NIST-800-171-3.1.7
2623 ··-·NIST-800-53-AU-12(c)2623 ··-·NIST-800-53-AU-12(c)
2624 ··-·NIST-800-53-AU-2(d)2624 ··-·NIST-800-53-AU-2(d)
2625 ··-·NIST-800-53-CM-6(a)2625 ··-·NIST-800-53-CM-6(a)
Offset 2756, 16 lines modifiedOffset 2756, 16 lines modified
2756 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002756 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2757 ········-F·auid!=unset·-F·key=perm_mod2757 ········-F·auid!=unset·-F·key=perm_mod
2758 ······create:·true2758 ······create:·true
2759 ······mode:·o-rwx2759 ······mode:·o-rwx
2760 ······state:·present2760 ······state:·present
Max diff block lines reached; 143408/152141 bytes (94.26%) of diff not shown.
1.81 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig.html
    
Offset 15543, 116 lines modifiedOffset 15543, 116 lines modified
0003cb60:·2d74·6172·6765·743d·2223·6964·6d38·3534··-target="#idm8540003cb60:·2d74·6172·6765·743d·2223·6964·6d38·3534··-target="#idm854
0003cb70:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·0003cb70:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0003cb80:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003cb80:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003cb90:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003cb90:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003cba0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003cba0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003cbb0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003cbb0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003cbc0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003cbc0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003cbd0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003cbd0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003cbe0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003cbe0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003cbf0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003cbf0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003cc00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003cc00:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003cc10:·6170·7365·2220·6964·3d22·6964·6d38·3534··apse"·id="idm8540003cc10:·7365·2220·6964·3d22·6964·6d38·3534·3122··se"·id="idm8541"
0003cc20:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=0003cc20:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003cc30:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003cc30:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003cc40:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003cc40:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003cc50:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003cc50:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003cc60:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003cc60:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003cc70:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003cc70:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003cc80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003cc80:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003cc90:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003cc90:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003cca0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003cca0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003ccb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003ccb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003ccc0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003ccc0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003ccd0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003ccd0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003cce0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003cce0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003ccf0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003cd00:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><0003ccf0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 0003cd00:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 0003cd10:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 0003cd20:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 0003cd30:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 0003cd40:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 0003cd50:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 0003cd60:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003cd70:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003cd80:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003cd90:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003cda0:·6172·6765·743d·2223·6964·6d38·3534·3222··arget="#idm8542"
 0003cdb0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003cdc0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003cdd0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003cde0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003cdf0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003ce00:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003ce10:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003ce20:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003ce30:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003ce40:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003ce50:·6964·3d22·6964·6d38·3534·3222·3e3c·7461··id="idm8542"><ta
 0003ce60:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003ce70:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003ce80:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003ce90:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003cea0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003ceb0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003cec0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003ced0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003cee0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003cef0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003cf00:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003cf10:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003cf20:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003cf30:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003cf40:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003cf50:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003cf60:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
 0003cf70:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
 0003cf80:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
 0003cf90:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 0003cfa0:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r
 0003cfb0:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 0003cfc0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 0003cfd0:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0003cfe0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 0003cff0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003d000:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003d010:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0003d020:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0003d030:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
0003cd10:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003d040:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003cd20:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003d050:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003cd30:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003d060:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003cd40:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003d070:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003cd50:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm850003d080:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm85
0003cd60:·3432·2220·7461·6269·6e64·6578·3d22·3022··42"·tabindex="0"0003d090:·3433·2220·7461·6269·6e64·6578·3d22·3022··43"·tabindex="0"
0003cd70:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003d0a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003cd80:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003d0b0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003cd90:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003d0c0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003cda0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003d0d0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003cdb0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003d0e0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003cdc0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003d0f0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003cdd0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003d100:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003cde0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003d110:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003cdf0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003d120:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003ce00:·7073·6522·2069·643d·2269·646d·3835·3432··pse"·id="idm85420003d130:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm85
0003ce10:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003d140:·3433·223e·3c74·6162·6c65·2063·6c61·7373··43"><table·class
0003ce20:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003d150:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003ce30:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003d160:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003ce40:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003d170:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003ce50:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003d180:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003ce60:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003d190:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003ce70:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003d1a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003ce80:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003d1b0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003ce90:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003d1c0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003cea0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003d1d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003ceb0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003d1e0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003cec0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003d1f0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003ced0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003d200:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003d210:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 0003d220:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
0003cee0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003cef0:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
0003cf00:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
0003cf10:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
0003cf20:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0003cf30:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0003cf40:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0003cf50:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003cf60:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003cf70:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003cf80:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003cf90:·7461·7267·6574·3d22·2369·646d·3835·3433··target="#idm8543 
0003cfa0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003cfb0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003cfc0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003cfd0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003cfe0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
Max diff block lines reached; 1502589/1517245 bytes (99.03%) of diff not shown.
371 KB
html2text {}
    
Offset 123, 20 lines modifiedOffset 123, 14 lines modified
123 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed123 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
124 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule124 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
125 Remediation_OSBuild_Blueprint_snippet_⇲125 Remediation_OSBuild_Blueprint_snippet_⇲
  
126 [[packages]]126 [[packages]]
127 name·=·"aide"127 name·=·"aide"
128 version·=·"*"128 version·=·"*"
129 Remediation_Anaconda_snippet_⇲ 
130 Complexity:·low 
131 Disruption:·low 
132 Strategy:···enable 
  
133 package·--add=aide 
134 Remediation_Puppet_snippet_⇲129 Remediation_Puppet_snippet_⇲
135 Complexity:·low130 Complexity:·low
136 Disruption:·low131 Disruption:·low
137 Strategy:···enable132 Strategy:···enable
138 include·install_aide133 include·install_aide
  
139 class·install_aide·{134 class·install_aide·{
Offset 154, 14 lines modifiedOffset 148, 20 lines modified
154 if·!·rpm·-q·--quiet·"aide"·;·then148 if·!·rpm·-q·--quiet·"aide"·;·then
155 ····yum·install·-y·"aide"149 ····yum·install·-y·"aide"
156 fi150 fi
  
157 else151 else
158 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'152 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
159 fi153 fi
 154 Remediation_Anaconda_snippet_⇲
 155 Complexity:·low
 156 Disruption:·low
 157 Strategy:···enable
  
 158 package·--add=aide
160 Remediation_Ansible_snippet_⇲159 Remediation_Ansible_snippet_⇲
161 Complexity:·low160 Complexity:·low
162 Disruption:·low161 Disruption:·low
163 Strategy:···enable162 Strategy:···enable
164 -·name:·Ensure·aide·is·installed163 -·name:·Ensure·aide·is·installed
165 ··package:164 ··package:
166 ····name:·aide165 ····name:·aide
Offset 4697, 20 lines modifiedOffset 4697, 14 lines modified
4697 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed4697 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed
4698 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·SV-244527r743830_rule4698 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·SV-244527r743830_rule
4699 Remediation_OSBuild_Blueprint_snippet_⇲4699 Remediation_OSBuild_Blueprint_snippet_⇲
  
4700 [[packages]]4700 [[packages]]
4701 name·=·"rng-tools"4701 name·=·"rng-tools"
4702 version·=·"*"4702 version·=·"*"
4703 Remediation_Anaconda_snippet_⇲ 
4704 Complexity:·low 
4705 Disruption:·low 
4706 Strategy:···enable 
  
4707 package·--add=rng-tools 
4708 Remediation_Puppet_snippet_⇲4703 Remediation_Puppet_snippet_⇲
4709 Complexity:·low4704 Complexity:·low
4710 Disruption:·low4705 Disruption:·low
4711 Strategy:···enable4706 Strategy:···enable
4712 include·install_rng-tools4707 include·install_rng-tools
  
4713 class·install_rng-tools·{4708 class·install_rng-tools·{
Offset 4722, 14 lines modifiedOffset 4716, 20 lines modified
4722 Complexity:·low4716 Complexity:·low
4723 Disruption:·low4717 Disruption:·low
4724 Strategy:···enable4718 Strategy:···enable
  
4725 if·!·rpm·-q·--quiet·"rng-tools"·;·then4719 if·!·rpm·-q·--quiet·"rng-tools"·;·then
4726 ····yum·install·-y·"rng-tools"4720 ····yum·install·-y·"rng-tools"
4727 fi4721 fi
 4722 Remediation_Anaconda_snippet_⇲
 4723 Complexity:·low
 4724 Disruption:·low
 4725 Strategy:···enable
  
 4726 package·--add=rng-tools
4728 Remediation_Ansible_snippet_⇲4727 Remediation_Ansible_snippet_⇲
4729 Complexity:·low4728 Complexity:·low
4730 Disruption:·low4729 Disruption:·low
4731 Strategy:···enable4730 Strategy:···enable
4732 -·name:·Ensure·rng-tools·is·installed4731 -·name:·Ensure·rng-tools·is·installed
4733 ··package:4732 ··package:
4734 ····name:·rng-tools4733 ····name:·rng-tools
Offset 4745, 20 lines modifiedOffset 4745, 14 lines modified
4745 ***·Rule  ·Uninstall·abrt-addon-ccpp·Package·  [ref]·***4745 ***·Rule  ·Uninstall·abrt-addon-ccpp·Package·  [ref]·***
4746 The·abrt-addon-ccpp·package·can·be·removed·with·the·following·command:4746 The·abrt-addon-ccpp·package·can·be·removed·with·the·following·command:
4747 $·sudo·yum·erase·abrt-addon-ccpp4747 $·sudo·yum·erase·abrt-addon-ccpp
4748 Rationale:·················abrt-addon-ccpp·contains·hooks·for·C/C++·crashed·programs·and·abrt's·C/C++·analyzer·plugin.4748 Rationale:·················abrt-addon-ccpp·contains·hooks·for·C/C++·crashed·programs·and·abrt's·C/C++·analyzer·plugin.
4749 Severity: ················low4749 Severity: ················low
4750 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed4750 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed
4751 Identifiers·and·References·References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·SV-230488r627750_rule4751 Identifiers·and·References·References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·SV-230488r627750_rule
4752 Remediation_Anaconda_snippet_⇲ 
4753 Complexity:·low 
4754 Disruption:·low 
4755 Strategy:···disable 
  
4756 package·--remove=abrt-addon-ccpp 
4757 Remediation_Puppet_snippet_⇲4752 Remediation_Puppet_snippet_⇲
4758 Complexity:·low4753 Complexity:·low
4759 Disruption:·low4754 Disruption:·low
4760 Strategy:···disable4755 Strategy:···disable
4761 include·remove_abrt-addon-ccpp4756 include·remove_abrt-addon-ccpp
  
4762 class·remove_abrt-addon-ccpp·{4757 class·remove_abrt-addon-ccpp·{
Offset 4778, 14 lines modifiedOffset 4772, 20 lines modified
4778 #»      ···system!4772 #»      ···system!
  
4779 if·rpm·-q·--quiet·"abrt-addon-ccpp"·;·then4773 if·rpm·-q·--quiet·"abrt-addon-ccpp"·;·then
  
4780 ····yum·remove·-y·"abrt-addon-ccpp"4774 ····yum·remove·-y·"abrt-addon-ccpp"
  
4781 fi4775 fi
 4776 Remediation_Anaconda_snippet_⇲
 4777 Complexity:·low
 4778 Disruption:·low
 4779 Strategy:···disable
  
 4780 package·--remove=abrt-addon-ccpp
4782 Remediation_Ansible_snippet_⇲4781 Remediation_Ansible_snippet_⇲
4783 Complexity:·low4782 Complexity:·low
4784 Disruption:·low4783 Disruption:·low
4785 Strategy:···disable4784 Strategy:···disable
4786 -·name:·Ensure·abrt-addon-ccpp·is·removed4785 -·name:·Ensure·abrt-addon-ccpp·is·removed
4787 ··package:4786 ··package:
4788 ····name:·abrt-addon-ccpp4787 ····name:·abrt-addon-ccpp
Offset 4801, 20 lines modifiedOffset 4801, 14 lines modified
4801 ***·Rule  ·Uninstall·abrt-addon-kerneloops·Package·  [ref]·***4801 ***·Rule  ·Uninstall·abrt-addon-kerneloops·Package·  [ref]·***
Max diff block lines reached; 375937/379906 bytes (98.96%) of diff not shown.
1.78 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig_gui.html
    
Offset 15562, 116 lines modifiedOffset 15562, 116 lines modified
0003cc90:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm850003cc90:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm85
0003cca0:·3431·2220·7461·6269·6e64·6578·3d22·3022··41"·tabindex="0"0003cca0:·3431·2220·7461·6269·6e64·6578·3d22·3022··41"·tabindex="0"
0003ccb0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003ccb0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003ccc0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003ccc0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003ccd0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003ccd0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003cce0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003cce0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003ccf0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003ccf0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003cd00:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0003cd00:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003cd10:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003cd10:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003cd20:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003cd20:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003cd30:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003cd30:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003cd40:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm850003cd40:·7073·6522·2069·643d·2269·646d·3835·3431··pse"·id="idm8541
0003cd50:·3431·223e·3c74·6162·6c65·2063·6c61·7373··41"><table·class0003cd50:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003cd60:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003cd60:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003cd70:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003cd70:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003cd80:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003cd80:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003cd90:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003cd90:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003cda0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003cda0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003cdb0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003cdb0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003cdc0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003cdc0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003cdd0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003cdd0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003cde0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003cde0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003cdf0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003cdf0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003ce00:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003ce00:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003ce10:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003ce10:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003ce20:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
0003ce30:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>0003ce20:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 0003ce30:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 0003ce40:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 0003ce50:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 0003ce60:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 0003ce70:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 0003ce80:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 0003ce90:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003cea0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003ceb0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003cec0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003ced0:·7461·7267·6574·3d22·2369·646d·3835·3432··target="#idm8542
 0003cee0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003cef0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003cf00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003cf10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003cf20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003cf30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003cf40:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 0003cf50:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003cf60:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003cf70:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003cf80:·2069·643d·2269·646d·3835·3432·223e·3c74···id="idm8542"><t
 0003cf90:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003cfa0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003cfb0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003cfc0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003cfd0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003cfe0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003cff0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003d000:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003d010:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003d020:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003d030:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003d040:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003d050:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003d060:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003d070:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003d080:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003d090:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
 0003d0a0:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
 0003d0b0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
 0003d0c0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 0003d0d0:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!·
 0003d0e0:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"
 0003d0f0:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.···
 0003d100:·2079·756d·2069·6e73·7461·6c6c·202d·7920···yum·install·-y·
 0003d110:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else.
 0003d120:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 0003d130:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 0003d140:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 0003d150:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 0003d160:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
0003ce40:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003d170:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003ce50:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003d180:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003ce60:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003d190:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003ce70:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003d1a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003ce80:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003d1b0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003ce90:·3534·3222·2074·6162·696e·6465·783d·2230··542"·tabindex="00003d1c0:·3534·3322·2074·6162·696e·6465·783d·2230··543"·tabindex="0
0003cea0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003d1d0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003ceb0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003d1e0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003cec0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003d1f0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003ced0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003d200:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003cee0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003d210:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003cef0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003d220:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
0003cf00:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003d230:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003cf10:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003d240:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003cf20:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003d250:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003cf30:·6170·7365·2220·6964·3d22·6964·6d38·3534··apse"·id="idm8540003d260:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003cf40:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=0003d270:·3534·3322·3e3c·7461·626c·6520·636c·6173··543"><table·clas
0003cf50:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003d280:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003cf60:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003d290:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003cf70:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003d2a0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003cf80:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003d2b0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003cf90:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003d2c0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003cfa0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003d2d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003cfb0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003d2e0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003cfc0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003d2f0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003cfd0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003d300:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003cfe0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003d310:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003cff0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003d320:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003d000:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003d330:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003d340:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 0003d350:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code
0003d010:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
0003d020:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class· 
0003d030:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.· 
0003d040:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide 
0003d050:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
0003d060:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
0003d070:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
0003d080:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003d090:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003d0a0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003d0b0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003d0c0:·2d74·6172·6765·743d·2223·6964·6d38·3534··-target="#idm854 
0003d0d0:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"· 
0003d0e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003d0f0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003d100:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003d110:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
Max diff block lines reached; 1473760/1488416 bytes (99.02%) of diff not shown.
368 KB
html2text {}
    
Offset 128, 20 lines modifiedOffset 128, 14 lines modified
128 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed128 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
129 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule129 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251710r854081_rule
130 Remediation_OSBuild_Blueprint_snippet_⇲130 Remediation_OSBuild_Blueprint_snippet_⇲
  
131 [[packages]]131 [[packages]]
132 name·=·"aide"132 name·=·"aide"
133 version·=·"*"133 version·=·"*"
134 Remediation_Anaconda_snippet_⇲ 
135 Complexity:·low 
136 Disruption:·low 
137 Strategy:···enable 
  
138 package·--add=aide 
139 Remediation_Puppet_snippet_⇲134 Remediation_Puppet_snippet_⇲
140 Complexity:·low135 Complexity:·low
141 Disruption:·low136 Disruption:·low
142 Strategy:···enable137 Strategy:···enable
143 include·install_aide138 include·install_aide
  
144 class·install_aide·{139 class·install_aide·{
Offset 159, 14 lines modifiedOffset 153, 20 lines modified
159 if·!·rpm·-q·--quiet·"aide"·;·then153 if·!·rpm·-q·--quiet·"aide"·;·then
160 ····yum·install·-y·"aide"154 ····yum·install·-y·"aide"
161 fi155 fi
  
162 else156 else
163 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'157 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
164 fi158 fi
 159 Remediation_Anaconda_snippet_⇲
 160 Complexity:·low
 161 Disruption:·low
 162 Strategy:···enable
  
 163 package·--add=aide
165 Remediation_Ansible_snippet_⇲164 Remediation_Ansible_snippet_⇲
166 Complexity:·low165 Complexity:·low
167 Disruption:·low166 Disruption:·low
168 Strategy:···enable167 Strategy:···enable
169 -·name:·Ensure·aide·is·installed168 -·name:·Ensure·aide·is·installed
170 ··package:169 ··package:
171 ····name:·aide170 ····name:·aide
Offset 4702, 20 lines modifiedOffset 4702, 14 lines modified
4702 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed4702 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed
4703 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·SV-244527r743830_rule4703 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·SV-244527r743830_rule
4704 Remediation_OSBuild_Blueprint_snippet_⇲4704 Remediation_OSBuild_Blueprint_snippet_⇲
  
4705 [[packages]]4705 [[packages]]
4706 name·=·"rng-tools"4706 name·=·"rng-tools"
4707 version·=·"*"4707 version·=·"*"
4708 Remediation_Anaconda_snippet_⇲ 
4709 Complexity:·low 
4710 Disruption:·low 
4711 Strategy:···enable 
  
4712 package·--add=rng-tools 
4713 Remediation_Puppet_snippet_⇲4708 Remediation_Puppet_snippet_⇲
4714 Complexity:·low4709 Complexity:·low
4715 Disruption:·low4710 Disruption:·low
4716 Strategy:···enable4711 Strategy:···enable
4717 include·install_rng-tools4712 include·install_rng-tools
  
4718 class·install_rng-tools·{4713 class·install_rng-tools·{
Offset 4727, 14 lines modifiedOffset 4721, 20 lines modified
4727 Complexity:·low4721 Complexity:·low
4728 Disruption:·low4722 Disruption:·low
4729 Strategy:···enable4723 Strategy:···enable
  
4730 if·!·rpm·-q·--quiet·"rng-tools"·;·then4724 if·!·rpm·-q·--quiet·"rng-tools"·;·then
4731 ····yum·install·-y·"rng-tools"4725 ····yum·install·-y·"rng-tools"
4732 fi4726 fi
 4727 Remediation_Anaconda_snippet_⇲
 4728 Complexity:·low
 4729 Disruption:·low
 4730 Strategy:···enable
  
 4731 package·--add=rng-tools
4733 Remediation_Ansible_snippet_⇲4732 Remediation_Ansible_snippet_⇲
4734 Complexity:·low4733 Complexity:·low
4735 Disruption:·low4734 Disruption:·low
4736 Strategy:···enable4735 Strategy:···enable
4737 -·name:·Ensure·rng-tools·is·installed4736 -·name:·Ensure·rng-tools·is·installed
4738 ··package:4737 ··package:
4739 ····name:·rng-tools4738 ····name:·rng-tools
Offset 4750, 20 lines modifiedOffset 4750, 14 lines modified
4750 ***·Rule  ·Uninstall·abrt-addon-ccpp·Package·  [ref]·***4750 ***·Rule  ·Uninstall·abrt-addon-ccpp·Package·  [ref]·***
4751 The·abrt-addon-ccpp·package·can·be·removed·with·the·following·command:4751 The·abrt-addon-ccpp·package·can·be·removed·with·the·following·command:
4752 $·sudo·yum·erase·abrt-addon-ccpp4752 $·sudo·yum·erase·abrt-addon-ccpp
4753 Rationale:·················abrt-addon-ccpp·contains·hooks·for·C/C++·crashed·programs·and·abrt's·C/C++·analyzer·plugin.4753 Rationale:·················abrt-addon-ccpp·contains·hooks·for·C/C++·crashed·programs·and·abrt's·C/C++·analyzer·plugin.
4754 Severity: ················low4754 Severity: ················low
4755 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed4755 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed
4756 Identifiers·and·References·References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·SV-230488r627750_rule4756 Identifiers·and·References·References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·SV-230488r627750_rule
4757 Remediation_Anaconda_snippet_⇲ 
4758 Complexity:·low 
4759 Disruption:·low 
4760 Strategy:···disable 
  
4761 package·--remove=abrt-addon-ccpp 
4762 Remediation_Puppet_snippet_⇲4757 Remediation_Puppet_snippet_⇲
4763 Complexity:·low4758 Complexity:·low
4764 Disruption:·low4759 Disruption:·low
4765 Strategy:···disable4760 Strategy:···disable
4766 include·remove_abrt-addon-ccpp4761 include·remove_abrt-addon-ccpp
  
4767 class·remove_abrt-addon-ccpp·{4762 class·remove_abrt-addon-ccpp·{
Offset 4783, 14 lines modifiedOffset 4777, 20 lines modified
4783 #»      ···system!4777 #»      ···system!
  
4784 if·rpm·-q·--quiet·"abrt-addon-ccpp"·;·then4778 if·rpm·-q·--quiet·"abrt-addon-ccpp"·;·then
  
4785 ····yum·remove·-y·"abrt-addon-ccpp"4779 ····yum·remove·-y·"abrt-addon-ccpp"
  
4786 fi4780 fi
 4781 Remediation_Anaconda_snippet_⇲
 4782 Complexity:·low
 4783 Disruption:·low
 4784 Strategy:···disable
  
 4785 package·--remove=abrt-addon-ccpp
4787 Remediation_Ansible_snippet_⇲4786 Remediation_Ansible_snippet_⇲
4788 Complexity:·low4787 Complexity:·low
4789 Disruption:·low4788 Disruption:·low
4790 Strategy:···disable4789 Strategy:···disable
4791 -·name:·Ensure·abrt-addon-ccpp·is·removed4790 -·name:·Ensure·abrt-addon-ccpp·is·removed
4792 ··package:4791 ··package:
4793 ····name:·abrt-addon-ccpp4792 ····name:·abrt-addon-ccpp
Offset 4806, 20 lines modifiedOffset 4806, 14 lines modified
4806 ***·Rule  ·Uninstall·abrt-addon-kerneloops·Package·  [ref]·***4806 ***·Rule  ·Uninstall·abrt-addon-kerneloops·Package·  [ref]·***
Max diff block lines reached; 372441/376410 bytes (98.95%) of diff not shown.
655 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_enhanced.html
    
Offset 15349, 116 lines modifiedOffset 15349, 116 lines modified
0003bf40:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003bf40:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003bf50:·3630·3522·2074·6162·696e·6465·783d·2230··605"·tabindex="00003bf50:·3630·3522·2074·6162·696e·6465·783d·2230··605"·tabindex="0
0003bf60:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bf60:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bf70:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bf70:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003bf80:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003bf80:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003bf90:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003bf90:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003bfa0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003bfa0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003bfb0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003bfb0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003bfc0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003bfc0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bfd0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003bfd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bfe0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003bfe0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bff0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003bff0:·6170·7365·2220·6964·3d22·6964·6d37·3630··apse"·id="idm760
0003c000:·3630·3522·3e3c·7461·626c·6520·636c·6173··605"><table·clas0003c000:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=
0003c010:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003c010:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c020:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003c020:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c030:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003c030:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c040:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003c040:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c050:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003c050:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c060:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c060:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c070:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c070:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c080:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c080:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c090:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c090:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c0a0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c0a0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c0b0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c0b0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003c0c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c0c0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003c0d0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003c0e0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003c0d0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003c0e0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003c0f0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003c100:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003c110:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003c120:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003c130:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003c140:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003c150:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003c160:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003c170:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003c180:·2d74·6172·6765·743d·2223·6964·6d37·3630··-target="#idm760
 0003c190:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
 0003c1a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003c1b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003c1c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003c1d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003c1e0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003c1f0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003c200:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003c210:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003c220:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003c230:·2220·6964·3d22·6964·6d37·3630·3622·3e3c··"·id="idm7606"><
 0003c240:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003c250:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003c260:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003c270:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003c280:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003c290:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003c2a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c2b0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003c2c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003c2d0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003c2e0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003c2f0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003c300:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003c310:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003c320:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003c330:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003c340:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003c350:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003c360:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003c370:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003c380:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003c390:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003c3a0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003c3b0:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y
 0003c3c0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003c3d0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003c3e0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003c3f0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003c400:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003c410:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003c0f0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003c420:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003c100:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003c430:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003c110:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003c440:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003c120:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003c450:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003c130:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c460:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c140:·3736·3036·2220·7461·6269·6e64·6578·3d22··7606"·tabindex="0003c470:·3736·3037·2220·7461·6269·6e64·6578·3d22··7607"·tabindex="
0003c150:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c480:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c160:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c490:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c170:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c4a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c180:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c4b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c190:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c4c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c1a0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003c4d0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003c1b0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003c4e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003c1c0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003c4f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003c1d0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003c500:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003c1e0:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm760003c510:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003c1f0:·3036·223e·3c74·6162·6c65·2063·6c61·7373··06"><table·class0003c520:·3736·3037·223e·3c74·6162·6c65·2063·6c61··7607"><table·cla
0003c200:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003c530:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003c210:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003c540:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c220:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003c550:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003c230:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003c560:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003c240:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003c570:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003c250:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c580:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c260:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003c590:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003c270:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003c5a0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003c280:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c5b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c290:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003c5c0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003c2a0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003c5d0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003c2b0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003c5e0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c5f0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003c600:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003c2c0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003c2d0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003c2e0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003c2f0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003c300:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003c310:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003c320:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003c330:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c340:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c350:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c360:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c370:·612d·7461·7267·6574·3d22·2369·646d·3736··a-target="#idm76 
0003c380:·3037·2220·7461·6269·6e64·6578·3d22·3022··07"·tabindex="0" 
0003c390:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c3a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c3b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c3c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 598254/612910 bytes (97.61%) of diff not shown.
56.2 KB
html2text {}
    
Offset 107, 20 lines modifiedOffset 107, 14 lines modified
107 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199107 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
108 References108 References
109 Remediation_OSBuild_Blueprint_snippet_⇲109 Remediation_OSBuild_Blueprint_snippet_⇲
  
110 [[packages]]110 [[packages]]
111 name·=·"aide"111 name·=·"aide"
112 version·=·"*"112 version·=·"*"
113 Remediation_Anaconda_snippet_⇲ 
114 Complexity:·low 
115 Disruption:·low 
116 Strategy:···enable 
  
117 package·--add=aide 
118 Remediation_Puppet_snippet_⇲113 Remediation_Puppet_snippet_⇲
119 Complexity:·low114 Complexity:·low
120 Disruption:·low115 Disruption:·low
121 Strategy:···enable116 Strategy:···enable
122 include·install_aide117 include·install_aide
  
123 class·install_aide·{118 class·install_aide·{
Offset 138, 14 lines modifiedOffset 132, 20 lines modified
138 if·!·rpm·-q·--quiet·"aide"·;·then132 if·!·rpm·-q·--quiet·"aide"·;·then
139 ····dnf·install·-y·"aide"133 ····dnf·install·-y·"aide"
140 fi134 fi
  
141 else135 else
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
143 fi137 fi
 138 Remediation_Anaconda_snippet_⇲
 139 Complexity:·low
 140 Disruption:·low
 141 Strategy:···enable
  
 142 package·--add=aide
144 Remediation_Ansible_snippet_⇲143 Remediation_Ansible_snippet_⇲
145 Complexity:·low144 Complexity:·low
146 Disruption:·low145 Disruption:·low
147 Strategy:···enable146 Strategy:···enable
148 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
149 ··package:148 ··package:
150 ····name:·aide149 ····name:·aide
Offset 399, 20 lines modifiedOffset 399, 14 lines modified
399 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed399 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
400 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125400 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
401 Remediation_OSBuild_Blueprint_snippet_⇲401 Remediation_OSBuild_Blueprint_snippet_⇲
  
402 [[packages]]402 [[packages]]
403 name·=·"sudo"403 name·=·"sudo"
404 version·=·"*"404 version·=·"*"
405 Remediation_Anaconda_snippet_⇲ 
406 Complexity:·low 
407 Disruption:·low 
408 Strategy:···enable 
  
409 package·--add=sudo 
410 Remediation_Puppet_snippet_⇲405 Remediation_Puppet_snippet_⇲
411 Complexity:·low406 Complexity:·low
412 Disruption:·low407 Disruption:·low
413 Strategy:···enable408 Strategy:···enable
414 include·install_sudo409 include·install_sudo
  
415 class·install_sudo·{410 class·install_sudo·{
Offset 430, 14 lines modifiedOffset 424, 20 lines modified
430 if·!·rpm·-q·--quiet·"sudo"·;·then424 if·!·rpm·-q·--quiet·"sudo"·;·then
431 ····dnf·install·-y·"sudo"425 ····dnf·install·-y·"sudo"
432 fi426 fi
  
433 else427 else
434 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'428 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
435 fi429 fi
 430 Remediation_Anaconda_snippet_⇲
 431 Complexity:·low
 432 Disruption:·low
 433 Strategy:···enable
  
 434 package·--add=sudo
436 Remediation_Ansible_snippet_⇲435 Remediation_Ansible_snippet_⇲
437 Complexity:·low436 Complexity:·low
438 Disruption:·low437 Disruption:·low
439 Strategy:···enable438 Strategy:···enable
440 -·name:·Ensure·sudo·is·installed439 -·name:·Ensure·sudo·is·installed
441 ··package:440 ··package:
442 ····name:·sudo441 ····name:·sudo
Offset 766, 20 lines modifiedOffset 766, 14 lines modified
766 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed766 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
767 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080767 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
768 Remediation_OSBuild_Blueprint_snippet_⇲768 Remediation_OSBuild_Blueprint_snippet_⇲
  
769 [[packages]]769 [[packages]]
770 name·=·"dnf-automatic"770 name·=·"dnf-automatic"
771 version·=·"*"771 version·=·"*"
772 Remediation_Anaconda_snippet_⇲ 
773 Complexity:·low 
774 Disruption:·low 
775 Strategy:···enable 
  
776 package·--add=dnf-automatic 
777 Remediation_Puppet_snippet_⇲772 Remediation_Puppet_snippet_⇲
778 Complexity:·low773 Complexity:·low
779 Disruption:·low774 Disruption:·low
780 Strategy:···enable775 Strategy:···enable
781 include·install_dnf-automatic776 include·install_dnf-automatic
  
782 class·install_dnf-automatic·{777 class·install_dnf-automatic·{
Offset 791, 14 lines modifiedOffset 785, 20 lines modified
791 Complexity:·low785 Complexity:·low
792 Disruption:·low786 Disruption:·low
793 Strategy:···enable787 Strategy:···enable
  
794 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then788 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
795 ····dnf·install·-y·"dnf-automatic"789 ····dnf·install·-y·"dnf-automatic"
796 fi790 fi
 791 Remediation_Anaconda_snippet_⇲
 792 Complexity:·low
 793 Disruption:·low
 794 Strategy:···enable
  
 795 package·--add=dnf-automatic
797 Remediation_Ansible_snippet_⇲796 Remediation_Ansible_snippet_⇲
798 Complexity:·low797 Complexity:·low
799 Disruption:·low798 Disruption:·low
800 Strategy:···enable799 Strategy:···enable
801 -·name:·Ensure·dnf-automatic·is·installed800 -·name:·Ensure·dnf-automatic·is·installed
802 ··package:801 ··package:
803 ····name:·dnf-automatic802 ····name:·dnf-automatic
Offset 7464, 15 lines modifiedOffset 7464, 15 lines modified
7464 Severity: ·medium7464 Severity: ·medium
Max diff block lines reached; 54455/57506 bytes (94.69%) of diff not shown.
712 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_high.html
    
Offset 15348, 116 lines modifiedOffset 15348, 116 lines modified
0003bf30:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003bf30:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003bf40:·3630·3522·2074·6162·696e·6465·783d·2230··605"·tabindex="00003bf40:·3630·3522·2074·6162·696e·6465·783d·2230··605"·tabindex="0
0003bf50:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bf50:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bf60:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bf60:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003bf70:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003bf70:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003bf80:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003bf80:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003bf90:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003bf90:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003bfa0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003bfa0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003bfb0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003bfb0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bfc0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003bfc0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bfd0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003bfd0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bfe0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003bfe0:·6170·7365·2220·6964·3d22·6964·6d37·3630··apse"·id="idm760
0003bff0:·3630·3522·3e3c·7461·626c·6520·636c·6173··605"><table·clas0003bff0:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=
0003c000:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003c000:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c010:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003c010:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c020:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003c020:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c030:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003c030:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c040:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003c040:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c050:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c050:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c060:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c060:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c070:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c070:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c080:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c080:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c090:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c090:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c0a0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c0a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003c0b0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c0b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003c0c0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003c0d0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003c0c0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003c0d0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003c0e0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003c0f0:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003c100:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003c110:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003c120:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003c130:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003c140:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003c150:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003c160:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003c170:·2d74·6172·6765·743d·2223·6964·6d37·3630··-target="#idm760
 0003c180:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
 0003c190:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003c1a0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003c1b0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003c1c0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003c1d0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003c1e0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003c1f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003c200:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003c210:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003c220:·2220·6964·3d22·6964·6d37·3630·3622·3e3c··"·id="idm7606"><
 0003c230:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003c240:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003c250:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003c260:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003c270:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003c280:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003c290:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c2a0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003c2b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003c2c0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003c2d0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003c2e0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003c2f0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003c300:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003c310:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003c320:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003c330:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003c340:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003c350:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003c360:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003c370:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003c380:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003c390:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003c3a0:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y
 0003c3b0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003c3c0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003c3d0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003c3e0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003c3f0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003c400:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003c0e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003c410:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003c0f0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003c420:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003c100:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003c430:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003c110:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003c440:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003c120:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c450:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c130:·3736·3036·2220·7461·6269·6e64·6578·3d22··7606"·tabindex="0003c460:·3736·3037·2220·7461·6269·6e64·6578·3d22··7607"·tabindex="
0003c140:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c470:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c150:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c480:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c160:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c490:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c170:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c4a0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c180:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c4b0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c190:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003c4c0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003c1a0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003c4d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003c1b0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003c4e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003c1c0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003c4f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003c1d0:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm760003c500:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003c1e0:·3036·223e·3c74·6162·6c65·2063·6c61·7373··06"><table·class0003c510:·3736·3037·223e·3c74·6162·6c65·2063·6c61··7607"><table·cla
0003c1f0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003c520:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003c200:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003c530:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c210:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003c540:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003c220:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003c550:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003c230:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003c560:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003c240:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c570:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c250:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003c580:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003c260:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003c590:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003c270:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c5a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c280:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003c5b0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003c290:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003c5c0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003c2a0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003c5d0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c5e0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003c5f0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003c2b0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003c2c0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003c2d0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003c2e0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003c2f0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003c300:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003c310:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003c320:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c330:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c340:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c350:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c360:·612d·7461·7267·6574·3d22·2369·646d·3736··a-target="#idm76 
0003c370:·3037·2220·7461·6269·6e64·6578·3d22·3022··07"·tabindex="0" 
0003c380:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c390:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c3a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c3b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 652444/667100 bytes (97.80%) of diff not shown.
60.4 KB
html2text {}
    
Offset 107, 20 lines modifiedOffset 107, 14 lines modified
107 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199107 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
108 References108 References
109 Remediation_OSBuild_Blueprint_snippet_⇲109 Remediation_OSBuild_Blueprint_snippet_⇲
  
110 [[packages]]110 [[packages]]
111 name·=·"aide"111 name·=·"aide"
112 version·=·"*"112 version·=·"*"
113 Remediation_Anaconda_snippet_⇲ 
114 Complexity:·low 
115 Disruption:·low 
116 Strategy:···enable 
  
117 package·--add=aide 
118 Remediation_Puppet_snippet_⇲113 Remediation_Puppet_snippet_⇲
119 Complexity:·low114 Complexity:·low
120 Disruption:·low115 Disruption:·low
121 Strategy:···enable116 Strategy:···enable
122 include·install_aide117 include·install_aide
  
123 class·install_aide·{118 class·install_aide·{
Offset 138, 14 lines modifiedOffset 132, 20 lines modified
138 if·!·rpm·-q·--quiet·"aide"·;·then132 if·!·rpm·-q·--quiet·"aide"·;·then
139 ····dnf·install·-y·"aide"133 ····dnf·install·-y·"aide"
140 fi134 fi
  
141 else135 else
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
143 fi137 fi
 138 Remediation_Anaconda_snippet_⇲
 139 Complexity:·low
 140 Disruption:·low
 141 Strategy:···enable
  
 142 package·--add=aide
144 Remediation_Ansible_snippet_⇲143 Remediation_Ansible_snippet_⇲
145 Complexity:·low144 Complexity:·low
146 Disruption:·low145 Disruption:·low
147 Strategy:···enable146 Strategy:···enable
148 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
149 ··package:148 ··package:
150 ····name:·aide149 ····name:·aide
Offset 653, 20 lines modifiedOffset 653, 14 lines modified
653 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed653 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
654 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125654 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
655 Remediation_OSBuild_Blueprint_snippet_⇲655 Remediation_OSBuild_Blueprint_snippet_⇲
  
656 [[packages]]656 [[packages]]
657 name·=·"sudo"657 name·=·"sudo"
658 version·=·"*"658 version·=·"*"
659 Remediation_Anaconda_snippet_⇲ 
660 Complexity:·low 
661 Disruption:·low 
662 Strategy:···enable 
  
663 package·--add=sudo 
664 Remediation_Puppet_snippet_⇲659 Remediation_Puppet_snippet_⇲
665 Complexity:·low660 Complexity:·low
666 Disruption:·low661 Disruption:·low
667 Strategy:···enable662 Strategy:···enable
668 include·install_sudo663 include·install_sudo
  
669 class·install_sudo·{664 class·install_sudo·{
Offset 684, 14 lines modifiedOffset 678, 20 lines modified
684 if·!·rpm·-q·--quiet·"sudo"·;·then678 if·!·rpm·-q·--quiet·"sudo"·;·then
685 ····dnf·install·-y·"sudo"679 ····dnf·install·-y·"sudo"
686 fi680 fi
  
687 else681 else
688 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'682 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
689 fi683 fi
 684 Remediation_Anaconda_snippet_⇲
 685 Complexity:·low
 686 Disruption:·low
 687 Strategy:···enable
  
 688 package·--add=sudo
690 Remediation_Ansible_snippet_⇲689 Remediation_Ansible_snippet_⇲
691 Complexity:·low690 Complexity:·low
692 Disruption:·low691 Disruption:·low
693 Strategy:···enable692 Strategy:···enable
694 -·name:·Ensure·sudo·is·installed693 -·name:·Ensure·sudo·is·installed
695 ··package:694 ··package:
696 ····name:·sudo695 ····name:·sudo
Offset 1020, 20 lines modifiedOffset 1020, 14 lines modified
1020 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1020 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1021 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000801021 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1022 Remediation_OSBuild_Blueprint_snippet_⇲1022 Remediation_OSBuild_Blueprint_snippet_⇲
  
1023 [[packages]]1023 [[packages]]
1024 name·=·"dnf-automatic"1024 name·=·"dnf-automatic"
1025 version·=·"*"1025 version·=·"*"
1026 Remediation_Anaconda_snippet_⇲ 
1027 Complexity:·low 
1028 Disruption:·low 
1029 Strategy:···enable 
  
1030 package·--add=dnf-automatic 
1031 Remediation_Puppet_snippet_⇲1026 Remediation_Puppet_snippet_⇲
1032 Complexity:·low1027 Complexity:·low
1033 Disruption:·low1028 Disruption:·low
1034 Strategy:···enable1029 Strategy:···enable
1035 include·install_dnf-automatic1030 include·install_dnf-automatic
  
1036 class·install_dnf-automatic·{1031 class·install_dnf-automatic·{
Offset 1045, 14 lines modifiedOffset 1039, 20 lines modified
1045 Complexity:·low1039 Complexity:·low
1046 Disruption:·low1040 Disruption:·low
1047 Strategy:···enable1041 Strategy:···enable
  
1048 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1042 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1049 ····dnf·install·-y·"dnf-automatic"1043 ····dnf·install·-y·"dnf-automatic"
1050 fi1044 fi
 1045 Remediation_Anaconda_snippet_⇲
 1046 Complexity:·low
 1047 Disruption:·low
 1048 Strategy:···enable
  
 1049 package·--add=dnf-automatic
1051 Remediation_Ansible_snippet_⇲1050 Remediation_Ansible_snippet_⇲
1052 Complexity:·low1051 Complexity:·low
1053 Disruption:·low1052 Disruption:·low
1054 Strategy:···enable1053 Strategy:···enable
1055 -·name:·Ensure·dnf-automatic·is·installed1054 -·name:·Ensure·dnf-automatic·is·installed
1056 ··package:1055 ··package:
1057 ····name:·dnf-automatic1056 ····name:·dnf-automatic
Offset 7718, 15 lines modifiedOffset 7718, 15 lines modified
7718 Severity: ·medium7718 Severity: ·medium
Max diff block lines reached; 58740/61795 bytes (95.06%) of diff not shown.
655 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_intermediary.html
    
Offset 15343, 116 lines modifiedOffset 15343, 116 lines modified
0003bee0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003bee0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003bef0:·2223·6964·6d37·3630·3522·2074·6162·696e··"#idm7605"·tabin0003bef0:·2223·6964·6d37·3630·3522·2074·6162·696e··"#idm7605"·tabin
0003bf00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003bf00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003bf10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003bf10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003bf20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003bf20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003bf30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003bf30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003bf40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003bf40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003bf50:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003bf50:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
0003bf60:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003bf60:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
0003bf70:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003bf70:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003bf80:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003bf80:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003bf90:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003bf90:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003bfa0:·3d22·6964·6d37·3630·3522·3e3c·7461·626c··="idm7605"><tabl0003bfa0:·6964·6d37·3630·3522·3e3c·7461·626c·6520··idm7605"><table·
0003bfb0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003bfb0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003bfc0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003bfc0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003bfd0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003bfd0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003bfe0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003bfe0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003bff0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003bff0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003c000:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c000:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003c010:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003c010:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003c020:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003c020:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003c030:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c030:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c040:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003c040:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003c050:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c050:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003c060:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003c060:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003c070:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac0003c070:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
0003c080:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.0003c080:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003c090:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003c0a0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003c0b0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003c0c0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003c0d0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003c0e0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003c0f0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003c100:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003c110:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003c120:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003c130:·6964·6d37·3630·3622·2074·6162·696e·6465··idm7606"·tabinde
 0003c140:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003c150:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003c160:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003c170:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003c180:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003c190:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003c1a0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003c1b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003c1c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003c1d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
 0003c1e0:·3630·3622·3e3c·7461·626c·6520·636c·6173··606"><table·clas
 0003c1f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003c200:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003c210:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003c220:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003c230:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003c240:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003c250:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003c260:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003c270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003c280:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003c290:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003c2a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003c2b0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003c2c0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003c2d0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003c2e0:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 0003c2f0:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
 0003c300:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
 0003c310:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
 0003c320:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
 0003c330:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003c340:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003c350:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst
 0003c360:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003c370:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003c380:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003c390:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003c3a0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003c3b0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
0003c090:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003c3c0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003c0a0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003c3d0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003c0b0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003c3e0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003c0c0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003c3f0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003c0d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003c400:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003c0e0:·3d22·2369·646d·3736·3036·2220·7461·6269··="#idm7606"·tabi0003c410:·3d22·2369·646d·3736·3037·2220·7461·6269··="#idm7607"·tabi
0003c0f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003c420:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003c100:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003c430:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003c110:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003c440:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003c120:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003c450:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003c130:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003c460:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003c140:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003c470:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003c150:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003c480:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003c160:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003c490:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003c170:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003c4a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003c180:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003c4b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003c190:·2269·646d·3736·3036·223e·3c74·6162·6c65··"idm7606"><table0003c4c0:·643d·2269·646d·3736·3037·223e·3c74·6162··d="idm7607"><tab
0003c1a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003c4d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003c1b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003c4e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003c1c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003c4f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003c1d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003c500:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003c1e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003c510:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003c1f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c520:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c200:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003c530:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003c210:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003c540:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003c220:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003c550:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c230:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003c560:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003c240:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003c570:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003c250:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003c580:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003c590:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003c5a0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
0003c260:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003c270:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003c280:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003c290:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003c2a0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003c2b0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003c2c0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003c2d0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003c2e0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003c2f0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003c300:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003c310:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003c320:·2369·646d·3736·3037·2220·7461·6269·6e64··#idm7607"·tabind 
0003c330:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003c340:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003c350:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003c360:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003c370:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
Max diff block lines reached; 598171/612827 bytes (97.61%) of diff not shown.
56.2 KB
html2text {}
    
Offset 106, 20 lines modifiedOffset 106, 14 lines modified
106 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199106 and·········A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
107 References107 References
108 Remediation_OSBuild_Blueprint_snippet_⇲108 Remediation_OSBuild_Blueprint_snippet_⇲
  
109 [[packages]]109 [[packages]]
110 name·=·"aide"110 name·=·"aide"
111 version·=·"*"111 version·=·"*"
112 Remediation_Anaconda_snippet_⇲ 
113 Complexity:·low 
114 Disruption:·low 
115 Strategy:···enable 
  
116 package·--add=aide 
117 Remediation_Puppet_snippet_⇲112 Remediation_Puppet_snippet_⇲
118 Complexity:·low113 Complexity:·low
119 Disruption:·low114 Disruption:·low
120 Strategy:···enable115 Strategy:···enable
121 include·install_aide116 include·install_aide
  
122 class·install_aide·{117 class·install_aide·{
Offset 137, 14 lines modifiedOffset 131, 20 lines modified
137 if·!·rpm·-q·--quiet·"aide"·;·then131 if·!·rpm·-q·--quiet·"aide"·;·then
138 ····dnf·install·-y·"aide"132 ····dnf·install·-y·"aide"
139 fi133 fi
  
140 else134 else
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
142 fi136 fi
 137 Remediation_Anaconda_snippet_⇲
 138 Complexity:·low
 139 Disruption:·low
 140 Strategy:···enable
  
 141 package·--add=aide
143 Remediation_Ansible_snippet_⇲142 Remediation_Ansible_snippet_⇲
144 Complexity:·low143 Complexity:·low
145 Disruption:·low144 Disruption:·low
146 Strategy:···enable145 Strategy:···enable
147 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
148 ··package:147 ··package:
149 ····name:·aide148 ····name:·aide
Offset 398, 20 lines modifiedOffset 398, 14 lines modified
398 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed398 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
399 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125399 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
400 Remediation_OSBuild_Blueprint_snippet_⇲400 Remediation_OSBuild_Blueprint_snippet_⇲
  
401 [[packages]]401 [[packages]]
402 name·=·"sudo"402 name·=·"sudo"
403 version·=·"*"403 version·=·"*"
404 Remediation_Anaconda_snippet_⇲ 
405 Complexity:·low 
406 Disruption:·low 
407 Strategy:···enable 
  
408 package·--add=sudo 
409 Remediation_Puppet_snippet_⇲404 Remediation_Puppet_snippet_⇲
410 Complexity:·low405 Complexity:·low
411 Disruption:·low406 Disruption:·low
412 Strategy:···enable407 Strategy:···enable
413 include·install_sudo408 include·install_sudo
  
414 class·install_sudo·{409 class·install_sudo·{
Offset 429, 14 lines modifiedOffset 423, 20 lines modified
429 if·!·rpm·-q·--quiet·"sudo"·;·then423 if·!·rpm·-q·--quiet·"sudo"·;·then
430 ····dnf·install·-y·"sudo"424 ····dnf·install·-y·"sudo"
431 fi425 fi
  
432 else426 else
433 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'427 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
434 fi428 fi
 429 Remediation_Anaconda_snippet_⇲
 430 Complexity:·low
 431 Disruption:·low
 432 Strategy:···enable
  
 433 package·--add=sudo
435 Remediation_Ansible_snippet_⇲434 Remediation_Ansible_snippet_⇲
436 Complexity:·low435 Complexity:·low
437 Disruption:·low436 Disruption:·low
438 Strategy:···enable437 Strategy:···enable
439 -·name:·Ensure·sudo·is·installed438 -·name:·Ensure·sudo·is·installed
440 ··package:439 ··package:
441 ····name:·sudo440 ····name:·sudo
Offset 765, 20 lines modifiedOffset 765, 14 lines modified
765 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed765 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
766 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080766 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
767 Remediation_OSBuild_Blueprint_snippet_⇲767 Remediation_OSBuild_Blueprint_snippet_⇲
  
768 [[packages]]768 [[packages]]
769 name·=·"dnf-automatic"769 name·=·"dnf-automatic"
770 version·=·"*"770 version·=·"*"
771 Remediation_Anaconda_snippet_⇲ 
772 Complexity:·low 
773 Disruption:·low 
774 Strategy:···enable 
  
775 package·--add=dnf-automatic 
776 Remediation_Puppet_snippet_⇲771 Remediation_Puppet_snippet_⇲
777 Complexity:·low772 Complexity:·low
778 Disruption:·low773 Disruption:·low
779 Strategy:···enable774 Strategy:···enable
780 include·install_dnf-automatic775 include·install_dnf-automatic
  
781 class·install_dnf-automatic·{776 class·install_dnf-automatic·{
Offset 790, 14 lines modifiedOffset 784, 20 lines modified
790 Complexity:·low784 Complexity:·low
791 Disruption:·low785 Disruption:·low
792 Strategy:···enable786 Strategy:···enable
  
793 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then787 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
794 ····dnf·install·-y·"dnf-automatic"788 ····dnf·install·-y·"dnf-automatic"
795 fi789 fi
 790 Remediation_Anaconda_snippet_⇲
 791 Complexity:·low
 792 Disruption:·low
 793 Strategy:···enable
  
 794 package·--add=dnf-automatic
796 Remediation_Ansible_snippet_⇲795 Remediation_Ansible_snippet_⇲
797 Complexity:·low796 Complexity:·low
798 Disruption:·low797 Disruption:·low
799 Strategy:···enable798 Strategy:···enable
800 -·name:·Ensure·dnf-automatic·is·installed799 -·name:·Ensure·dnf-automatic·is·installed
801 ··package:800 ··package:
802 ····name:·dnf-automatic801 ····name:·dnf-automatic
Offset 7062, 15 lines modifiedOffset 7062, 15 lines modified
7062 Severity: ·medium7062 Severity: ·medium
Max diff block lines reached; 54455/57506 bytes (94.69%) of diff not shown.
245 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_minimal.html
    
Offset 15992, 107 lines modifiedOffset 15992, 107 lines modified
0003e770:·2d74·6172·6765·743d·2223·6964·6d31·3134··-target="#idm1140003e770:·2d74·6172·6765·743d·2223·6964·6d31·3134··-target="#idm114
0003e780:·3937·2220·7461·6269·6e64·6578·3d22·3022··97"·tabindex="0"0003e780:·3937·2220·7461·6269·6e64·6578·3d22·3022··97"·tabindex="0"
0003e790:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003e790:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003e7a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003e7a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003e7b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003e7b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003e7c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003e7c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003e7d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003e7d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003e7e0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0003e7e0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003e7f0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003e7f0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003e800:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003e800:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003e810:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003e810:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003e820:·6c61·7073·6522·2069·643d·2269·646d·3131··lapse"·id="idm110003e820:·7073·6522·2069·643d·2269·646d·3131·3439··pse"·id="idm1149
0003e830:·3439·3722·3e3c·7461·626c·6520·636c·6173··497"><table·clas0003e830:·3722·3e3c·7461·626c·6520·636c·6173·733d··7"><table·class=
0003e840:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003e840:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003e850:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003e850:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003e860:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003e860:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003e870:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003e870:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003e880:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003e880:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003e890:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003e8a0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003e8b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003e8c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003e8d0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003e8e0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003e8f0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003e900:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003e910:·616c·6c5f·646e·662d·6175·746f·6d61·7469··all_dnf-automati
 0003e920:·630a·0a63·6c61·7373·2069·6e73·7461·6c6c··c..class·install
 0003e930:·5f64·6e66·2d61·7574·6f6d·6174·6963·207b··_dnf-automatic·{
 0003e940:·0a20·2070·6163·6b61·6765·207b·2027·646e··.··package·{·'dn
 0003e950:·662d·6175·746f·6d61·7469·6327·3a0a·2020··f-automatic':.··
 0003e960:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003e970:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003e980:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003e990:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003e9a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003e9b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003e9c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003e9d0:·6574·3d22·2369·646d·3131·3439·3822·2074··et="#idm11498"·t
 0003e9e0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003e9f0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003ea00:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003ea10:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003ea20:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003ea30:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003ea40:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003ea50:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003ea60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003ea70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003ea80:·3d22·6964·6d31·3134·3938·223e·3c74·6162··="idm11498"><tab
 0003ea90:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003eaa0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003eab0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003eac0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003ead0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003eae0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003eaf0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003eb00:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003e890:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003eb10:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003e8a0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003e8b0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003e8c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003e8d0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003e8e0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003e8f0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003e900:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003e910:·2d61·6464·3d64·6e66·2d61·7574·6f6d·6174··-add=dnf-automat0003eb20:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003eb30:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003eb40:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003eb50:·653e·3c70·7265·3e3c·636f·6465·3e0a·6966··e><pre><code>.if
 0003eb60:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003eb70:·7420·2264·6e66·2d61·7574·6f6d·6174·6963··t·"dnf-automatic
 0003eb80:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf
 0003eb90:·2069·6e73·7461·6c6c·202d·7920·2264·6e66···install·-y·"dnf
 0003eba0:·2d61·7574·6f6d·6174·6963·220a·6669·0a3c··-automatic".fi.<
0003e920:·6963·0a3c·2f63·6f64·653e·3c2f·7072·653e··ic.</code></pre>0003ebb0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003e930:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003ebc0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003e940:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003ebd0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003e950:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003ebe0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003e960:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003ebf0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003e970:·6765·743d·2223·6964·6d31·3134·3938·2220··get="#idm11498"·0003ec00:·2223·6964·6d31·3134·3939·2220·7461·6269··"#idm11499"·tabi
0003e980:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003ec10:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003e990:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003ec20:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003e9a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003ec30:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003e9b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003ec40:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003e9c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003ec50:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003e9d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003ec60:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003e9e0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet0003ec70:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003e9f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003ec80:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003ea00:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003ec90:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003ea10:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003eca0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003ea20:·2069·643d·2269·646d·3131·3439·3822·3e3c···id="idm11498"><0003ecb0:·643d·2269·646d·3131·3439·3922·3e3c·7461··d="idm11499"><ta
0003ea30:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003ecc0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003ea40:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003ecd0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003ea50:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003ece0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003ea60:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003ecf0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003ea70:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003ed00:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003ea80:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003ed10:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003ea90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ed20:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003eaa0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003ed30:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003eab0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003ed40:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003eac0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003ed50:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003ead0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003ed60:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003eae0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003ed70:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003eaf0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003ed80:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003ed90:·6163·6b61·6765·202d·2d61·6464·3d64·6e66··ackage·--add=dnf
0003eb00:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003eb10:·646e·662d·6175·746f·6d61·7469·630a·0a63··dnf-automatic..c 
0003eb20:·6c61·7373·2069·6e73·7461·6c6c·5f64·6e66··lass·install_dnf 
0003eb30:·2d61·7574·6f6d·6174·6963·207b·0a20·2070··-automatic·{.··p 
0003eb40:·6163·6b61·6765·207b·2027·646e·662d·6175··ackage·{·'dnf-au 
0003eb50:·746f·6d61·7469·6327·3a0a·2020·2020·656e··tomatic':.····en 
0003eb60:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003eb70:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003eb80:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003eb90:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003eba0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003ebb0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003ebc0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003ebd0:·2369·646d·3131·3439·3922·2074·6162·696e··#idm11499"·tabin 
0003ebe0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003ebf0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003ec00:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003ec10:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003ec20:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003ec30:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003ec40:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
Max diff block lines reached; 219674/233088 bytes (94.25%) of diff not shown.
17.3 KB
html2text {}
    
Offset 259, 20 lines modifiedOffset 259, 14 lines modified
259 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed259 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
260 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080260 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
261 Remediation_OSBuild_Blueprint_snippet_⇲261 Remediation_OSBuild_Blueprint_snippet_⇲
  
262 [[packages]]262 [[packages]]
263 name·=·"dnf-automatic"263 name·=·"dnf-automatic"
264 version·=·"*"264 version·=·"*"
265 Remediation_Anaconda_snippet_⇲ 
266 Complexity:·low 
267 Disruption:·low 
268 Strategy:···enable 
  
269 package·--add=dnf-automatic 
270 Remediation_Puppet_snippet_⇲265 Remediation_Puppet_snippet_⇲
271 Complexity:·low266 Complexity:·low
272 Disruption:·low267 Disruption:·low
273 Strategy:···enable268 Strategy:···enable
274 include·install_dnf-automatic269 include·install_dnf-automatic
  
275 class·install_dnf-automatic·{270 class·install_dnf-automatic·{
Offset 284, 14 lines modifiedOffset 278, 20 lines modified
284 Complexity:·low278 Complexity:·low
285 Disruption:·low279 Disruption:·low
286 Strategy:···enable280 Strategy:···enable
  
287 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then281 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
288 ····dnf·install·-y·"dnf-automatic"282 ····dnf·install·-y·"dnf-automatic"
289 fi283 fi
 284 Remediation_Anaconda_snippet_⇲
 285 Complexity:·low
 286 Disruption:·low
 287 Strategy:···enable
  
 288 package·--add=dnf-automatic
290 Remediation_Ansible_snippet_⇲289 Remediation_Ansible_snippet_⇲
291 Complexity:·low290 Complexity:·low
292 Disruption:·low291 Disruption:·low
293 Strategy:···enable292 Strategy:···enable
294 -·name:·Ensure·dnf-automatic·is·installed293 -·name:·Ensure·dnf-automatic·is·installed
295 ··package:294 ··package:
296 ····name:·dnf-automatic295 ····name:·dnf-automatic
Offset 6856, 20 lines modifiedOffset 6856, 14 lines modified
6856 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-6856 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
6857 ············002276857 ············00227
6858 Remediation_OSBuild_Blueprint_snippet_⇲6858 Remediation_OSBuild_Blueprint_snippet_⇲
  
6859 [[packages]]6859 [[packages]]
6860 name·=·"rsyslog"6860 name·=·"rsyslog"
6861 version·=·"*"6861 version·=·"*"
6862 Remediation_Anaconda_snippet_⇲ 
6863 Complexity:·low 
6864 Disruption:·low 
6865 Strategy:···enable 
  
6866 package·--add=rsyslog 
6867 Remediation_Puppet_snippet_⇲6862 Remediation_Puppet_snippet_⇲
6868 Complexity:·low6863 Complexity:·low
6869 Disruption:·low6864 Disruption:·low
6870 Strategy:···enable6865 Strategy:···enable
6871 include·install_rsyslog6866 include·install_rsyslog
  
6872 class·install_rsyslog·{6867 class·install_rsyslog·{
Offset 6887, 14 lines modifiedOffset 6881, 20 lines modified
6887 if·!·rpm·-q·--quiet·"rsyslog"·;·then6881 if·!·rpm·-q·--quiet·"rsyslog"·;·then
6888 ····dnf·install·-y·"rsyslog"6882 ····dnf·install·-y·"rsyslog"
6889 fi6883 fi
  
6890 else6884 else
6891 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6885 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6892 fi6886 fi
 6887 Remediation_Anaconda_snippet_⇲
 6888 Complexity:·low
 6889 Disruption:·low
 6890 Strategy:···enable
  
 6891 package·--add=rsyslog
6893 Remediation_Ansible_snippet_⇲6892 Remediation_Ansible_snippet_⇲
6894 Complexity:·low6893 Complexity:·low
6895 Disruption:·low6894 Disruption:·low
6896 Strategy:···enable6895 Strategy:···enable
6897 -·name:·Ensure·rsyslog·is·installed6896 -·name:·Ensure·rsyslog·is·installed
6898 ··package:6897 ··package:
6899 ····name:·rsyslog6898 ····name:·rsyslog
Offset 7079, 20 lines modifiedOffset 7079, 14 lines modified
7079 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,7079 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,
7080 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7080 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
7081 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,7081 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
7082 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR7082 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
7083 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR7083 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
7084 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,7084 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
7085 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-37085 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3
7086 Remediation_Anaconda_snippet_⇲ 
7087 Complexity:·low 
7088 Disruption:·low 
7089 Strategy:···disable 
  
7090 package·--remove=dhcp-server 
7091 Remediation_Puppet_snippet_⇲7086 Remediation_Puppet_snippet_⇲
7092 Complexity:·low7087 Complexity:·low
7093 Disruption:·low7088 Disruption:·low
7094 Strategy:···disable7089 Strategy:···disable
7095 include·remove_dhcp-server7090 include·remove_dhcp-server
  
7096 class·remove_dhcp-server·{7091 class·remove_dhcp-server·{
Offset 7112, 14 lines modifiedOffset 7106, 20 lines modified
7112 #»      ···system!7106 #»      ···system!
  
7113 if·rpm·-q·--quiet·"dhcp-server"·;·then7107 if·rpm·-q·--quiet·"dhcp-server"·;·then
  
7114 ····dnf·remove·-y·"dhcp-server"7108 ····dnf·remove·-y·"dhcp-server"
  
7115 fi7109 fi
 7110 Remediation_Anaconda_snippet_⇲
 7111 Complexity:·low
 7112 Disruption:·low
 7113 Strategy:···disable
  
 7114 package·--remove=dhcp-server
7116 Remediation_Ansible_snippet_⇲7115 Remediation_Ansible_snippet_⇲
7117 Complexity:·low7116 Complexity:·low
7118 Disruption:·low7117 Disruption:·low
7119 Strategy:···disable7118 Strategy:···disable
7120 -·name:·Ensure·dhcp-server·is·removed7119 -·name:·Ensure·dhcp-server·is·removed
7121 ··package:7120 ··package:
7122 ····name:·dhcp-server7121 ····name:·dhcp-server
Offset 7166, 20 lines modifiedOffset 7166, 14 lines modified
7166 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7166 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
Max diff block lines reached; 14227/17715 bytes (80.31%) of diff not shown.
1.74 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis.html
    
Offset 15383, 116 lines modifiedOffset 15383, 116 lines modified
0003c160:·7267·6574·3d22·2369·646d·3736·3035·2220··rget="#idm7605"·0003c160:·7267·6574·3d22·2369·646d·3736·3035·2220··rget="#idm7605"·
0003c170:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003c170:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003c180:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003c180:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003c190:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003c190:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003c1a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003c1a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003c1b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003c1b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003c1c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003c1c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003c1d0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp0003c1d0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003c1e0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003c1e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c1f0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003c1f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c200:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003c200:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c210:·6522·2069·643d·2269·646d·3736·3035·223e··e"·id="idm7605">0003c210:·2069·643d·2269·646d·3736·3035·223e·3c74···id="idm7605"><t
0003c220:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003c220:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c230:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003c230:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c240:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003c240:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c250:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003c250:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c260:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003c260:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c270:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003c270:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003c280:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c280:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c290:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003c290:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003c2a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c2a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c2b0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003c2b0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003c2c0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003c2c0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003c2d0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003c2d0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003c2e0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003c2e0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
0003c2f0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=0003c2f0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003c300:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003c310:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003c320:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003c330:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003c340:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003c350:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003c360:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003c370:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003c380:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003c390:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003c3a0:·6574·3d22·2369·646d·3736·3036·2220·7461··et="#idm7606"·ta
 0003c3b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003c3c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003c3d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003c3e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003c3f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003c400:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003c410:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003c420:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003c430:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003c440:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003c450:·2269·646d·3736·3036·223e·3c74·6162·6c65··"idm7606"><table
 0003c460:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003c470:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003c480:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003c490:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003c4a0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003c4b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003c4c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003c4d0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003c4e0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003c4f0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003c500:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003c510:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003c520:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003c530:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003c540:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003c550:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003c560:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0003c570:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0003c580:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0003c590:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0003c5a0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003c5b0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 0003c5c0:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf
 0003c5d0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003c5e0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 0003c5f0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003c600:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003c610:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003c620:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
0003c300:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003c630:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003c310:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003c640:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003c320:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003c650:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003c330:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003c660:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003c340:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003c670:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003c350:·6172·6765·743d·2223·6964·6d37·3630·3622··arget="#idm7606"0003c680:·6172·6765·743d·2223·6964·6d37·3630·3722··arget="#idm7607"
0003c360:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c690:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c370:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c6a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c380:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c6b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c390:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c6c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c3a0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c6d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c3b0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c6e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003c3c0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003c6f0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003c3d0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003c700:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003c3e0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003c710:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003c3f0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003c720:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003c400:·2220·6964·3d22·6964·6d37·3630·3622·3e3c··"·id="idm7606"><0003c730:·7365·2220·6964·3d22·6964·6d37·3630·3722··se"·id="idm7607"
0003c410:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003c740:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003c420:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003c750:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003c430:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003c760:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003c440:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003c770:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003c450:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003c780:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c460:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003c790:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003c470:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c7a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c480:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003c7b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003c490:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c7c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c4a0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003c7d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003c4b0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003c7e0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003c4c0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003c7f0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003c4d0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003c800:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c810:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
0003c4e0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003c4f0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003c500:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003c510:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003c520:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003c530:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003c540:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003c550:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c560:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c570:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003c580:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c590:·6765·743d·2223·6964·6d37·3630·3722·2074··get="#idm7607"·t 
0003c5a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c5b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c5c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c5d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c5e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c5f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c600:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 1470480/1485136 bytes (99.01%) of diff not shown.
335 KB
html2text {}
    
Offset 110, 20 lines modifiedOffset 110, 14 lines modified
110 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed110 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
111 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199111 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
112 Remediation_OSBuild_Blueprint_snippet_⇲112 Remediation_OSBuild_Blueprint_snippet_⇲
  
113 [[packages]]113 [[packages]]
114 name·=·"aide"114 name·=·"aide"
115 version·=·"*"115 version·=·"*"
116 Remediation_Anaconda_snippet_⇲ 
117 Complexity:·low 
118 Disruption:·low 
119 Strategy:···enable 
  
120 package·--add=aide 
121 Remediation_Puppet_snippet_⇲116 Remediation_Puppet_snippet_⇲
122 Complexity:·low117 Complexity:·low
123 Disruption:·low118 Disruption:·low
124 Strategy:···enable119 Strategy:···enable
125 include·install_aide120 include·install_aide
  
126 class·install_aide·{121 class·install_aide·{
Offset 141, 14 lines modifiedOffset 135, 20 lines modified
141 if·!·rpm·-q·--quiet·"aide"·;·then135 if·!·rpm·-q·--quiet·"aide"·;·then
142 ····dnf·install·-y·"aide"136 ····dnf·install·-y·"aide"
143 fi137 fi
  
144 else138 else
145 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'139 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
146 fi140 fi
 141 Remediation_Anaconda_snippet_⇲
 142 Complexity:·low
 143 Disruption:·low
 144 Strategy:···enable
  
 145 package·--add=aide
147 Remediation_Ansible_snippet_⇲146 Remediation_Ansible_snippet_⇲
148 Complexity:·low147 Complexity:·low
149 Disruption:·low148 Disruption:·low
150 Strategy:···enable149 Strategy:···enable
151 -·name:·Ensure·aide·is·installed150 -·name:·Ensure·aide·is·installed
152 ··package:151 ··package:
153 ····name:·aide152 ····name:·aide
Offset 1200, 20 lines modifiedOffset 1200, 14 lines modified
1200 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1200 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1201 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001251201 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
1202 Remediation_OSBuild_Blueprint_snippet_⇲1202 Remediation_OSBuild_Blueprint_snippet_⇲
  
1203 [[packages]]1203 [[packages]]
1204 name·=·"sudo"1204 name·=·"sudo"
1205 version·=·"*"1205 version·=·"*"
1206 Remediation_Anaconda_snippet_⇲ 
1207 Complexity:·low 
1208 Disruption:·low 
1209 Strategy:···enable 
  
1210 package·--add=sudo 
1211 Remediation_Puppet_snippet_⇲1206 Remediation_Puppet_snippet_⇲
1212 Complexity:·low1207 Complexity:·low
1213 Disruption:·low1208 Disruption:·low
1214 Strategy:···enable1209 Strategy:···enable
1215 include·install_sudo1210 include·install_sudo
  
1216 class·install_sudo·{1211 class·install_sudo·{
Offset 1231, 14 lines modifiedOffset 1225, 20 lines modified
1231 if·!·rpm·-q·--quiet·"sudo"·;·then1225 if·!·rpm·-q·--quiet·"sudo"·;·then
1232 ····dnf·install·-y·"sudo"1226 ····dnf·install·-y·"sudo"
1233 fi1227 fi
  
1234 else1228 else
1235 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1229 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1236 fi1230 fi
 1231 Remediation_Anaconda_snippet_⇲
 1232 Complexity:·low
 1233 Disruption:·low
 1234 Strategy:···enable
  
 1235 package·--add=sudo
1237 Remediation_Ansible_snippet_⇲1236 Remediation_Ansible_snippet_⇲
1238 Complexity:·low1237 Complexity:·low
1239 Disruption:·low1238 Disruption:·low
1240 Strategy:···enable1239 Strategy:···enable
1241 -·name:·Ensure·sudo·is·installed1240 -·name:·Ensure·sudo·is·installed
1242 ··package:1241 ··package:
1243 ····name:·sudo1242 ····name:·sudo
Offset 7880, 15 lines modifiedOffset 7880, 15 lines modified
7880 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.7880 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
7881 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.7881 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
7882 Severity: ················medium7882 Severity: ················medium
7883 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod7883 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
7884 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019407884 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
7885 Remediation_Shell_script_⇲7885 Remediation_Shell_script_⇲
7886 #·Remediation·is·applicable·only·in·certain·platforms7886 #·Remediation·is·applicable·only·in·certain·platforms
7887 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7887 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7888 #·First·perform·the·remediation·of·the·syscall·rule7888 #·First·perform·the·remediation·of·the·syscall·rule
7889 #·Retrieve·hardware·architecture·of·the·underlying·system7889 #·Retrieve·hardware·architecture·of·the·underlying·system
7890 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")7890 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
7891 for·ARCH·in·"${RULE_ARCHS[@]}"7891 for·ARCH·in·"${RULE_ARCHS[@]}"
7892 do7892 do
Offset 8234, 16 lines modifiedOffset 8234, 16 lines modified
8234 ··-·reboot_required8234 ··-·reboot_required
8235 ··-·restrict_strategy8235 ··-·restrict_strategy
  
8236 -·name:·Set·architecture·for·audit·chmod·tasks8236 -·name:·Set·architecture·for·audit·chmod·tasks
8237 ··set_fact:8237 ··set_fact:
8238 ····audit_arch:·b648238 ····audit_arch:·b64
8239 ··when:8239 ··when:
8240 ··-·'"audit"·in·ansible_facts.packages' 
8241 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8240 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8241 ··-·'"audit"·in·ansible_facts.packages'
8242 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8242 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8243 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8243 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8244 ··tags:8244 ··tags:
8245 ··-·CJIS-5.4.1.18245 ··-·CJIS-5.4.1.1
8246 ··-·NIST-800-171-3.1.78246 ··-·NIST-800-171-3.1.7
8247 ··-·NIST-800-53-AU-12(c)8247 ··-·NIST-800-53-AU-12(c)
8248 ··-·NIST-800-53-AU-2(d)8248 ··-·NIST-800-53-AU-2(d)
Offset 8379, 16 lines modifiedOffset 8379, 16 lines modified
8379 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008379 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8380 ········-F·auid!=unset·-F·key=perm_mod8380 ········-F·auid!=unset·-F·key=perm_mod
8381 ······create:·true8381 ······create:·true
8382 ······mode:·o-rwx8382 ······mode:·o-rwx
8383 ······state:·present8383 ······state:·present
8384 ····when:·syscalls_found·|·length·==·08384 ····when:·syscalls_found·|·length·==·0
8385 ··when:8385 ··when:
8386 ··-·'"audit"·in·ansible_facts.packages' 
8387 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8386 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
Max diff block lines reached; 337210/343507 bytes (98.17%) of diff not shown.
885 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_server_l1.html
    
Offset 15373, 116 lines modifiedOffset 15373, 116 lines modified
0003c0c0:·6574·3d22·2369·646d·3736·3035·2220·7461··et="#idm7605"·ta0003c0c0:·6574·3d22·2369·646d·3736·3035·2220·7461··et="#idm7605"·ta
0003c0d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c0d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c0e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c0e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c0f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c0f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c100:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c100:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c110:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c110:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c120:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c120:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c130:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet0003c130:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
0003c140:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003c140:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003c150:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003c150:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003c160:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003c160:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003c170:·2069·643d·2269·646d·3736·3035·223e·3c74···id="idm7605"><t0003c170:·643d·2269·646d·3736·3035·223e·3c74·6162··d="idm7605"><tab
0003c180:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003c180:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003c190:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003c190:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003c1a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003c1a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003c1b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003c1b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003c1c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003c1c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003c1d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003c1d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c1e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c1e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003c1f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003c1f0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003c200:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c200:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c210:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003c210:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003c220:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003c220:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003c230:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003c230:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003c240:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.0003c240:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
0003c250:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai0003c250:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 0003c260:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 0003c270:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 0003c280:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 0003c290:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0003c2a0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0003c2b0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003c2c0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003c2d0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003c2e0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003c2f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003c300:·3d22·2369·646d·3736·3036·2220·7461·6269··="#idm7606"·tabi
 0003c310:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0003c320:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0003c330:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0003c340:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0003c350:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003c360:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003c370:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003c380:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003c390:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003c3a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003c3b0:·646d·3736·3036·223e·3c74·6162·6c65·2063··dm7606"><table·c
 0003c3c0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003c3d0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003c3e0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003c3f0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003c400:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003c410:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003c420:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003c430:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003c440:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003c450:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003c460:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003c470:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003c480:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 0003c490:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 0003c4a0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 0003c4b0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 0003c4c0:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
 0003c4d0:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
 0003c4e0:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
 0003c4f0:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t
 0003c500:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 0003c510:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"·
 0003c520:·3b20·7468·656e·0a20·2020·2064·6e66·2069··;·then.····dnf·i
 0003c530:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 0003c540:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 0003c550:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 0003c560:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 0003c570:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 0003c580:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
0003c260:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>0003c590:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
0003c270:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003c5a0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003c280:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003c5b0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003c290:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003c5c0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003c2a0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003c5d0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003c2b0:·6765·743d·2223·6964·6d37·3630·3622·2074··get="#idm7606"·t0003c5e0:·6765·743d·2223·6964·6d37·3630·3722·2074··get="#idm7607"·t
0003c2c0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003c5f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003c2d0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003c600:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003c2e0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003c610:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003c2f0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003c620:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003c300:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003c630:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003c310:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003c640:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003c320:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·0003c650:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
0003c330:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003c660:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c340:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003c670:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c350:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003c680:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c360:·6964·3d22·6964·6d37·3630·3622·3e3c·7461··id="idm7606"><ta0003c690:·2220·6964·3d22·6964·6d37·3630·3722·3e3c··"·id="idm7607"><
0003c370:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003c6a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c380:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003c6b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c390:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003c6c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c3a0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003c6d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c3b0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003c6e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c3c0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003c6f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c3d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c700:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c3e0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003c710:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003c3f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c720:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c400:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003c730:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003c410:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003c740:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003c420:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003c750:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003c430:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in0003c760:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003c770:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a
0003c440:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai 
0003c450:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal 
0003c460:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa 
0003c470:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.··· 
0003c480:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
0003c490:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
0003c4a0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003c4b0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003c4c0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003c4d0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003c4e0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003c4f0:·743d·2223·6964·6d37·3630·3722·2074·6162··t="#idm7607"·tab 
0003c500:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003c510:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003c520:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003c530:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003c540:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003c550:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003c560:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
Max diff block lines reached; 801400/816056 bytes (98.20%) of diff not shown.
88.1 KB
html2text {}
    
Offset 108, 20 lines modifiedOffset 108, 14 lines modified
108 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed108 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
109 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199109 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
110 Remediation_OSBuild_Blueprint_snippet_⇲110 Remediation_OSBuild_Blueprint_snippet_⇲
  
111 [[packages]]111 [[packages]]
112 name·=·"aide"112 name·=·"aide"
113 version·=·"*"113 version·=·"*"
114 Remediation_Anaconda_snippet_⇲ 
115 Complexity:·low 
116 Disruption:·low 
117 Strategy:···enable 
  
118 package·--add=aide 
119 Remediation_Puppet_snippet_⇲114 Remediation_Puppet_snippet_⇲
120 Complexity:·low115 Complexity:·low
121 Disruption:·low116 Disruption:·low
122 Strategy:···enable117 Strategy:···enable
123 include·install_aide118 include·install_aide
  
124 class·install_aide·{119 class·install_aide·{
Offset 139, 14 lines modifiedOffset 133, 20 lines modified
139 if·!·rpm·-q·--quiet·"aide"·;·then133 if·!·rpm·-q·--quiet·"aide"·;·then
140 ····dnf·install·-y·"aide"134 ····dnf·install·-y·"aide"
141 fi135 fi
  
142 else136 else
143 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'137 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
144 fi138 fi
 139 Remediation_Anaconda_snippet_⇲
 140 Complexity:·low
 141 Disruption:·low
 142 Strategy:···enable
  
 143 package·--add=aide
145 Remediation_Ansible_snippet_⇲144 Remediation_Ansible_snippet_⇲
146 Complexity:·low145 Complexity:·low
147 Disruption:·low146 Disruption:·low
148 Strategy:···enable147 Strategy:···enable
149 -·name:·Ensure·aide·is·installed148 -·name:·Ensure·aide·is·installed
150 ··package:149 ··package:
151 ····name:·aide150 ····name:·aide
Offset 1113, 20 lines modifiedOffset 1113, 14 lines modified
1113 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1113 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1114 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001251114 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
1115 Remediation_OSBuild_Blueprint_snippet_⇲1115 Remediation_OSBuild_Blueprint_snippet_⇲
  
1116 [[packages]]1116 [[packages]]
1117 name·=·"sudo"1117 name·=·"sudo"
1118 version·=·"*"1118 version·=·"*"
1119 Remediation_Anaconda_snippet_⇲ 
1120 Complexity:·low 
1121 Disruption:·low 
1122 Strategy:···enable 
  
1123 package·--add=sudo 
1124 Remediation_Puppet_snippet_⇲1119 Remediation_Puppet_snippet_⇲
1125 Complexity:·low1120 Complexity:·low
1126 Disruption:·low1121 Disruption:·low
1127 Strategy:···enable1122 Strategy:···enable
1128 include·install_sudo1123 include·install_sudo
  
1129 class·install_sudo·{1124 class·install_sudo·{
Offset 1144, 14 lines modifiedOffset 1138, 20 lines modified
1144 if·!·rpm·-q·--quiet·"sudo"·;·then1138 if·!·rpm·-q·--quiet·"sudo"·;·then
1145 ····dnf·install·-y·"sudo"1139 ····dnf·install·-y·"sudo"
1146 fi1140 fi
  
1147 else1141 else
1148 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1149 fi1143 fi
 1144 Remediation_Anaconda_snippet_⇲
 1145 Complexity:·low
 1146 Disruption:·low
 1147 Strategy:···enable
  
 1148 package·--add=sudo
1150 Remediation_Ansible_snippet_⇲1149 Remediation_Ansible_snippet_⇲
1151 Complexity:·low1150 Complexity:·low
1152 Disruption:·low1151 Disruption:·low
1153 Strategy:···enable1152 Strategy:···enable
1154 -·name:·Ensure·sudo·is·installed1153 -·name:·Ensure·sudo·is·installed
1155 ··package:1154 ··package:
1156 ····name:·sudo1155 ····name:·sudo
Offset 7737, 15 lines modifiedOffset 7737, 15 lines modified
7737 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg7737 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg
7738 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-002277738 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227
7739 Remediation_Shell_script_⇲7739 Remediation_Shell_script_⇲
7740 Complexity:·low7740 Complexity:·low
7741 Disruption:·low7741 Disruption:·low
7742 Strategy:···configure7742 Strategy:···configure
7743 #·Remediation·is·applicable·only·in·certain·platforms7743 #·Remediation·is·applicable·only·in·certain·platforms
7744 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then7744 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
7745 chgrp·0·/boot/grub2/grub.cfg7745 chgrp·0·/boot/grub2/grub.cfg
  
7746 else7746 else
7747 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7747 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7748 fi7748 fi
7749 Remediation_Ansible_snippet_⇲7749 Remediation_Ansible_snippet_⇲
Offset 7769, 16 lines modifiedOffset 7769, 16 lines modified
7769 ··-·no_reboot_needed7769 ··-·no_reboot_needed
  
7770 -·name:·Test·for·existence·/boot/grub2/grub.cfg7770 -·name:·Test·for·existence·/boot/grub2/grub.cfg
7771 ··stat:7771 ··stat:
7772 ····path:·/boot/grub2/grub.cfg7772 ····path:·/boot/grub2/grub.cfg
7773 ··register:·file_exists7773 ··register:·file_exists
7774 ··when:7774 ··when:
7775 ··-·'"grub2-common"·in·ansible_facts.packages' 
7776 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'7775 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 7776 ··-·'"grub2-common"·in·ansible_facts.packages'
7777 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7777 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
7778 ··tags:7778 ··tags:
7779 ··-·CJIS-5.5.2.27779 ··-·CJIS-5.5.2.2
7780 ··-·NIST-800-171-3.4.57780 ··-·NIST-800-171-3.4.5
7781 ··-·NIST-800-53-AC-6(1)7781 ··-·NIST-800-53-AC-6(1)
7782 ··-·NIST-800-53-CM-6(a)7782 ··-·NIST-800-53-CM-6(a)
7783 ··-·PCI-DSS-Req-7.17783 ··-·PCI-DSS-Req-7.1
Offset 7790, 16 lines modifiedOffset 7790, 16 lines modified
7790 ··-·no_reboot_needed7790 ··-·no_reboot_needed
  
7791 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg7791 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
7792 ··file:7792 ··file:
7793 ····path:·/boot/grub2/grub.cfg7793 ····path:·/boot/grub2/grub.cfg
7794 ····group:·'0'7794 ····group:·'0'
7795 ··when:7795 ··when:
7796 ··-·'"grub2-common"·in·ansible_facts.packages' 
7797 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'7796 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
Max diff block lines reached; 85357/90180 bytes (94.65%) of diff not shown.
854 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_workstation_l1.html
    
Offset 15368, 116 lines modifiedOffset 15368, 116 lines modified
0003c070:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003c070:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003c080:·2369·646d·3736·3035·2220·7461·6269·6e64··#idm7605"·tabind0003c080:·2369·646d·3736·3035·2220·7461·6269·6e64··#idm7605"·tabind
0003c090:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003c090:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003c0a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003c0a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003c0b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003c0b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c0c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003c0c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c0d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003c0d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c0e0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003c0e0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003c0f0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003c0f0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003c100:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003c100:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003c110:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003c110:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003c120:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003c120:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003c130:·2269·646d·3736·3035·223e·3c74·6162·6c65··"idm7605"><table0003c130:·646d·3736·3035·223e·3c74·6162·6c65·2063··dm7605"><table·c
0003c140:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003c140:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003c150:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003c150:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003c160:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003c160:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003c170:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003c170:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003c180:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003c180:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003c190:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c190:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c1a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003c1a0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003c1b0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003c1b0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003c1c0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003c1c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c1d0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003c1d0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003c1e0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003c1e0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003c1f0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003c1f0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0003c200:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
0003c210:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<0003c200:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 0003c210:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 0003c220:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 0003c230:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 0003c240:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 0003c250:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 0003c260:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 0003c270:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003c280:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003c290:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003c2a0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003c2b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003c2c0:·646d·3736·3036·2220·7461·6269·6e64·6578··dm7606"·tabindex
 0003c2d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003c2e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003c2f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003c300:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003c310:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003c320:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 0003c330:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003c340:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003c350:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003c360:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm76
 0003c370:·3036·223e·3c74·6162·6c65·2063·6c61·7373··06"><table·class
 0003c380:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003c390:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003c3a0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003c3b0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003c3c0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003c3d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003c3e0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003c3f0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003c400:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003c410:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003c420:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003c430:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c440:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0003c450:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0003c460:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0003c470:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
 0003c480:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
 0003c490:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
 0003c4a0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
 0003c4b0:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.
 0003c4c0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 0003c4d0:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 0003c4e0:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta
 0003c4f0:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 0003c500:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 0003c510:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 0003c520:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 0003c530:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 0003c540:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
0003c220:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003c550:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003c230:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003c560:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003c240:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003c570:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003c250:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003c580:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003c260:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003c590:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c270:·2223·6964·6d37·3630·3622·2074·6162·696e··"#idm7606"·tabin0003c5a0:·2223·6964·6d37·3630·3722·2074·6162·696e··"#idm7607"·tabin
0003c280:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003c5b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c290:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003c5c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c2a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003c5d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c2b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003c5e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c2c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003c5f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c2d0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup0003c600:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
0003c2e0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<0003c610:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
0003c2f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003c620:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003c300:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003c630:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003c310:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003c640:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003c320:·6964·6d37·3630·3622·3e3c·7461·626c·6520··idm7606"><table·0003c650:·3d22·6964·6d37·3630·3722·3e3c·7461·626c··="idm7607"><tabl
0003c330:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003c660:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003c340:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003c670:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003c350:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003c680:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003c360:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003c690:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003c370:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003c6a0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003c380:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c6b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c390:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003c6c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003c3a0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003c6d0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003c3b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c6e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c3c0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003c6f0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003c3d0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003c700:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003c3e0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003c710:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003c720:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003c730:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
0003c3f0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ 
0003c400:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003c410:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003c420:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003c430:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003c440:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003c450:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003c460:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003c470:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003c480:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003c490:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003c4a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003c4b0:·6964·6d37·3630·3722·2074·6162·696e·6465··idm7607"·tabinde 
0003c4c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003c4d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003c4e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003c4f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
Max diff block lines reached; 773742/788398 bytes (98.14%) of diff not shown.
83.8 KB
html2text {}
    
Offset 107, 20 lines modifiedOffset 107, 14 lines modified
107 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed107 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
108 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199108 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
109 Remediation_OSBuild_Blueprint_snippet_⇲109 Remediation_OSBuild_Blueprint_snippet_⇲
  
110 [[packages]]110 [[packages]]
111 name·=·"aide"111 name·=·"aide"
112 version·=·"*"112 version·=·"*"
113 Remediation_Anaconda_snippet_⇲ 
114 Complexity:·low 
115 Disruption:·low 
116 Strategy:···enable 
  
117 package·--add=aide 
118 Remediation_Puppet_snippet_⇲113 Remediation_Puppet_snippet_⇲
119 Complexity:·low114 Complexity:·low
120 Disruption:·low115 Disruption:·low
121 Strategy:···enable116 Strategy:···enable
122 include·install_aide117 include·install_aide
  
123 class·install_aide·{118 class·install_aide·{
Offset 138, 14 lines modifiedOffset 132, 20 lines modified
138 if·!·rpm·-q·--quiet·"aide"·;·then132 if·!·rpm·-q·--quiet·"aide"·;·then
139 ····dnf·install·-y·"aide"133 ····dnf·install·-y·"aide"
140 fi134 fi
  
141 else135 else
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
143 fi137 fi
 138 Remediation_Anaconda_snippet_⇲
 139 Complexity:·low
 140 Disruption:·low
 141 Strategy:···enable
  
 142 package·--add=aide
144 Remediation_Ansible_snippet_⇲143 Remediation_Ansible_snippet_⇲
145 Complexity:·low144 Complexity:·low
146 Disruption:·low145 Disruption:·low
147 Strategy:···enable146 Strategy:···enable
148 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
149 ··package:148 ··package:
150 ····name:·aide149 ····name:·aide
Offset 1112, 20 lines modifiedOffset 1112, 14 lines modified
1112 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1112 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1113 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001251113 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
1114 Remediation_OSBuild_Blueprint_snippet_⇲1114 Remediation_OSBuild_Blueprint_snippet_⇲
  
1115 [[packages]]1115 [[packages]]
1116 name·=·"sudo"1116 name·=·"sudo"
1117 version·=·"*"1117 version·=·"*"
1118 Remediation_Anaconda_snippet_⇲ 
1119 Complexity:·low 
1120 Disruption:·low 
1121 Strategy:···enable 
  
1122 package·--add=sudo 
1123 Remediation_Puppet_snippet_⇲1118 Remediation_Puppet_snippet_⇲
1124 Complexity:·low1119 Complexity:·low
1125 Disruption:·low1120 Disruption:·low
1126 Strategy:···enable1121 Strategy:···enable
1127 include·install_sudo1122 include·install_sudo
  
1128 class·install_sudo·{1123 class·install_sudo·{
Offset 1143, 14 lines modifiedOffset 1137, 20 lines modified
1143 if·!·rpm·-q·--quiet·"sudo"·;·then1137 if·!·rpm·-q·--quiet·"sudo"·;·then
1144 ····dnf·install·-y·"sudo"1138 ····dnf·install·-y·"sudo"
1145 fi1139 fi
  
1146 else1140 else
1147 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1148 fi1142 fi
 1143 Remediation_Anaconda_snippet_⇲
 1144 Complexity:·low
 1145 Disruption:·low
 1146 Strategy:···enable
  
 1147 package·--add=sudo
1149 Remediation_Ansible_snippet_⇲1148 Remediation_Ansible_snippet_⇲
1150 Complexity:·low1149 Complexity:·low
1151 Disruption:·low1150 Disruption:·low
1152 Strategy:···enable1151 Strategy:···enable
1153 -·name:·Ensure·sudo·is·installed1152 -·name:·Ensure·sudo·is·installed
1154 ··package:1153 ··package:
1155 ····name:·sudo1154 ····name:·sudo
Offset 7736, 15 lines modifiedOffset 7736, 15 lines modified
7736 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg7736 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg
7737 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-002277737 Identifiers·and·References·References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227
7738 Remediation_Shell_script_⇲7738 Remediation_Shell_script_⇲
7739 Complexity:·low7739 Complexity:·low
7740 Disruption:·low7740 Disruption:·low
7741 Strategy:···configure7741 Strategy:···configure
7742 #·Remediation·is·applicable·only·in·certain·platforms7742 #·Remediation·is·applicable·only·in·certain·platforms
7743 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then7743 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
7744 chgrp·0·/boot/grub2/grub.cfg7744 chgrp·0·/boot/grub2/grub.cfg
  
7745 else7745 else
7746 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7746 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7747 fi7747 fi
7748 Remediation_Ansible_snippet_⇲7748 Remediation_Ansible_snippet_⇲
Offset 7768, 16 lines modifiedOffset 7768, 16 lines modified
7768 ··-·no_reboot_needed7768 ··-·no_reboot_needed
  
7769 -·name:·Test·for·existence·/boot/grub2/grub.cfg7769 -·name:·Test·for·existence·/boot/grub2/grub.cfg
7770 ··stat:7770 ··stat:
7771 ····path:·/boot/grub2/grub.cfg7771 ····path:·/boot/grub2/grub.cfg
7772 ··register:·file_exists7772 ··register:·file_exists
7773 ··when:7773 ··when:
7774 ··-·'"grub2-common"·in·ansible_facts.packages' 
7775 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'7774 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 7775 ··-·'"grub2-common"·in·ansible_facts.packages'
7776 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7776 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
7777 ··tags:7777 ··tags:
7778 ··-·CJIS-5.5.2.27778 ··-·CJIS-5.5.2.2
7779 ··-·NIST-800-171-3.4.57779 ··-·NIST-800-171-3.4.5
7780 ··-·NIST-800-53-AC-6(1)7780 ··-·NIST-800-53-AC-6(1)
7781 ··-·NIST-800-53-CM-6(a)7781 ··-·NIST-800-53-CM-6(a)
7782 ··-·PCI-DSS-Req-7.17782 ··-·PCI-DSS-Req-7.1
Offset 7789, 16 lines modifiedOffset 7789, 16 lines modified
7789 ··-·no_reboot_needed7789 ··-·no_reboot_needed
  
7790 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg7790 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
7791 ··file:7791 ··file:
7792 ····path:·/boot/grub2/grub.cfg7792 ····path:·/boot/grub2/grub.cfg
7793 ····group:·'0'7793 ····group:·'0'
7794 ··when:7794 ··when:
7795 ··-·'"grub2-common"·in·ansible_facts.packages' 
7796 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'7795 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
Max diff block lines reached; 80978/85801 bytes (94.38%) of diff not shown.
1.71 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_workstation_l2.html
    
Offset 15379, 116 lines modifiedOffset 15379, 116 lines modified
0003c120:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003c120:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003c130:·3630·3522·2074·6162·696e·6465·783d·2230··605"·tabindex="00003c130:·3630·3522·2074·6162·696e·6465·783d·2230··605"·tabindex="0
0003c140:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c140:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c150:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c150:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c160:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c160:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c170:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c170:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c180:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c180:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c190:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003c190:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003c1a0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003c1a0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003c1b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003c1b0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003c1c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003c1c0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003c1d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003c1d0:·6170·7365·2220·6964·3d22·6964·6d37·3630··apse"·id="idm760
0003c1e0:·3630·3522·3e3c·7461·626c·6520·636c·6173··605"><table·clas0003c1e0:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=
0003c1f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003c1f0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c200:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003c200:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c210:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003c210:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c220:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003c220:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c230:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003c230:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c240:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c240:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c250:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c250:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c260:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c260:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c270:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c280:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c280:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c290:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c290:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003c2a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c2a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003c2b0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003c2c0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003c2b0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003c2c0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003c2d0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003c2e0:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003c2f0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003c300:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003c310:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003c320:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003c330:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003c340:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003c350:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003c360:·2d74·6172·6765·743d·2223·6964·6d37·3630··-target="#idm760
 0003c370:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
 0003c380:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003c390:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003c3a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003c3b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003c3c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003c3d0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003c3e0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003c3f0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003c400:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003c410:·2220·6964·3d22·6964·6d37·3630·3622·3e3c··"·id="idm7606"><
 0003c420:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003c430:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003c440:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003c450:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003c460:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003c470:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003c480:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c490:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003c4a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003c4b0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003c4c0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003c4d0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003c4e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003c4f0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003c500:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003c510:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003c520:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003c530:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003c540:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003c550:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003c560:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003c570:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003c580:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003c590:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y
 0003c5a0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003c5b0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003c5c0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003c5d0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003c5e0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003c5f0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003c2d0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003c600:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003c2e0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003c610:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003c2f0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003c620:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003c300:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003c630:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003c310:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c640:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c320:·3736·3036·2220·7461·6269·6e64·6578·3d22··7606"·tabindex="0003c650:·3736·3037·2220·7461·6269·6e64·6578·3d22··7607"·tabindex="
0003c330:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c660:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c340:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c670:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c350:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c680:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c360:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c690:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c370:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c6a0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c380:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003c6b0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003c390:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003c6c0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003c3a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003c6d0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003c3b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003c6e0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003c3c0:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm760003c6f0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003c3d0:·3036·223e·3c74·6162·6c65·2063·6c61·7373··06"><table·class0003c700:·3736·3037·223e·3c74·6162·6c65·2063·6c61··7607"><table·cla
0003c3e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003c710:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003c3f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003c720:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c400:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003c730:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003c410:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003c740:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003c420:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003c750:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003c430:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c760:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c440:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003c770:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003c450:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003c780:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003c460:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c790:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c470:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003c7a0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003c480:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003c7b0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003c490:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003c7c0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c7d0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003c7e0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003c4a0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003c4b0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003c4c0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003c4d0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003c4e0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003c4f0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003c500:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003c510:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003c520:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003c530:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003c540:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003c550:·612d·7461·7267·6574·3d22·2369·646d·3736··a-target="#idm76 
0003c560:·3037·2220·7461·6269·6e64·6578·3d22·3022··07"·tabindex="0" 
0003c570:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003c580:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003c590:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003c5a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 1435989/1450645 bytes (98.99%) of diff not shown.
332 KB
html2text {}
    
Offset 109, 20 lines modifiedOffset 109, 14 lines modified
109 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed109 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
110 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199110 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
111 Remediation_OSBuild_Blueprint_snippet_⇲111 Remediation_OSBuild_Blueprint_snippet_⇲
  
112 [[packages]]112 [[packages]]
113 name·=·"aide"113 name·=·"aide"
114 version·=·"*"114 version·=·"*"
115 Remediation_Anaconda_snippet_⇲ 
116 Complexity:·low 
117 Disruption:·low 
118 Strategy:···enable 
  
119 package·--add=aide 
120 Remediation_Puppet_snippet_⇲115 Remediation_Puppet_snippet_⇲
121 Complexity:·low116 Complexity:·low
122 Disruption:·low117 Disruption:·low
123 Strategy:···enable118 Strategy:···enable
124 include·install_aide119 include·install_aide
  
125 class·install_aide·{120 class·install_aide·{
Offset 140, 14 lines modifiedOffset 134, 20 lines modified
140 if·!·rpm·-q·--quiet·"aide"·;·then134 if·!·rpm·-q·--quiet·"aide"·;·then
141 ····dnf·install·-y·"aide"135 ····dnf·install·-y·"aide"
142 fi136 fi
  
143 else137 else
144 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'138 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
145 fi139 fi
 140 Remediation_Anaconda_snippet_⇲
 141 Complexity:·low
 142 Disruption:·low
 143 Strategy:···enable
  
 144 package·--add=aide
146 Remediation_Ansible_snippet_⇲145 Remediation_Ansible_snippet_⇲
147 Complexity:·low146 Complexity:·low
148 Disruption:·low147 Disruption:·low
149 Strategy:···enable148 Strategy:···enable
150 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
151 ··package:150 ··package:
152 ····name:·aide151 ····name:·aide
Offset 1199, 20 lines modifiedOffset 1199, 14 lines modified
1199 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed1199 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
1200 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001251200 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
1201 Remediation_OSBuild_Blueprint_snippet_⇲1201 Remediation_OSBuild_Blueprint_snippet_⇲
  
1202 [[packages]]1202 [[packages]]
1203 name·=·"sudo"1203 name·=·"sudo"
1204 version·=·"*"1204 version·=·"*"
1205 Remediation_Anaconda_snippet_⇲ 
1206 Complexity:·low 
1207 Disruption:·low 
1208 Strategy:···enable 
  
1209 package·--add=sudo 
1210 Remediation_Puppet_snippet_⇲1205 Remediation_Puppet_snippet_⇲
1211 Complexity:·low1206 Complexity:·low
1212 Disruption:·low1207 Disruption:·low
1213 Strategy:···enable1208 Strategy:···enable
1214 include·install_sudo1209 include·install_sudo
  
1215 class·install_sudo·{1210 class·install_sudo·{
Offset 1230, 14 lines modifiedOffset 1224, 20 lines modified
1230 if·!·rpm·-q·--quiet·"sudo"·;·then1224 if·!·rpm·-q·--quiet·"sudo"·;·then
1231 ····dnf·install·-y·"sudo"1225 ····dnf·install·-y·"sudo"
1232 fi1226 fi
  
1233 else1227 else
1234 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1228 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1235 fi1229 fi
 1230 Remediation_Anaconda_snippet_⇲
 1231 Complexity:·low
 1232 Disruption:·low
 1233 Strategy:···enable
  
 1234 package·--add=sudo
1236 Remediation_Ansible_snippet_⇲1235 Remediation_Ansible_snippet_⇲
1237 Complexity:·low1236 Complexity:·low
1238 Disruption:·low1237 Disruption:·low
1239 Strategy:···enable1238 Strategy:···enable
1240 -·name:·Ensure·sudo·is·installed1239 -·name:·Ensure·sudo·is·installed
1241 ··package:1240 ··package:
1242 ····name:·sudo1241 ····name:·sudo
Offset 7879, 15 lines modifiedOffset 7879, 15 lines modified
7879 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.7879 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
7880 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.7880 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
7881 Severity: ················medium7881 Severity: ················medium
7882 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod7882 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
7883 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019407883 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
7884 Remediation_Shell_script_⇲7884 Remediation_Shell_script_⇲
7885 #·Remediation·is·applicable·only·in·certain·platforms7885 #·Remediation·is·applicable·only·in·certain·platforms
7886 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7886 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7887 #·First·perform·the·remediation·of·the·syscall·rule7887 #·First·perform·the·remediation·of·the·syscall·rule
7888 #·Retrieve·hardware·architecture·of·the·underlying·system7888 #·Retrieve·hardware·architecture·of·the·underlying·system
7889 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")7889 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
7890 for·ARCH·in·"${RULE_ARCHS[@]}"7890 for·ARCH·in·"${RULE_ARCHS[@]}"
7891 do7891 do
Offset 8233, 16 lines modifiedOffset 8233, 16 lines modified
8233 ··-·reboot_required8233 ··-·reboot_required
8234 ··-·restrict_strategy8234 ··-·restrict_strategy
  
8235 -·name:·Set·architecture·for·audit·chmod·tasks8235 -·name:·Set·architecture·for·audit·chmod·tasks
8236 ··set_fact:8236 ··set_fact:
8237 ····audit_arch:·b648237 ····audit_arch:·b64
8238 ··when:8238 ··when:
8239 ··-·'"audit"·in·ansible_facts.packages' 
8240 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8239 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8240 ··-·'"audit"·in·ansible_facts.packages'
8241 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8241 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8242 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8242 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8243 ··tags:8243 ··tags:
8244 ··-·CJIS-5.4.1.18244 ··-·CJIS-5.4.1.1
8245 ··-·NIST-800-171-3.1.78245 ··-·NIST-800-171-3.1.7
8246 ··-·NIST-800-53-AU-12(c)8246 ··-·NIST-800-53-AU-12(c)
8247 ··-·NIST-800-53-AU-2(d)8247 ··-·NIST-800-53-AU-2(d)
Offset 8378, 16 lines modifiedOffset 8378, 16 lines modified
8378 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008378 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8379 ········-F·auid!=unset·-F·key=perm_mod8379 ········-F·auid!=unset·-F·key=perm_mod
8380 ······create:·true8380 ······create:·true
8381 ······mode:·o-rwx8381 ······mode:·o-rwx
8382 ······state:·present8382 ······state:·present
8383 ····when:·syscalls_found·|·length·==·08383 ····when:·syscalls_found·|·length·==·0
8384 ··when:8384 ··when:
8385 ··-·'"audit"·in·ansible_facts.packages' 
8386 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8385 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
Max diff block lines reached; 333760/340057 bytes (98.15%) of diff not shown.
428 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cui.html
    
Offset 16071, 107 lines modifiedOffset 16071, 107 lines modified
0003ec60:·7461·7267·6574·3d22·2369·646d·3832·3731··target="#idm82710003ec60:·7461·7267·6574·3d22·2369·646d·3832·3731··target="#idm8271
0003ec70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ec70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003ec80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ec80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003ec90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003ec90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003eca0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003eca0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003ecb0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003ecb0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003ecc0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003ecc0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003ecd0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni0003ecd0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
0003ece0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003ece0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003ecf0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003ecf0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003ed00:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003ed00:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003ed10:·7073·6522·2069·643d·2269·646d·3832·3731··pse"·id="idm82710003ed10:·6522·2069·643d·2269·646d·3832·3731·223e··e"·id="idm8271">
0003ed20:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003ed20:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003ed30:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003ed30:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003ed40:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003ed40:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003ed50:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003ed50:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003ed60:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003ed60:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003ed70:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003ed70:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003ed80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003ed80:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003ed90:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003ed90:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003eda0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003edb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003edc0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003edd0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003ede0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003edf0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
0003ee00:·643d·6372·7970·746f·2d70·6f6c·6963·6965··d=crypto-policie 
0003ee10:·730a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··s.</code></pre>< 
0003ee20:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003ee30:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003ee40:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003ee50:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003ee60:·6574·3d22·2369·646d·3832·3732·2220·7461··et="#idm8272"·ta 
0003ee70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003ee80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003ee90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003eea0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003eeb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003eec0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003eed0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·. 
0003eee0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003eef0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003ef00:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003ef10:·643d·2269·646d·3832·3732·223e·3c74·6162··d="idm8272"><tab 
0003ef20:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003ef30:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003ef40:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003ef50:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003ef60:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003ef70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ef80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003ef90:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003efa0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003efb0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003efc0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003efd0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003efe0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc 
0003eff0:·6c75·6465·2069·6e73·7461·6c6c·5f63·7279··lude·install_cry 
0003f000:·7074·6f2d·706f·6c69·6369·6573·0a0a·636c··pto-policies..cl 
0003f010:·6173·7320·696e·7374·616c·6c5f·6372·7970··ass·install_cryp 
0003f020:·746f·2d70·6f6c·6963·6965·7320·7b0a·2020··to-policies·{.·· 
0003f030:·7061·636b·6167·6520·7b20·2763·7279·7074··package·{·'crypt 
0003f040:·6f2d·706f·6c69·6369·6573·273a·0a20·2020··o-policies':.··· 
0003f050:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
0003f060:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
0003f070:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003f080:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003f090:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003f0a0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003f0b0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003f0c0:·743d·2223·6964·6d38·3237·3322·2074·6162··t="#idm8273"·tab 
0003f0d0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003f0e0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003f0f0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003f100:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003f110:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003f120:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003f130:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003f140:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003f150:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003f160:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003f170:·6964·6d38·3237·3322·3e3c·7461·626c·6520··idm8273"><table· 
0003f180:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003f190:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003f1a0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003f1b0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003f1c0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003f1d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003eda0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003f1e0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003edb0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003edc0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003edd0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003ede0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003edf0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003ee00:·5f63·7279·7074·6f2d·706f·6c69·6369·6573··_crypto-policies
 0003ee10:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003ee20:·6372·7970·746f·2d70·6f6c·6963·6965·7320··crypto-policies·
 0003ee30:·7b0a·2020·7061·636b·6167·6520·7b20·2763··{.··package·{·'c
 0003ee40:·7279·7074·6f2d·706f·6c69·6369·6573·273a··rypto-policies':
 0003ee50:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 0003ee60:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 0003ee70:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 0003ee80:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003ee90:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003eea0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003eeb0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003eec0:·6172·6765·743d·2223·6964·6d38·3237·3222··arget="#idm8272"
 0003eed0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003eee0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003eef0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003ef00:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003ef10:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003ef20:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003ef30:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003ef40:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003ef50:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003ef60:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003ef70:·6964·3d22·6964·6d38·3237·3222·3e3c·7461··id="idm8272"><ta
 0003ef80:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003ef90:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003efa0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003efb0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003efc0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003efd0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003efe0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003f1f0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003eff0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003f000:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003f010:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
Max diff block lines reached; 380535/393949 bytes (96.59%) of diff not shown.
43.0 KB
html2text {}
    
Offset 248, 20 lines modifiedOffset 248, 14 lines modified
248 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed248 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
249 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174249 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
250 Remediation_OSBuild_Blueprint_snippet_⇲250 Remediation_OSBuild_Blueprint_snippet_⇲
  
251 [[packages]]251 [[packages]]
252 name·=·"crypto-policies"252 name·=·"crypto-policies"
253 version·=·"*"253 version·=·"*"
254 Remediation_Anaconda_snippet_⇲ 
255 Complexity:·low 
256 Disruption:·low 
257 Strategy:···enable 
  
258 package·--add=crypto-policies 
259 Remediation_Puppet_snippet_⇲254 Remediation_Puppet_snippet_⇲
260 Complexity:·low255 Complexity:·low
261 Disruption:·low256 Disruption:·low
262 Strategy:···enable257 Strategy:···enable
263 include·install_crypto-policies258 include·install_crypto-policies
  
264 class·install_crypto-policies·{259 class·install_crypto-policies·{
Offset 273, 14 lines modifiedOffset 267, 20 lines modified
273 Complexity:·low267 Complexity:·low
274 Disruption:·low268 Disruption:·low
275 Strategy:···enable269 Strategy:···enable
  
276 if·!·rpm·-q·--quiet·"crypto-policies"·;·then270 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
277 ····dnf·install·-y·"crypto-policies"271 ····dnf·install·-y·"crypto-policies"
278 fi272 fi
 273 Remediation_Anaconda_snippet_⇲
 274 Complexity:·low
 275 Disruption:·low
 276 Strategy:···enable
  
 277 package·--add=crypto-policies
279 Remediation_Ansible_snippet_⇲278 Remediation_Ansible_snippet_⇲
280 Complexity:·low279 Complexity:·low
281 Disruption:·low280 Disruption:·low
282 Strategy:···enable281 Strategy:···enable
283 -·name:·Ensure·crypto-policies·is·installed282 -·name:·Ensure·crypto-policies·is·installed
284 ··package:283 ··package:
285 ····name:·crypto-policies284 ····name:·crypto-policies
Offset 570, 20 lines modifiedOffset 570, 14 lines modified
570 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed570 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
571 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125571 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
572 Remediation_OSBuild_Blueprint_snippet_⇲572 Remediation_OSBuild_Blueprint_snippet_⇲
  
573 [[packages]]573 [[packages]]
574 name·=·"sudo"574 name·=·"sudo"
575 version·=·"*"575 version·=·"*"
576 Remediation_Anaconda_snippet_⇲ 
577 Complexity:·low 
578 Disruption:·low 
579 Strategy:···enable 
  
580 package·--add=sudo 
581 Remediation_Puppet_snippet_⇲576 Remediation_Puppet_snippet_⇲
582 Complexity:·low577 Complexity:·low
583 Disruption:·low578 Disruption:·low
584 Strategy:···enable579 Strategy:···enable
585 include·install_sudo580 include·install_sudo
  
586 class·install_sudo·{581 class·install_sudo·{
Offset 601, 14 lines modifiedOffset 595, 20 lines modified
601 if·!·rpm·-q·--quiet·"sudo"·;·then595 if·!·rpm·-q·--quiet·"sudo"·;·then
602 ····dnf·install·-y·"sudo"596 ····dnf·install·-y·"sudo"
603 fi597 fi
  
604 else598 else
605 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'599 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
606 fi600 fi
 601 Remediation_Anaconda_snippet_⇲
 602 Complexity:·low
 603 Disruption:·low
 604 Strategy:···enable
  
 605 package·--add=sudo
607 Remediation_Ansible_snippet_⇲606 Remediation_Ansible_snippet_⇲
608 Complexity:·low607 Complexity:·low
609 Disruption:·low608 Disruption:·low
610 Strategy:···enable609 Strategy:···enable
611 -·name:·Ensure·sudo·is·installed610 -·name:·Ensure·sudo·is·installed
612 ··package:611 ··package:
613 ····name:·sudo612 ····name:·sudo
Offset 633, 20 lines modifiedOffset 633, 14 lines modified
633 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed633 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed
634 Identifiers·and·References·References: ·FIA_X509_EXT.1,·FIA_X509_EXT.2,·SRG-OS-000480-GPOS-00227634 Identifiers·and·References·References: ·FIA_X509_EXT.1,·FIA_X509_EXT.2,·SRG-OS-000480-GPOS-00227
635 Remediation_OSBuild_Blueprint_snippet_⇲635 Remediation_OSBuild_Blueprint_snippet_⇲
  
636 [[packages]]636 [[packages]]
637 name·=·"gnutls-utils"637 name·=·"gnutls-utils"
638 version·=·"*"638 version·=·"*"
639 Remediation_Anaconda_snippet_⇲ 
640 Complexity:·low 
641 Disruption:·low 
642 Strategy:···enable 
  
643 package·--add=gnutls-utils 
644 Remediation_Puppet_snippet_⇲639 Remediation_Puppet_snippet_⇲
645 Complexity:·low640 Complexity:·low
646 Disruption:·low641 Disruption:·low
647 Strategy:···enable642 Strategy:···enable
648 include·install_gnutls-utils643 include·install_gnutls-utils
  
649 class·install_gnutls-utils·{644 class·install_gnutls-utils·{
Offset 658, 14 lines modifiedOffset 652, 20 lines modified
658 Complexity:·low652 Complexity:·low
659 Disruption:·low653 Disruption:·low
660 Strategy:···enable654 Strategy:···enable
  
661 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then655 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then
662 ····dnf·install·-y·"gnutls-utils"656 ····dnf·install·-y·"gnutls-utils"
663 fi657 fi
 658 Remediation_Anaconda_snippet_⇲
 659 Complexity:·low
 660 Disruption:·low
 661 Strategy:···enable
  
 662 package·--add=gnutls-utils
664 Remediation_Ansible_snippet_⇲663 Remediation_Ansible_snippet_⇲
665 Complexity:·low664 Complexity:·low
666 Disruption:·low665 Disruption:·low
667 Strategy:···enable666 Strategy:···enable
668 -·name:·Ensure·gnutls-utils·is·installed667 -·name:·Ensure·gnutls-utils·is·installed
669 ··package:668 ··package:
670 ····name:·gnutls-utils669 ····name:·gnutls-utils
Offset 685, 20 lines modifiedOffset 685, 14 lines modified
685 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_openscap-scanner_installed685 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_openscap-scanner_installed
Max diff block lines reached; 40619/43998 bytes (92.32%) of diff not shown.
691 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-e8.html
    
Offset 20519, 116 lines modifiedOffset 20519, 116 lines modified
00050260:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00050260:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00050270:·6964·6d31·3132·3932·2220·7461·6269·6e64··idm11292"·tabind00050270:·6964·6d31·3132·3932·2220·7461·6269·6e64··idm11292"·tabind
00050280:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00050280:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00050290:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00050290:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
000502a0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title000502a0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
000502b0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re000502b0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
000502c0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">000502c0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
000502d0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac000502d0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
000502e0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...000502e0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
000502f0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla000502f0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
00050300:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00050300:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
00050310:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00050310:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
00050320:·2269·646d·3131·3239·3222·3e3c·7461·626c··"idm11292"><tabl00050320:·646d·3131·3239·3222·3e3c·7461·626c·6520··dm11292"><table·
00050330:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00050330:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00050340:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00050340:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00050350:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00050350:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00050360:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00050360:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00050370:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00050370:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00050380:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00050380:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00050390:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00050390:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
000503a0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t000503a0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
000503b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><000503b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
000503c0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:000503c0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
000503d0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<000503d0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
000503e0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table000503e0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
000503f0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac000503f0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
00050400:·6b61·6765·202d·2d61·6464·3d72·6561·720a··kage·--add=rear. 
00050410:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
00050420:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
00050430:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00050440:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00050450:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00050460:·3d22·2369·646d·3131·3239·3322·2074·6162··="#idm11293"·tab 
00050470:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
00050480:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
00050490:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
000504a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
000504b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
000504c0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P 
000504d0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·.. 
000504e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
000504f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00050400:·6520·696e·7374·616c·6c5f·7265·6172·0a0a··e·install_rear..
 00050410:·636c·6173·7320·696e·7374·616c·6c5f·7265··class·install_re
 00050420:·6172·207b·0a20·2070·6163·6b61·6765·207b··ar·{.··package·{
 00050430:·2027·7265·6172·273a·0a20·2020·2065·6e73···'rear':.····ens
 00050440:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 00050450:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 00050460:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00050470:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00050480:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00050490:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 000504a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 000504b0:·6964·6d31·3132·3933·2220·7461·6269·6e64··idm11293"·tabind
 000504c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 000504d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 000504e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 000504f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 00050500:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 00050510:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 00050520:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 00050530:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
00050500:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00050540:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00050550:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00050560:·3131·3239·3322·3e3c·7461·626c·6520·636c··11293"><table·cl
 00050570:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00050580:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00050590:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 000505a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 000505b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
00050510:·3d22·6964·6d31·3132·3933·223e·3c74·6162··="idm11293"><tab 
00050520:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
00050530:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
00050540:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
00050550:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
00050560:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
00050570:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00050580:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
00050590:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
000505a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>000505c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
000505b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
000505c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable000505d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 000505e0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 000505f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00050600:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 00050610:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 00050620:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00050630:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 00050640:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 00050650:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 00050660:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 00050670:·2021·2067·7265·7020·2d71·2061·6172·6368···!·grep·-q·aarch
 00050680:·3634·202f·7072·6f63·2f73·7973·2f6b·6572··64·/proc/sys/ker
 00050690:·6e65·6c2f·6f73·7265·6c65·6173·653b·2074··nel/osrelease;·t
 000506a0:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 000506b0:·202d·2d71·7569·6574·2022·7265·6172·2220···--quiet·"rear"·
 000506c0:·3b20·7468·656e·0a20·2020·2064·6e66·2069··;·then.····dnf·i
 000506d0:·6e73·7461·6c6c·202d·7920·2272·6561·7222··nstall·-y·"rear"
 000506e0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 000506f0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 00050700:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 00050710:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 00050720:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 00050730:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 00050740:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 00050750:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00050760:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00050770:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 00050780:·6765·743d·2223·6964·6d31·3132·3934·2220··get="#idm11294"·
 00050790:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 000507a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 000507b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 000507c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 000507d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 000507e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 000507f0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
 00050800:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00050810:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00050820:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00050830:·6522·2069·643d·2269·646d·3131·3239·3422··e"·id="idm11294"
 00050840:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00050850:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00050860:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 00050870:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 00050880:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 00050890:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
000505d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl000508a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 000508b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
Max diff block lines reached; 552208/566864 bytes (97.41%) of diff not shown.
138 KB
html2text {}
    
Offset 908, 20 lines modifiedOffset 908, 14 lines modified
908 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed908 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
909 Identifiers·and·References909 Identifiers·and·References
910 Remediation_OSBuild_Blueprint_snippet_⇲910 Remediation_OSBuild_Blueprint_snippet_⇲
  
911 [[packages]]911 [[packages]]
912 name·=·"rear"912 name·=·"rear"
913 version·=·"*"913 version·=·"*"
914 Remediation_Anaconda_snippet_⇲ 
915 Complexity:·low 
916 Disruption:·low 
917 Strategy:···enable 
  
918 package·--add=rear 
919 Remediation_Puppet_snippet_⇲914 Remediation_Puppet_snippet_⇲
920 Complexity:·low915 Complexity:·low
921 Disruption:·low916 Disruption:·low
922 Strategy:···enable917 Strategy:···enable
923 include·install_rear918 include·install_rear
  
924 class·install_rear·{919 class·install_rear·{
Offset 939, 14 lines modifiedOffset 933, 20 lines modified
939 if·!·rpm·-q·--quiet·"rear"·;·then933 if·!·rpm·-q·--quiet·"rear"·;·then
940 ····dnf·install·-y·"rear"934 ····dnf·install·-y·"rear"
941 fi935 fi
  
942 else936 else
943 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'937 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
944 fi938 fi
 939 Remediation_Anaconda_snippet_⇲
 940 Complexity:·low
 941 Disruption:·low
 942 Strategy:···enable
  
 943 package·--add=rear
945 Remediation_Ansible_snippet_⇲944 Remediation_Ansible_snippet_⇲
946 Complexity:·low945 Complexity:·low
947 Disruption:·low946 Disruption:·low
948 Strategy:···enable947 Strategy:···enable
949 -·name:·Ensure·rear·is·installed948 -·name:·Ensure·rear·is·installed
950 ··package:949 ··package:
951 ····name:·rear950 ····name:·rear
Offset 1820, 15 lines modifiedOffset 1820, 15 lines modified
1820 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1820 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1821 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1821 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1822 Severity: ················medium1822 Severity: ················medium
1823 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1823 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1824 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019401824 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
1825 Remediation_Shell_script_⇲1825 Remediation_Shell_script_⇲
1826 #·Remediation·is·applicable·only·in·certain·platforms1826 #·Remediation·is·applicable·only·in·certain·platforms
1827 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1827 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1828 #·First·perform·the·remediation·of·the·syscall·rule1828 #·First·perform·the·remediation·of·the·syscall·rule
1829 #·Retrieve·hardware·architecture·of·the·underlying·system1829 #·Retrieve·hardware·architecture·of·the·underlying·system
1830 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1830 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1831 for·ARCH·in·"${RULE_ARCHS[@]}"1831 for·ARCH·in·"${RULE_ARCHS[@]}"
1832 do1832 do
Offset 2174, 16 lines modifiedOffset 2174, 16 lines modified
2174 ··-·reboot_required2174 ··-·reboot_required
2175 ··-·restrict_strategy2175 ··-·restrict_strategy
  
2176 -·name:·Set·architecture·for·audit·chmod·tasks2176 -·name:·Set·architecture·for·audit·chmod·tasks
2177 ··set_fact:2177 ··set_fact:
2178 ····audit_arch:·b642178 ····audit_arch:·b64
2179 ··when:2179 ··when:
2180 ··-·'"audit"·in·ansible_facts.packages' 
2181 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2180 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2181 ··-·'"audit"·in·ansible_facts.packages'
2182 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2182 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2183 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2183 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2184 ··tags:2184 ··tags:
2185 ··-·CJIS-5.4.1.12185 ··-·CJIS-5.4.1.1
2186 ··-·NIST-800-171-3.1.72186 ··-·NIST-800-171-3.1.7
2187 ··-·NIST-800-53-AU-12(c)2187 ··-·NIST-800-53-AU-12(c)
2188 ··-·NIST-800-53-AU-2(d)2188 ··-·NIST-800-53-AU-2(d)
Offset 2319, 16 lines modifiedOffset 2319, 16 lines modified
2319 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002319 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2320 ········-F·auid!=unset·-F·key=perm_mod2320 ········-F·auid!=unset·-F·key=perm_mod
2321 ······create:·true2321 ······create:·true
2322 ······mode:·o-rwx2322 ······mode:·o-rwx
2323 ······state:·present2323 ······state:·present
2324 ····when:·syscalls_found·|·length·==·02324 ····when:·syscalls_found·|·length·==·0
2325 ··when:2325 ··when:
2326 ··-·'"audit"·in·ansible_facts.packages' 
2327 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2326 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2327 ··-·'"audit"·in·ansible_facts.packages'
2328 ··tags:2328 ··tags:
2329 ··-·CJIS-5.4.1.12329 ··-·CJIS-5.4.1.1
2330 ··-·NIST-800-171-3.1.72330 ··-·NIST-800-171-3.1.7
2331 ··-·NIST-800-53-AU-12(c)2331 ··-·NIST-800-53-AU-12(c)
2332 ··-·NIST-800-53-AU-2(d)2332 ··-·NIST-800-53-AU-2(d)
2333 ··-·NIST-800-53-CM-6(a)2333 ··-·NIST-800-53-CM-6(a)
2334 ··-·PCI-DSS-Req-10.5.52334 ··-·PCI-DSS-Req-10.5.5
Offset 2462, 16 lines modifiedOffset 2462, 16 lines modified
2462 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002462 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2463 ········-F·auid!=unset·-F·key=perm_mod2463 ········-F·auid!=unset·-F·key=perm_mod
2464 ······create:·true2464 ······create:·true
2465 ······mode:·o-rwx2465 ······mode:·o-rwx
2466 ······state:·present2466 ······state:·present
2467 ····when:·syscalls_found·|·length·==·02467 ····when:·syscalls_found·|·length·==·0
2468 ··when:2468 ··when:
2469 ··-·'"audit"·in·ansible_facts.packages' 
2470 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2469 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2470 ··-·'"audit"·in·ansible_facts.packages'
2471 ··-·audit_arch·==·"b64"2471 ··-·audit_arch·==·"b64"
2472 ··tags:2472 ··tags:
2473 ··-·CJIS-5.4.1.12473 ··-·CJIS-5.4.1.1
2474 ··-·NIST-800-171-3.1.72474 ··-·NIST-800-171-3.1.7
2475 ··-·NIST-800-53-AU-12(c)2475 ··-·NIST-800-53-AU-12(c)
2476 ··-·NIST-800-53-AU-2(d)2476 ··-·NIST-800-53-AU-2(d)
2477 ··-·NIST-800-53-CM-6(a)2477 ··-·NIST-800-53-CM-6(a)
Offset 2494, 15 lines modifiedOffset 2494, 15 lines modified
2494 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2494 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2495 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2495 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2496 Severity: ················medium2496 Severity: ················medium
2497 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2497 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2498 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019402498 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
2499 Remediation_Shell_script_⇲2499 Remediation_Shell_script_⇲
2500 #·Remediation·is·applicable·only·in·certain·platforms2500 #·Remediation·is·applicable·only·in·certain·platforms
2501 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2501 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2502 #·First·perform·the·remediation·of·the·syscall·rule2502 #·First·perform·the·remediation·of·the·syscall·rule
2503 #·Retrieve·hardware·architecture·of·the·underlying·system2503 #·Retrieve·hardware·architecture·of·the·underlying·system
2504 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2504 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2505 for·ARCH·in·"${RULE_ARCHS[@]}"2505 for·ARCH·in·"${RULE_ARCHS[@]}"
2506 do2506 do
Max diff block lines reached; 132930/141021 bytes (94.26%) of diff not shown.
1.22 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-hipaa.html
    
Offset 23059, 94 lines modifiedOffset 23059, 94 lines modified
0005a120:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0005a120:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0005a130:·2369·646d·3134·3737·3022·2074·6162·696e··#idm14770"·tabin0005a130:·2369·646d·3134·3737·3022·2074·6162·696e··#idm14770"·tabin
0005a140:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0005a140:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0005a150:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0005a150:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0005a160:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0005a160:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0005a170:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0005a170:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0005a180:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0005a180:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0005a190:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub0005a190:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 0005a1a0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 0005a1b0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0005a1c0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0005a1d0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0005a1e0:·6c61·7073·6522·2069·643d·2269·646d·3134··lapse"·id="idm14
 0005a1f0:·3737·3022·3e3c·7072·653e·3c63·6f64·653e··770"><pre><code>
 0005a200:·0a5b·6375·7374·6f6d·697a·6174·696f·6e73··.[customizations
 0005a210:·2e73·6572·7669·6365·735d·0a64·6973·6162··.services].disab
 0005a220:·6c65·6420·3d20·5b22·6465·6275·672d·7368··led·=·["debug-sh
 0005a230:·656c·6c22·5d0a·3c2f·636f·6465·3e3c·2f70··ell"].</code></p
0005a1a0:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet· 
0005a1b0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0005a1c0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0005a1d0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0005a1e0:·6964·3d22·6964·6d31·3437·3730·223e·3c70··id="idm14770"><p 
0005a1f0:·7265·3e3c·636f·6465·3e2d·2d2d·0a61·7069··re><code>---.api 
0005a200:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine 
0005a210:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op 
0005a220:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki 
0005a230:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi 
0005a240:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config 
0005a250:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:. 
0005a260:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3 
0005a270:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd 
0005a280:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.· 
0005a290:·2020·2020·202d·2065·6e61·626c·6564·3a20·······-·enabled:· 
0005a2a0:·6661·6c73·650a·2020·2020·2020·2020·6e61··false.········na 
0005a2b0:·6d65·3a20·6465·6275·672d·7368·656c·6c2e··me:·debug-shell. 
0005a2c0:·7365·7276·6963·650a·3c2f·636f·6465·3e3c··service.</code>< 
0005a2d0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0005a240:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0005a2e0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0005a250:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0005a2f0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0005a260:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0005a300:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0005a270:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0005a310:·612d·7461·7267·6574·3d22·2369·646d·3134··a-target="#idm140005a280:·7461·7267·6574·3d22·2369·646d·3134·3737··target="#idm1477
0005a320:·3737·3122·2074·6162·696e·6465·783d·2230··771"·tabindex="00005a290:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0005a330:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0005a2a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0005a340:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0005a2b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0005a350:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0005a2c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0005a360:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0005a2d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0005a370:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0005a2e0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0005a380:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
0005a390:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
0005a3a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0005a3b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0005a3c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0005a3d0:·2069·643d·2269·646d·3134·3737·3122·3e3c···id="idm14771">< 
0005a3e0:·7072·653e·3c63·6f64·653e·0a5b·6375·7374··pre><code>.[cust 
0005a3f0:·6f6d·697a·6174·696f·6e73·2e73·6572·7669··omizations.servi 
0005a400:·6365·735d·0a64·6973·6162·6c65·6420·3d20··ces].disabled·=· 
0005a410:·5b22·6465·6275·672d·7368·656c·6c22·5d0a··["debug-shell"].0005a2f0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
 0005a300:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0005a310:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0005a320:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0005a330:·7365·2220·6964·3d22·6964·6d31·3437·3731··se"·id="idm14771
 0005a340:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0005a350:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0005a360:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0005a370:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0005a380:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0005a390:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0005a3a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0005a3b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0005a3c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0005a3d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0005a3e0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0005a3f0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0005a400:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0005a410:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab
 0005a420:·6c65·5f64·6562·7567·2d73·6865·6c6c·0a0a··le_debug-shell..
 0005a430:·636c·6173·7320·6469·7361·626c·655f·6465··class·disable_de
 0005a440:·6275·672d·7368·656c·6c20·7b0a·2020·7365··bug-shell·{.··se
 0005a450:·7276·6963·6520·7b27·6465·6275·672d·7368··rvice·{'debug-sh
 0005a460:·656c·6c27·3a0a·2020·2020·656e·6162·6c65··ell':.····enable
 0005a470:·203d·2667·743b·2066·616c·7365·2c0a·2020···=&gt;·false,.··
 0005a480:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0005a490:·7374·6f70·7065·6427·2c0a·2020·7d0a·7d0a··stopped',.··}.}.
0005a420:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0005a4a0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0005a430:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0005a4b0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0005a440:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0005a4c0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0005a450:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0005a4d0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0005a460:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0005a4e0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0005a470:·3d22·2369·646d·3134·3737·3222·2074·6162··="#idm14772"·tab0005a4f0:·3d22·2369·646d·3134·3737·3222·2074·6162··="#idm14772"·tab
0005a480:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0005a500:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0005a490:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0005a510:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0005a4a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0005a520:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0005a4b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0005a530:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0005a4c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0005a540:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0005a4d0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0005a550:·2122·3e52·656d·6564·6961·7469·6f6e·204b··!">Remediation·K
0005a4e0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0005a560:·7562·6572·6e65·7465·7320·736e·6970·7065··ubernetes·snippe
0005a4f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0005a570:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0005a500:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0005a580:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0005a510:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0005a590:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0005a520:·3d22·6964·6d31·3437·3732·223e·3c74·6162··="idm14772"><tab0005a5a0:·2220·6964·3d22·6964·6d31·3437·3732·223e··"·id="idm14772">
 0005a5b0:·3c70·7265·3e3c·636f·6465·3e2d·2d2d·0a61··<pre><code>---.a
 0005a5c0:·7069·5665·7273·696f·6e3a·206d·6163·6869··piVersion:·machi
 0005a5d0:·6e65·636f·6e66·6967·7572·6174·696f·6e2e··neconfiguration.
 0005a5e0:·6f70·656e·7368·6966·742e·696f·2f76·310a··openshift.io/v1.
 0005a5f0:·6b69·6e64·3a20·4d61·6368·696e·6543·6f6e··kind:·MachineCon
 0005a600:·6669·670a·7370·6563·3a0a·2020·636f·6e66··fig.spec:.··conf
 0005a610:·6967·3a0a·2020·2020·6967·6e69·7469·6f6e··ig:.····ignition
 0005a620:·3a0a·2020·2020·2020·7665·7273·696f·6e3a··:.······version:
 0005a630:·2033·2e31·2e30·0a20·2020·2073·7973·7465···3.1.0.····syste
 0005a640:·6d64·3a0a·2020·2020·2020·756e·6974·733a··md:.······units:
 0005a650:·0a20·2020·2020·202d·2065·6e61·626c·6564··.······-·enabled
 0005a660:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
 0005a670:·6e61·6d65·3a20·6465·6275·672d·7368·656c··name:·debug-shel
 0005a680:·6c2e·7365·7276·6963·650a·3c2f·636f·6465··l.service.</code
0005a530:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0005a540:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0005a550:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0005a560:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0005a570:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0005a580:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0005a590:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0005a5a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0005a5b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0005a5c0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0005a5d0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0005a5e0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
Max diff block lines reached; 917831/929449 bytes (98.75%) of diff not shown.
339 KB
html2text {}
    
Offset 1315, 26 lines modifiedOffset 1315, 14 lines modified
  
1315 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:1315 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
1316 $·sudo·systemctl·mask·--now·debug-shell.service1316 $·sudo·systemctl·mask·--now·debug-shell.service
1317 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.1317 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
1318 Severity: ················medium1318 Severity: ················medium
1319 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1319 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1320 Identifiers·and·References·References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271320 Identifiers·and·References·References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1321 Remediation_Kubernetes_snippet_⇲ 
1322 --- 
1323 apiVersion:·machineconfiguration.openshift.io/v1 
1324 kind:·MachineConfig 
1325 spec: 
1326 ··config: 
1327 ····ignition: 
1328 ······version:·3.1.0 
1329 ····systemd: 
1330 ······units: 
1331 ······-·enabled:·false 
1332 ········name:·debug-shell.service 
1333 Remediation_OSBuild_Blueprint_snippet_⇲1321 Remediation_OSBuild_Blueprint_snippet_⇲
  
1334 [customizations.services]1322 [customizations.services]
1335 disabled·=·["debug-shell"]1323 disabled·=·["debug-shell"]
1336 Remediation_Puppet_snippet_⇲1324 Remediation_Puppet_snippet_⇲
1337 Complexity:·low1325 Complexity:·low
1338 Disruption:·low1326 Disruption:·low
Offset 1343, 14 lines modifiedOffset 1331, 26 lines modified
  
1343 class·disable_debug-shell·{1331 class·disable_debug-shell·{
1344 ··service·{'debug-shell':1332 ··service·{'debug-shell':
1345 ····enable·=>·false,1333 ····enable·=>·false,
1346 ····ensure·=>·'stopped',1334 ····ensure·=>·'stopped',
1347 ··}1335 ··}
1348 }1336 }
 1337 Remediation_Kubernetes_snippet_⇲
 1338 ---
 1339 apiVersion:·machineconfiguration.openshift.io/v1
 1340 kind:·MachineConfig
 1341 spec:
 1342 ··config:
 1343 ····ignition:
 1344 ······version:·3.1.0
 1345 ····systemd:
 1346 ······units:
 1347 ······-·enabled:·false
 1348 ········name:·debug-shell.service
1349 Remediation_Shell_script_⇲1349 Remediation_Shell_script_⇲
1350 Complexity:·low1350 Complexity:·low
1351 Disruption:·low1351 Disruption:·low
1352 Strategy:···disable1352 Strategy:···disable
1353 #·Remediation·is·applicable·only·in·certain·platforms1353 #·Remediation·is·applicable·only·in·certain·platforms
1354 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1354 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
Offset 2183, 15 lines modifiedOffset 2183, 15 lines modified
2183 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2183 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2184 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2184 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2185 Severity: ················medium2185 Severity: ················medium
2186 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod2186 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
2187 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019402187 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
2188 Remediation_Shell_script_⇲2188 Remediation_Shell_script_⇲
2189 #·Remediation·is·applicable·only·in·certain·platforms2189 #·Remediation·is·applicable·only·in·certain·platforms
2190 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2190 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2191 #·First·perform·the·remediation·of·the·syscall·rule2191 #·First·perform·the·remediation·of·the·syscall·rule
2192 #·Retrieve·hardware·architecture·of·the·underlying·system2192 #·Retrieve·hardware·architecture·of·the·underlying·system
2193 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2193 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2194 for·ARCH·in·"${RULE_ARCHS[@]}"2194 for·ARCH·in·"${RULE_ARCHS[@]}"
2195 do2195 do
Offset 2537, 16 lines modifiedOffset 2537, 16 lines modified
2537 ··-·reboot_required2537 ··-·reboot_required
2538 ··-·restrict_strategy2538 ··-·restrict_strategy
  
2539 -·name:·Set·architecture·for·audit·chmod·tasks2539 -·name:·Set·architecture·for·audit·chmod·tasks
2540 ··set_fact:2540 ··set_fact:
2541 ····audit_arch:·b642541 ····audit_arch:·b64
2542 ··when:2542 ··when:
2543 ··-·'"audit"·in·ansible_facts.packages' 
2544 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2543 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2544 ··-·'"audit"·in·ansible_facts.packages'
2545 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2545 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2546 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2546 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2547 ··tags:2547 ··tags:
2548 ··-·CJIS-5.4.1.12548 ··-·CJIS-5.4.1.1
2549 ··-·NIST-800-171-3.1.72549 ··-·NIST-800-171-3.1.7
2550 ··-·NIST-800-53-AU-12(c)2550 ··-·NIST-800-53-AU-12(c)
2551 ··-·NIST-800-53-AU-2(d)2551 ··-·NIST-800-53-AU-2(d)
Offset 2682, 16 lines modifiedOffset 2682, 16 lines modified
2682 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002682 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2683 ········-F·auid!=unset·-F·key=perm_mod2683 ········-F·auid!=unset·-F·key=perm_mod
2684 ······create:·true2684 ······create:·true
2685 ······mode:·o-rwx2685 ······mode:·o-rwx
2686 ······state:·present2686 ······state:·present
2687 ····when:·syscalls_found·|·length·==·02687 ····when:·syscalls_found·|·length·==·0
2688 ··when:2688 ··when:
2689 ··-·'"audit"·in·ansible_facts.packages' 
2690 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2689 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2690 ··-·'"audit"·in·ansible_facts.packages'
2691 ··tags:2691 ··tags:
2692 ··-·CJIS-5.4.1.12692 ··-·CJIS-5.4.1.1
2693 ··-·NIST-800-171-3.1.72693 ··-·NIST-800-171-3.1.7
2694 ··-·NIST-800-53-AU-12(c)2694 ··-·NIST-800-53-AU-12(c)
2695 ··-·NIST-800-53-AU-2(d)2695 ··-·NIST-800-53-AU-2(d)
2696 ··-·NIST-800-53-CM-6(a)2696 ··-·NIST-800-53-CM-6(a)
2697 ··-·PCI-DSS-Req-10.5.52697 ··-·PCI-DSS-Req-10.5.5
Offset 2825, 16 lines modifiedOffset 2825, 16 lines modified
2825 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002825 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2826 ········-F·auid!=unset·-F·key=perm_mod2826 ········-F·auid!=unset·-F·key=perm_mod
2827 ······create:·true2827 ······create:·true
2828 ······mode:·o-rwx2828 ······mode:·o-rwx
2829 ······state:·present2829 ······state:·present
2830 ····when:·syscalls_found·|·length·==·02830 ····when:·syscalls_found·|·length·==·0
2831 ··when:2831 ··when:
2832 ··-·'"audit"·in·ansible_facts.packages' 
2833 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2832 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2833 ··-·'"audit"·in·ansible_facts.packages'
2834 ··-·audit_arch·==·"b64"2834 ··-·audit_arch·==·"b64"
2835 ··tags:2835 ··tags:
2836 ··-·CJIS-5.4.1.12836 ··-·CJIS-5.4.1.1
2837 ··-·NIST-800-171-3.1.72837 ··-·NIST-800-171-3.1.7
2838 ··-·NIST-800-53-AU-12(c)2838 ··-·NIST-800-53-AU-12(c)
2839 ··-·NIST-800-53-AU-2(d)2839 ··-·NIST-800-53-AU-2(d)
2840 ··-·NIST-800-53-CM-6(a)2840 ··-·NIST-800-53-CM-6(a)
Offset 2857, 15 lines modifiedOffset 2857, 15 lines modified
2857 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2857 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2858 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2858 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2859 Severity: ················medium2859 Severity: ················medium
Max diff block lines reached; 339908/346998 bytes (97.96%) of diff not shown.
874 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ism_o.html
    
Offset 18095, 116 lines modifiedOffset 18095, 116 lines modified
00046ae0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00046ae0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00046af0:·6d37·3630·3522·2074·6162·696e·6465·783d··m7605"·tabindex=00046af0:·6d37·3630·3522·2074·6162·696e·6465·783d··m7605"·tabindex=
00046b00:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button00046b00:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
00046b10:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=00046b10:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00046b20:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A00046b20:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
00046b30:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea00046b30:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
00046b40:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem00046b40:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
00046b50:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond00046b50:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
00046b60:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a00046b60:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
00046b70:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=00046b70:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00046b80:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·00046b80:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
00046b90:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id00046b90:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
00046ba0:·6d37·3630·3522·3e3c·7461·626c·6520·636c··m7605"><table·cl00046ba0:·3630·3522·3e3c·7461·626c·6520·636c·6173··605"><table·clas
00046bb0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table00046bb0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
00046bc0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b00046bc0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
00046bd0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co00046bd0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00046be0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th00046be0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
00046bf0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th00046bf0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
00046c00:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t00046c00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00046c10:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup00046c10:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
00046c20:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo00046c20:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
00046c30:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00046c30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00046c40:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th00046c40:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00046c50:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>00046c50:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
00046c60:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr00046c60:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
00046c70:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
00046c80:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co00046c70:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 00046c80:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 00046c90:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 00046ca0:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 00046cb0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 00046cc0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 00046cd0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 00046ce0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00046cf0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00046d00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 00046d10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 00046d20:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
 00046d30:·3630·3622·2074·6162·696e·6465·783d·2230··606"·tabindex="0
 00046d40:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 00046d50:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 00046d60:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 00046d70:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 00046d80:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00046d90:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 00046da0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 00046db0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00046dc0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00046dd0:·7365·2220·6964·3d22·6964·6d37·3630·3622··se"·id="idm7606"
 00046de0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00046df0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00046e00:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 00046e10:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 00046e20:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 00046e30:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 00046e40:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00046e50:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 00046e60:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00046e70:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 00046e80:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 00046e90:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 00046ea0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 00046eb0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 00046ec0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 00046ed0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 00046ee0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-
 00046ef0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·
 00046f00:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-
 00046f10:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe
 00046f20:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if
 00046f30:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 00046f40:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 00046f50:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install·
 00046f60:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 00046f70:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 00046f80:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 00046f90:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 00046fa0:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 00046fb0:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
00046c90:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><00046fc0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
00046ca0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn00046fd0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
00046cb0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t00046fe0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
00046cc0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"00046ff0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
00046cd0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i00047000:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
00046ce0:·646d·3736·3036·2220·7461·6269·6e64·6578··dm7606"·tabindex00047010:·646d·3736·3037·2220·7461·6269·6e64·6578··dm7607"·tabindex
00046cf0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00047020:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00046d00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00047030:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00046d10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00047040:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00046d20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00047050:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00046d30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00047060:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00046d40:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet00047070:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
00046d50:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>00047080:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
00046d60:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00047090:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
00046d70:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c000470a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
00046d80:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm000470b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
00046d90:·3736·3036·223e·3c74·6162·6c65·2063·6c61··7606"><table·cla000470c0:·646d·3736·3037·223e·3c74·6162·6c65·2063··dm7607"><table·c
00046da0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-000470d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
00046db0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo000470e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
00046dc0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con000470f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
00046dd0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>00047100:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
00046de0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>00047110:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
00046df0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr00047120:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
00046e00:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt00047130:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
00046e10:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low00047140:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
00046e20:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00047150:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00046e30:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>00047160:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00046e40:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><00047170:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
00046e50:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre00047180:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00047190:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 000471a0:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
00046e60:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
00046e70:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
00046e80:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
00046e90:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
00046ea0:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
00046eb0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
00046ec0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
00046ed0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
00046ee0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
00046ef0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
00046f00:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
00046f10:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
00046f20:·3736·3037·2220·7461·6269·6e64·6578·3d22··7607"·tabindex=" 
00046f30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
00046f40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
00046f50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
00046f60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
Max diff block lines reached; 708491/723147 bytes (97.97%) of diff not shown.
167 KB
html2text {}
    
Offset 524, 20 lines modifiedOffset 524, 14 lines modified
524 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed524 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
525 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199525 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
526 Remediation_OSBuild_Blueprint_snippet_⇲526 Remediation_OSBuild_Blueprint_snippet_⇲
  
527 [[packages]]527 [[packages]]
528 name·=·"aide"528 name·=·"aide"
529 version·=·"*"529 version·=·"*"
530 Remediation_Anaconda_snippet_⇲ 
531 Complexity:·low 
532 Disruption:·low 
533 Strategy:···enable 
  
534 package·--add=aide 
535 Remediation_Puppet_snippet_⇲530 Remediation_Puppet_snippet_⇲
536 Complexity:·low531 Complexity:·low
537 Disruption:·low532 Disruption:·low
538 Strategy:···enable533 Strategy:···enable
539 include·install_aide534 include·install_aide
  
540 class·install_aide·{535 class·install_aide·{
Offset 555, 14 lines modifiedOffset 549, 20 lines modified
555 if·!·rpm·-q·--quiet·"aide"·;·then549 if·!·rpm·-q·--quiet·"aide"·;·then
556 ····dnf·install·-y·"aide"550 ····dnf·install·-y·"aide"
557 fi551 fi
  
558 else552 else
559 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'553 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
560 fi554 fi
 555 Remediation_Anaconda_snippet_⇲
 556 Complexity:·low
 557 Disruption:·low
 558 Strategy:···enable
  
 559 package·--add=aide
561 Remediation_Ansible_snippet_⇲560 Remediation_Ansible_snippet_⇲
562 Complexity:·low561 Complexity:·low
563 Disruption:·low562 Disruption:·low
564 Strategy:···enable563 Strategy:···enable
565 -·name:·Ensure·aide·is·installed564 -·name:·Ensure·aide·is·installed
566 ··package:565 ··package:
567 ····name:·aide566 ····name:·aide
Offset 783, 20 lines modifiedOffset 783, 14 lines modified
783 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed783 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
784 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125784 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
785 Remediation_OSBuild_Blueprint_snippet_⇲785 Remediation_OSBuild_Blueprint_snippet_⇲
  
786 [[packages]]786 [[packages]]
787 name·=·"sudo"787 name·=·"sudo"
788 version·=·"*"788 version·=·"*"
789 Remediation_Anaconda_snippet_⇲ 
790 Complexity:·low 
791 Disruption:·low 
792 Strategy:···enable 
  
793 package·--add=sudo 
794 Remediation_Puppet_snippet_⇲789 Remediation_Puppet_snippet_⇲
795 Complexity:·low790 Complexity:·low
796 Disruption:·low791 Disruption:·low
797 Strategy:···enable792 Strategy:···enable
798 include·install_sudo793 include·install_sudo
  
799 class·install_sudo·{794 class·install_sudo·{
Offset 814, 14 lines modifiedOffset 808, 20 lines modified
814 if·!·rpm·-q·--quiet·"sudo"·;·then808 if·!·rpm·-q·--quiet·"sudo"·;·then
815 ····dnf·install·-y·"sudo"809 ····dnf·install·-y·"sudo"
816 fi810 fi
  
817 else811 else
818 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'812 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
819 fi813 fi
 814 Remediation_Anaconda_snippet_⇲
 815 Complexity:·low
 816 Disruption:·low
 817 Strategy:···enable
  
 818 package·--add=sudo
820 Remediation_Ansible_snippet_⇲819 Remediation_Ansible_snippet_⇲
821 Complexity:·low820 Complexity:·low
822 Disruption:·low821 Disruption:·low
823 Strategy:···enable822 Strategy:···enable
824 -·name:·Ensure·sudo·is·installed823 -·name:·Ensure·sudo·is·installed
825 ··package:824 ··package:
826 ····name:·sudo825 ····name:·sudo
Offset 1087, 20 lines modifiedOffset 1087, 14 lines modified
1087 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed1087 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
1088 Identifiers·and·References1088 Identifiers·and·References
1089 Remediation_OSBuild_Blueprint_snippet_⇲1089 Remediation_OSBuild_Blueprint_snippet_⇲
  
1090 [[packages]]1090 [[packages]]
1091 name·=·"rear"1091 name·=·"rear"
1092 version·=·"*"1092 version·=·"*"
1093 Remediation_Anaconda_snippet_⇲ 
1094 Complexity:·low 
1095 Disruption:·low 
1096 Strategy:···enable 
  
1097 package·--add=rear 
1098 Remediation_Puppet_snippet_⇲1093 Remediation_Puppet_snippet_⇲
1099 Complexity:·low1094 Complexity:·low
1100 Disruption:·low1095 Disruption:·low
1101 Strategy:···enable1096 Strategy:···enable
1102 include·install_rear1097 include·install_rear
  
1103 class·install_rear·{1098 class·install_rear·{
Offset 1118, 14 lines modifiedOffset 1112, 20 lines modified
1118 if·!·rpm·-q·--quiet·"rear"·;·then1112 if·!·rpm·-q·--quiet·"rear"·;·then
1119 ····dnf·install·-y·"rear"1113 ····dnf·install·-y·"rear"
1120 fi1114 fi
  
1121 else1115 else
1122 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1116 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1123 fi1117 fi
 1118 Remediation_Anaconda_snippet_⇲
 1119 Complexity:·low
 1120 Disruption:·low
 1121 Strategy:···enable
  
 1122 package·--add=rear
1124 Remediation_Ansible_snippet_⇲1123 Remediation_Ansible_snippet_⇲
1125 Complexity:·low1124 Complexity:·low
1126 Disruption:·low1125 Disruption:·low
1127 Strategy:···enable1126 Strategy:···enable
1128 -·name:·Ensure·rear·is·installed1127 -·name:·Ensure·rear·is·installed
1129 ··package:1128 ··package:
1130 ····name:·rear1129 ····name:·rear
Offset 6082, 15 lines modifiedOffset 6082, 15 lines modified
6082 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.6082 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
Max diff block lines reached; 167191/171220 bytes (97.65%) of diff not shown.
428 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ospp.html
    
Offset 16038, 108 lines modifiedOffset 16038, 108 lines modified
0003ea50:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003ea50:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003ea60:·2223·6964·6d38·3237·3122·2074·6162·696e··"#idm8271"·tabin0003ea60:·2223·6964·6d38·3237·3122·2074·6162·696e··"#idm8271"·tabin
0003ea70:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003ea70:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003ea80:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003ea80:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003ea90:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003ea90:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003eaa0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003eaa0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003eab0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003eab0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003eac0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003eac0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
0003ead0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003ead0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
0003eae0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003eae0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003eaf0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003eaf0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003eb00:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003eb00:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003eb10:·3d22·6964·6d38·3237·3122·3e3c·7461·626c··="idm8271"><tabl0003eb10:·6964·6d38·3237·3122·3e3c·7461·626c·6520··idm8271"><table·
0003eb20:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003eb20:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003eb30:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003eb30:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003eb40:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003eb40:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003eb50:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003eb50:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003eb60:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003eb60:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003eb70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003eb70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003eb80:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003eb80:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003eb90:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003eb90:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003eba0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003ebb0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003ebc0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003ebd0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003ebe0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac 
0003ebf0:·6b61·6765·202d·2d61·6464·3d63·7279·7074··kage·--add=crypt 
0003ec00:·6f2d·706f·6c69·6369·6573·0a3c·2f63·6f64··o-policies.</cod 
0003ec10:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003ec20:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ec30:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ec40:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ec50:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003ec60:·6d38·3237·3222·2074·6162·696e·6465·783d··m8272"·tabindex= 
0003ec70:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003ec80:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003ec90:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003eca0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003ecb0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003ecc0:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet· 
0003ecd0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003ece0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003ecf0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003ed00:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003ed10:·3237·3222·3e3c·7461·626c·6520·636c·6173··272"><table·clas 
0003ed20:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003ed30:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003ed40:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003ed50:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003ed60:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003ed70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003ed80:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003ed90:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003eda0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003edb0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003edc0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003edd0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003ede0:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003edf0:·7374·616c·6c5f·6372·7970·746f·2d70·6f6c··stall_crypto-pol 
0003ee00:·6963·6965·730a·0a63·6c61·7373·2069·6e73··icies..class·ins 
0003ee10:·7461·6c6c·5f63·7279·7074·6f2d·706f·6c69··tall_crypto-poli 
0003ee20:·6369·6573·207b·0a20·2070·6163·6b61·6765··cies·{.··package 
0003ee30:·207b·2027·6372·7970·746f·2d70·6f6c·6963···{·'crypto-polic 
0003ee40:·6965·7327·3a0a·2020·2020·656e·7375·7265··ies':.····ensure 
0003ee50:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003ee60:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003ee70:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003ee80:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003ee90:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003eea0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003eeb0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003eec0:·3832·3733·2220·7461·6269·6e64·6578·3d22··8273"·tabindex=" 
0003eed0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003eee0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003eef0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003ef00:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003ef10:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003ef20:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003ef30:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003ef40:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003ef50:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003ef60:·7073·6522·2069·643d·2269·646d·3832·3733··pse"·id="idm8273 
0003ef70:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003ef80:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003ef90:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003efa0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003efb0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003efc0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003efd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003eba0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003ebb0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003ebc0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003ebd0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003ebe0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0003ebf0:·6520·696e·7374·616c·6c5f·6372·7970·746f··e·install_crypto
 0003ec00:·2d70·6f6c·6963·6965·730a·0a63·6c61·7373··-policies..class
 0003ec10:·2069·6e73·7461·6c6c·5f63·7279·7074·6f2d···install_crypto-
 0003ec20:·706f·6c69·6369·6573·207b·0a20·2070·6163··policies·{.··pac
 0003ec30:·6b61·6765·207b·2027·6372·7970·746f·2d70··kage·{·'crypto-p
 0003ec40:·6f6c·6963·6965·7327·3a0a·2020·2020·656e··olicies':.····en
 0003ec50:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003ec60:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003ec70:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003ec80:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003ec90:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003eca0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003ecb0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003ecc0:·2369·646d·3832·3732·2220·7461·6269·6e64··#idm8272"·tabind
 0003ecd0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003ece0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003ecf0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003ed00:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003ed10:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003ed20:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003ed30:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003ed40:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003ed50:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003ed60:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003ed70:·3832·3732·223e·3c74·6162·6c65·2063·6c61··8272"><table·cla
 0003ed80:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003ed90:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003eda0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003edb0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003edc0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003edd0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003efe0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003ede0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003edf0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003ee00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
Max diff block lines reached; 380397/393949 bytes (96.56%) of diff not shown.
43.0 KB
html2text {}
    
Offset 239, 20 lines modifiedOffset 239, 14 lines modified
239 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed239 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
240 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174240 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
241 Remediation_OSBuild_Blueprint_snippet_⇲241 Remediation_OSBuild_Blueprint_snippet_⇲
  
242 [[packages]]242 [[packages]]
243 name·=·"crypto-policies"243 name·=·"crypto-policies"
244 version·=·"*"244 version·=·"*"
245 Remediation_Anaconda_snippet_⇲ 
246 Complexity:·low 
247 Disruption:·low 
248 Strategy:···enable 
  
249 package·--add=crypto-policies 
250 Remediation_Puppet_snippet_⇲245 Remediation_Puppet_snippet_⇲
251 Complexity:·low246 Complexity:·low
252 Disruption:·low247 Disruption:·low
253 Strategy:···enable248 Strategy:···enable
254 include·install_crypto-policies249 include·install_crypto-policies
  
255 class·install_crypto-policies·{250 class·install_crypto-policies·{
Offset 264, 14 lines modifiedOffset 258, 20 lines modified
264 Complexity:·low258 Complexity:·low
265 Disruption:·low259 Disruption:·low
266 Strategy:···enable260 Strategy:···enable
  
267 if·!·rpm·-q·--quiet·"crypto-policies"·;·then261 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
268 ····dnf·install·-y·"crypto-policies"262 ····dnf·install·-y·"crypto-policies"
269 fi263 fi
 264 Remediation_Anaconda_snippet_⇲
 265 Complexity:·low
 266 Disruption:·low
 267 Strategy:···enable
  
 268 package·--add=crypto-policies
270 Remediation_Ansible_snippet_⇲269 Remediation_Ansible_snippet_⇲
271 Complexity:·low270 Complexity:·low
272 Disruption:·low271 Disruption:·low
273 Strategy:···enable272 Strategy:···enable
274 -·name:·Ensure·crypto-policies·is·installed273 -·name:·Ensure·crypto-policies·is·installed
275 ··package:274 ··package:
276 ····name:·crypto-policies275 ····name:·crypto-policies
Offset 561, 20 lines modifiedOffset 561, 14 lines modified
561 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed561 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
562 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125562 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
563 Remediation_OSBuild_Blueprint_snippet_⇲563 Remediation_OSBuild_Blueprint_snippet_⇲
  
564 [[packages]]564 [[packages]]
565 name·=·"sudo"565 name·=·"sudo"
566 version·=·"*"566 version·=·"*"
567 Remediation_Anaconda_snippet_⇲ 
568 Complexity:·low 
569 Disruption:·low 
570 Strategy:···enable 
  
571 package·--add=sudo 
572 Remediation_Puppet_snippet_⇲567 Remediation_Puppet_snippet_⇲
573 Complexity:·low568 Complexity:·low
574 Disruption:·low569 Disruption:·low
575 Strategy:···enable570 Strategy:···enable
576 include·install_sudo571 include·install_sudo
  
577 class·install_sudo·{572 class·install_sudo·{
Offset 592, 14 lines modifiedOffset 586, 20 lines modified
592 if·!·rpm·-q·--quiet·"sudo"·;·then586 if·!·rpm·-q·--quiet·"sudo"·;·then
593 ····dnf·install·-y·"sudo"587 ····dnf·install·-y·"sudo"
594 fi588 fi
  
595 else589 else
596 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'590 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
597 fi591 fi
 592 Remediation_Anaconda_snippet_⇲
 593 Complexity:·low
 594 Disruption:·low
 595 Strategy:···enable
  
 596 package·--add=sudo
598 Remediation_Ansible_snippet_⇲597 Remediation_Ansible_snippet_⇲
599 Complexity:·low598 Complexity:·low
600 Disruption:·low599 Disruption:·low
601 Strategy:···enable600 Strategy:···enable
602 -·name:·Ensure·sudo·is·installed601 -·name:·Ensure·sudo·is·installed
603 ··package:602 ··package:
604 ····name:·sudo603 ····name:·sudo
Offset 624, 20 lines modifiedOffset 624, 14 lines modified
624 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed624 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed
625 Identifiers·and·References·References: ·FIA_X509_EXT.1,·FIA_X509_EXT.2,·SRG-OS-000480-GPOS-00227625 Identifiers·and·References·References: ·FIA_X509_EXT.1,·FIA_X509_EXT.2,·SRG-OS-000480-GPOS-00227
626 Remediation_OSBuild_Blueprint_snippet_⇲626 Remediation_OSBuild_Blueprint_snippet_⇲
  
627 [[packages]]627 [[packages]]
628 name·=·"gnutls-utils"628 name·=·"gnutls-utils"
629 version·=·"*"629 version·=·"*"
630 Remediation_Anaconda_snippet_⇲ 
631 Complexity:·low 
632 Disruption:·low 
633 Strategy:···enable 
  
634 package·--add=gnutls-utils 
635 Remediation_Puppet_snippet_⇲630 Remediation_Puppet_snippet_⇲
636 Complexity:·low631 Complexity:·low
637 Disruption:·low632 Disruption:·low
638 Strategy:···enable633 Strategy:···enable
639 include·install_gnutls-utils634 include·install_gnutls-utils
  
640 class·install_gnutls-utils·{635 class·install_gnutls-utils·{
Offset 649, 14 lines modifiedOffset 643, 20 lines modified
649 Complexity:·low643 Complexity:·low
650 Disruption:·low644 Disruption:·low
651 Strategy:···enable645 Strategy:···enable
  
652 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then646 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then
653 ····dnf·install·-y·"gnutls-utils"647 ····dnf·install·-y·"gnutls-utils"
654 fi648 fi
 649 Remediation_Anaconda_snippet_⇲
 650 Complexity:·low
 651 Disruption:·low
 652 Strategy:···enable
  
 653 package·--add=gnutls-utils
655 Remediation_Ansible_snippet_⇲654 Remediation_Ansible_snippet_⇲
656 Complexity:·low655 Complexity:·low
657 Disruption:·low656 Disruption:·low
658 Strategy:···enable657 Strategy:···enable
659 -·name:·Ensure·gnutls-utils·is·installed658 -·name:·Ensure·gnutls-utils·is·installed
660 ··package:659 ··package:
661 ····name:·gnutls-utils660 ····name:·gnutls-utils
Offset 676, 20 lines modifiedOffset 676, 14 lines modified
676 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_openscap-scanner_installed676 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_openscap-scanner_installed
Max diff block lines reached; 40619/43998 bytes (92.32%) of diff not shown.
974 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-pci-dss.html
    
Offset 17149, 116 lines modifiedOffset 17149, 116 lines modified
00042fc0:·2d74·6172·6765·743d·2223·6964·6d37·3630··-target="#idm76000042fc0:·2d74·6172·6765·743d·2223·6964·6d37·3630··-target="#idm760
00042fd0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·00042fd0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·
00042fe0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00042fe0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00042ff0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00042ff0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00043000:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00043000:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00043010:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00043010:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00043020:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00043020:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00043030:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn00043030:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
00043040:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br00043040:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
00043050:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00043050:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00043060:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00043060:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00043070:·6170·7365·2220·6964·3d22·6964·6d37·3630··apse"·id="idm76000043070:·7365·2220·6964·3d22·6964·6d37·3630·3522··se"·id="idm7605"
00043080:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=00043080:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00043090:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str00043090:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
000430a0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde000430a0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
000430b0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden000430b0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
000430c0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com000430c0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
000430d0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td000430d0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
000430e0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t000430e0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
000430f0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption000430f0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
00043100:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00043100:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00043110:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00043110:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
00043120:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00043120:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00043130:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00043130:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00043140:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00043140:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
00043150:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
00043160:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><00043150:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 00043160:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 00043170:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 00043180:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 00043190:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 000431a0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 000431b0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 000431c0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 000431d0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 000431e0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 000431f0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00043200:·6172·6765·743d·2223·6964·6d37·3630·3622··arget="#idm7606"
 00043210:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00043220:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00043230:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00043240:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00043250:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00043260:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00043270:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 00043280:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00043290:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 000432a0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 000432b0:·6964·3d22·6964·6d37·3630·3622·3e3c·7461··id="idm7606"><ta
 000432c0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 000432d0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 000432e0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 000432f0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00043300:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 00043310:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 00043320:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00043330:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00043340:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00043350:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 00043360:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 00043370:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 00043380:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 00043390:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 000433a0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 000433b0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 000433c0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
 000433d0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
 000433e0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
 000433f0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 00043400:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r
 00043410:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 00043420:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 00043430:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·"
 00043440:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 00043450:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 00043460:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 00043470:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 00043480:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 00043490:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
00043170:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl000434a0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
00043180:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc000434b0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
00043190:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl000434c0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
000431a0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat000434d0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
000431b0:·612d·7461·7267·6574·3d22·2369·646d·3736··a-target="#idm76000434e0:·612d·7461·7267·6574·3d22·2369·646d·3736··a-target="#idm76
000431c0:·3036·2220·7461·6269·6e64·6578·3d22·3022··06"·tabindex="0"000434f0:·3037·2220·7461·6269·6e64·6578·3d22·3022··07"·tabindex="0"
000431d0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00043500:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
000431e0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00043510:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
000431f0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00043520:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00043200:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00043530:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00043210:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00043540:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00043220:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni00043550:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
00043230:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>00043560:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00043240:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane00043570:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00043250:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00043580:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00043260:·7073·6522·2069·643d·2269·646d·3736·3036··pse"·id="idm760600043590:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm76
00043270:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="000435a0:·3037·223e·3c74·6162·6c65·2063·6c61·7373··07"><table·class
00043280:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri000435b0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
00043290:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border000435c0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
000432a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens000435d0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
000432b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp000435e0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
000432c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>000435f0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
000432d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00043600:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
000432e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:00043610:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
000432f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00043620:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00043300:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00043630:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00043310:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>00043640:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00043320:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>00043650:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
00043330:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co00043660:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00043670:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 00043680:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
00043340:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
00043350:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
00043360:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
00043370:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
00043380:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
00043390:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
000433a0:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
000433b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
000433c0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
000433d0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
000433e0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
000433f0:·7461·7267·6574·3d22·2369·646d·3736·3037··target="#idm7607 
00043400:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
00043410:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
00043420:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
00043430:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
00043440:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
Max diff block lines reached; 705003/719659 bytes (97.96%) of diff not shown.
271 KB
html2text {}
    
Offset 396, 20 lines modifiedOffset 396, 14 lines modified
396 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed396 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
397 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199397 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
398 Remediation_OSBuild_Blueprint_snippet_⇲398 Remediation_OSBuild_Blueprint_snippet_⇲
  
399 [[packages]]399 [[packages]]
400 name·=·"aide"400 name·=·"aide"
401 version·=·"*"401 version·=·"*"
402 Remediation_Anaconda_snippet_⇲ 
403 Complexity:·low 
404 Disruption:·low 
405 Strategy:···enable 
  
406 package·--add=aide 
407 Remediation_Puppet_snippet_⇲402 Remediation_Puppet_snippet_⇲
408 Complexity:·low403 Complexity:·low
409 Disruption:·low404 Disruption:·low
410 Strategy:···enable405 Strategy:···enable
411 include·install_aide406 include·install_aide
  
412 class·install_aide·{407 class·install_aide·{
Offset 427, 14 lines modifiedOffset 421, 20 lines modified
427 if·!·rpm·-q·--quiet·"aide"·;·then421 if·!·rpm·-q·--quiet·"aide"·;·then
428 ····dnf·install·-y·"aide"422 ····dnf·install·-y·"aide"
429 fi423 fi
  
430 else424 else
431 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'425 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
432 fi426 fi
 427 Remediation_Anaconda_snippet_⇲
 428 Complexity:·low
 429 Disruption:·low
 430 Strategy:···enable
  
 431 package·--add=aide
433 Remediation_Ansible_snippet_⇲432 Remediation_Ansible_snippet_⇲
434 Complexity:·low433 Complexity:·low
435 Disruption:·low434 Disruption:·low
436 Strategy:···enable435 Strategy:···enable
437 -·name:·Ensure·aide·is·installed436 -·name:·Ensure·aide·is·installed
438 ··package:437 ··package:
439 ····name:·aide438 ····name:·aide
Offset 6335, 20 lines modifiedOffset 6335, 14 lines modified
6335 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed6335 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed
6336 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-0015206336 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520
6337 Remediation_OSBuild_Blueprint_snippet_⇲6337 Remediation_OSBuild_Blueprint_snippet_⇲
  
6338 [[packages]]6338 [[packages]]
6339 name·=·"opensc"6339 name·=·"opensc"
6340 version·=·"*"6340 version·=·"*"
6341 Remediation_Anaconda_snippet_⇲ 
6342 Complexity:·low 
6343 Disruption:·low 
6344 Strategy:···enable 
  
6345 package·--add=opensc 
6346 Remediation_Puppet_snippet_⇲6341 Remediation_Puppet_snippet_⇲
6347 Complexity:·low6342 Complexity:·low
6348 Disruption:·low6343 Disruption:·low
6349 Strategy:···enable6344 Strategy:···enable
6350 include·install_opensc6345 include·install_opensc
  
6351 class·install_opensc·{6346 class·install_opensc·{
Offset 6366, 14 lines modifiedOffset 6360, 20 lines modified
6366 if·!·rpm·-q·--quiet·"opensc"·;·then6360 if·!·rpm·-q·--quiet·"opensc"·;·then
6367 ····dnf·install·-y·"opensc"6361 ····dnf·install·-y·"opensc"
6368 fi6362 fi
  
6369 else6363 else
6370 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6364 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6371 fi6365 fi
 6366 Remediation_Anaconda_snippet_⇲
 6367 Complexity:·low
 6368 Disruption:·low
 6369 Strategy:···enable
  
 6370 package·--add=opensc
6372 Remediation_Ansible_snippet_⇲6371 Remediation_Ansible_snippet_⇲
6373 Complexity:·low6372 Complexity:·low
6374 Disruption:·low6373 Disruption:·low
6375 Strategy:···enable6374 Strategy:···enable
6376 -·name:·Ensure·opensc·is·installed6375 -·name:·Ensure·opensc·is·installed
6377 ··package:6376 ··package:
6378 ····name:·opensc6377 ····name:·opensc
Offset 6395, 20 lines modifiedOffset 6395, 14 lines modified
6395 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed6395 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
6396 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015306396 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
6397 Remediation_OSBuild_Blueprint_snippet_⇲6397 Remediation_OSBuild_Blueprint_snippet_⇲
  
6398 [[packages]]6398 [[packages]]
6399 name·=·"pcsc-lite"6399 name·=·"pcsc-lite"
6400 version·=·"*"6400 version·=·"*"
6401 Remediation_Anaconda_snippet_⇲ 
6402 Complexity:·low 
6403 Disruption:·low 
6404 Strategy:···enable 
  
6405 package·--add=pcsc-lite 
6406 Remediation_Puppet_snippet_⇲6401 Remediation_Puppet_snippet_⇲
6407 Complexity:·low6402 Complexity:·low
6408 Disruption:·low6403 Disruption:·low
6409 Strategy:···enable6404 Strategy:···enable
6410 include·install_pcsc-lite6405 include·install_pcsc-lite
  
6411 class·install_pcsc-lite·{6406 class·install_pcsc-lite·{
Offset 6426, 14 lines modifiedOffset 6420, 20 lines modified
6426 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then6420 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
6427 ····dnf·install·-y·"pcsc-lite"6421 ····dnf·install·-y·"pcsc-lite"
6428 fi6422 fi
  
6429 else6423 else
6430 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6424 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6431 fi6425 fi
 6426 Remediation_Anaconda_snippet_⇲
 6427 Complexity:·low
 6428 Disruption:·low
 6429 Strategy:···enable
  
 6430 package·--add=pcsc-lite
6432 Remediation_Ansible_snippet_⇲6431 Remediation_Ansible_snippet_⇲
6433 Complexity:·low6432 Complexity:·low
6434 Disruption:·low6433 Disruption:·low
6435 Strategy:···enable6434 Strategy:···enable
6436 -·name:·Ensure·pcsc-lite·is·installed6435 -·name:·Ensure·pcsc-lite·is·installed
6437 ··package:6436 ··package:
6438 ····name:·pcsc-lite6437 ····name:·pcsc-lite
Offset 7135, 15 lines modifiedOffset 7135, 15 lines modified
7135 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.7135 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
Max diff block lines reached; 273654/277896 bytes (98.47%) of diff not shown.
2.1 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-stig.html
    
Offset 15410, 116 lines modifiedOffset 15410, 116 lines modified
0003c310:·6172·6765·743d·2223·6964·6d37·3630·3522··arget="#idm7605"0003c310:·6172·6765·743d·2223·6964·6d37·3630·3522··arget="#idm7605"
0003c320:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c320:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c330:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c330:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c340:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c340:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c350:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c350:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c360:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c360:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c370:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c370:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003c380:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip0003c380:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
0003c390:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003c390:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c3a0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003c3a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c3b0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003c3b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c3c0:·7365·2220·6964·3d22·6964·6d37·3630·3522··se"·id="idm7605"0003c3c0:·2220·6964·3d22·6964·6d37·3630·3522·3e3c··"·id="idm7605"><
0003c3d0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003c3d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c3e0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003c3e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c3f0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003c3f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c400:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003c400:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c410:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003c410:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c420:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003c420:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c430:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c430:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c440:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003c440:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003c450:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c450:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c460:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003c460:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003c470:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003c470:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003c480:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003c480:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003c490:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003c490:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003c4a0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add0003c4a0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003c4b0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003c4c0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003c4d0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003c4e0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003c4f0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003c500:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003c510:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003c520:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003c530:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003c540:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003c550:·6765·743d·2223·6964·6d37·3630·3622·2074··get="#idm7606"·t
 0003c560:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003c570:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003c580:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003c590:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003c5a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003c5b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003c5c0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003c5d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003c5e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003c5f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003c600:·3d22·6964·6d37·3630·3622·3e3c·7461·626c··="idm7606"><tabl
 0003c610:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003c620:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003c630:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003c640:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003c650:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003c660:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003c670:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003c680:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003c690:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003c6a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003c6b0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003c6c0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003c6d0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 0003c6e0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003c6f0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003c700:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003c710:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do
 0003c720:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&
 0003c730:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run
 0003c740:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]
 0003c750:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 0003c760:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid
 0003c770:·6522·203b·2074·6865·6e0a·2020·2020·646e··e"·;·then.····dn
 0003c780:·6620·696e·7374·616c·6c20·2d79·2022·6169··f·install·-y·"ai
 0003c790:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.···
 0003c7a0:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo
 0003c7b0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is
 0003c7c0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable,
 0003c7d0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don
0003c4b0:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p0003c7e0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p
0003c4c0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003c7f0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0003c4d0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003c800:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0003c4e0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003c810:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0003c4f0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003c820:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0003c500:·7461·7267·6574·3d22·2369·646d·3736·3036··target="#idm76060003c830:·7461·7267·6574·3d22·2369·646d·3736·3037··target="#idm7607
0003c510:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003c840:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c520:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003c850:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c530:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003c860:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c540:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003c870:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c550:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003c880:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c560:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003c890:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003c570:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003c8a0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
0003c580:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003c8b0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003c590:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003c8c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003c5a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003c8d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003c5b0:·6522·2069·643d·2269·646d·3736·3036·223e··e"·id="idm7606">0003c8e0:·7073·6522·2069·643d·2269·646d·3736·3037··pse"·id="idm7607
0003c5c0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003c8f0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003c5d0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003c900:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003c5e0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003c910:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003c5f0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003c920:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003c600:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003c930:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003c610:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003c940:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003c620:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c950:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c630:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003c960:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c640:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c970:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c650:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003c980:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003c660:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003c990:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003c670:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003c9a0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003c680:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003c9b0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003c9c0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
0003c690:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003c6a0:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins 
0003c6b0:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa 
0003c6c0:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':. 
0003c6d0:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
0003c6e0:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.·· 
0003c6f0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre 
0003c700:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c710:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c720:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c730:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c740:·7267·6574·3d22·2369·646d·3736·3037·2220··rget="#idm7607"· 
0003c750:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c760:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c770:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c780:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c790:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c7a0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c7b0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
Max diff block lines reached; 1736019/1750675 bytes (99.16%) of diff not shown.
439 KB
html2text {}
    
Offset 114, 20 lines modifiedOffset 114, 14 lines modified
114 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed114 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
115 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199115 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
116 Remediation_OSBuild_Blueprint_snippet_⇲116 Remediation_OSBuild_Blueprint_snippet_⇲
  
117 [[packages]]117 [[packages]]
118 name·=·"aide"118 name·=·"aide"
119 version·=·"*"119 version·=·"*"
120 Remediation_Anaconda_snippet_⇲ 
121 Complexity:·low 
122 Disruption:·low 
123 Strategy:···enable 
  
124 package·--add=aide 
125 Remediation_Puppet_snippet_⇲120 Remediation_Puppet_snippet_⇲
126 Complexity:·low121 Complexity:·low
127 Disruption:·low122 Disruption:·low
128 Strategy:···enable123 Strategy:···enable
129 include·install_aide124 include·install_aide
  
130 class·install_aide·{125 class·install_aide·{
Offset 145, 14 lines modifiedOffset 139, 20 lines modified
145 if·!·rpm·-q·--quiet·"aide"·;·then139 if·!·rpm·-q·--quiet·"aide"·;·then
146 ····dnf·install·-y·"aide"140 ····dnf·install·-y·"aide"
147 fi141 fi
  
148 else142 else
149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'143 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
150 fi144 fi
 145 Remediation_Anaconda_snippet_⇲
 146 Complexity:·low
 147 Disruption:·low
 148 Strategy:···enable
  
 149 package·--add=aide
151 Remediation_Ansible_snippet_⇲150 Remediation_Ansible_snippet_⇲
152 Complexity:·low151 Complexity:·low
153 Disruption:·low152 Disruption:·low
154 Strategy:···enable153 Strategy:···enable
155 -·name:·Ensure·aide·is·installed154 -·name:·Ensure·aide·is·installed
156 ··package:155 ··package:
157 ····name:·aide156 ····name:·aide
Offset 1469, 20 lines modifiedOffset 1469, 14 lines modified
1469 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed1469 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
1470 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001741470 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
1471 Remediation_OSBuild_Blueprint_snippet_⇲1471 Remediation_OSBuild_Blueprint_snippet_⇲
  
1472 [[packages]]1472 [[packages]]
1473 name·=·"crypto-policies"1473 name·=·"crypto-policies"
1474 version·=·"*"1474 version·=·"*"
1475 Remediation_Anaconda_snippet_⇲ 
1476 Complexity:·low 
1477 Disruption:·low 
1478 Strategy:···enable 
  
1479 package·--add=crypto-policies 
1480 Remediation_Puppet_snippet_⇲1475 Remediation_Puppet_snippet_⇲
1481 Complexity:·low1476 Complexity:·low
1482 Disruption:·low1477 Disruption:·low
1483 Strategy:···enable1478 Strategy:···enable
1484 include·install_crypto-policies1479 include·install_crypto-policies
  
1485 class·install_crypto-policies·{1480 class·install_crypto-policies·{
Offset 1494, 14 lines modifiedOffset 1488, 20 lines modified
1494 Complexity:·low1488 Complexity:·low
1495 Disruption:·low1489 Disruption:·low
1496 Strategy:···enable1490 Strategy:···enable
  
1497 if·!·rpm·-q·--quiet·"crypto-policies"·;·then1491 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
1498 ····dnf·install·-y·"crypto-policies"1492 ····dnf·install·-y·"crypto-policies"
1499 fi1493 fi
 1494 Remediation_Anaconda_snippet_⇲
 1495 Complexity:·low
 1496 Disruption:·low
 1497 Strategy:···enable
  
 1498 package·--add=crypto-policies
1500 Remediation_Ansible_snippet_⇲1499 Remediation_Ansible_snippet_⇲
1501 Complexity:·low1500 Complexity:·low
1502 Disruption:·low1501 Disruption:·low
1503 Strategy:···enable1502 Strategy:···enable
1504 -·name:·Ensure·crypto-policies·is·installed1503 -·name:·Ensure·crypto-policies·is·installed
1505 ··package:1504 ··package:
1506 ····name:·crypto-policies1505 ····name:·crypto-policies
Offset 3710, 20 lines modifiedOffset 3710, 14 lines modified
3710 ***·Rule  ·Remove·the·GDM·Package·Group·  [ref]·***3710 ***·Rule  ·Remove·the·GDM·Package·Group·  [ref]·***
3711 By·removing·the·gdm·package,·the·system·no·longer·has·GNOME·installed·installed.·If·X·Windows·is·not·installed·then·the·system·cannot·boot·into·graphical·user·mode.·This·prevents·the·system·from·being·accidentally·or·maliciously·booted·into·a·graphical.target·mode.·To·do·so,·run·the·following·command:3711 By·removing·the·gdm·package,·the·system·no·longer·has·GNOME·installed·installed.·If·X·Windows·is·not·installed·then·the·system·cannot·boot·into·graphical·user·mode.·This·prevents·the·system·from·being·accidentally·or·maliciously·booted·into·a·graphical.target·mode.·To·do·so,·run·the·following·command:
3712 $·sudo·yum·remove·gdm3712 $·sudo·yum·remove·gdm
3713 Rationale:·················Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack·surface·of·the·system.·A·graphical·environment·is·unnecessary·for·certain·types·of·systems·including·a·virtualization·hypervisor.3713 Rationale:·················Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack·surface·of·the·system.·A·graphical·environment·is·unnecessary·for·certain·types·of·systems·including·a·virtualization·hypervisor.
3714 Severity: ················medium3714 Severity: ················medium
3715 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gdm_removed3715 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gdm_removed
3716 Identifiers·and·References·References: ·CM-7(a),·CM-7(b),·CM-6(a),·SRG-OS-000480-GPOS-002273716 Identifiers·and·References·References: ·CM-7(a),·CM-7(b),·CM-6(a),·SRG-OS-000480-GPOS-00227
3717 Remediation_Anaconda_snippet_⇲ 
3718 Complexity:·low 
3719 Disruption:·low 
3720 Strategy:···disable 
  
3721 package·--remove=gdm 
3722 Remediation_Puppet_snippet_⇲3717 Remediation_Puppet_snippet_⇲
3723 Complexity:·low3718 Complexity:·low
3724 Disruption:·low3719 Disruption:·low
3725 Strategy:···disable3720 Strategy:···disable
3726 include·remove_gdm3721 include·remove_gdm
  
3727 class·remove_gdm·{3722 class·remove_gdm·{
Offset 3749, 14 lines modifiedOffset 3743, 20 lines modified
3749 ····dnf·remove·-y·"gdm"3743 ····dnf·remove·-y·"gdm"
  
3750 fi3744 fi
  
3751 else3745 else
3752 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3746 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3753 fi3747 fi
 3748 Remediation_Anaconda_snippet_⇲
 3749 Complexity:·low
 3750 Disruption:·low
 3751 Strategy:···disable
  
 3752 package·--remove=gdm
3754 Remediation_Ansible_snippet_⇲3753 Remediation_Ansible_snippet_⇲
3755 Complexity:·low3754 Complexity:·low
3756 Disruption:·low3755 Disruption:·low
3757 Strategy:···disable3756 Strategy:···disable
3758 -·name:·Gather·the·package·facts3757 -·name:·Gather·the·package·facts
3759 ··package_facts:3758 ··package_facts:
3760 ····manager:·auto3759 ····manager:·auto
Offset 3817, 20 lines modifiedOffset 3817, 14 lines modified
3817 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed3817 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
Max diff block lines reached; 445159/449599 bytes (99.01%) of diff not shown.
2.03 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-stig_gui.html
    
Offset 15428, 116 lines modifiedOffset 15428, 116 lines modified
0003c430:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003c430:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003c440:·6964·6d37·3630·3522·2074·6162·696e·6465··idm7605"·tabinde0003c440:·6964·6d37·3630·3522·2074·6162·696e·6465··idm7605"·tabinde
0003c450:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003c450:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003c460:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003c460:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003c470:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003c470:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003c480:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003c480:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003c490:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003c490:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003c4a0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003c4a0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
0003c4b0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003c4b0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003c4c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003c4c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003c4d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003c4d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003c4e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003c4e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003c4f0:·6964·6d37·3630·3522·3e3c·7461·626c·6520··idm7605"><table·0003c4f0:·6d37·3630·3522·3e3c·7461·626c·6520·636c··m7605"><table·cl
0003c500:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003c500:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003c510:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003c510:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003c520:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003c520:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003c530:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003c530:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003c540:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003c540:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003c550:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c550:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c560:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003c560:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003c570:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003c570:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003c580:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c580:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003c590:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003c590:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003c5a0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003c5a0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003c5b0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003c5b0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003c5c0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003c5d0:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</0003c5c0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003c5d0:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003c5e0:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003c5f0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003c600:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003c610:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003c620:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003c630:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003c640:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003c650:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003c660:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003c670:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003c680:·6d37·3630·3622·2074·6162·696e·6465·783d··m7606"·tabindex=
 0003c690:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003c6a0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003c6b0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003c6c0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003c6d0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003c6e0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003c6f0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003c700:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003c710:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003c720:·6170·7365·2220·6964·3d22·6964·6d37·3630··apse"·id="idm760
 0003c730:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=
 0003c740:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003c750:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003c760:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003c770:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003c780:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003c790:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003c7a0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003c7b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c7c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003c7d0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003c7e0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003c7f0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003c800:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 0003c810:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 0003c820:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 0003c830:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
 0003c840:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
 0003c850:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
 0003c860:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 0003c870:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
 0003c880:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003c890:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003c8a0:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal
 0003c8b0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003c8c0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003c8d0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003c8e0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003c8f0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003c900:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
0003c5e0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003c910:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003c5f0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003c920:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003c600:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003c930:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003c610:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003c940:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003c620:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003c950:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003c630:·2369·646d·3736·3036·2220·7461·6269·6e64··#idm7606"·tabind0003c960:·2369·646d·3736·3037·2220·7461·6269·6e64··#idm7607"·tabind
0003c640:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003c970:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003c650:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003c980:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003c660:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003c990:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c670:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003c9a0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c680:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003c9b0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c690:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003c9c0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003c6a0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003c9d0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003c6b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c9e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003c6c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c9f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003c6d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003ca00:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003c6e0:·646d·3736·3036·223e·3c74·6162·6c65·2063··dm7606"><table·c0003ca10:·2269·646d·3736·3037·223e·3c74·6162·6c65··"idm7607"><table
0003c6f0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003ca20:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003c700:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003ca30:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003c710:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003ca40:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003c720:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003ca50:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003c730:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003ca60:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003c740:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003ca70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c750:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003ca80:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003c760:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003ca90:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003c770:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003caa0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c780:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003cab0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003c790:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003cac0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003c7a0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003cad0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003cae0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003caf0:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
0003c7b0:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003c7c0:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003c7d0:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003c7e0:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003c7f0:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003c800:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003c810:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003c820:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003c830:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003c840:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003c850:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003c860:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003c870:·646d·3736·3037·2220·7461·6269·6e64·6578··dm7607"·tabindex 
0003c880:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003c890:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003c8a0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003c8b0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
Max diff block lines reached; 1676494/1691150 bytes (99.13%) of diff not shown.
431 KB
html2text {}
    
Offset 120, 20 lines modifiedOffset 120, 14 lines modified
120 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed120 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
121 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199121 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
122 Remediation_OSBuild_Blueprint_snippet_⇲122 Remediation_OSBuild_Blueprint_snippet_⇲
  
123 [[packages]]123 [[packages]]
124 name·=·"aide"124 name·=·"aide"
125 version·=·"*"125 version·=·"*"
126 Remediation_Anaconda_snippet_⇲ 
127 Complexity:·low 
128 Disruption:·low 
129 Strategy:···enable 
  
130 package·--add=aide 
131 Remediation_Puppet_snippet_⇲126 Remediation_Puppet_snippet_⇲
132 Complexity:·low127 Complexity:·low
133 Disruption:·low128 Disruption:·low
134 Strategy:···enable129 Strategy:···enable
135 include·install_aide130 include·install_aide
  
136 class·install_aide·{131 class·install_aide·{
Offset 151, 14 lines modifiedOffset 145, 20 lines modified
151 if·!·rpm·-q·--quiet·"aide"·;·then145 if·!·rpm·-q·--quiet·"aide"·;·then
152 ····dnf·install·-y·"aide"146 ····dnf·install·-y·"aide"
153 fi147 fi
  
154 else148 else
155 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
156 fi150 fi
 151 Remediation_Anaconda_snippet_⇲
 152 Complexity:·low
 153 Disruption:·low
 154 Strategy:···enable
  
 155 package·--add=aide
157 Remediation_Ansible_snippet_⇲156 Remediation_Ansible_snippet_⇲
158 Complexity:·low157 Complexity:·low
159 Disruption:·low158 Disruption:·low
160 Strategy:···enable159 Strategy:···enable
161 -·name:·Ensure·aide·is·installed160 -·name:·Ensure·aide·is·installed
162 ··package:161 ··package:
163 ····name:·aide162 ····name:·aide
Offset 1475, 20 lines modifiedOffset 1475, 14 lines modified
1475 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed1475 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
1476 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001741476 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
1477 Remediation_OSBuild_Blueprint_snippet_⇲1477 Remediation_OSBuild_Blueprint_snippet_⇲
  
1478 [[packages]]1478 [[packages]]
1479 name·=·"crypto-policies"1479 name·=·"crypto-policies"
1480 version·=·"*"1480 version·=·"*"
1481 Remediation_Anaconda_snippet_⇲ 
1482 Complexity:·low 
1483 Disruption:·low 
1484 Strategy:···enable 
  
1485 package·--add=crypto-policies 
1486 Remediation_Puppet_snippet_⇲1481 Remediation_Puppet_snippet_⇲
1487 Complexity:·low1482 Complexity:·low
1488 Disruption:·low1483 Disruption:·low
1489 Strategy:···enable1484 Strategy:···enable
1490 include·install_crypto-policies1485 include·install_crypto-policies
  
1491 class·install_crypto-policies·{1486 class·install_crypto-policies·{
Offset 1500, 14 lines modifiedOffset 1494, 20 lines modified
1500 Complexity:·low1494 Complexity:·low
1501 Disruption:·low1495 Disruption:·low
1502 Strategy:···enable1496 Strategy:···enable
  
1503 if·!·rpm·-q·--quiet·"crypto-policies"·;·then1497 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
1504 ····dnf·install·-y·"crypto-policies"1498 ····dnf·install·-y·"crypto-policies"
1505 fi1499 fi
 1500 Remediation_Anaconda_snippet_⇲
 1501 Complexity:·low
 1502 Disruption:·low
 1503 Strategy:···enable
  
 1504 package·--add=crypto-policies
1506 Remediation_Ansible_snippet_⇲1505 Remediation_Ansible_snippet_⇲
1507 Complexity:·low1506 Complexity:·low
1508 Disruption:·low1507 Disruption:·low
1509 Strategy:···enable1508 Strategy:···enable
1510 -·name:·Ensure·crypto-policies·is·installed1509 -·name:·Ensure·crypto-policies·is·installed
1511 ··package:1510 ··package:
1512 ····name:·crypto-policies1511 ····name:·crypto-policies
Offset 3744, 20 lines modifiedOffset 3744, 14 lines modified
3744 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed3744 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
3745 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001253745 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
3746 Remediation_OSBuild_Blueprint_snippet_⇲3746 Remediation_OSBuild_Blueprint_snippet_⇲
  
3747 [[packages]]3747 [[packages]]
3748 name·=·"sudo"3748 name·=·"sudo"
3749 version·=·"*"3749 version·=·"*"
3750 Remediation_Anaconda_snippet_⇲ 
3751 Complexity:·low 
3752 Disruption:·low 
3753 Strategy:···enable 
  
3754 package·--add=sudo 
3755 Remediation_Puppet_snippet_⇲3750 Remediation_Puppet_snippet_⇲
3756 Complexity:·low3751 Complexity:·low
3757 Disruption:·low3752 Disruption:·low
3758 Strategy:···enable3753 Strategy:···enable
3759 include·install_sudo3754 include·install_sudo
  
3760 class·install_sudo·{3755 class·install_sudo·{
Offset 3775, 14 lines modifiedOffset 3769, 20 lines modified
3775 if·!·rpm·-q·--quiet·"sudo"·;·then3769 if·!·rpm·-q·--quiet·"sudo"·;·then
3776 ····dnf·install·-y·"sudo"3770 ····dnf·install·-y·"sudo"
3777 fi3771 fi
  
3778 else3772 else
3779 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3773 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3780 fi3774 fi
 3775 Remediation_Anaconda_snippet_⇲
 3776 Complexity:·low
 3777 Disruption:·low
 3778 Strategy:···enable
  
 3779 package·--add=sudo
3781 Remediation_Ansible_snippet_⇲3780 Remediation_Ansible_snippet_⇲
3782 Complexity:·low3781 Complexity:·low
3783 Disruption:·low3782 Disruption:·low
3784 Strategy:···enable3783 Strategy:···enable
3785 -·name:·Ensure·sudo·is·installed3784 -·name:·Ensure·sudo·is·installed
3786 ··package:3785 ··package:
3787 ····name:·sudo3786 ····name:·sudo
Offset 4447, 20 lines modifiedOffset 4447, 14 lines modified
4447 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed4447 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed
Max diff block lines reached; 437744/441663 bytes (99.11%) of diff not shown.
1.42 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-ospp.html
    
Offset 25991, 107 lines modifiedOffset 25991, 107 lines modified
00065860:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00065860:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00065870:·6964·6d35·3538·3422·2074·6162·696e·6465··idm5584"·tabinde00065870:·6964·6d35·3538·3422·2074·6162·696e·6465··idm5584"·tabinde
00065880:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00065880:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
00065890:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00065890:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
000658a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=000658a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
000658b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev000658b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
000658c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R000658c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
000658d0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco000658d0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
000658e0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<000658e0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
000658f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas000658f0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
00065900:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00065900:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
00065910:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00065910:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
00065920:·6964·6d35·3538·3422·3e3c·7461·626c·6520··idm5584"><table·00065920:·6d35·3538·3422·3e3c·7461·626c·6520·636c··m5584"><table·cl
00065930:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab00065930:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
00065940:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00065940:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
00065950:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00065950:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
00065960:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00065960:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
00065970:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00065970:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
00065980:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00065980:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00065990:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00065990:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
000659a0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>000659a0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
000659b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr000659b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
000659c0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</000659c0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
000659d0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t000659d0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
000659e0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><000659e0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 000659f0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 00065a00:·696e·7374·616c·6c5f·646e·662d·6175·746f··install_dnf-auto
 00065a10:·6d61·7469·630a·0a63·6c61·7373·2069·6e73··matic..class·ins
 00065a20:·7461·6c6c·5f64·6e66·2d61·7574·6f6d·6174··tall_dnf-automat
 00065a30:·6963·207b·0a20·2070·6163·6b61·6765·207b··ic·{.··package·{
000659f0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
00065a00:·6765·202d·2d61·6464·3d64·6e66·2d61·7574··ge·--add=dnf-aut 
00065a10:·6f6d·6174·6963·0a3c·2f63·6f64·653e·3c2f··omatic.</code></ 
00065a20:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00065a30:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00065a40:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00065a50:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00065a60:·2d74·6172·6765·743d·2223·6964·6d35·3538··-target="#idm558 
00065a70:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"· 
00065a80:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00065a90:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00065aa0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00065ab0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
00065ac0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
00065ad0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip 
00065ae0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
00065af0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00065b00:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00065b10:·7365·2220·6964·3d22·6964·6d35·3538·3522··se"·id="idm5585" 
00065b20:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00065b30:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00065b40:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00065b50:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00065b60:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00065b70:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00065b80:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00065b90:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00065ba0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00065bb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
00065bc0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
00065bd0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
00065be0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
00065bf0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
00065c00:·6c5f·646e·662d·6175·746f·6d61·7469·630a··l_dnf-automatic.00065a40:·2027·646e·662d·6175·746f·6d61·7469·6327···'dnf-automatic'
00065c10:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f64··.class·install_d00065a50:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 00065a60:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 00065a70:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 00065a80:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 00065a90:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 00065aa0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 00065ab0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 00065ac0:·7461·7267·6574·3d22·2369·646d·3535·3835··target="#idm5585
 00065ad0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 00065ae0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 00065af0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 00065b00:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 00065b10:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 00065b20:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00065b30:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 00065b40:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00065b50:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00065b60:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00065b70:·2069·643d·2269·646d·3535·3835·223e·3c74···id="idm5585"><t
 00065b80:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00065b90:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00065ba0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00065bb0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00065bc0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00065bd0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00065be0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00065bf0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00065c00:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00065c10:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00065c20:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00065c30:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00065c40:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 00065c50:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 00065c60:·6965·7420·2264·6e66·2d61·7574·6f6d·6174··iet·"dnf-automat
 00065c70:·6963·2220·3b20·7468·656e·0a20·2020·2064··ic"·;·then.····d
 00065c80:·6e66·2069·6e73·7461·6c6c·202d·7920·2264··nf·install·-y·"d
00065c20:·6e66·2d61·7574·6f6d·6174·6963·207b·0a20··nf-automatic·{.·00065c90:·6e66·2d61·7574·6f6d·6174·6963·220a·6669··nf-automatic".fi
 00065ca0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00065cb0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00065cc0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00065cd0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 00065ce0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 00065cf0:·743d·2223·6964·6d35·3538·3622·2074·6162··t="#idm5586"·tab
 00065d00:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00065d10:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00065c30:·2070·6163·6b61·6765·207b·2027·646e·662d···package·{·'dnf- 
00065c40:·6175·746f·6d61·7469·6327·3a0a·2020·2020··automatic':.···· 
00065c50:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
00065c60:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
00065c70:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
00065c80:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
00065c90:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00065ca0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00065cb0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00065cc0:·3d22·2369·646d·3535·3836·2220·7461·6269··="#idm5586"·tabi 
00065cd0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00065ce0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00065cf0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00065d20:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00065d00:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00065d10:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00065d20:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
00065d30:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
00065d40:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
Max diff block lines reached; 1044195/1057609 bytes (98.73%) of diff not shown.
418 KB
html2text {}
    
Offset 2202, 20 lines modifiedOffset 2202, 14 lines modified
2202 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed2202 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
2203 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000802203 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
2204 Remediation_OSBuild_Blueprint_snippet_⇲2204 Remediation_OSBuild_Blueprint_snippet_⇲
  
2205 [[packages]]2205 [[packages]]
2206 name·=·"dnf-automatic"2206 name·=·"dnf-automatic"
2207 version·=·"*"2207 version·=·"*"
2208 Remediation_Anaconda_snippet_⇲ 
2209 Complexity:·low 
2210 Disruption:·low 
2211 Strategy:···enable 
  
2212 package·--add=dnf-automatic 
2213 Remediation_Puppet_snippet_⇲2208 Remediation_Puppet_snippet_⇲
2214 Complexity:·low2209 Complexity:·low
2215 Disruption:·low2210 Disruption:·low
2216 Strategy:···enable2211 Strategy:···enable
2217 include·install_dnf-automatic2212 include·install_dnf-automatic
  
2218 class·install_dnf-automatic·{2213 class·install_dnf-automatic·{
Offset 2227, 14 lines modifiedOffset 2221, 20 lines modified
2227 Complexity:·low2221 Complexity:·low
2228 Disruption:·low2222 Disruption:·low
2229 Strategy:···enable2223 Strategy:···enable
  
2230 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then2224 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
2231 ····dnf·install·-y·"dnf-automatic"2225 ····dnf·install·-y·"dnf-automatic"
2232 fi2226 fi
 2227 Remediation_Anaconda_snippet_⇲
 2228 Complexity:·low
 2229 Disruption:·low
 2230 Strategy:···enable
  
 2231 package·--add=dnf-automatic
2233 Remediation_Ansible_snippet_⇲2232 Remediation_Ansible_snippet_⇲
2234 Complexity:·low2233 Complexity:·low
2235 Disruption:·low2234 Disruption:·low
2236 Strategy:···enable2235 Strategy:···enable
2237 -·name:·Ensure·dnf-automatic·is·installed2236 -·name:·Ensure·dnf-automatic·is·installed
2238 ··package:2237 ··package:
2239 ····name:·dnf-automatic2238 ····name:·dnf-automatic
Offset 6967, 20 lines modifiedOffset 6967, 14 lines modified
6967 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_screen_installed6967 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_screen_installed
6968 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-0001106968 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110
6969 Remediation_OSBuild_Blueprint_snippet_⇲6969 Remediation_OSBuild_Blueprint_snippet_⇲
  
6970 [[packages]]6970 [[packages]]
6971 name·=·"screen"6971 name·=·"screen"
6972 version·=·"*"6972 version·=·"*"
6973 Remediation_Anaconda_snippet_⇲ 
6974 Complexity:·low 
6975 Disruption:·low 
6976 Strategy:···enable 
  
6977 package·--add=screen 
6978 Remediation_Puppet_snippet_⇲6973 Remediation_Puppet_snippet_⇲
6979 Complexity:·low6974 Complexity:·low
6980 Disruption:·low6975 Disruption:·low
6981 Strategy:···enable6976 Strategy:···enable
6982 include·install_screen6977 include·install_screen
  
6983 class·install_screen·{6978 class·install_screen·{
Offset 6998, 14 lines modifiedOffset 6992, 20 lines modified
6998 if·!·rpm·-q·--quiet·"screen"·;·then6992 if·!·rpm·-q·--quiet·"screen"·;·then
6999 ····dnf·install·-y·"screen"6993 ····dnf·install·-y·"screen"
7000 fi6994 fi
  
7001 else6995 else
7002 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6996 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7003 fi6997 fi
 6998 Remediation_Anaconda_snippet_⇲
 6999 Complexity:·low
 7000 Disruption:·low
 7001 Strategy:···enable
  
 7002 package·--add=screen
7004 Remediation_Ansible_snippet_⇲7003 Remediation_Ansible_snippet_⇲
7005 Complexity:·low7004 Complexity:·low
7006 Disruption:·low7005 Disruption:·low
7007 Strategy:···enable7006 Strategy:···enable
7008 -·name:·Ensure·screen·is·installed7007 -·name:·Ensure·screen·is·installed
7009 ··package:7008 ··package:
7010 ····name:·screen7009 ····name:·screen
Offset 7025, 26 lines modifiedOffset 7025, 14 lines modified
  
7025 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:7025 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
7026 $·sudo·systemctl·mask·--now·debug-shell.service7026 $·sudo·systemctl·mask·--now·debug-shell.service
7027 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.7027 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
7028 Severity: ················medium7028 Severity: ················medium
7029 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled7029 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
7030 Identifiers·and·References·References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002277030 Identifiers·and·References·References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
7031 Remediation_Kubernetes_snippet_⇲ 
7032 --- 
7033 apiVersion:·machineconfiguration.openshift.io/v1 
7034 kind:·MachineConfig 
7035 spec: 
7036 ··config: 
7037 ····ignition: 
7038 ······version:·3.1.0 
7039 ····systemd: 
7040 ······units: 
7041 ······-·enabled:·false 
7042 ········name:·debug-shell.service 
7043 Remediation_OSBuild_Blueprint_snippet_⇲7031 Remediation_OSBuild_Blueprint_snippet_⇲
  
7044 [customizations.services]7032 [customizations.services]
7045 disabled·=·["debug-shell"]7033 disabled·=·["debug-shell"]
7046 Remediation_Puppet_snippet_⇲7034 Remediation_Puppet_snippet_⇲
7047 Complexity:·low7035 Complexity:·low
7048 Disruption:·low7036 Disruption:·low
Offset 7053, 14 lines modifiedOffset 7041, 26 lines modified
  
7053 class·disable_debug-shell·{7041 class·disable_debug-shell·{
7054 ··service·{'debug-shell':7042 ··service·{'debug-shell':
7055 ····enable·=>·false,7043 ····enable·=>·false,
7056 ····ensure·=>·'stopped',7044 ····ensure·=>·'stopped',
7057 ··}7045 ··}
7058 }7046 }
 7047 Remediation_Kubernetes_snippet_⇲
 7048 ---
 7049 apiVersion:·machineconfiguration.openshift.io/v1
 7050 kind:·MachineConfig
 7051 spec:
 7052 ··config:
 7053 ····ignition:
 7054 ······version:·3.1.0
 7055 ····systemd:
Max diff block lines reached; 423718/427714 bytes (99.07%) of diff not shown.
959 KB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-pci-dss.html
    
Offset 17059, 116 lines modifiedOffset 17059, 116 lines modified
00042a20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00042a20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00042a30:·2369·646d·3137·3232·2220·7461·6269·6e64··#idm1722"·tabind00042a30:·2369·646d·3137·3232·2220·7461·6269·6e64··#idm1722"·tabind
00042a40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00042a40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00042a50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00042a50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
00042a60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00042a60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00042a70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00042a70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00042a80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00042a80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00042a90:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac00042a90:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
00042aa0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...00042aa0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
00042ab0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00042ab0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
00042ac0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00042ac0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
00042ad0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00042ad0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
00042ae0:·2269·646d·3137·3232·223e·3c74·6162·6c65··"idm1722"><table00042ae0:·646d·3137·3232·223e·3c74·6162·6c65·2063··dm1722"><table·c
00042af0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00042af0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
00042b00:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00042b00:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
00042b10:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table00042b10:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
00042b20:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>00042b20:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
00042b30:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<00042b30:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
00042b40:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00042b40:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
00042b50:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis00042b50:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
00042b60:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td00042b60:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
00042b70:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00042b70:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00042b80:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<00042b80:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00042b90:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</00042b90:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
00042ba0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>00042ba0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
00042bb0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
00042bc0:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<00042bb0:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 00042bc0:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 00042bd0:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 00042be0:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 00042bf0:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 00042c00:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 00042c10:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 00042c20:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 00042c30:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 00042c40:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 00042c50:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 00042c60:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 00042c70:·646d·3137·3233·2220·7461·6269·6e64·6578··dm1723"·tabindex
 00042c80:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 00042c90:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 00042ca0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 00042cb0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 00042cc0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00042cd0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 00042ce0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 00042cf0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00042d00:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00042d10:·6c61·7073·6522·2069·643d·2269·646d·3137··lapse"·id="idm17
 00042d20:·3233·223e·3c74·6162·6c65·2063·6c61·7373··23"><table·class
 00042d30:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00042d40:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00042d50:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00042d60:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00042d70:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 00042d80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00042d90:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00042da0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 00042db0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00042dc0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 00042dd0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 00042de0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00042df0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 00042e00:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 00042e10:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 00042e20:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
 00042e30:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
 00042e40:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
 00042e50:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
 00042e60:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.
 00042e70:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 00042e80:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 00042e90:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta
 00042ea0:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 00042eb0:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 00042ec0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 00042ed0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 00042ee0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 00042ef0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
00042bd0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di00042f00:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
00042be0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·00042f10:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
00042bf0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat00042f20:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
00042c00:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap00042f30:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
00042c10:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00042f40:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00042c20:·2223·6964·6d31·3732·3322·2074·6162·696e··"#idm1723"·tabin00042f50:·2223·6964·6d31·3732·3422·2074·6162·696e··"#idm1724"·tabin
00042c30:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00042f60:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00042c40:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00042f70:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00042c50:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00042f80:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00042c60:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00042f90:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00042c70:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00042fa0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00042c80:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup00042fb0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
00042c90:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<00042fc0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
00042ca0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00042fd0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
00042cb0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00042fe0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
00042cc0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00042ff0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
00042cd0:·6964·6d31·3732·3322·3e3c·7461·626c·6520··idm1723"><table·00043000:·3d22·6964·6d31·3732·3422·3e3c·7461·626c··="idm1724"><tabl
00042ce0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab00043010:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
00042cf0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00043020:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
00042d00:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00043030:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
00042d10:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00043040:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
00042d20:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00043050:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00042d30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00043060:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00042d40:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00043070:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
00042d50:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00043080:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
00042d60:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00043090:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00042d70:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</000430a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
00042d80:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t000430b0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
00042d90:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><000430c0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 000430d0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 000430e0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
00042da0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ 
00042db0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
00042dc0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
00042dd0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
00042de0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
00042df0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
00042e00:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
00042e10:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00042e20:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00042e30:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00042e40:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00042e50:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00042e60:·6964·6d31·3732·3422·2074·6162·696e·6465··idm1724"·tabinde 
00042e70:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00042e80:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00042e90:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00042ea0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
Max diff block lines reached; 683672/698328 bytes (97.90%) of diff not shown.
277 KB
html2text {}
    
Offset 379, 20 lines modifiedOffset 379, 14 lines modified
379 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed379 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
380 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199380 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
381 Remediation_OSBuild_Blueprint_snippet_⇲381 Remediation_OSBuild_Blueprint_snippet_⇲
  
382 [[packages]]382 [[packages]]
383 name·=·"aide"383 name·=·"aide"
384 version·=·"*"384 version·=·"*"
385 Remediation_Anaconda_snippet_⇲ 
386 Complexity:·low 
387 Disruption:·low 
388 Strategy:···enable 
  
389 package·--add=aide 
390 Remediation_Puppet_snippet_⇲385 Remediation_Puppet_snippet_⇲
391 Complexity:·low386 Complexity:·low
392 Disruption:·low387 Disruption:·low
393 Strategy:···enable388 Strategy:···enable
394 include·install_aide389 include·install_aide
  
395 class·install_aide·{390 class·install_aide·{
Offset 410, 14 lines modifiedOffset 404, 20 lines modified
410 if·!·rpm·-q·--quiet·"aide"·;·then404 if·!·rpm·-q·--quiet·"aide"·;·then
411 ····dnf·install·-y·"aide"405 ····dnf·install·-y·"aide"
412 fi406 fi
  
413 else407 else
414 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'408 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
415 fi409 fi
 410 Remediation_Anaconda_snippet_⇲
 411 Complexity:·low
 412 Disruption:·low
 413 Strategy:···enable
  
 414 package·--add=aide
416 Remediation_Ansible_snippet_⇲415 Remediation_Ansible_snippet_⇲
417 Complexity:·low416 Complexity:·low
418 Disruption:·low417 Disruption:·low
419 Strategy:···enable418 Strategy:···enable
420 -·name:·Ensure·aide·is·installed419 -·name:·Ensure·aide·is·installed
421 ··package:420 ··package:
422 ····name:·aide421 ····name:·aide
Offset 5853, 20 lines modifiedOffset 5853, 14 lines modified
5853 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed5853 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed
5854 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-0015205854 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520
5855 Remediation_OSBuild_Blueprint_snippet_⇲5855 Remediation_OSBuild_Blueprint_snippet_⇲
  
5856 [[packages]]5856 [[packages]]
5857 name·=·"opensc"5857 name·=·"opensc"
5858 version·=·"*"5858 version·=·"*"
5859 Remediation_Anaconda_snippet_⇲ 
5860 Complexity:·low 
5861 Disruption:·low 
5862 Strategy:···enable 
  
5863 package·--add=opensc 
5864 Remediation_Puppet_snippet_⇲5859 Remediation_Puppet_snippet_⇲
5865 Complexity:·low5860 Complexity:·low
5866 Disruption:·low5861 Disruption:·low
5867 Strategy:···enable5862 Strategy:···enable
5868 include·install_opensc5863 include·install_opensc
  
5869 class·install_opensc·{5864 class·install_opensc·{
Offset 5884, 14 lines modifiedOffset 5878, 20 lines modified
5884 if·!·rpm·-q·--quiet·"opensc"·;·then5878 if·!·rpm·-q·--quiet·"opensc"·;·then
5885 ····dnf·install·-y·"opensc"5879 ····dnf·install·-y·"opensc"
5886 fi5880 fi
  
5887 else5881 else
5888 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5882 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5889 fi5883 fi
 5884 Remediation_Anaconda_snippet_⇲
 5885 Complexity:·low
 5886 Disruption:·low
 5887 Strategy:···enable
  
 5888 package·--add=opensc
5890 Remediation_Ansible_snippet_⇲5889 Remediation_Ansible_snippet_⇲
5891 Complexity:·low5890 Complexity:·low
5892 Disruption:·low5891 Disruption:·low
5893 Strategy:···enable5892 Strategy:···enable
5894 -·name:·Ensure·opensc·is·installed5893 -·name:·Ensure·opensc·is·installed
5895 ··package:5894 ··package:
5896 ····name:·opensc5895 ····name:·opensc
Offset 5913, 20 lines modifiedOffset 5913, 14 lines modified
5913 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed5913 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
5914 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015305914 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
5915 Remediation_OSBuild_Blueprint_snippet_⇲5915 Remediation_OSBuild_Blueprint_snippet_⇲
  
5916 [[packages]]5916 [[packages]]
5917 name·=·"pcsc-lite"5917 name·=·"pcsc-lite"
5918 version·=·"*"5918 version·=·"*"
5919 Remediation_Anaconda_snippet_⇲ 
5920 Complexity:·low 
5921 Disruption:·low 
5922 Strategy:···enable 
  
5923 package·--add=pcsc-lite 
5924 Remediation_Puppet_snippet_⇲5919 Remediation_Puppet_snippet_⇲
5925 Complexity:·low5920 Complexity:·low
5926 Disruption:·low5921 Disruption:·low
5927 Strategy:···enable5922 Strategy:···enable
5928 include·install_pcsc-lite5923 include·install_pcsc-lite
  
5929 class·install_pcsc-lite·{5924 class·install_pcsc-lite·{
Offset 5944, 14 lines modifiedOffset 5938, 20 lines modified
5944 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then5938 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
5945 ····dnf·install·-y·"pcsc-lite"5939 ····dnf·install·-y·"pcsc-lite"
5946 fi5940 fi
  
5947 else5941 else
5948 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5942 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5949 fi5943 fi
 5944 Remediation_Anaconda_snippet_⇲
 5945 Complexity:·low
 5946 Disruption:·low
 5947 Strategy:···enable
  
 5948 package·--add=pcsc-lite
5950 Remediation_Ansible_snippet_⇲5949 Remediation_Ansible_snippet_⇲
5951 Complexity:·low5950 Complexity:·low
5952 Disruption:·low5951 Disruption:·low
5953 Strategy:···enable5952 Strategy:···enable
5954 -·name:·Ensure·pcsc-lite·is·installed5953 -·name:·Ensure·pcsc-lite·is·installed
5955 ··package:5954 ··package:
5956 ····name:·pcsc-lite5955 ····name:·pcsc-lite
Offset 6690, 15 lines modifiedOffset 6690, 15 lines modified
6690 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.6690 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
Max diff block lines reached; 279806/284048 bytes (98.51%) of diff not shown.
566 KB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-standard.html
    
Offset 33567, 21 lines modifiedOffset 33567, 21 lines modified
000831e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla000831e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000831f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap000831f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00083200:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00083200:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
00083210:·2269·646d·3136·3238·3722·3e3c·7072·653e··"idm16287"><pre>00083210:·2269·646d·3136·3238·3722·3e3c·7072·653e··"idm16287"><pre>
00083220:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat00083220:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
00083230:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl00083230:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
00083240:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai00083240:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
00083250:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[00083250:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 00083260:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au
 00083270:·6469·7420·2661·6d70·3b26·616d·703b·205b··dit·&amp;&amp;·[
00083260:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren00083280:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
00083270:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[00083290:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
00083280:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont000832a0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
00083290:·6169·6e65·7265·6e76·205d·2026·616d·703b··ainerenv·]·&amp;000832b0:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
000832a0:·2661·6d70·3b20·7270·6d20·2d2d·7175·6965··&amp;·rpm·--quie 
000832b0:·7420·2d71·2061·7564·6974·3b20·7468·656e··t·-q·audit;·then 
000832c0:·0a0a·2320·4669·7273·7420·7065·7266·6f72··..#·First·perfor000832c0:·0a0a·2320·4669·7273·7420·7065·7266·6f72··..#·First·perfor
000832d0:·6d20·7468·6520·7265·6d65·6469·6174·696f··m·the·remediatio000832d0:·6d20·7468·6520·7265·6d65·6469·6174·696f··m·the·remediatio
000832e0:·6e20·6f66·2074·6865·2073·7973·6361·6c6c··n·of·the·syscall000832e0:·6e20·6f66·2074·6865·2073·7973·6361·6c6c··n·of·the·syscall
000832f0:·2072·756c·650a·2320·5265·7472·6965·7665···rule.#·Retrieve000832f0:·2072·756c·650a·2320·5265·7472·6965·7665···rule.#·Retrieve
00083300:·2068·6172·6477·6172·6520·6172·6368·6974···hardware·archit00083300:·2068·6172·6477·6172·6520·6172·6368·6974···hardware·archit
00083310:·6563·7475·7265·206f·6620·7468·6520·756e··ecture·of·the·un00083310:·6563·7475·7265·206f·6620·7468·6520·756e··ecture·of·the·un
00083320:·6465·726c·7969·6e67·2073·7973·7465·6d0a··derlying·system.00083320:·6465·726c·7969·6e67·2073·7973·7465·6d0a··derlying·system.
Offset 34459, 23 lines modifiedOffset 34459, 23 lines modified
000869a0:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r000869a0:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r
000869b0:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy000869b0:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
000869c0:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar000869c0:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar
000869d0:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a000869d0:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a
000869e0:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks000869e0:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks
000869f0:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···000869f0:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
00086a00:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b6400086a00:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b64
00086a10:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans00086a10:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a
00086a20:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat 
00086a30:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in· 
00086a40:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc" 
00086a50:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod 
00086a60:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container 
00086a70:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"· 
00086a80:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
00086a90:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a00086a20:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible
 00086a30:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
 00086a40:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir
 00086a50:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 00086a60:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 00086a70:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 00086a80:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 00086a90:·6f6e·7461·696e·6572·225d·0a20·202d·2061··ontainer"].··-·a
00086aa0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect00086aa0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
00086ab0:·7572·6520·3d3d·2022·6161·7263·6836·3422··ure·==·"aarch64"00086ab0:·7572·6520·3d3d·2022·6161·7263·6836·3422··ure·==·"aarch64"
00086ac0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch00086ac0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch
00086ad0:·6974·6563·7475·7265·203d·3d20·2270·7063··itecture·==·"ppc00086ad0:·6974·6563·7475·7265·203d·3d20·2270·7063··itecture·==·"ppc
00086ae0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a00086ae0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a
00086af0:·7263·6869·7465·6374·7572·650a·2020·2020··rchitecture.····00086af0:·7263·6869·7465·6374·7572·650a·2020·2020··rchitecture.····
00086b00:·3d3d·2022·7070·6336·346c·6522·206f·7220··==·"ppc64le"·or·00086b00:·3d3d·2022·7070·6336·346c·6522·206f·7220··==·"ppc64le"·or·
Offset 34781, 22 lines modifiedOffset 34781, 22 lines modified
00087dc0:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea00087dc0:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea
00087dd0:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m00087dd0:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m
00087de0:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····00087de0:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····
00087df0:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.00087df0:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
00087e00:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal00087e00:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal
00087e10:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt00087e10:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt
00087e20:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·00087e20:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·
00087e30:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu 
00087e40:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
00087e50:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
00087e60:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
00087e70:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
00087e80:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a 
00087e90:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
00087ea0:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'00087e30:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a
 00087e40:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
 00087e50:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib
 00087e60:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 00087e70:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 00087e80:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 00087e90:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 00087ea0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
00087eb0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI00087eb0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI
00087ec0:·532d·352e·342e·312e·310a·2020·2d20·4e49··S-5.4.1.1.··-·NI00087ec0:·532d·352e·342e·312e·310a·2020·2d20·4e49··S-5.4.1.1.··-·NI
00087ed0:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.700087ed0:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.7
00087ee0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-5300087ee0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
00087ef0:·2d41·552d·3132·2863·290a·2020·2d20·4e49··-AU-12(c).··-·NI00087ef0:·2d41·552d·3132·2863·290a·2020·2d20·4e49··-AU-12(c).··-·NI
00087f00:·5354·2d38·3030·2d35·332d·4155·2d32·2864··ST-800-53-AU-2(d00087f00:·5354·2d38·3030·2d35·332d·4155·2d32·2864··ST-800-53-AU-2(d
00087f10:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-500087f10:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5
Offset 35091, 22 lines modifiedOffset 35091, 22 lines modified
00089120:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:00089120:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:
00089130:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode00089130:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode
00089140:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st00089140:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st
00089150:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···00089150:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···
00089160:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_00089160:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_
00089170:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=00089170:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=
00089180:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·00089180:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·
00089190:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali 
000891a0:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not· 
000891b0:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l 
000891c0:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·" 
000891d0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai 
000891e0:·6e65·7222·5d0a·2020·2d20·2722·6175·6469··ner"].··-·'"audi 
000891f0:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
00089200:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··00089190:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi
 000891a0:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
 000891b0:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_
 000891c0:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
 000891d0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
 000891e0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
 000891f0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
 00089200:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
00089210:·2d20·6175·6469·745f·6172·6368·203d·3d20··-·audit_arch·==·00089210:·2d20·6175·6469·745f·6172·6368·203d·3d20··-·audit_arch·==·
00089220:·2262·3634·220a·2020·7461·6773·3a0a·2020··"b64".··tags:.··00089220:·2262·3634·220a·2020·7461·6773·3a0a·2020··"b64".··tags:.··
00089230:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·00089230:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
00089240:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-00089240:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
00089250:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-800089250:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8
00089260:·3030·2d35·332d·4155·2d31·3228·6329·0a20··00-53-AU-12(c).·00089260:·3030·2d35·332d·4155·2d31·3228·6329·0a20··00-53-AU-12(c).·
00089270:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A00089270:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A
Offset 36044, 21 lines modifiedOffset 36044, 21 lines modified
0008ccb0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0008ccb0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0008ccc0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0008ccc0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0008ccd0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10008ccd0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
0008cce0:·3634·3433·223e·3c70·7265·3e3c·636f·6465··6443"><pre><code0008cce0:·3634·3433·223e·3c70·7265·3e3c·636f·6465··6443"><pre><code
0008ccf0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i0008ccf0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
0008cd00:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl0008cd00:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
0008cd10:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla0008cd10:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
0008cd20:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f0008cd20:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
0008cd30:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&0008cd30:·7175·6965·7420·2d71·2061·7564·6974·2026··quiet·-q·audit·&
0008cd40:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f0008cd40:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 0008cd50:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 0008cd60:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
Max diff block lines reached; 397169/407028 bytes (97.58%) of diff not shown.
169 KB
html2text {}
    
Offset 2303, 15 lines modifiedOffset 2303, 15 lines modified
2303 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2303 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2304 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2304 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2305 Severity: ················medium2305 Severity: ················medium
2306 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod2306 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
2307 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019402307 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
2308 Remediation_Shell_script_⇲2308 Remediation_Shell_script_⇲
2309 #·Remediation·is·applicable·only·in·certain·platforms2309 #·Remediation·is·applicable·only·in·certain·platforms
2310 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then2310 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
2311 #·First·perform·the·remediation·of·the·syscall·rule2311 #·First·perform·the·remediation·of·the·syscall·rule
2312 #·Retrieve·hardware·architecture·of·the·underlying·system2312 #·Retrieve·hardware·architecture·of·the·underlying·system
2313 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2313 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2314 for·ARCH·in·"${RULE_ARCHS[@]}"2314 for·ARCH·in·"${RULE_ARCHS[@]}"
2315 do2315 do
Offset 2657, 16 lines modifiedOffset 2657, 16 lines modified
2657 ··-·reboot_required2657 ··-·reboot_required
2658 ··-·restrict_strategy2658 ··-·restrict_strategy
  
2659 -·name:·Set·architecture·for·audit·chmod·tasks2659 -·name:·Set·architecture·for·audit·chmod·tasks
2660 ··set_fact:2660 ··set_fact:
2661 ····audit_arch:·b642661 ····audit_arch:·b64
2662 ··when:2662 ··when:
2663 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2664 ··-·'"audit"·in·ansible_facts.packages'2663 ··-·'"audit"·in·ansible_facts.packages'
 2664 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2665 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2665 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2666 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2666 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2667 ··tags:2667 ··tags:
2668 ··-·CJIS-5.4.1.12668 ··-·CJIS-5.4.1.1
2669 ··-·NIST-800-171-3.1.72669 ··-·NIST-800-171-3.1.7
2670 ··-·NIST-800-53-AU-12(c)2670 ··-·NIST-800-53-AU-12(c)
2671 ··-·NIST-800-53-AU-2(d)2671 ··-·NIST-800-53-AU-2(d)
Offset 2802, 16 lines modifiedOffset 2802, 16 lines modified
2802 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002802 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2803 ········-F·auid!=unset·-F·key=perm_mod2803 ········-F·auid!=unset·-F·key=perm_mod
2804 ······create:·true2804 ······create:·true
2805 ······mode:·o-rwx2805 ······mode:·o-rwx
2806 ······state:·present2806 ······state:·present
2807 ····when:·syscalls_found·|·length·==·02807 ····when:·syscalls_found·|·length·==·0
2808 ··when:2808 ··when:
2809 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2810 ··-·'"audit"·in·ansible_facts.packages'2809 ··-·'"audit"·in·ansible_facts.packages'
 2810 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2811 ··tags:2811 ··tags:
2812 ··-·CJIS-5.4.1.12812 ··-·CJIS-5.4.1.1
2813 ··-·NIST-800-171-3.1.72813 ··-·NIST-800-171-3.1.7
2814 ··-·NIST-800-53-AU-12(c)2814 ··-·NIST-800-53-AU-12(c)
2815 ··-·NIST-800-53-AU-2(d)2815 ··-·NIST-800-53-AU-2(d)
2816 ··-·NIST-800-53-CM-6(a)2816 ··-·NIST-800-53-CM-6(a)
2817 ··-·PCI-DSS-Req-10.5.52817 ··-·PCI-DSS-Req-10.5.5
Offset 2945, 16 lines modifiedOffset 2945, 16 lines modified
2945 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002945 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2946 ········-F·auid!=unset·-F·key=perm_mod2946 ········-F·auid!=unset·-F·key=perm_mod
2947 ······create:·true2947 ······create:·true
2948 ······mode:·o-rwx2948 ······mode:·o-rwx
2949 ······state:·present2949 ······state:·present
2950 ····when:·syscalls_found·|·length·==·02950 ····when:·syscalls_found·|·length·==·0
2951 ··when:2951 ··when:
2952 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2953 ··-·'"audit"·in·ansible_facts.packages'2952 ··-·'"audit"·in·ansible_facts.packages'
 2953 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2954 ··-·audit_arch·==·"b64"2954 ··-·audit_arch·==·"b64"
2955 ··tags:2955 ··tags:
2956 ··-·CJIS-5.4.1.12956 ··-·CJIS-5.4.1.1
2957 ··-·NIST-800-171-3.1.72957 ··-·NIST-800-171-3.1.7
2958 ··-·NIST-800-53-AU-12(c)2958 ··-·NIST-800-53-AU-12(c)
2959 ··-·NIST-800-53-AU-2(d)2959 ··-·NIST-800-53-AU-2(d)
2960 ··-·NIST-800-53-CM-6(a)2960 ··-·NIST-800-53-CM-6(a)
Offset 2977, 15 lines modifiedOffset 2977, 15 lines modified
2977 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2977 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2978 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2978 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2979 Severity: ················medium2979 Severity: ················medium
2980 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2980 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2981 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019402981 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
2982 Remediation_Shell_script_⇲2982 Remediation_Shell_script_⇲
2983 #·Remediation·is·applicable·only·in·certain·platforms2983 #·Remediation·is·applicable·only·in·certain·platforms
2984 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then2984 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
2985 #·First·perform·the·remediation·of·the·syscall·rule2985 #·First·perform·the·remediation·of·the·syscall·rule
2986 #·Retrieve·hardware·architecture·of·the·underlying·system2986 #·Retrieve·hardware·architecture·of·the·underlying·system
2987 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2987 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2988 for·ARCH·in·"${RULE_ARCHS[@]}"2988 for·ARCH·in·"${RULE_ARCHS[@]}"
2989 do2989 do
Offset 3331, 16 lines modifiedOffset 3331, 16 lines modified
3331 ··-·reboot_required3331 ··-·reboot_required
3332 ··-·restrict_strategy3332 ··-·restrict_strategy
  
3333 -·name:·Set·architecture·for·audit·chown·tasks3333 -·name:·Set·architecture·for·audit·chown·tasks
3334 ··set_fact:3334 ··set_fact:
3335 ····audit_arch:·b643335 ····audit_arch:·b64
3336 ··when:3336 ··when:
3337 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3338 ··-·'"audit"·in·ansible_facts.packages'3337 ··-·'"audit"·in·ansible_facts.packages'
 3338 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3339 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3339 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3340 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3340 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3341 ··tags:3341 ··tags:
3342 ··-·CJIS-5.4.1.13342 ··-·CJIS-5.4.1.1
3343 ··-·NIST-800-171-3.1.73343 ··-·NIST-800-171-3.1.7
3344 ··-·NIST-800-53-AU-12(c)3344 ··-·NIST-800-53-AU-12(c)
3345 ··-·NIST-800-53-AU-2(d)3345 ··-·NIST-800-53-AU-2(d)
Offset 3478, 16 lines modifiedOffset 3478, 16 lines modified
3478 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003478 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3479 ········-F·auid!=unset·-F·key=perm_mod3479 ········-F·auid!=unset·-F·key=perm_mod
3480 ······create:·true3480 ······create:·true
3481 ······mode:·o-rwx3481 ······mode:·o-rwx
3482 ······state:·present3482 ······state:·present
3483 ····when:·syscalls_found·|·length·==·03483 ····when:·syscalls_found·|·length·==·0
3484 ··when:3484 ··when:
3485 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3486 ··-·'"audit"·in·ansible_facts.packages'3485 ··-·'"audit"·in·ansible_facts.packages'
 3486 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3487 ··tags:3487 ··tags:
3488 ··-·CJIS-5.4.1.13488 ··-·CJIS-5.4.1.1
3489 ··-·NIST-800-171-3.1.73489 ··-·NIST-800-171-3.1.7
3490 ··-·NIST-800-53-AU-12(c)3490 ··-·NIST-800-53-AU-12(c)
3491 ··-·NIST-800-53-AU-2(d)3491 ··-·NIST-800-53-AU-2(d)
3492 ··-·NIST-800-53-CM-6(a)3492 ··-·NIST-800-53-CM-6(a)
3493 ··-·PCI-DSS-Req-10.5.53493 ··-·PCI-DSS-Req-10.5.5
Offset 3623, 16 lines modifiedOffset 3623, 16 lines modified
3623 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003623 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3624 ········-F·auid!=unset·-F·key=perm_mod3624 ········-F·auid!=unset·-F·key=perm_mod
3625 ······create:·true3625 ······create:·true
3626 ······mode:·o-rwx3626 ······mode:·o-rwx
3627 ······state:·present3627 ······state:·present
Max diff block lines reached; 163856/172748 bytes (94.85%) of diff not shown.
564 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_enhanced.html
    
Offset 15244, 116 lines modifiedOffset 15244, 116 lines modified
0003b8b0:·7461·7267·6574·3d22·2369·646d·3632·3834··target="#idm62840003b8b0:·7461·7267·6574·3d22·2369·646d·3632·3834··target="#idm6284
0003b8c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b8c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b8d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b8d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b8e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b8e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b8f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b8f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b900:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b900:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b910:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b910:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b920:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni0003b920:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
0003b930:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003b930:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003b940:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b940:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003b950:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b950:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003b960:·7073·6522·2069·643d·2269·646d·3632·3834··pse"·id="idm62840003b960:·6522·2069·643d·2269·646d·3632·3834·223e··e"·id="idm6284">
0003b970:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b970:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003b980:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b980:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003b990:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b990:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003b9a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b9a0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003b9b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b9b0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003b9c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b9c0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003b9d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b9d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b9e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b9e0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003b9f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b9f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003ba00:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003ba00:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003ba10:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003ba10:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003ba20:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003ba20:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003ba30:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003ba30:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003ba40:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad0003ba40:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003ba50:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins
 0003ba60:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa
 0003ba70:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':.
 0003ba80:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 0003ba90:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 0003baa0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 0003bab0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003bac0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003bad0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003bae0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003baf0:·7267·6574·3d22·2369·646d·3632·3835·2220··rget="#idm6285"·
 0003bb00:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003bb10:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003bb20:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003bb30:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003bb40:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003bb50:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003bb60:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0003bb70:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003bb80:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003bb90:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003bba0:·643d·2269·646d·3632·3835·223e·3c74·6162··d="idm6285"><tab
 0003bbb0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003bbc0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003bbd0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003bbe0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003bbf0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003bc00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003bc10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003bc20:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003bc30:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003bc40:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003bc50:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003bc60:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003bc70:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 0003bc80:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003bc90:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003bca0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003bcb0:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d
 0003bcc0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;
 0003bcd0:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru
 0003bce0:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·
 0003bcf0:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp
 0003bd00:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 0003bd10:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y
 0003bd20:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a
 0003bd30:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 0003bd40:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003bd50:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003bd60:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003bd70:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
0003ba50:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></0003bd80:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
0003ba60:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003bd90:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003ba70:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003bda0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003ba80:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003bdb0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003ba90:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003bdc0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003baa0:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm6280003bdd0:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628
0003bab0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·0003bde0:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
0003bac0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003bdf0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bad0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003be00:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bae0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003be10:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003baf0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003be20:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bb00:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003be30:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bb10:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip0003be40:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
0003bb20:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003be50:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bb30:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003be60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bb40:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003be70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bb50:·7365·2220·6964·3d22·6964·6d36·3238·3522··se"·id="idm6285"0003be80:·6170·7365·2220·6964·3d22·6964·6d36·3238··apse"·id="idm628
0003bb60:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003be90:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=
0003bb70:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003bea0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bb80:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003beb0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bb90:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003bec0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003bba0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003bed0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003bbb0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003bee0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bbc0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003bef0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bbd0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003bf00:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003bbe0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bf10:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003bbf0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003bf20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003bc00:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003bf30:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003bc10:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003bf40:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003bc20:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003bf50:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003bf60:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003bf70:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><
0003bc30:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003bc40:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in 
0003bc50:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p 
0003bc60:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide': 
0003bc70:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0003bc80:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0003bc90:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0003bca0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bcb0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003bcc0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003bcd0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003bce0:·6172·6765·743d·2223·6964·6d36·3238·3622··arget="#idm6286" 
0003bcf0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003bd00:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003bd10:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003bd20:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003bd30:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003bd40:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
Max diff block lines reached; 523340/537996 bytes (97.28%) of diff not shown.
38.0 KB
html2text {}
    
Offset 107, 20 lines modifiedOffset 107, 14 lines modified
107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,
108 ············OL07-00-020029,·SV-251701r833031_rule108 ············OL07-00-020029,·SV-251701r833031_rule
109 Remediation_OSBuild_Blueprint_snippet_⇲109 Remediation_OSBuild_Blueprint_snippet_⇲
  
110 [[packages]]110 [[packages]]
111 name·=·"aide"111 name·=·"aide"
112 version·=·"*"112 version·=·"*"
113 Remediation_Anaconda_snippet_⇲ 
114 Complexity:·low 
115 Disruption:·low 
116 Strategy:···enable 
  
117 package·--add=aide 
118 Remediation_Puppet_snippet_⇲113 Remediation_Puppet_snippet_⇲
119 Complexity:·low114 Complexity:·low
120 Disruption:·low115 Disruption:·low
121 Strategy:···enable116 Strategy:···enable
122 include·install_aide117 include·install_aide
  
123 class·install_aide·{118 class·install_aide·{
Offset 138, 14 lines modifiedOffset 132, 20 lines modified
138 if·!·rpm·-q·--quiet·"aide"·;·then132 if·!·rpm·-q·--quiet·"aide"·;·then
139 ····yum·install·-y·"aide"133 ····yum·install·-y·"aide"
140 fi134 fi
  
141 else135 else
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
143 fi137 fi
 138 Remediation_Anaconda_snippet_⇲
 139 Complexity:·low
 140 Disruption:·low
 141 Strategy:···enable
  
 142 package·--add=aide
144 Remediation_Ansible_snippet_⇲143 Remediation_Ansible_snippet_⇲
145 Complexity:·low144 Complexity:·low
146 Disruption:·low145 Disruption:·low
147 Strategy:···enable146 Strategy:···enable
148 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
149 ··package:148 ··package:
150 ····name:·aide149 ····name:·aide
Offset 476, 20 lines modifiedOffset 476, 14 lines modified
476 and·········00125476 and·········00125
477 References477 References
478 Remediation_OSBuild_Blueprint_snippet_⇲478 Remediation_OSBuild_Blueprint_snippet_⇲
  
479 [[packages]]479 [[packages]]
480 name·=·"sudo"480 name·=·"sudo"
481 version·=·"*"481 version·=·"*"
482 Remediation_Anaconda_snippet_⇲ 
483 Complexity:·low 
484 Disruption:·low 
485 Strategy:···enable 
  
486 package·--add=sudo 
487 Remediation_Puppet_snippet_⇲482 Remediation_Puppet_snippet_⇲
488 Complexity:·low483 Complexity:·low
489 Disruption:·low484 Disruption:·low
490 Strategy:···enable485 Strategy:···enable
491 include·install_sudo486 include·install_sudo
  
492 class·install_sudo·{487 class·install_sudo·{
Offset 507, 14 lines modifiedOffset 501, 20 lines modified
507 if·!·rpm·-q·--quiet·"sudo"·;·then501 if·!·rpm·-q·--quiet·"sudo"·;·then
508 ····yum·install·-y·"sudo"502 ····yum·install·-y·"sudo"
509 fi503 fi
  
510 else504 else
511 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'505 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
512 fi506 fi
 507 Remediation_Anaconda_snippet_⇲
 508 Complexity:·low
 509 Disruption:·low
 510 Strategy:···enable
  
 511 package·--add=sudo
513 Remediation_Ansible_snippet_⇲512 Remediation_Ansible_snippet_⇲
514 Complexity:·low513 Complexity:·low
515 Disruption:·low514 Disruption:·low
516 Strategy:···enable515 Strategy:···enable
517 -·name:·Ensure·sudo·is·installed516 -·name:·Ensure·sudo·is·installed
518 ··package:517 ··package:
519 ····name:·sudo518 ····name:·sudo
Offset 8131, 15 lines modifiedOffset 8131, 15 lines modified
8131 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),8131 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
8132 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,8132 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,
8133 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-8133 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-
8134 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·OL07-00-8134 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·OL07-00-
8135 ············030690,·SV-221809r833067_rule8135 ············030690,·SV-221809r833067_rule
8136 Remediation_Shell_script_⇲8136 Remediation_Shell_script_⇲
8137 #·Remediation·is·applicable·only·in·certain·platforms8137 #·Remediation·is·applicable·only·in·certain·platforms
8138 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then8138 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
8139 ACTION_ARCH_FILTERS="-a·always,exit"8139 ACTION_ARCH_FILTERS="-a·always,exit"
8140 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"8140 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
8141 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"8141 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
8142 SYSCALL=""8142 SYSCALL=""
8143 KEY="privileged"8143 KEY="privileged"
8144 SYSCALL_GROUPING=""8144 SYSCALL_GROUPING=""
Offset 8600, 16 lines modifiedOffset 8600, 16 lines modified
8600 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x8600 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
8601 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged8601 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
8602 ······create:·true8602 ······create:·true
8603 ······mode:·o-rwx8603 ······mode:·o-rwx
8604 ······state:·present8604 ······state:·present
8605 ····when:·syscalls_found·|·length·==·08605 ····when:·syscalls_found·|·length·==·0
8606 ··when:8606 ··when:
8607 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8608 ··-·'"audit"·in·ansible_facts.packages'8607 ··-·'"audit"·in·ansible_facts.packages'
 8608 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8609 ··tags:8609 ··tags:
8610 ··-·DISA-STIG-OL07-00-0306908610 ··-·DISA-STIG-OL07-00-030690
8611 ··-·NIST-800-171-3.1.78611 ··-·NIST-800-171-3.1.7
8612 ··-·NIST-800-53-AC-6(9)8612 ··-·NIST-800-53-AC-6(9)
8613 ··-·NIST-800-53-AU-12(c)8613 ··-·NIST-800-53-AU-12(c)
8614 ··-·NIST-800-53-AU-2(d)8614 ··-·NIST-800-53-AU-2(d)
8615 ··-·NIST-800-53-CM-6(a)8615 ··-·NIST-800-53-CM-6(a)
Offset 9259, 20 lines modifiedOffset 9259, 14 lines modified
9259 References··A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-9259 References··A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-
9260 ············000051-GPOS-00024,·SRG-OS-000480-GPOS-002279260 ············000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
9261 Remediation_OSBuild_Blueprint_snippet_⇲9261 Remediation_OSBuild_Blueprint_snippet_⇲
  
9262 [[packages]]9262 [[packages]]
9263 name·=·"rsyslog"9263 name·=·"rsyslog"
9264 version·=·"*"9264 version·=·"*"
9265 Remediation_Anaconda_snippet_⇲ 
9266 Complexity:·low 
Max diff block lines reached; 35165/38921 bytes (90.35%) of diff not shown.
620 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_high.html
    
Offset 15244, 116 lines modifiedOffset 15244, 116 lines modified
0003b8b0:·7461·7267·6574·3d22·2369·646d·3632·3834··target="#idm62840003b8b0:·7461·7267·6574·3d22·2369·646d·3632·3834··target="#idm6284
0003b8c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b8c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b8d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b8d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b8e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b8e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b8f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b8f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b900:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b900:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b910:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b910:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b920:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni0003b920:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
0003b930:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003b930:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003b940:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b940:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003b950:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b950:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003b960:·7073·6522·2069·643d·2269·646d·3632·3834··pse"·id="idm62840003b960:·6522·2069·643d·2269·646d·3632·3834·223e··e"·id="idm6284">
0003b970:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b970:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003b980:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b980:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003b990:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b990:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003b9a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b9a0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003b9b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b9b0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003b9c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b9c0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003b9d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b9d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b9e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b9e0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003b9f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b9f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003ba00:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003ba00:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003ba10:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003ba10:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003ba20:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003ba20:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003ba30:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003ba30:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003ba40:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad0003ba40:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003ba50:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins
 0003ba60:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa
 0003ba70:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':.
 0003ba80:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 0003ba90:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 0003baa0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 0003bab0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003bac0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003bad0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003bae0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003baf0:·7267·6574·3d22·2369·646d·3632·3835·2220··rget="#idm6285"·
 0003bb00:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003bb10:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003bb20:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003bb30:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003bb40:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003bb50:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003bb60:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0003bb70:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003bb80:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003bb90:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003bba0:·643d·2269·646d·3632·3835·223e·3c74·6162··d="idm6285"><tab
 0003bbb0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003bbc0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003bbd0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003bbe0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003bbf0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003bc00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003bc10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003bc20:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003bc30:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003bc40:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003bc50:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003bc60:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003bc70:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 0003bc80:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003bc90:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003bca0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003bcb0:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d
 0003bcc0:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;
 0003bcd0:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru
 0003bce0:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·
 0003bcf0:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp
 0003bd00:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 0003bd10:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y
 0003bd20:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a
 0003bd30:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 0003bd40:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003bd50:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003bd60:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003bd70:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
0003ba50:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></0003bd80:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
0003ba60:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003bd90:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003ba70:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003bda0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003ba80:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003bdb0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003ba90:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003bdc0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003baa0:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm6280003bdd0:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628
0003bab0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·0003bde0:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
0003bac0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003bdf0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bad0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003be00:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bae0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003be10:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003baf0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003be20:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bb00:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003be30:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bb10:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip0003be40:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
0003bb20:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003be50:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bb30:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003be60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bb40:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003be70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bb50:·7365·2220·6964·3d22·6964·6d36·3238·3522··se"·id="idm6285"0003be80:·6170·7365·2220·6964·3d22·6964·6d36·3238··apse"·id="idm628
0003bb60:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003be90:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=
0003bb70:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003bea0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bb80:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003beb0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bb90:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003bec0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003bba0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003bed0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003bbb0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003bee0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bbc0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003bef0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bbd0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003bf00:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003bbe0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bf10:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003bbf0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003bf20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003bc00:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003bf30:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003bc10:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003bf40:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003bc20:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003bf50:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003bf60:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003bf70:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><
0003bc30:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003bc40:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in 
0003bc50:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p 
0003bc60:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide': 
0003bc70:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0003bc80:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0003bc90:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0003bca0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bcb0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003bcc0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003bcd0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003bce0:·6172·6765·743d·2223·6964·6d36·3238·3622··arget="#idm6286" 
0003bcf0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003bd00:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003bd10:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003bd20:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003bd30:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003bd40:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
Max diff block lines reached; 577670/592326 bytes (97.53%) of diff not shown.
41.6 KB
html2text {}
    
Offset 107, 20 lines modifiedOffset 107, 14 lines modified
107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,
108 ············OL07-00-020029,·SV-251701r833031_rule108 ············OL07-00-020029,·SV-251701r833031_rule
109 Remediation_OSBuild_Blueprint_snippet_⇲109 Remediation_OSBuild_Blueprint_snippet_⇲
  
110 [[packages]]110 [[packages]]
111 name·=·"aide"111 name·=·"aide"
112 version·=·"*"112 version·=·"*"
113 Remediation_Anaconda_snippet_⇲ 
114 Complexity:·low 
115 Disruption:·low 
116 Strategy:···enable 
  
117 package·--add=aide 
118 Remediation_Puppet_snippet_⇲113 Remediation_Puppet_snippet_⇲
119 Complexity:·low114 Complexity:·low
120 Disruption:·low115 Disruption:·low
121 Strategy:···enable116 Strategy:···enable
122 include·install_aide117 include·install_aide
  
123 class·install_aide·{118 class·install_aide·{
Offset 138, 14 lines modifiedOffset 132, 20 lines modified
138 if·!·rpm·-q·--quiet·"aide"·;·then132 if·!·rpm·-q·--quiet·"aide"·;·then
139 ····yum·install·-y·"aide"133 ····yum·install·-y·"aide"
140 fi134 fi
  
141 else135 else
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
143 fi137 fi
 138 Remediation_Anaconda_snippet_⇲
 139 Complexity:·low
 140 Disruption:·low
 141 Strategy:···enable
  
 142 package·--add=aide
144 Remediation_Ansible_snippet_⇲143 Remediation_Ansible_snippet_⇲
145 Complexity:·low144 Complexity:·low
146 Disruption:·low145 Disruption:·low
147 Strategy:···enable146 Strategy:···enable
148 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
149 ··package:148 ··package:
150 ····name:·aide149 ····name:·aide
Offset 825, 20 lines modifiedOffset 825, 14 lines modified
825 and·········00125825 and·········00125
826 References826 References
827 Remediation_OSBuild_Blueprint_snippet_⇲827 Remediation_OSBuild_Blueprint_snippet_⇲
  
828 [[packages]]828 [[packages]]
829 name·=·"sudo"829 name·=·"sudo"
830 version·=·"*"830 version·=·"*"
831 Remediation_Anaconda_snippet_⇲ 
832 Complexity:·low 
833 Disruption:·low 
834 Strategy:···enable 
  
835 package·--add=sudo 
836 Remediation_Puppet_snippet_⇲831 Remediation_Puppet_snippet_⇲
837 Complexity:·low832 Complexity:·low
838 Disruption:·low833 Disruption:·low
839 Strategy:···enable834 Strategy:···enable
840 include·install_sudo835 include·install_sudo
  
841 class·install_sudo·{836 class·install_sudo·{
Offset 856, 14 lines modifiedOffset 850, 20 lines modified
856 if·!·rpm·-q·--quiet·"sudo"·;·then850 if·!·rpm·-q·--quiet·"sudo"·;·then
857 ····yum·install·-y·"sudo"851 ····yum·install·-y·"sudo"
858 fi852 fi
  
859 else853 else
860 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'854 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
861 fi855 fi
 856 Remediation_Anaconda_snippet_⇲
 857 Complexity:·low
 858 Disruption:·low
 859 Strategy:···enable
  
 860 package·--add=sudo
862 Remediation_Ansible_snippet_⇲861 Remediation_Ansible_snippet_⇲
863 Complexity:·low862 Complexity:·low
864 Disruption:·low863 Disruption:·low
865 Strategy:···enable864 Strategy:···enable
866 -·name:·Ensure·sudo·is·installed865 -·name:·Ensure·sudo·is·installed
867 ··package:866 ··package:
868 ····name:·sudo867 ····name:·sudo
Offset 8480, 15 lines modifiedOffset 8480, 15 lines modified
8480 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),8480 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
8481 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,8481 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,
8482 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-8482 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-
8483 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·OL07-00-8483 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·OL07-00-
8484 ············030690,·SV-221809r833067_rule8484 ············030690,·SV-221809r833067_rule
8485 Remediation_Shell_script_⇲8485 Remediation_Shell_script_⇲
8486 #·Remediation·is·applicable·only·in·certain·platforms8486 #·Remediation·is·applicable·only·in·certain·platforms
8487 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then8487 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
8488 ACTION_ARCH_FILTERS="-a·always,exit"8488 ACTION_ARCH_FILTERS="-a·always,exit"
8489 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"8489 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
8490 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"8490 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
8491 SYSCALL=""8491 SYSCALL=""
8492 KEY="privileged"8492 KEY="privileged"
8493 SYSCALL_GROUPING=""8493 SYSCALL_GROUPING=""
Offset 8949, 16 lines modifiedOffset 8949, 16 lines modified
8949 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x8949 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
8950 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged8950 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
8951 ······create:·true8951 ······create:·true
8952 ······mode:·o-rwx8952 ······mode:·o-rwx
8953 ······state:·present8953 ······state:·present
8954 ····when:·syscalls_found·|·length·==·08954 ····when:·syscalls_found·|·length·==·0
8955 ··when:8955 ··when:
8956 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8957 ··-·'"audit"·in·ansible_facts.packages'8956 ··-·'"audit"·in·ansible_facts.packages'
 8957 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8958 ··tags:8958 ··tags:
8959 ··-·DISA-STIG-OL07-00-0306908959 ··-·DISA-STIG-OL07-00-030690
8960 ··-·NIST-800-171-3.1.78960 ··-·NIST-800-171-3.1.7
8961 ··-·NIST-800-53-AC-6(9)8961 ··-·NIST-800-53-AC-6(9)
8962 ··-·NIST-800-53-AU-12(c)8962 ··-·NIST-800-53-AU-12(c)
8963 ··-·NIST-800-53-AU-2(d)8963 ··-·NIST-800-53-AU-2(d)
8964 ··-·NIST-800-53-CM-6(a)8964 ··-·NIST-800-53-CM-6(a)
Offset 9723, 20 lines modifiedOffset 9723, 14 lines modified
9723 References··A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-9723 References··A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-
9724 ············000051-GPOS-00024,·SRG-OS-000480-GPOS-002279724 ············000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
9725 Remediation_OSBuild_Blueprint_snippet_⇲9725 Remediation_OSBuild_Blueprint_snippet_⇲
  
9726 [[packages]]9726 [[packages]]
9727 name·=·"rsyslog"9727 name·=·"rsyslog"
9728 version·=·"*"9728 version·=·"*"
9729 Remediation_Anaconda_snippet_⇲ 
9730 Complexity:·low 
Max diff block lines reached; 38786/42542 bytes (91.17%) of diff not shown.
564 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_intermediary.html
    
Offset 15238, 116 lines modifiedOffset 15238, 116 lines modified
0003b850:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b850:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b860:·646d·3632·3834·2220·7461·6269·6e64·6578··dm6284"·tabindex0003b860:·646d·3632·3834·2220·7461·6269·6e64·6578··dm6284"·tabindex
0003b870:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b870:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b880:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b880:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b890:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b890:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b8a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b8a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b8b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b8b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b8c0:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon0003b8c0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet
0003b8d0:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</0003b8d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003b8e0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b8e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b8f0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b8f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b900:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b900:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b910:·646d·3632·3834·223e·3c74·6162·6c65·2063··dm6284"><table·c0003b910:·3632·3834·223e·3c74·6162·6c65·2063·6c61··6284"><table·cla
0003b920:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b920:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003b930:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b930:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003b940:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b940:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003b950:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b950:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003b960:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b960:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003b970:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b970:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003b980:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b980:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003b990:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b990:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003b9a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b9a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b9b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003b9b0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003b9c0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003b9c0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003b9d0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003b9d0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
0003b9e0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
0003b9f0:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c0003b9e0:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i
 0003b9f0:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla
 0003ba00:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide·
 0003ba10:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a
 0003ba20:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure
 0003ba30:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe
 0003ba40:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
 0003ba50:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003ba60:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003ba70:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003ba80:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003ba90:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003baa0:·3632·3835·2220·7461·6269·6e64·6578·3d22··6285"·tabindex="
 0003bab0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003bac0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003bad0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003bae0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003baf0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003bb00:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 0003bb10:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003bb20:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003bb30:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003bb40:·7073·6522·2069·643d·2269·646d·3632·3835··pse"·id="idm6285
 0003bb50:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003bb60:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003bb70:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003bb80:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003bb90:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003bba0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003bbb0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003bbc0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003bbd0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003bbe0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003bbf0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003bc00:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003bc10:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003bc20:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003bc30:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003bc40:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003bc50:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
 0003bc60:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
 0003bc70:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
 0003bc80:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
 0003bc90:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i
 0003bca0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 0003bcb0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then
 0003bcc0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install
 0003bcd0:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e
 0003bce0:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp
 0003bcf0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia
 0003bd00:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl
 0003bd10:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·
 0003bd20:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c
0003ba00:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003bd30:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003ba10:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003bd40:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003ba20:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003bd50:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003ba30:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003bd60:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003ba40:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bd70:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003ba50:·6964·6d36·3238·3522·2074·6162·696e·6465··idm6285"·tabinde0003bd80:·6964·6d36·3238·3622·2074·6162·696e·6465··idm6286"·tabinde
0003ba60:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bd90:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003ba70:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bda0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003ba80:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bdb0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003ba90:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bdc0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003baa0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bdd0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003bab0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe0003bde0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco
0003bac0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a0003bdf0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<
0003bad0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003be00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003bae0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003be10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003baf0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003be20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003bb00:·6d36·3238·3522·3e3c·7461·626c·6520·636c··m6285"><table·cl0003be30:·6964·6d36·3238·3622·3e3c·7461·626c·6520··idm6286"><table·
0003bb10:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003be40:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003bb20:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003be50:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003bb30:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003be60:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003bb40:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003be70:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003bb50:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003be80:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003bb60:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003be90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003bb70:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003bea0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003bb80:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003beb0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003bb90:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003bec0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bba0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003bed0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003bbb0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003bee0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003bbc0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003bef0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003bf00:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003bf10:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</
0003bbd0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
0003bbe0:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl 
0003bbf0:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide 
0003bc00:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
0003bc10:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur 
0003bc20:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
0003bc30:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
0003bc40:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003bc50:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bc60:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003bc70:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003bc80:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003bc90:·6d36·3238·3622·2074·6162·696e·6465·783d··m6286"·tabindex= 
0003bca0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bcb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bcc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bcd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
Max diff block lines reached; 523401/538057 bytes (97.28%) of diff not shown.
38.0 KB
html2text {}
    
Offset 106, 20 lines modifiedOffset 106, 14 lines modified
106 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,106 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,
107 ············OL07-00-020029,·SV-251701r833031_rule107 ············OL07-00-020029,·SV-251701r833031_rule
108 Remediation_OSBuild_Blueprint_snippet_⇲108 Remediation_OSBuild_Blueprint_snippet_⇲
  
109 [[packages]]109 [[packages]]
110 name·=·"aide"110 name·=·"aide"
111 version·=·"*"111 version·=·"*"
112 Remediation_Anaconda_snippet_⇲ 
113 Complexity:·low 
114 Disruption:·low 
115 Strategy:···enable 
  
116 package·--add=aide 
117 Remediation_Puppet_snippet_⇲112 Remediation_Puppet_snippet_⇲
118 Complexity:·low113 Complexity:·low
119 Disruption:·low114 Disruption:·low
120 Strategy:···enable115 Strategy:···enable
121 include·install_aide116 include·install_aide
  
122 class·install_aide·{117 class·install_aide·{
Offset 137, 14 lines modifiedOffset 131, 20 lines modified
137 if·!·rpm·-q·--quiet·"aide"·;·then131 if·!·rpm·-q·--quiet·"aide"·;·then
138 ····yum·install·-y·"aide"132 ····yum·install·-y·"aide"
139 fi133 fi
  
140 else134 else
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
142 fi136 fi
 137 Remediation_Anaconda_snippet_⇲
 138 Complexity:·low
 139 Disruption:·low
 140 Strategy:···enable
  
 141 package·--add=aide
143 Remediation_Ansible_snippet_⇲142 Remediation_Ansible_snippet_⇲
144 Complexity:·low143 Complexity:·low
145 Disruption:·low144 Disruption:·low
146 Strategy:···enable145 Strategy:···enable
147 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
148 ··package:147 ··package:
149 ····name:·aide148 ····name:·aide
Offset 475, 20 lines modifiedOffset 475, 14 lines modified
475 and·········00125475 and·········00125
476 References476 References
477 Remediation_OSBuild_Blueprint_snippet_⇲477 Remediation_OSBuild_Blueprint_snippet_⇲
  
478 [[packages]]478 [[packages]]
479 name·=·"sudo"479 name·=·"sudo"
480 version·=·"*"480 version·=·"*"
481 Remediation_Anaconda_snippet_⇲ 
482 Complexity:·low 
483 Disruption:·low 
484 Strategy:···enable 
  
485 package·--add=sudo 
486 Remediation_Puppet_snippet_⇲481 Remediation_Puppet_snippet_⇲
487 Complexity:·low482 Complexity:·low
488 Disruption:·low483 Disruption:·low
489 Strategy:···enable484 Strategy:···enable
490 include·install_sudo485 include·install_sudo
  
491 class·install_sudo·{486 class·install_sudo·{
Offset 506, 14 lines modifiedOffset 500, 20 lines modified
506 if·!·rpm·-q·--quiet·"sudo"·;·then500 if·!·rpm·-q·--quiet·"sudo"·;·then
507 ····yum·install·-y·"sudo"501 ····yum·install·-y·"sudo"
508 fi502 fi
  
509 else503 else
510 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'504 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
511 fi505 fi
 506 Remediation_Anaconda_snippet_⇲
 507 Complexity:·low
 508 Disruption:·low
 509 Strategy:···enable
  
 510 package·--add=sudo
512 Remediation_Ansible_snippet_⇲511 Remediation_Ansible_snippet_⇲
513 Complexity:·low512 Complexity:·low
514 Disruption:·low513 Disruption:·low
515 Strategy:···enable514 Strategy:···enable
516 -·name:·Ensure·sudo·is·installed515 -·name:·Ensure·sudo·is·installed
517 ··package:516 ··package:
518 ····name:·sudo517 ····name:·sudo
Offset 7689, 15 lines modifiedOffset 7689, 15 lines modified
7689 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),7689 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
7690 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,7690 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,
7691 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-7691 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-
7692 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·OL07-00-7692 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·OL07-00-
7693 ············030690,·SV-221809r833067_rule7693 ············030690,·SV-221809r833067_rule
7694 Remediation_Shell_script_⇲7694 Remediation_Shell_script_⇲
7695 #·Remediation·is·applicable·only·in·certain·platforms7695 #·Remediation·is·applicable·only·in·certain·platforms
7696 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then7696 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
7697 ACTION_ARCH_FILTERS="-a·always,exit"7697 ACTION_ARCH_FILTERS="-a·always,exit"
7698 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"7698 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
7699 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"7699 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
7700 SYSCALL=""7700 SYSCALL=""
7701 KEY="privileged"7701 KEY="privileged"
7702 SYSCALL_GROUPING=""7702 SYSCALL_GROUPING=""
Offset 8158, 16 lines modifiedOffset 8158, 16 lines modified
8158 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x8158 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
8159 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged8159 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
8160 ······create:·true8160 ······create:·true
8161 ······mode:·o-rwx8161 ······mode:·o-rwx
8162 ······state:·present8162 ······state:·present
8163 ····when:·syscalls_found·|·length·==·08163 ····when:·syscalls_found·|·length·==·0
8164 ··when:8164 ··when:
8165 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8166 ··-·'"audit"·in·ansible_facts.packages'8165 ··-·'"audit"·in·ansible_facts.packages'
 8166 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8167 ··tags:8167 ··tags:
8168 ··-·DISA-STIG-OL07-00-0306908168 ··-·DISA-STIG-OL07-00-030690
8169 ··-·NIST-800-171-3.1.78169 ··-·NIST-800-171-3.1.7
8170 ··-·NIST-800-53-AC-6(9)8170 ··-·NIST-800-53-AC-6(9)
8171 ··-·NIST-800-53-AU-12(c)8171 ··-·NIST-800-53-AU-12(c)
8172 ··-·NIST-800-53-AU-2(d)8172 ··-·NIST-800-53-AU-2(d)
8173 ··-·NIST-800-53-CM-6(a)8173 ··-·NIST-800-53-CM-6(a)
Offset 8748, 20 lines modifiedOffset 8748, 14 lines modified
8748 References··A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-8748 References··A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-
8749 ············000051-GPOS-00024,·SRG-OS-000480-GPOS-002278749 ············000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
8750 Remediation_OSBuild_Blueprint_snippet_⇲8750 Remediation_OSBuild_Blueprint_snippet_⇲
  
8751 [[packages]]8751 [[packages]]
8752 name·=·"rsyslog"8752 name·=·"rsyslog"
8753 version·=·"*"8753 version·=·"*"
8754 Remediation_Anaconda_snippet_⇲ 
8755 Complexity:·low 
Max diff block lines reached; 35165/38921 bytes (90.35%) of diff not shown.
230 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_minimal.html
    
Offset 39762, 117 lines modifiedOffset 39762, 117 lines modified
0009b510:·2d74·6172·6765·743d·2223·6964·6d33·3730··-target="#idm3700009b510:·2d74·6172·6765·743d·2223·6964·6d33·3730··-target="#idm370
0009b520:·3039·2220·7461·6269·6e64·6578·3d22·3022··09"·tabindex="0"0009b520:·3039·2220·7461·6269·6e64·6578·3d22·3022··09"·tabindex="0"
0009b530:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0009b530:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0009b540:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0009b540:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0009b550:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0009b550:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0009b560:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0009b560:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0009b570:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0009b570:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0009b580:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0009b580:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0009b590:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0009b590:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0009b5a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0009b5a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0009b5b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0009b5b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0009b5c0:·6c61·7073·6522·2069·643d·2269·646d·3337··lapse"·id="idm370009b5c0:·7073·6522·2069·643d·2269·646d·3337·3030··pse"·id="idm3700
0009b5d0:·3030·3922·3e3c·7461·626c·6520·636c·6173··009"><table·clas0009b5d0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=
0009b5e0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0009b5e0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0009b5f0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0009b5f0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0009b600:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0009b600:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0009b610:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0009b610:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0009b620:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0009b620:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0009b630:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0009b630:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0009b640:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0009b640:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0009b650:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0009b650:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0009b660:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0009b660:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0009b670:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0009b670:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0009b680:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0009b680:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0009b690:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0009b690:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0009b6a0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0009b6b0:·2d61·6464·3d72·7379·736c·6f67·0a3c·2f63··-add=rsyslog.</c0009b6a0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0009b6b0:·616c·6c5f·7273·7973·6c6f·670a·0a63·6c61··all_rsyslog..cla
 0009b6c0:·7373·2069·6e73·7461·6c6c·5f72·7379·736c··ss·install_rsysl
 0009b6d0:·6f67·207b·0a20·2070·6163·6b61·6765·207b··og·{.··package·{
 0009b6e0:·2027·7273·7973·6c6f·6727·3a0a·2020·2020···'rsyslog':.····
 0009b6f0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 0009b700:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 0009b710:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0009b720:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0009b730:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0009b740:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0009b750:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0009b760:·3d22·2369·646d·3337·3031·3022·2074·6162··="#idm37010"·tab
 0009b770:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0009b780:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0009b790:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0009b7a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0009b7b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0009b7c0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 0009b7d0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0009b7e0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0009b7f0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0009b800:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0009b810:·6964·6d33·3730·3130·223e·3c74·6162·6c65··idm37010"><table
 0009b820:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0009b830:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0009b840:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0009b850:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0009b860:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0009b870:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0009b880:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0009b890:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0009b8a0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0009b8b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0009b8c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0009b8d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0009b8e0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0009b8f0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0009b900:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0009b910:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0009b920:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0009b930:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0009b940:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0009b950:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0009b960:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0009b970:·2d71·202d·2d71·7569·6574·2022·7273·7973··-q·--quiet·"rsys
 0009b980:·6c6f·6722·203b·2074·6865·6e0a·2020·2020··log"·;·then.····
 0009b990:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0009b9a0:·7273·7973·6c6f·6722·0a66·690a·0a65·6c73··rsyslog".fi..els
 0009b9b0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0009b9c0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0009b9d0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0009b9e0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0009b9f0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
0009b6c0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0009ba00:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0009b6d0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0009ba10:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0009b6e0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0009ba20:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0009b6f0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0009ba30:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0009b700:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0009ba40:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0009b710:·6964·6d33·3730·3130·2220·7461·6269·6e64··idm37010"·tabind0009ba50:·6d33·3730·3131·2220·7461·6269·6e64·6578··m37011"·tabindex
0009b720:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0009ba60:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0009b730:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0009ba70:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0009b740:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0009ba80:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0009b750:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0009ba90:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0009b760:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0009baa0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0009b770:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0009bab0:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0009b780:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0009bac0:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0009b790:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0009bad0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0009b7a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0009bae0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0009b7b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0009baf0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0009b7c0:·646d·3337·3031·3022·3e3c·7461·626c·6520··dm37010"><table·0009bb00:·646d·3337·3031·3122·3e3c·7461·626c·6520··dm37011"><table·
0009b7d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0009bb10:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0009b7e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0009bb20:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0009b7f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0009bb30:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0009b800:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0009bb40:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0009b810:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0009bb50:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0009b820:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0009bb60:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0009b830:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0009bb70:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0009b840:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0009bb80:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0009b850:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0009bb90:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0009b860:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0009bba0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0009b870:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0009bbb0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0009b880:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0009bbc0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0009b890:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ0009bbd0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0009bbe0:·6765·202d·2d61·6464·3d72·7379·736c·6f67··ge·--add=rsyslog
0009b8a0:·6520·696e·7374·616c·6c5f·7273·7973·6c6f··e·install_rsyslo 
0009b8b0:·670a·0a63·6c61·7373·2069·6e73·7461·6c6c··g..class·install 
0009b8c0:·5f72·7379·736c·6f67·207b·0a20·2070·6163··_rsyslog·{.··pac 
0009b8d0:·6b61·6765·207b·2027·7273·7973·6c6f·6727··kage·{·'rsyslog' 
0009b8e0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0009b8f0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0009b900:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0009b910:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0009b920:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0009b930:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0009b940:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0009b950:·7461·7267·6574·3d22·2369·646d·3337·3031··target="#idm3701 
0009b960:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
0009b970:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0009b980:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0009b990:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
Max diff block lines reached; 203914/218708 bytes (93.24%) of diff not shown.
16.4 KB
html2text {}
    
Offset 6496, 20 lines modifiedOffset 6496, 14 lines modified
6496 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-6496 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
6497 ············002276497 ············00227
6498 Remediation_OSBuild_Blueprint_snippet_⇲6498 Remediation_OSBuild_Blueprint_snippet_⇲
  
6499 [[packages]]6499 [[packages]]
6500 name·=·"rsyslog"6500 name·=·"rsyslog"
6501 version·=·"*"6501 version·=·"*"
6502 Remediation_Anaconda_snippet_⇲ 
6503 Complexity:·low 
6504 Disruption:·low 
6505 Strategy:···enable 
  
6506 package·--add=rsyslog 
6507 Remediation_Puppet_snippet_⇲6502 Remediation_Puppet_snippet_⇲
6508 Complexity:·low6503 Complexity:·low
6509 Disruption:·low6504 Disruption:·low
6510 Strategy:···enable6505 Strategy:···enable
6511 include·install_rsyslog6506 include·install_rsyslog
  
6512 class·install_rsyslog·{6507 class·install_rsyslog·{
Offset 6527, 14 lines modifiedOffset 6521, 20 lines modified
6527 if·!·rpm·-q·--quiet·"rsyslog"·;·then6521 if·!·rpm·-q·--quiet·"rsyslog"·;·then
6528 ····yum·install·-y·"rsyslog"6522 ····yum·install·-y·"rsyslog"
6529 fi6523 fi
  
6530 else6524 else
6531 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6525 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6532 fi6526 fi
 6527 Remediation_Anaconda_snippet_⇲
 6528 Complexity:·low
 6529 Disruption:·low
 6530 Strategy:···enable
  
 6531 package·--add=rsyslog
6533 Remediation_Ansible_snippet_⇲6532 Remediation_Ansible_snippet_⇲
6534 Complexity:·low6533 Complexity:·low
6535 Disruption:·low6534 Disruption:·low
6536 Strategy:···enable6535 Strategy:···enable
6537 -·name:·Ensure·rsyslog·is·installed6536 -·name:·Ensure·rsyslog·is·installed
6538 ··package:6537 ··package:
6539 ····name:·rsyslog6538 ····name:·rsyslog
Offset 6717, 20 lines modifiedOffset 6717, 14 lines modified
6717 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,6717 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,
6718 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,6718 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
6719 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,6719 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
6720 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR6720 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
6721 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR6721 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
6722 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,6722 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
6723 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-36723 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3
6724 Remediation_Anaconda_snippet_⇲ 
6725 Complexity:·low 
6726 Disruption:·low 
6727 Strategy:···disable 
  
6728 package·--remove=dhcp 
6729 Remediation_Puppet_snippet_⇲6724 Remediation_Puppet_snippet_⇲
6730 Complexity:·low6725 Complexity:·low
6731 Disruption:·low6726 Disruption:·low
6732 Strategy:···disable6727 Strategy:···disable
6733 include·remove_dhcp6728 include·remove_dhcp
  
6734 class·remove_dhcp·{6729 class·remove_dhcp·{
Offset 6750, 14 lines modifiedOffset 6744, 20 lines modified
6750 #»      ···system!6744 #»      ···system!
  
6751 if·rpm·-q·--quiet·"dhcp"·;·then6745 if·rpm·-q·--quiet·"dhcp"·;·then
  
6752 ····yum·remove·-y·"dhcp"6746 ····yum·remove·-y·"dhcp"
  
6753 fi6747 fi
 6748 Remediation_Anaconda_snippet_⇲
 6749 Complexity:·low
 6750 Disruption:·low
 6751 Strategy:···disable
  
 6752 package·--remove=dhcp
6754 Remediation_Ansible_snippet_⇲6753 Remediation_Ansible_snippet_⇲
6755 Complexity:·low6754 Complexity:·low
6756 Disruption:·low6755 Disruption:·low
6757 Strategy:···disable6756 Strategy:···disable
6758 -·name:·Ensure·dhcp·is·removed6757 -·name:·Ensure·dhcp·is·removed
6759 ··package:6758 ··package:
6760 ····name:·dhcp6759 ····name:·dhcp
Offset 6804, 20 lines modifiedOffset 6804, 14 lines modified
6804 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,6804 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
6805 Identifiers·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,6805 Identifiers·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
6806 and·········4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR6806 and·········4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
6807 References··1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR6807 References··1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
6808 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,6808 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
6809 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,·SRG-OS-000480-GPOS-00227,·SRG-OS-6809 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,·SRG-OS-000480-GPOS-00227,·SRG-OS-
6810 ············000095-GPOS-000496810 ············000095-GPOS-00049
6811 Remediation_Anaconda_snippet_⇲ 
6812 Complexity:·low 
6813 Disruption:·low 
6814 Strategy:···disable 
  
6815 package·--remove=sendmail 
6816 Remediation_Puppet_snippet_⇲6811 Remediation_Puppet_snippet_⇲
6817 Complexity:·low6812 Complexity:·low
6818 Disruption:·low6813 Disruption:·low
6819 Strategy:···disable6814 Strategy:···disable
6820 include·remove_sendmail6815 include·remove_sendmail
  
6821 class·remove_sendmail·{6816 class·remove_sendmail·{
Offset 6843, 14 lines modifiedOffset 6837, 20 lines modified
6843 ····yum·remove·-y·"sendmail"6837 ····yum·remove·-y·"sendmail"
  
6844 fi6838 fi
  
6845 else6839 else
6846 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6840 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6847 fi6841 fi
 6842 Remediation_Anaconda_snippet_⇲
 6843 Complexity:·low
 6844 Disruption:·low
 6845 Strategy:···disable
  
 6846 package·--remove=sendmail
6848 Remediation_Ansible_snippet_⇲6847 Remediation_Ansible_snippet_⇲
6849 Complexity:·low6848 Complexity:·low
6850 Disruption:·low6849 Disruption:·low
6851 Strategy:···disable6850 Strategy:···disable
6852 -·name:·Ensure·sendmail·is·removed6851 -·name:·Ensure·sendmail·is·removed
6853 ··package:6852 ··package:
6854 ····name:·sendmail6853 ····name:·sendmail
Offset 6896, 20 lines modifiedOffset 6896, 14 lines modified
6896 Identifiers·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,6896 Identifiers·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,
Max diff block lines reached; 12974/16719 bytes (77.60%) of diff not shown.
609 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-cjis.html
    
Offset 17078, 116 lines modifiedOffset 17078, 116 lines modified
00042b50:·6574·3d22·2369·646d·3632·3834·2220·7461··et="#idm6284"·ta00042b50:·6574·3d22·2369·646d·3632·3834·2220·7461··et="#idm6284"·ta
00042b60:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00042b60:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00042b70:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00042b70:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00042b80:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00042b80:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00042b90:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00042b90:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00042ba0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00042ba0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00042bb0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00042bb0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00042bc0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet00042bc0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
00042bd0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div00042bd0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00042be0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00042be0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00042bf0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00042bf0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00042c00:·2069·643d·2269·646d·3632·3834·223e·3c74···id="idm6284"><t00042c00:·643d·2269·646d·3632·3834·223e·3c74·6162··d="idm6284"><tab
00042c10:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00042c10:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00042c20:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00042c20:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00042c30:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00042c30:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00042c40:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00042c40:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00042c50:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00042c50:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00042c60:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<00042c60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00042c70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00042c70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00042c80:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th00042c80:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00042c90:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t00042c90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00042ca0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate00042ca0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
00042cb0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab00042cb0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
00042cc0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta00042cc0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
00042cd0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.00042cd0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
00042ce0:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai00042ce0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 00042cf0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 00042d00:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 00042d10:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 00042d20:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 00042d30:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 00042d40:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 00042d50:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 00042d60:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00042d70:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00042d80:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00042d90:·3d22·2369·646d·3632·3835·2220·7461·6269··="#idm6285"·tabi
 00042da0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 00042db0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 00042dc0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 00042dd0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 00042de0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 00042df0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 00042e00:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 00042e10:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00042e20:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00042e30:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00042e40:·646d·3632·3835·223e·3c74·6162·6c65·2063··dm6285"><table·c
 00042e50:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 00042e60:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 00042e70:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 00042e80:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 00042e90:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 00042ea0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00042eb0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 00042ec0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 00042ed0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00042ee0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00042ef0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 00042f00:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00042f10:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 00042f20:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 00042f30:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 00042f40:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 00042f50:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
 00042f60:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
 00042f70:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
 00042f80:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t
 00042f90:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 00042fa0:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"·
 00042fb0:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 00042fc0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 00042fd0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 00042fe0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 00042ff0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 00043000:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 00043010:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
00042cf0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>00043020:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
00042d00:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="00043030:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
00042d10:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"00043040:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
00042d20:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co00043050:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
00042d30:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar00043060:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
00042d40:·6765·743d·2223·6964·6d36·3238·3522·2074··get="#idm6285"·t00043070:·6765·743d·2223·6964·6d36·3238·3622·2074··get="#idm6286"·t
00042d50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00043080:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00042d60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00043090:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00042d70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·000430a0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00042d80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·000430b0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00042d90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=000430c0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00042da0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation000430d0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00042db0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·000430e0:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
00042dc0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·000430f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
00042dd0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col00043100:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00042de0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·00043110:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
00042df0:·6964·3d22·6964·6d36·3238·3522·3e3c·7461··id="idm6285"><ta00043120:·2220·6964·3d22·6964·6d36·3238·3622·3e3c··"·id="idm6286"><
00042e00:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table00043130:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
00042e10:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t00043140:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
00042e20:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta00043150:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
00042e30:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><00043160:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
00042e40:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit00043170:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
00042e50:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</00043180:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00042e60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00043190:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00042e70:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>000431a0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
00042e80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr000431b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
00042e90:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg000431c0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
00042ea0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl000431d0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
00042eb0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab000431e0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
00042ec0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in000431f0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00043200:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a
00042ed0:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai 
00042ee0:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal 
00042ef0:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa 
00042f00:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.··· 
00042f10:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
00042f20:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
00042f30:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
00042f40:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
00042f50:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
00042f60:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
00042f70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00042f80:·743d·2223·6964·6d36·3238·3622·2074·6162··t="#idm6286"·tab 
00042f90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
00042fa0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
00042fb0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
00042fc0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
00042fd0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
00042fe0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
00042ff0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
Max diff block lines reached; 414075/428731 bytes (96.58%) of diff not shown.
190 KB
html2text {}
    
Offset 387, 20 lines modifiedOffset 387, 14 lines modified
387 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed387 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
388 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule388 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule
389 Remediation_OSBuild_Blueprint_snippet_⇲389 Remediation_OSBuild_Blueprint_snippet_⇲
  
390 [[packages]]390 [[packages]]
391 name·=·"aide"391 name·=·"aide"
392 version·=·"*"392 version·=·"*"
393 Remediation_Anaconda_snippet_⇲ 
394 Complexity:·low 
395 Disruption:·low 
396 Strategy:···enable 
  
397 package·--add=aide 
398 Remediation_Puppet_snippet_⇲393 Remediation_Puppet_snippet_⇲
399 Complexity:·low394 Complexity:·low
400 Disruption:·low395 Disruption:·low
401 Strategy:···enable396 Strategy:···enable
402 include·install_aide397 include·install_aide
  
403 class·install_aide·{398 class·install_aide·{
Offset 418, 14 lines modifiedOffset 412, 20 lines modified
418 if·!·rpm·-q·--quiet·"aide"·;·then412 if·!·rpm·-q·--quiet·"aide"·;·then
419 ····yum·install·-y·"aide"413 ····yum·install·-y·"aide"
420 fi414 fi
  
421 else415 else
422 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'416 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
423 fi417 fi
 418 Remediation_Anaconda_snippet_⇲
 419 Complexity:·low
 420 Disruption:·low
 421 Strategy:···enable
  
 422 package·--add=aide
424 Remediation_Ansible_snippet_⇲423 Remediation_Ansible_snippet_⇲
425 Complexity:·low424 Complexity:·low
426 Disruption:·low425 Disruption:·low
427 Strategy:···enable426 Strategy:···enable
428 -·name:·Ensure·aide·is·installed427 -·name:·Ensure·aide·is·installed
429 ··package:428 ··package:
430 ····name:·aide429 ····name:·aide
Offset 3726, 15 lines modifiedOffset 3726, 15 lines modified
3726 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.3726 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
3727 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.3727 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
3728 Severity: ················medium3728 Severity: ················medium
3729 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod3729 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
3730 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule3730 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule
3731 Remediation_Shell_script_⇲3731 Remediation_Shell_script_⇲
3732 #·Remediation·is·applicable·only·in·certain·platforms3732 #·Remediation·is·applicable·only·in·certain·platforms
3733 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then3733 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
3734 #·First·perform·the·remediation·of·the·syscall·rule3734 #·First·perform·the·remediation·of·the·syscall·rule
3735 #·Retrieve·hardware·architecture·of·the·underlying·system3735 #·Retrieve·hardware·architecture·of·the·underlying·system
3736 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3736 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3737 for·ARCH·in·"${RULE_ARCHS[@]}"3737 for·ARCH·in·"${RULE_ARCHS[@]}"
3738 do3738 do
Offset 4081, 16 lines modifiedOffset 4081, 16 lines modified
4081 ··-·reboot_required4081 ··-·reboot_required
4082 ··-·restrict_strategy4082 ··-·restrict_strategy
  
4083 -·name:·Set·architecture·for·audit·chmod·tasks4083 -·name:·Set·architecture·for·audit·chmod·tasks
4084 ··set_fact:4084 ··set_fact:
4085 ····audit_arch:·b644085 ····audit_arch:·b64
4086 ··when:4086 ··when:
4087 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4088 ··-·'"audit"·in·ansible_facts.packages'4087 ··-·'"audit"·in·ansible_facts.packages'
 4088 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4089 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4089 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4090 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4090 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4091 ··tags:4091 ··tags:
4092 ··-·CJIS-5.4.1.14092 ··-·CJIS-5.4.1.1
4093 ··-·DISA-STIG-OL07-00-0304104093 ··-·DISA-STIG-OL07-00-030410
4094 ··-·NIST-800-171-3.1.74094 ··-·NIST-800-171-3.1.7
4095 ··-·NIST-800-53-AU-12(c)4095 ··-·NIST-800-53-AU-12(c)
Offset 4227, 16 lines modifiedOffset 4227, 16 lines modified
4227 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004227 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4228 ········-F·auid!=unset·-F·key=perm_mod4228 ········-F·auid!=unset·-F·key=perm_mod
4229 ······create:·true4229 ······create:·true
4230 ······mode:·o-rwx4230 ······mode:·o-rwx
4231 ······state:·present4231 ······state:·present
4232 ····when:·syscalls_found·|·length·==·04232 ····when:·syscalls_found·|·length·==·0
4233 ··when:4233 ··when:
4234 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4235 ··-·'"audit"·in·ansible_facts.packages'4234 ··-·'"audit"·in·ansible_facts.packages'
 4235 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4236 ··tags:4236 ··tags:
4237 ··-·CJIS-5.4.1.14237 ··-·CJIS-5.4.1.1
4238 ··-·DISA-STIG-OL07-00-0304104238 ··-·DISA-STIG-OL07-00-030410
4239 ··-·NIST-800-171-3.1.74239 ··-·NIST-800-171-3.1.7
4240 ··-·NIST-800-53-AU-12(c)4240 ··-·NIST-800-53-AU-12(c)
4241 ··-·NIST-800-53-AU-2(d)4241 ··-·NIST-800-53-AU-2(d)
4242 ··-·NIST-800-53-CM-6(a)4242 ··-·NIST-800-53-CM-6(a)
Offset 4371, 16 lines modifiedOffset 4371, 16 lines modified
4371 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004371 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4372 ········-F·auid!=unset·-F·key=perm_mod4372 ········-F·auid!=unset·-F·key=perm_mod
4373 ······create:·true4373 ······create:·true
4374 ······mode:·o-rwx4374 ······mode:·o-rwx
4375 ······state:·present4375 ······state:·present
4376 ····when:·syscalls_found·|·length·==·04376 ····when:·syscalls_found·|·length·==·0
4377 ··when:4377 ··when:
4378 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4379 ··-·'"audit"·in·ansible_facts.packages'4378 ··-·'"audit"·in·ansible_facts.packages'
 4379 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4380 ··-·audit_arch·==·"b64"4380 ··-·audit_arch·==·"b64"
4381 ··tags:4381 ··tags:
4382 ··-·CJIS-5.4.1.14382 ··-·CJIS-5.4.1.1
4383 ··-·DISA-STIG-OL07-00-0304104383 ··-·DISA-STIG-OL07-00-030410
4384 ··-·NIST-800-171-3.1.74384 ··-·NIST-800-171-3.1.7
4385 ··-·NIST-800-53-AU-12(c)4385 ··-·NIST-800-53-AU-12(c)
4386 ··-·NIST-800-53-AU-2(d)4386 ··-·NIST-800-53-AU-2(d)
Offset 4404, 15 lines modifiedOffset 4404, 15 lines modified
4404 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.4404 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
4405 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.4405 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
4406 Severity: ················medium4406 Severity: ················medium
4407 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown4407 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
4408 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030370,·SV-221778r810481_rule4408 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030370,·SV-221778r810481_rule
4409 Remediation_Shell_script_⇲4409 Remediation_Shell_script_⇲
4410 #·Remediation·is·applicable·only·in·certain·platforms4410 #·Remediation·is·applicable·only·in·certain·platforms
4411 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then4411 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
4412 #·First·perform·the·remediation·of·the·syscall·rule4412 #·First·perform·the·remediation·of·the·syscall·rule
4413 #·Retrieve·hardware·architecture·of·the·underlying·system4413 #·Retrieve·hardware·architecture·of·the·underlying·system
4414 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4414 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4415 for·ARCH·in·"${RULE_ARCHS[@]}"4415 for·ARCH·in·"${RULE_ARCHS[@]}"
4416 do4416 do
Max diff block lines reached; 185786/194840 bytes (95.35%) of diff not shown.
284 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-cui.html
    
Offset 15200, 57 lines modifiedOffset 15200, 57 lines modified
0003b5f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b5f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b600:·3d22·2369·646d·3638·3130·2220·7461·6269··="#idm6810"·tabi0003b600:·3d22·2369·646d·3638·3130·2220·7461·6269··="#idm6810"·tabi
0003b610:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b610:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b620:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b620:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b630:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b630:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b640:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b640:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b650:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b650:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b660:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b660:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
0003b670:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0003b680:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b690:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b6a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b6b0:·643d·2269·646d·3638·3130·223e·3c70·7265··d="idm6810"><pre 
0003b6c0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003b6d0:·2d2d·6164·643d·6472·6163·7574·2d66·6970··--add=dracut-fip 
0003b6e0:·730a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··s.</code></pre>< 
0003b6f0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b700:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b710:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b720:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b730:·6574·3d22·2369·646d·3638·3131·2220·7461··et="#idm6811"·ta 
0003b740:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b750:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b760:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b770:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b780:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b790:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b7a0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...0003b670:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
0003b7b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b680:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b7c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b690:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b7d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b6a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b7e0:·2269·646d·3638·3131·223e·3c70·7265·3e3c··"idm6811"><pre><0003b6b0:·646d·3638·3130·223e·3c70·7265·3e3c·636f··dm6810"><pre><co
0003b7f0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati0003b6c0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
0003b800:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable0003b6d0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
0003b810:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain0003b6e0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
0003b820:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·0003b6f0:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
0003b830:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv0003b700:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
0003b840:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·0003b710:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
0003b850:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta0003b720:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
0003b860:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.0003b730:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i
0003b870:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q0003b740:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
0003b880:·7569·6574·2022·6472·6163·7574·2d66·6970··uiet·"dracut-fip0003b750:·6574·2022·6472·6163·7574·2d66·6970·7322··et·"dracut-fips"
0003b890:·7322·203b·2074·6865·6e0a·2020·2020·7975··s"·;·then.····yu0003b760:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
0003b8a0:·6d20·696e·7374·616c·6c20·2d79·2022·6472··m·install·-y·"dr0003b770:·696e·7374·616c·6c20·2d79·2022·6472·6163··install·-y·"drac
0003b8b0:·6163·7574·2d66·6970·7322·0a66·690a·0a65··acut-fips".fi..e0003b780:·7574·2d66·6970·7322·0a66·690a·0a65·6c73··ut-fips".fi..els
0003b8c0:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp0003b790:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
0003b8d0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia0003b7a0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
0003b8e0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl0003b7b0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
0003b8f0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·0003b7c0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
0003b900:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c0003b7d0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003b7e0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b7f0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b800:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b810:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b820:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b830:·6d36·3831·3122·2074·6162·696e·6465·783d··m6811"·tabindex=
 0003b840:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b850:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b860:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b870:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b880:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b890:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
 0003b8a0:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
 0003b8b0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b8c0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b8d0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b8e0:·6d36·3831·3122·3e3c·7072·653e·3c63·6f64··m6811"><pre><cod
 0003b8f0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
 0003b900:·3d64·7261·6375·742d·6669·7073·0a3c·2f63··=dracut-fips.</c
0003b910:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003b910:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003b920:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003b920:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003b930:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003b930:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003b940:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003b940:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003b950:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b950:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b960:·6964·6d36·3831·3222·2074·6162·696e·6465··idm6812"·tabinde0003b960:·6964·6d36·3831·3222·2074·6162·696e·6465··idm6812"·tabinde
0003b970:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b970:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
Offset 15892, 208 lines modifiedOffset 15892, 208 lines modified
0003e130:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003e130:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003e140:·3d22·2369·646d·3639·3236·2220·7461·6269··="#idm6926"·tabi0003e140:·3d22·2369·646d·3639·3236·2220·7461·6269··="#idm6926"·tabi
0003e150:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003e150:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003e160:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003e160:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003e170:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003e170:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003e180:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003e180:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003e190:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003e190:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003e1a0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003e1a0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
0003e1b0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003e1b0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
0003e1c0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003e1c0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003e1d0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003e1d0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003e1e0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003e1e0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003e1f0:·643d·2269·646d·3639·3236·223e·3c70·7265··d="idm6926"><pre0003e1f0:·646d·3639·3236·223e·3c70·7265·3e3c·636f··dm6926"><pre><co
 0003e200:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003e210:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003e220:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003e230:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
 0003e240:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
 0003e250:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
 0003e260:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
 0003e270:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
 0003e280:·703b·207b·2072·706d·202d·2d71·7569·6574··p;·{·rpm·--quiet
 0003e290:·202d·7120·6772·7562·322d·636f·6d6d·6f6e···-q·grub2-common
 0003e2a0:·3b20·7d3b·2074·6865·6e0a·0a23·2070·7265··;·};·then..#·pre
 0003e2b0:·6c69·6e6b·206e·6f74·2069·6e73·7461·6c6c··link·not·install
 0003e2c0:·6564·0a69·6620·7465·7374·202d·6520·2f65··ed.if·test·-e·/e
 0003e2d0:·7463·2f73·7973·636f·6e66·6967·2f70·7265··tc/sysconfig/pre
 0003e2e0:·6c69·6e6b·202d·6f20·2d65·202f·7573·722f··link·-o·-e·/usr/
 0003e2f0:·7362·696e·2f70·7265·6c69·6e6b·3b20·7468··sbin/prelink;·th
 0003e300:·656e·0a20·2020·2069·6620·6772·6570·202d··en.····if·grep·-
 0003e310:·7120·5e50·5245·4c49·4e4b·494e·4720·2f65··q·^PRELINKING·/e
 0003e320:·7463·2f73·7973·636f·6e66·6967·2f70·7265··tc/sysconfig/pre
 0003e330:·6c69·6e6b·0a20·2020·2074·6865·6e0a·2020··link.····then.··
 0003e340:·2020·2020·2020·7365·6420·2d69·2027·732f········sed·-i·'s/
 0003e350:·5e50·5245·4c49·4e4b·494e·475b·3a62·6c61··^PRELINKING[:bla
 0003e360:·6e6b·3a5d·2a3d·5b3a·626c·616e·6b3a·5d2a··nk:]*=[:blank:]*
 0003e370:·5b3a·616c·7068·613a·5d2a·2f50·5245·4c49··[:alpha:]*/PRELI
 0003e380:·4e4b·494e·473d·6e6f·2f27·202f·6574·632f··NKING=no/'·/etc/
 0003e390:·7379·7363·6f6e·6669·672f·7072·656c·696e··sysconfig/prelin
 0003e3a0:·6b0a·2020·2020·656c·7365·0a20·2020·2020··k.····else.·····
 0003e3b0:·2020·2070·7269·6e74·6620·275c·6e27·2026·····printf·'\n'·&
 0003e3c0:·6774·3b26·6774·3b20·2f65·7463·2f73·7973··gt;&gt;·/etc/sys
0003e200:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003e210:·2d2d·6164·643d·6472·6163·7574·2d66·6970··--add=dracut-fip 
0003e220:·7320·2d2d·6164·643d·6472·6163·7574·2d66··s·--add=dracut-f 
0003e230:·6970·732d·6165·736e·690a·3c2f·636f·6465··ips-aesni.</code 
0003e240:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003e250:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003e260:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003e270:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
Max diff block lines reached; 224608/258886 bytes (86.76%) of diff not shown.
30.7 KB
html2text {}
    
Offset 86, 28 lines modifiedOffset 86, 28 lines modified
86 To·enable·FIPS,·the·system·requires·that·the·dracut-fips·package·be·installed.·The·dracut-fips·package·can·be·installed·with·the·following·command:86 To·enable·FIPS,·the·system·requires·that·the·dracut-fips·package·be·installed.·The·dracut-fips·package·can·be·installed·with·the·following·command:
87 $·sudo·yum·install·dracut-fips87 $·sudo·yum·install·dracut-fips
88 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.88 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
89 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.89 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
90 Severity: ················medium90 Severity: ················medium
91 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed91 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed
92 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-00159092 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590
93 Remediation_Anaconda_snippet_⇲ 
  
94 package·--add=dracut-fips 
95 Remediation_Shell_script_⇲93 Remediation_Shell_script_⇲
96 #·Remediation·is·applicable·only·in·certain·platforms94 #·Remediation·is·applicable·only·in·certain·platforms
97 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then95 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
98 if·!·rpm·-q·--quiet·"dracut-fips"·;·then96 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
99 ····yum·install·-y·"dracut-fips"97 ····yum·install·-y·"dracut-fips"
100 fi98 fi
  
101 else99 else
102 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'100 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
103 fi101 fi
 102 Remediation_Anaconda_snippet_⇲
  
 103 package·--add=dracut-fips
104 Remediation_Ansible_snippet_⇲104 Remediation_Ansible_snippet_⇲
105 Complexity:·low105 Complexity:·low
106 Disruption:·low106 Disruption:·low
107 Strategy:···enable107 Strategy:···enable
108 -·name:·Ensure·dracut-fips·is·installed108 -·name:·Ensure·dracut-fips·is·installed
109 ··package:109 ··package:
110 ····name:·dracut-fips110 ····name:·dracut-fips
Offset 149, 17 lines modifiedOffset 149, 14 lines modified
149 will·overwrite·the·existing·initramfs·file.149 will·overwrite·the·existing·initramfs·file.
150 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.150 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
151 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.151 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
152 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.152 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
153 Severity: ················high153 Severity: ················high
154 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode154 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
155 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule155 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule
156 Remediation_Anaconda_snippet_⇲ 
  
157 package·--add=dracut-fips·--add=dracut-fips-aesni 
158 Remediation_Shell_script_⇲156 Remediation_Shell_script_⇲
159 #·Remediation·is·applicable·only·in·certain·platforms157 #·Remediation·is·applicable·only·in·certain·platforms
160 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then158 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
161 #·prelink·not·installed159 #·prelink·not·installed
162 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then160 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
163 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink161 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 218, 14 lines modifiedOffset 215, 17 lines modified
218 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader215 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
219 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"216 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
220 fi217 fi
  
221 else218 else
222 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'219 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
223 fi220 fi
 221 Remediation_Anaconda_snippet_⇲
  
 222 package·--add=dracut-fips·--add=dracut-fips-aesni
224 Remediation_Ansible_snippet_⇲223 Remediation_Ansible_snippet_⇲
225 Complexity:·high224 Complexity:·high
226 Disruption:·medium225 Disruption:·medium
227 Reboot:·····true226 Reboot:·····true
228 Strategy:···restrict227 Strategy:···restrict
229 -·name:·Gather·the·package·facts228 -·name:·Gather·the·package·facts
230 ··package_facts:229 ··package_facts:
Offset 4794, 20 lines modifiedOffset 4794, 14 lines modified
4794 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_screen_installed4794 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_screen_installed
4795 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110,·OL07-00-0100904795 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110,·OL07-00-010090
4796 Remediation_OSBuild_Blueprint_snippet_⇲4796 Remediation_OSBuild_Blueprint_snippet_⇲
  
4797 [[packages]]4797 [[packages]]
4798 name·=·"screen"4798 name·=·"screen"
4799 version·=·"*"4799 version·=·"*"
4800 Remediation_Anaconda_snippet_⇲ 
4801 Complexity:·low 
4802 Disruption:·low 
4803 Strategy:···enable 
  
4804 package·--add=screen 
4805 Remediation_Puppet_snippet_⇲4800 Remediation_Puppet_snippet_⇲
4806 Complexity:·low4801 Complexity:·low
4807 Disruption:·low4802 Disruption:·low
4808 Strategy:···enable4803 Strategy:···enable
4809 include·install_screen4804 include·install_screen
  
4810 class·install_screen·{4805 class·install_screen·{
Offset 4825, 14 lines modifiedOffset 4819, 20 lines modified
4825 if·!·rpm·-q·--quiet·"screen"·;·then4819 if·!·rpm·-q·--quiet·"screen"·;·then
4826 ····yum·install·-y·"screen"4820 ····yum·install·-y·"screen"
4827 fi4821 fi
  
4828 else4822 else
4829 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4823 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4830 fi4824 fi
 4825 Remediation_Anaconda_snippet_⇲
 4826 Complexity:·low
 4827 Disruption:·low
 4828 Strategy:···enable
  
 4829 package·--add=screen
4831 Remediation_Ansible_snippet_⇲4830 Remediation_Ansible_snippet_⇲
4832 Complexity:·low4831 Complexity:·low
4833 Disruption:·low4832 Disruption:·low
4834 Strategy:···enable4833 Strategy:···enable
4835 -·name:·Ensure·screen·is·installed4834 -·name:·Ensure·screen·is·installed
4836 ··package:4835 ··package:
4837 ····name:·screen4836 ····name:·screen
Offset 5979, 15 lines modifiedOffset 5979, 15 lines modified
5979 flush·=·incremental_async5979 flush·=·incremental_async
5980 Rationale:·················Audit·data·should·be·synchronously·written·to·disk·to·ensure·log·integrity.·These·parameters·assure·that·all·audit·event·data·is·fully·synchronized·with·the·log·files·on·the·disk.5980 Rationale:·················Audit·data·should·be·synchronously·written·to·disk·to·ensure·log·integrity.·These·parameters·assure·that·all·audit·event·data·is·fully·synchronized·with·the·log·files·on·the·disk.
5981 Severity: ················medium5981 Severity: ················medium
5982 Rule·ID:···················xccdf_org.ssgproject.content_rule_auditd_data_retention_flush5982 Rule·ID:···················xccdf_org.ssgproject.content_rule_auditd_data_retention_flush
5983 Identifiers·and·References·References: ·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·CCI-001576,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·CIP-004-6_R2.2.3,·CIP-004-6_R3.3,·CIP-007-3_R5.2,·CIP-007-3_R5.3.1,·CIP-007-3_R5.3.2,·CIP-007-3_R5.3.3,·CIP-007-3_R6.5,·AU-11,·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·SRG-OS-000480-GPOS-002275983 Identifiers·and·References·References: ·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·CCI-001576,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·CIP-004-6_R2.2.3,·CIP-004-6_R3.3,·CIP-007-3_R5.2,·CIP-007-3_R5.3.1,·CIP-007-3_R5.3.2,·CIP-007-3_R5.3.3,·CIP-007-3_R6.5,·AU-11,·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·SRG-OS-000480-GPOS-00227
5984 Remediation_Shell_script_⇲5984 Remediation_Shell_script_⇲
5985 #·Remediation·is·applicable·only·in·certain·platforms5985 #·Remediation·is·applicable·only·in·certain·platforms
5986 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then5986 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
5987 var_auditd_flush='incremental_async'5987 var_auditd_flush='incremental_async'
  
  
5988 AUDITCONFIG=/etc/audit/auditd.conf5988 AUDITCONFIG=/etc/audit/auditd.conf
  
5989 #·if·flush·is·present,·flush·param·edited·to·var_auditd_flush5989 #·if·flush·is·present,·flush·param·edited·to·var_auditd_flush
Offset 6045, 16 lines modifiedOffset 6045, 16 lines modified
6045 ··lineinfile:6045 ··lineinfile:
Max diff block lines reached; 22383/31395 bytes (71.29%) of diff not shown.
621 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-e8.html
    
Offset 19398, 104 lines modifiedOffset 19398, 104 lines modified
0004bc50:·7461·7267·6574·3d22·2369·646d·3130·3432··target="#idm10420004bc50:·7461·7267·6574·3d22·2369·646d·3130·3432··target="#idm1042
0004bc60:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·0004bc60:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·
0004bc70:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0004bc70:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0004bc80:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0004bc80:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0004bc90:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0004bc90:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0004bca0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0004bca0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0004bcb0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0004bcb0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0004bcc0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0004bcc0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0004bcd0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0004bcd0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0004bce0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0004bce0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0004bcf0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0004bcf0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0004bd00:·6170·7365·2220·6964·3d22·6964·6d31·3034··apse"·id="idm1040004bd00:·7365·2220·6964·3d22·6964·6d31·3034·3234··se"·id="idm10424
0004bd10:·3234·223e·3c74·6162·6c65·2063·6c61·7373··24"><table·class0004bd10:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0004bd20:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0004bd20:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0004bd30:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0004bd30:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0004bd40:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0004bd40:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0004bd50:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0004bd50:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0004bd60:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0004bd60:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0004bd70:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0004bd70:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0004bd80:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0004bd80:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0004bd90:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0004bd90:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0004bda0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0004bda0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0004bdb0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0004bdb0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0004bdc0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0004bdc0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0004bdd0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0004bdd0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0004bde0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
0004bdf0:·6164·643d·7265·6172·0a3c·2f63·6f64·653e··add=rear.</code> 
0004be00:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0004be10:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0004be20:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0004be30:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0004be40:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
0004be50:·3034·3235·2220·7461·6269·6e64·6578·3d22··0425"·tabindex=" 
0004be60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0004be70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0004be80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0004be90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0004bea0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0004beb0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s 
0004bec0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0004bed0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0004bee0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0004bef0:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm10 
0004bf00:·3432·3522·3e3c·7461·626c·6520·636c·6173··425"><table·clas 
0004bf10:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0004bf20:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0004bf30:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0004bf40:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0004bf50:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0004bf60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0004bf70:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0004bde0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 0004bdf0:·6c6c·5f72·6561·720a·0a63·6c61·7373·2069··ll_rear..class·i
 0004be00:·6e73·7461·6c6c·5f72·6561·7220·7b0a·2020··nstall_rear·{.··
 0004be10:·7061·636b·6167·6520·7b20·2772·6561·7227··package·{·'rear'
 0004be20:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 0004be30:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 0004be40:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 0004be50:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0004be60:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0004be70:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0004be80:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0004be90:·7461·7267·6574·3d22·2369·646d·3130·3432··target="#idm1042
 0004bea0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·
 0004beb0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0004bec0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0004bed0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0004bee0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0004bef0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0004bf00:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0004bf10:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0004bf20:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0004bf30:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0004bf40:·2220·6964·3d22·6964·6d31·3034·3235·223e··"·id="idm10425">
 0004bf50:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0004bf60:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0004bf70:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0004bf80:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0004bf90:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0004bf80:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0004bfa0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0004bf90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0004bfb0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0004bfc0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0004bfd0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0004bfe0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0004bff0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0004bfa0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0004bfb0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0004bfc0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0004bfd0:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0004bfe0:·7374·616c·6c5f·7265·6172·0a0a·636c·6173··stall_rear..clas 
0004bff0:·7320·696e·7374·616c·6c5f·7265·6172·207b··s·install_rear·{ 
0004c000:·0a20·2070·6163·6b61·6765·207b·2027·7265··.··package·{·'re 
0004c010:·6172·273a·0a20·2020·2065·6e73·7572·6520··ar':.····ensure· 
0004c020:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0004c030:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0004c040:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0004c050:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0004c060:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0004c070:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0004c080:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
0004c090:·3034·3236·2220·7461·6269·6e64·6578·3d22··0426"·tabindex=" 
0004c0a0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0004c0b0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0004c0c0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0004c0d0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0004c0e0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0004c0f0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0004c100:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0004c110:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0004c120:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0004c130:·7073·6522·2069·643d·2269·646d·3130·3432··pse"·id="idm1042 
0004c140:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class= 
0004c150:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0004c160:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0004c170:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0004c180:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0004c190:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0004c1a0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0004c000:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0004c010:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0004c020:·3e0a·6966·2021·2072·706d·202d·7120·2d2d··>.if·!·rpm·-q·--
 0004c030:·7175·6965·7420·2272·6561·7222·203b·2074··quiet·"rear"·;·t
 0004c040:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 0004c050:·616c·6c20·2d79·2022·7265·6172·220a·6669··all·-y·"rear".fi
 0004c060:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0004c070:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0004c080:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0004c090:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0004c0a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
Max diff block lines reached; 478080/491080 bytes (97.35%) of diff not shown.
141 KB
html2text {}
    
Offset 760, 20 lines modifiedOffset 760, 14 lines modified
760 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed760 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
761 Identifiers·and·References761 Identifiers·and·References
762 Remediation_OSBuild_Blueprint_snippet_⇲762 Remediation_OSBuild_Blueprint_snippet_⇲
  
763 [[packages]]763 [[packages]]
764 name·=·"rear"764 name·=·"rear"
765 version·=·"*"765 version·=·"*"
766 Remediation_Anaconda_snippet_⇲ 
767 Complexity:·low 
768 Disruption:·low 
769 Strategy:···enable 
  
770 package·--add=rear 
771 Remediation_Puppet_snippet_⇲766 Remediation_Puppet_snippet_⇲
772 Complexity:·low767 Complexity:·low
773 Disruption:·low768 Disruption:·low
774 Strategy:···enable769 Strategy:···enable
775 include·install_rear770 include·install_rear
  
776 class·install_rear·{771 class·install_rear·{
Offset 785, 14 lines modifiedOffset 779, 20 lines modified
785 Complexity:·low779 Complexity:·low
786 Disruption:·low780 Disruption:·low
787 Strategy:···enable781 Strategy:···enable
  
788 if·!·rpm·-q·--quiet·"rear"·;·then782 if·!·rpm·-q·--quiet·"rear"·;·then
789 ····yum·install·-y·"rear"783 ····yum·install·-y·"rear"
790 fi784 fi
 785 Remediation_Anaconda_snippet_⇲
 786 Complexity:·low
 787 Disruption:·low
 788 Strategy:···enable
  
 789 package·--add=rear
791 Remediation_Ansible_snippet_⇲790 Remediation_Ansible_snippet_⇲
792 Complexity:·low791 Complexity:·low
793 Disruption:·low792 Disruption:·low
794 Strategy:···enable793 Strategy:···enable
795 -·name:·Ensure·rear·is·installed794 -·name:·Ensure·rear·is·installed
796 ··package:795 ··package:
797 ····name:·rear796 ····name:·rear
Offset 1447, 15 lines modifiedOffset 1447, 15 lines modified
1447 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1447 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1448 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1448 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1449 Severity: ················medium1449 Severity: ················medium
1450 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1450 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1451 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule1451 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule
1452 Remediation_Shell_script_⇲1452 Remediation_Shell_script_⇲
1453 #·Remediation·is·applicable·only·in·certain·platforms1453 #·Remediation·is·applicable·only·in·certain·platforms
1454 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1454 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1455 #·First·perform·the·remediation·of·the·syscall·rule1455 #·First·perform·the·remediation·of·the·syscall·rule
1456 #·Retrieve·hardware·architecture·of·the·underlying·system1456 #·Retrieve·hardware·architecture·of·the·underlying·system
1457 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1457 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1458 for·ARCH·in·"${RULE_ARCHS[@]}"1458 for·ARCH·in·"${RULE_ARCHS[@]}"
1459 do1459 do
Offset 1802, 16 lines modifiedOffset 1802, 16 lines modified
1802 ··-·reboot_required1802 ··-·reboot_required
1803 ··-·restrict_strategy1803 ··-·restrict_strategy
  
1804 -·name:·Set·architecture·for·audit·chmod·tasks1804 -·name:·Set·architecture·for·audit·chmod·tasks
1805 ··set_fact:1805 ··set_fact:
1806 ····audit_arch:·b641806 ····audit_arch:·b64
1807 ··when:1807 ··when:
1808 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1809 ··-·'"audit"·in·ansible_facts.packages'1808 ··-·'"audit"·in·ansible_facts.packages'
 1809 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1810 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1810 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1811 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1811 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1812 ··tags:1812 ··tags:
1813 ··-·CJIS-5.4.1.11813 ··-·CJIS-5.4.1.1
1814 ··-·DISA-STIG-OL07-00-0304101814 ··-·DISA-STIG-OL07-00-030410
1815 ··-·NIST-800-171-3.1.71815 ··-·NIST-800-171-3.1.7
1816 ··-·NIST-800-53-AU-12(c)1816 ··-·NIST-800-53-AU-12(c)
Offset 1948, 16 lines modifiedOffset 1948, 16 lines modified
1948 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001948 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1949 ········-F·auid!=unset·-F·key=perm_mod1949 ········-F·auid!=unset·-F·key=perm_mod
1950 ······create:·true1950 ······create:·true
1951 ······mode:·o-rwx1951 ······mode:·o-rwx
1952 ······state:·present1952 ······state:·present
1953 ····when:·syscalls_found·|·length·==·01953 ····when:·syscalls_found·|·length·==·0
1954 ··when:1954 ··when:
1955 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1956 ··-·'"audit"·in·ansible_facts.packages'1955 ··-·'"audit"·in·ansible_facts.packages'
 1956 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1957 ··tags:1957 ··tags:
1958 ··-·CJIS-5.4.1.11958 ··-·CJIS-5.4.1.1
1959 ··-·DISA-STIG-OL07-00-0304101959 ··-·DISA-STIG-OL07-00-030410
1960 ··-·NIST-800-171-3.1.71960 ··-·NIST-800-171-3.1.7
1961 ··-·NIST-800-53-AU-12(c)1961 ··-·NIST-800-53-AU-12(c)
1962 ··-·NIST-800-53-AU-2(d)1962 ··-·NIST-800-53-AU-2(d)
1963 ··-·NIST-800-53-CM-6(a)1963 ··-·NIST-800-53-CM-6(a)
Offset 2092, 16 lines modifiedOffset 2092, 16 lines modified
2092 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002092 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2093 ········-F·auid!=unset·-F·key=perm_mod2093 ········-F·auid!=unset·-F·key=perm_mod
2094 ······create:·true2094 ······create:·true
2095 ······mode:·o-rwx2095 ······mode:·o-rwx
2096 ······state:·present2096 ······state:·present
2097 ····when:·syscalls_found·|·length·==·02097 ····when:·syscalls_found·|·length·==·0
2098 ··when:2098 ··when:
2099 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2100 ··-·'"audit"·in·ansible_facts.packages'2099 ··-·'"audit"·in·ansible_facts.packages'
 2100 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2101 ··-·audit_arch·==·"b64"2101 ··-·audit_arch·==·"b64"
2102 ··tags:2102 ··tags:
2103 ··-·CJIS-5.4.1.12103 ··-·CJIS-5.4.1.1
2104 ··-·DISA-STIG-OL07-00-0304102104 ··-·DISA-STIG-OL07-00-030410
2105 ··-·NIST-800-171-3.1.72105 ··-·NIST-800-171-3.1.7
2106 ··-·NIST-800-53-AU-12(c)2106 ··-·NIST-800-53-AU-12(c)
2107 ··-·NIST-800-53-AU-2(d)2107 ··-·NIST-800-53-AU-2(d)
Offset 2125, 15 lines modifiedOffset 2125, 15 lines modified
2125 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2125 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2126 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2126 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2127 Severity: ················medium2127 Severity: ················medium
2128 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2128 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2129 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030370,·SV-221778r810481_rule2129 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030370,·SV-221778r810481_rule
2130 Remediation_Shell_script_⇲2130 Remediation_Shell_script_⇲
2131 #·Remediation·is·applicable·only·in·certain·platforms2131 #·Remediation·is·applicable·only·in·certain·platforms
2132 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then2132 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
2133 #·First·perform·the·remediation·of·the·syscall·rule2133 #·First·perform·the·remediation·of·the·syscall·rule
2134 #·Retrieve·hardware·architecture·of·the·underlying·system2134 #·Retrieve·hardware·architecture·of·the·underlying·system
2135 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2135 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2136 for·ARCH·in·"${RULE_ARCHS[@]}"2136 for·ARCH·in·"${RULE_ARCHS[@]}"
2137 do2137 do
Max diff block lines reached; 136488/144803 bytes (94.26%) of diff not shown.
1.19 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-hipaa.html
    
Offset 30507, 21 lines modifiedOffset 30507, 21 lines modified
000772a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p000772a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
000772b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co000772b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000772c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2000772c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
000772d0:·3135·3531·223e·3c70·7265·3e3c·636f·6465··1551"><pre><code000772d0:·3135·3531·223e·3c70·7265·3e3c·636f·6465··1551"><pre><code
000772e0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i000772e0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
000772f0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl000772f0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
00077300:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla00077300:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
00077310:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f00077310:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
00077320:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&00077320:·7175·6965·7420·2d71·2061·7564·6974·2026··quiet·-q·audit·&
00077330:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f00077330:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 00077340:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 00077350:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
00077340:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container00077360:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
00077350:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
00077360:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
00077370:·6175·6469·743b·2074·6865·6e0a·0a23·2046··audit;·then..#·F00077370:·656e·7620·5d3b·2074·6865·6e0a·0a23·2046··env·];·then..#·F
00077380:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the00077380:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the
00077390:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·00077390:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·
000773a0:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule000773a0:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule
000773b0:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard000773b0:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard
000773c0:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur000773c0:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur
000773d0:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly000773d0:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly
000773e0:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(000773e0:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(
Offset 31401, 23 lines modifiedOffset 31401, 23 lines modified
0007aa80:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_0007aa80:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
0007aa90:·7374·7261·7465·6779·0a0a·2d20·6e61·6d65··strategy..-·name0007aa90:·7374·7261·7465·6779·0a0a·2d20·6e61·6d65··strategy..-·name
0007aaa0:·3a20·5365·7420·6172·6368·6974·6563·7475··:·Set·architectu0007aaa0:·3a20·5365·7420·6172·6368·6974·6563·7475··:·Set·architectu
0007aab0:·7265·2066·6f72·2061·7564·6974·2063·686d··re·for·audit·chm0007aab0:·7265·2066·6f72·2061·7564·6974·2063·686d··re·for·audit·chm
0007aac0:·6f64·2074·6173·6b73·0a20·2073·6574·5f66··od·tasks.··set_f0007aac0:·6f64·2074·6173·6b73·0a20·2073·6574·5f66··od·tasks.··set_f
0007aad0:·6163·743a·0a20·2020·2061·7564·6974·5f61··act:.····audit_a0007aad0:·6163·743a·0a20·2020·2061·7564·6974·5f61··act:.····audit_a
0007aae0:·7263·683a·2062·3634·0a20·2077·6865·6e3a··rch:·b64.··when:0007aae0:·7263·683a·2062·3634·0a20·2077·6865·6e3a··rch:·b64.··when:
0007aaf0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
0007ab00:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
0007ab10:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
0007ab20:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
0007ab30:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
0007ab40:·6f6e·7461·696e·6572·225d·0a20·202d·2027··ontainer"].··-·' 
0007ab50:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib 
0007ab60:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package0007aaf0:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 0007ab00:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 0007ab10:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans
 0007ab20:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 0007ab30:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 0007ab40:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 0007ab50:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 0007ab60:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
0007ab70:·7327·0a20·202d·2061·6e73·6962·6c65·5f61··s'.··-·ansible_a0007ab70:·225d·0a20·202d·2061·6e73·6962·6c65·5f61··"].··-·ansible_a
0007ab80:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"0007ab80:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"
0007ab90:·6161·7263·6836·3422·206f·7220·616e·7369··aarch64"·or·ansi0007ab90:·6161·7263·6836·3422·206f·7220·616e·7369··aarch64"·or·ansi
0007aba0:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture0007aba0:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
0007abb0:·203d·3d20·2270·7063·3634·2220·6f72·2061···==·"ppc64"·or·a0007abb0:·203d·3d20·2270·7063·3634·2220·6f72·2061···==·"ppc64"·or·a
0007abc0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect0007abc0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
0007abd0:·7572·650a·2020·2020·3d3d·2022·7070·6336··ure.····==·"ppc60007abd0:·7572·650a·2020·2020·3d3d·2022·7070·6336··ure.····==·"ppc6
0007abe0:·346c·6522·206f·7220·616e·7369·626c·655f··4le"·or·ansible_0007abe0:·346c·6522·206f·7220·616e·7369·626c·655f··4le"·or·ansible_
Offset 31724, 23 lines modifiedOffset 31724, 23 lines modified
0007beb0:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····0007beb0:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····
0007bec0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··0007bec0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··
0007bed0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.0007bed0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.
0007bee0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre0007bee0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre
0007bef0:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s0007bef0:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s
0007bf00:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·0007bf00:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·
0007bf10:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh0007bf10:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh
0007bf20:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_ 
0007bf30:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
0007bf40:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
0007bf50:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
0007bf60:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
0007bf70:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].·· 
0007bf80:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an 
0007bf90:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack0007bf20:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit"
 0007bf30:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 0007bf40:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·
 0007bf50:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 0007bf60:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 0007bf70:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 0007bf80:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 0007bf90:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
0007bfa0:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··0007bfa0:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··
0007bfb0:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·0007bfb0:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
0007bfc0:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL00007bfc0:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL0
0007bfd0:·372d·3030·2d30·3330·3431·300a·2020·2d20··7-00-030410.··-·0007bfd0:·372d·3030·2d30·3330·3431·300a·2020·2d20··7-00-030410.··-·
0007bfe0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.10007bfe0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
0007bff0:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-0007bff0:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-
0007c000:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·0007c000:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·
0007c010:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-20007c010:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-2
Offset 32036, 22 lines modifiedOffset 32036, 22 lines modified
0007d230:·5f6d·6f64·0a20·2020·2020·2063·7265·6174··_mod.······creat0007d230:·5f6d·6f64·0a20·2020·2020·2063·7265·6174··_mod.······creat
0007d240:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo0007d240:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo
0007d250:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······0007d250:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······
0007d260:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·0007d260:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
0007d270:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall0007d270:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall
0007d280:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length0007d280:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length
0007d290:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··0007d290:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··
0007d2a0:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
0007d2b0:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
0007d2c0:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
0007d2d0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
0007d2e0:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont 
0007d2f0:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au 
0007d300:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
0007d310:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.0007d2a0:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 0007d2b0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 0007d2c0:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
 0007d2d0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 0007d2e0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 0007d2f0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 0007d300:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 0007d310:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
0007d320:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=0007d320:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=
0007d330:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.0007d330:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.
0007d340:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.10007d340:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1
0007d350:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O0007d350:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O
0007d360:·4c30·372d·3030·2d30·3330·3431·300a·2020··L07-00-030410.··0007d360:·4c30·372d·3030·2d30·3330·3431·300a·2020··L07-00-030410.··
0007d370:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-30007d370:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
0007d380:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-800007d380:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80
Offset 33004, 20 lines modifiedOffset 33004, 20 lines modified
00080eb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00080eb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00080ec0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00080ec0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
00080ed0:·2220·6964·3d22·6964·6d32·3137·3039·223e··"·id="idm21709">00080ed0:·2220·6964·3d22·6964·6d32·3137·3039·223e··"·id="idm21709">
00080ee0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem00080ee0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
00080ef0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl00080ef0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
00080f00:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c00080f00:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
00080f10:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms00080f10:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 00080f20:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet·
 00080f30:·2d71·2061·7564·6974·2026·616d·703b·2661··-q·audit·&amp;&a
00080f20:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc00080f40:·6d70·3b20·5b20·2120·2d66·202f·2e64·6f63··mp;·[·!·-f·/.doc
00080f30:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a00080f50:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
Max diff block lines reached; 875042/884901 bytes (98.89%) of diff not shown.
357 KB
html2text {}
    
Offset 1846, 15 lines modifiedOffset 1846, 15 lines modified
1846 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1846 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1847 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1847 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1848 Severity: ················medium1848 Severity: ················medium
1849 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1849 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1850 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule1850 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule
1851 Remediation_Shell_script_⇲1851 Remediation_Shell_script_⇲
1852 #·Remediation·is·applicable·only·in·certain·platforms1852 #·Remediation·is·applicable·only·in·certain·platforms
1853 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1853 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1854 #·First·perform·the·remediation·of·the·syscall·rule1854 #·First·perform·the·remediation·of·the·syscall·rule
1855 #·Retrieve·hardware·architecture·of·the·underlying·system1855 #·Retrieve·hardware·architecture·of·the·underlying·system
1856 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1856 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1857 for·ARCH·in·"${RULE_ARCHS[@]}"1857 for·ARCH·in·"${RULE_ARCHS[@]}"
1858 do1858 do
Offset 2201, 16 lines modifiedOffset 2201, 16 lines modified
2201 ··-·reboot_required2201 ··-·reboot_required
2202 ··-·restrict_strategy2202 ··-·restrict_strategy
  
2203 -·name:·Set·architecture·for·audit·chmod·tasks2203 -·name:·Set·architecture·for·audit·chmod·tasks
2204 ··set_fact:2204 ··set_fact:
2205 ····audit_arch:·b642205 ····audit_arch:·b64
2206 ··when:2206 ··when:
2207 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2208 ··-·'"audit"·in·ansible_facts.packages'2207 ··-·'"audit"·in·ansible_facts.packages'
 2208 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2209 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2209 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2210 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2210 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2211 ··tags:2211 ··tags:
2212 ··-·CJIS-5.4.1.12212 ··-·CJIS-5.4.1.1
2213 ··-·DISA-STIG-OL07-00-0304102213 ··-·DISA-STIG-OL07-00-030410
2214 ··-·NIST-800-171-3.1.72214 ··-·NIST-800-171-3.1.7
2215 ··-·NIST-800-53-AU-12(c)2215 ··-·NIST-800-53-AU-12(c)
Offset 2347, 16 lines modifiedOffset 2347, 16 lines modified
2347 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002347 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2348 ········-F·auid!=unset·-F·key=perm_mod2348 ········-F·auid!=unset·-F·key=perm_mod
2349 ······create:·true2349 ······create:·true
2350 ······mode:·o-rwx2350 ······mode:·o-rwx
2351 ······state:·present2351 ······state:·present
2352 ····when:·syscalls_found·|·length·==·02352 ····when:·syscalls_found·|·length·==·0
2353 ··when:2353 ··when:
2354 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2355 ··-·'"audit"·in·ansible_facts.packages'2354 ··-·'"audit"·in·ansible_facts.packages'
 2355 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2356 ··tags:2356 ··tags:
2357 ··-·CJIS-5.4.1.12357 ··-·CJIS-5.4.1.1
2358 ··-·DISA-STIG-OL07-00-0304102358 ··-·DISA-STIG-OL07-00-030410
2359 ··-·NIST-800-171-3.1.72359 ··-·NIST-800-171-3.1.7
2360 ··-·NIST-800-53-AU-12(c)2360 ··-·NIST-800-53-AU-12(c)
2361 ··-·NIST-800-53-AU-2(d)2361 ··-·NIST-800-53-AU-2(d)
2362 ··-·NIST-800-53-CM-6(a)2362 ··-·NIST-800-53-CM-6(a)
Offset 2491, 16 lines modifiedOffset 2491, 16 lines modified
2491 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002491 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2492 ········-F·auid!=unset·-F·key=perm_mod2492 ········-F·auid!=unset·-F·key=perm_mod
2493 ······create:·true2493 ······create:·true
2494 ······mode:·o-rwx2494 ······mode:·o-rwx
2495 ······state:·present2495 ······state:·present
2496 ····when:·syscalls_found·|·length·==·02496 ····when:·syscalls_found·|·length·==·0
2497 ··when:2497 ··when:
2498 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2499 ··-·'"audit"·in·ansible_facts.packages'2498 ··-·'"audit"·in·ansible_facts.packages'
 2499 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2500 ··-·audit_arch·==·"b64"2500 ··-·audit_arch·==·"b64"
2501 ··tags:2501 ··tags:
2502 ··-·CJIS-5.4.1.12502 ··-·CJIS-5.4.1.1
2503 ··-·DISA-STIG-OL07-00-0304102503 ··-·DISA-STIG-OL07-00-030410
2504 ··-·NIST-800-171-3.1.72504 ··-·NIST-800-171-3.1.7
2505 ··-·NIST-800-53-AU-12(c)2505 ··-·NIST-800-53-AU-12(c)
2506 ··-·NIST-800-53-AU-2(d)2506 ··-·NIST-800-53-AU-2(d)
Offset 2524, 15 lines modifiedOffset 2524, 15 lines modified
2524 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2524 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2525 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2525 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2526 Severity: ················medium2526 Severity: ················medium
2527 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2527 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2528 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030370,·SV-221778r810481_rule2528 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030370,·SV-221778r810481_rule
2529 Remediation_Shell_script_⇲2529 Remediation_Shell_script_⇲
2530 #·Remediation·is·applicable·only·in·certain·platforms2530 #·Remediation·is·applicable·only·in·certain·platforms
2531 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then2531 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
2532 #·First·perform·the·remediation·of·the·syscall·rule2532 #·First·perform·the·remediation·of·the·syscall·rule
2533 #·Retrieve·hardware·architecture·of·the·underlying·system2533 #·Retrieve·hardware·architecture·of·the·underlying·system
2534 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2534 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2535 for·ARCH·in·"${RULE_ARCHS[@]}"2535 for·ARCH·in·"${RULE_ARCHS[@]}"
2536 do2536 do
Offset 2879, 16 lines modifiedOffset 2879, 16 lines modified
2879 ··-·reboot_required2879 ··-·reboot_required
2880 ··-·restrict_strategy2880 ··-·restrict_strategy
  
2881 -·name:·Set·architecture·for·audit·chown·tasks2881 -·name:·Set·architecture·for·audit·chown·tasks
2882 ··set_fact:2882 ··set_fact:
2883 ····audit_arch:·b642883 ····audit_arch:·b64
2884 ··when:2884 ··when:
2885 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2886 ··-·'"audit"·in·ansible_facts.packages'2885 ··-·'"audit"·in·ansible_facts.packages'
 2886 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2887 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2887 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2888 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2888 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2889 ··tags:2889 ··tags:
2890 ··-·CJIS-5.4.1.12890 ··-·CJIS-5.4.1.1
2891 ··-·DISA-STIG-OL07-00-0303702891 ··-·DISA-STIG-OL07-00-030370
2892 ··-·NIST-800-171-3.1.72892 ··-·NIST-800-171-3.1.7
2893 ··-·NIST-800-53-AU-12(c)2893 ··-·NIST-800-53-AU-12(c)
Offset 3027, 16 lines modifiedOffset 3027, 16 lines modified
3027 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003027 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3028 ········-F·auid!=unset·-F·key=perm_mod3028 ········-F·auid!=unset·-F·key=perm_mod
3029 ······create:·true3029 ······create:·true
3030 ······mode:·o-rwx3030 ······mode:·o-rwx
3031 ······state:·present3031 ······state:·present
3032 ····when:·syscalls_found·|·length·==·03032 ····when:·syscalls_found·|·length·==·0
3033 ··when:3033 ··when:
3034 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3035 ··-·'"audit"·in·ansible_facts.packages'3034 ··-·'"audit"·in·ansible_facts.packages'
 3035 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3036 ··tags:3036 ··tags:
3037 ··-·CJIS-5.4.1.13037 ··-·CJIS-5.4.1.1
3038 ··-·DISA-STIG-OL07-00-0303703038 ··-·DISA-STIG-OL07-00-030370
3039 ··-·NIST-800-171-3.1.73039 ··-·NIST-800-171-3.1.7
3040 ··-·NIST-800-53-AU-12(c)3040 ··-·NIST-800-53-AU-12(c)
3041 ··-·NIST-800-53-AU-2(d)3041 ··-·NIST-800-53-AU-2(d)
3042 ··-·NIST-800-53-CM-6(a)3042 ··-·NIST-800-53-CM-6(a)
Offset 3173, 16 lines modifiedOffset 3173, 16 lines modified
3173 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003173 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3174 ········-F·auid!=unset·-F·key=perm_mod3174 ········-F·auid!=unset·-F·key=perm_mod
3175 ······create:·true3175 ······create:·true
3176 ······mode:·o-rwx3176 ······mode:·o-rwx
3177 ······state:·present3177 ······state:·present
Max diff block lines reached; 356126/365123 bytes (97.54%) of diff not shown.
1.54 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-ncp.html
    
Offset 17207, 116 lines modifiedOffset 17207, 116 lines modified
00043360:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00043360:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00043370:·2223·6964·6d36·3238·3422·2074·6162·696e··"#idm6284"·tabin00043370:·2223·6964·6d36·3238·3422·2074·6162·696e··"#idm6284"·tabin
00043380:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00043380:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00043390:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00043390:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
000433a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl000433a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
000433b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r000433b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
000433c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"000433c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
000433d0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana000433d0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
000433e0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..000433e0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
000433f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl000433f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00043400:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00043400:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00043410:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00043410:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00043420:·3d22·6964·6d36·3238·3422·3e3c·7461·626c··="idm6284"><tabl00043420:·6964·6d36·3238·3422·3e3c·7461·626c·6520··idm6284"><table·
00043430:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00043430:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00043440:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00043440:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00043450:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00043450:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00043460:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00043460:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00043470:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00043470:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00043480:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00043480:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00043490:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00043490:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
000434a0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t000434a0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
000434b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><000434b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
000434c0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:000434c0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
000434d0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<000434d0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
000434e0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table000434e0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
000434f0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac000434f0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
00043500:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.00043500:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 00043510:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 00043520:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 00043530:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 00043540:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 00043550:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 00043560:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00043570:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00043580:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00043590:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 000435a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 000435b0:·6964·6d36·3238·3522·2074·6162·696e·6465··idm6285"·tabinde
 000435c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 000435d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 000435e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 000435f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 00043600:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 00043610:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 00043620:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 00043630:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00043640:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00043650:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
 00043660:·3238·3522·3e3c·7461·626c·6520·636c·6173··285"><table·clas
 00043670:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00043680:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00043690:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 000436a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 000436b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 000436c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000436d0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 000436e0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 000436f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00043700:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00043710:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00043720:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00043730:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00043740:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00043750:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00043760:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 00043770:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
 00043780:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
 00043790:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
 000437a0:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
 000437b0:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 000437c0:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 000437d0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 000437e0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 000437f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 00043800:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 00043810:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 00043820:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 00043830:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
00043510:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00043840:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
00043520:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn00043850:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
00043530:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da00043860:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
00043540:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla00043870:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
00043550:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00043880:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00043560:·3d22·2369·646d·3632·3835·2220·7461·6269··="#idm6285"·tabi00043890:·3d22·2369·646d·3632·3836·2220·7461·6269··="#idm6286"·tabi
00043570:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b000438a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00043580:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa000438b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00043590:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit000438c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
000435a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·000438d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
000435b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!000438e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
000435c0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu000438f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
000435d0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...00043900:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
000435e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00043910:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
000435f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00043920:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00043600:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00043930:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00043610:·2269·646d·3632·3835·223e·3c74·6162·6c65··"idm6285"><table00043940:·643d·2269·646d·3632·3836·223e·3c74·6162··d="idm6286"><tab
00043620:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00043950:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00043630:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00043960:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00043640:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table00043970:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00043650:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>00043980:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00043660:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<00043990:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00043670:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>000439a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00043680:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis000439b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00043690:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td000439c0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
000436a0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t000439d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
000436b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<000439e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
000436c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</000439f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
000436d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>00043a00:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00043a10:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 00043a20:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
000436e0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
000436f0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
00043700:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
00043710:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
00043720:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
00043730:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
00043740:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
00043750:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00043760:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00043770:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00043780:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00043790:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
000437a0:·2369·646d·3632·3836·2220·7461·6269·6e64··#idm6286"·tabind 
000437b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
000437c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
000437d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
000437e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
000437f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
Max diff block lines reached; 1185103/1199759 bytes (98.78%) of diff not shown.
407 KB
html2text {}
    
Offset 415, 20 lines modifiedOffset 415, 14 lines modified
415 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed415 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
416 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule416 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule
417 Remediation_OSBuild_Blueprint_snippet_⇲417 Remediation_OSBuild_Blueprint_snippet_⇲
  
418 [[packages]]418 [[packages]]
419 name·=·"aide"419 name·=·"aide"
420 version·=·"*"420 version·=·"*"
421 Remediation_Anaconda_snippet_⇲ 
422 Complexity:·low 
423 Disruption:·low 
424 Strategy:···enable 
  
425 package·--add=aide 
426 Remediation_Puppet_snippet_⇲421 Remediation_Puppet_snippet_⇲
427 Complexity:·low422 Complexity:·low
428 Disruption:·low423 Disruption:·low
429 Strategy:···enable424 Strategy:···enable
430 include·install_aide425 include·install_aide
  
431 class·install_aide·{426 class·install_aide·{
Offset 446, 14 lines modifiedOffset 440, 20 lines modified
446 if·!·rpm·-q·--quiet·"aide"·;·then440 if·!·rpm·-q·--quiet·"aide"·;·then
447 ····yum·install·-y·"aide"441 ····yum·install·-y·"aide"
448 fi442 fi
  
449 else443 else
450 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'444 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
451 fi445 fi
 446 Remediation_Anaconda_snippet_⇲
 447 Complexity:·low
 448 Disruption:·low
 449 Strategy:···enable
  
 450 package·--add=aide
452 Remediation_Ansible_snippet_⇲451 Remediation_Ansible_snippet_⇲
453 Complexity:·low452 Complexity:·low
454 Disruption:·low453 Disruption:·low
455 Strategy:···enable454 Strategy:···enable
456 -·name:·Ensure·aide·is·installed455 -·name:·Ensure·aide·is·installed
457 ··package:456 ··package:
458 ····name:·aide457 ····name:·aide
Offset 929, 28 lines modifiedOffset 929, 28 lines modified
929 To·enable·FIPS,·the·system·requires·that·the·dracut-fips·package·be·installed.·The·dracut-fips·package·can·be·installed·with·the·following·command:929 To·enable·FIPS,·the·system·requires·that·the·dracut-fips·package·be·installed.·The·dracut-fips·package·can·be·installed·with·the·following·command:
930 $·sudo·yum·install·dracut-fips930 $·sudo·yum·install·dracut-fips
931 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.931 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
932 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.932 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
933 Severity: ················medium933 Severity: ················medium
934 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed934 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed
935 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590935 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590
936 Remediation_Anaconda_snippet_⇲ 
  
937 package·--add=dracut-fips 
938 Remediation_Shell_script_⇲936 Remediation_Shell_script_⇲
939 #·Remediation·is·applicable·only·in·certain·platforms937 #·Remediation·is·applicable·only·in·certain·platforms
940 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then938 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
941 if·!·rpm·-q·--quiet·"dracut-fips"·;·then939 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
942 ····yum·install·-y·"dracut-fips"940 ····yum·install·-y·"dracut-fips"
943 fi941 fi
  
944 else942 else
945 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'943 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
946 fi944 fi
 945 Remediation_Anaconda_snippet_⇲
  
 946 package·--add=dracut-fips
947 Remediation_Ansible_snippet_⇲947 Remediation_Ansible_snippet_⇲
948 Complexity:·low948 Complexity:·low
949 Disruption:·low949 Disruption:·low
950 Strategy:···enable950 Strategy:···enable
951 -·name:·Ensure·dracut-fips·is·installed951 -·name:·Ensure·dracut-fips·is·installed
952 ··package:952 ··package:
953 ····name:·dracut-fips953 ····name:·dracut-fips
Offset 992, 17 lines modifiedOffset 992, 14 lines modified
992 will·overwrite·the·existing·initramfs·file.992 will·overwrite·the·existing·initramfs·file.
993 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.993 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
994 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.994 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
995 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.995 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
996 Severity: ················high996 Severity: ················high
997 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode997 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
998 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule998 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule
999 Remediation_Anaconda_snippet_⇲ 
  
1000 package·--add=dracut-fips·--add=dracut-fips-aesni 
1001 Remediation_Shell_script_⇲999 Remediation_Shell_script_⇲
1002 #·Remediation·is·applicable·only·in·certain·platforms1000 #·Remediation·is·applicable·only·in·certain·platforms
1003 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then1001 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
1004 #·prelink·not·installed1002 #·prelink·not·installed
1005 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then1003 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
1006 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink1004 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 1061, 14 lines modifiedOffset 1058, 17 lines modified
1061 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader1058 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
1062 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"1059 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
1063 fi1060 fi
  
1064 else1061 else
1065 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1062 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1066 fi1063 fi
 1064 Remediation_Anaconda_snippet_⇲
  
 1065 package·--add=dracut-fips·--add=dracut-fips-aesni
1067 Remediation_Ansible_snippet_⇲1066 Remediation_Ansible_snippet_⇲
1068 Complexity:·high1067 Complexity:·high
1069 Disruption:·medium1068 Disruption:·medium
1070 Reboot:·····true1069 Reboot:·····true
1071 Strategy:···restrict1070 Strategy:···restrict
1072 -·name:·Gather·the·package·facts1071 -·name:·Gather·the·package·facts
1073 ··package_facts:1072 ··package_facts:
Offset 12241, 20 lines modifiedOffset 12241, 14 lines modified
12241 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_screen_installed12241 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_screen_installed
12242 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110,·OL07-00-01009012242 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110,·OL07-00-010090
12243 Remediation_OSBuild_Blueprint_snippet_⇲12243 Remediation_OSBuild_Blueprint_snippet_⇲
  
12244 [[packages]]12244 [[packages]]
12245 name·=·"screen"12245 name·=·"screen"
12246 version·=·"*"12246 version·=·"*"
12247 Remediation_Anaconda_snippet_⇲ 
12248 Complexity:·low 
12249 Disruption:·low 
12250 Strategy:···enable 
  
12251 package·--add=screen 
12252 Remediation_Puppet_snippet_⇲12247 Remediation_Puppet_snippet_⇲
12253 Complexity:·low12248 Complexity:·low
12254 Disruption:·low12249 Disruption:·low
12255 Strategy:···enable12250 Strategy:···enable
Max diff block lines reached; 408753/417236 bytes (97.97%) of diff not shown.
284 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-ospp.html
    
Offset 15175, 57 lines modifiedOffset 15175, 57 lines modified
0003b460:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b460:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b470:·3d22·2369·646d·3638·3130·2220·7461·6269··="#idm6810"·tabi0003b470:·3d22·2369·646d·3638·3130·2220·7461·6269··="#idm6810"·tabi
0003b480:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b480:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b490:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b490:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b4a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b4a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b4b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b4b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b4c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b4c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b4d0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b4d0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
0003b4e0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·. 
0003b4f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b500:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b510:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b520:·643d·2269·646d·3638·3130·223e·3c70·7265··d="idm6810"><pre 
0003b530:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003b540:·2d2d·6164·643d·6472·6163·7574·2d66·6970··--add=dracut-fip 
0003b550:·730a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··s.</code></pre>< 
0003b560:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b570:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b580:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b590:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b5a0:·6574·3d22·2369·646d·3638·3131·2220·7461··et="#idm6811"·ta 
0003b5b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b5c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b5d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b5e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b5f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b600:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b610:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...0003b4e0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
0003b620:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b4f0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b630:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b500:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b640:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b510:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b650:·2269·646d·3638·3131·223e·3c70·7265·3e3c··"idm6811"><pre><0003b520:·646d·3638·3130·223e·3c70·7265·3e3c·636f··dm6810"><pre><co
0003b660:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati0003b530:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
0003b670:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable0003b540:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
0003b680:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain0003b550:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
0003b690:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·0003b560:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
0003b6a0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv0003b570:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
0003b6b0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·0003b580:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
0003b6c0:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta0003b590:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
0003b6d0:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.0003b5a0:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i
0003b6e0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q0003b5b0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
0003b6f0:·7569·6574·2022·6472·6163·7574·2d66·6970··uiet·"dracut-fip0003b5c0:·6574·2022·6472·6163·7574·2d66·6970·7322··et·"dracut-fips"
0003b700:·7322·203b·2074·6865·6e0a·2020·2020·7975··s"·;·then.····yu0003b5d0:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
0003b710:·6d20·696e·7374·616c·6c20·2d79·2022·6472··m·install·-y·"dr0003b5e0:·696e·7374·616c·6c20·2d79·2022·6472·6163··install·-y·"drac
0003b720:·6163·7574·2d66·6970·7322·0a66·690a·0a65··acut-fips".fi..e0003b5f0:·7574·2d66·6970·7322·0a66·690a·0a65·6c73··ut-fips".fi..els
0003b730:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp0003b600:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
0003b740:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia0003b610:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
0003b750:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl0003b620:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
0003b760:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·0003b630:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
0003b770:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c0003b640:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003b650:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b660:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b670:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b680:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b690:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b6a0:·6d36·3831·3122·2074·6162·696e·6465·783d··m6811"·tabindex=
 0003b6b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b6c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b6d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b6e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b6f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b700:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
 0003b710:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
 0003b720:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b730:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b740:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b750:·6d36·3831·3122·3e3c·7072·653e·3c63·6f64··m6811"><pre><cod
 0003b760:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
 0003b770:·3d64·7261·6375·742d·6669·7073·0a3c·2f63··=dracut-fips.</c
0003b780:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003b780:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003b790:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003b790:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003b7a0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003b7a0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003b7b0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003b7b0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003b7c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b7c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b7d0:·6964·6d36·3831·3222·2074·6162·696e·6465··idm6812"·tabinde0003b7d0:·6964·6d36·3831·3222·2074·6162·696e·6465··idm6812"·tabinde
0003b7e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b7e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
Offset 15867, 208 lines modifiedOffset 15867, 208 lines modified
0003dfa0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003dfa0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003dfb0:·3d22·2369·646d·3639·3236·2220·7461·6269··="#idm6926"·tabi0003dfb0:·3d22·2369·646d·3639·3236·2220·7461·6269··="#idm6926"·tabi
0003dfc0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003dfc0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003dfd0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003dfd0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003dfe0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003dfe0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003dff0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003dff0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003e000:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003e000:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003e010:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003e010:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
0003e020:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003e020:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
0003e030:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003e030:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003e040:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003e040:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003e050:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003e050:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003e060:·643d·2269·646d·3639·3236·223e·3c70·7265··d="idm6926"><pre0003e060:·646d·3639·3236·223e·3c70·7265·3e3c·636f··dm6926"><pre><co
 0003e070:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003e080:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003e090:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003e0a0:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
 0003e0b0:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
 0003e0c0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
 0003e0d0:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
 0003e0e0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
 0003e0f0:·703b·207b·2072·706d·202d·2d71·7569·6574··p;·{·rpm·--quiet
 0003e100:·202d·7120·6772·7562·322d·636f·6d6d·6f6e···-q·grub2-common
 0003e110:·3b20·7d3b·2074·6865·6e0a·0a23·2070·7265··;·};·then..#·pre
 0003e120:·6c69·6e6b·206e·6f74·2069·6e73·7461·6c6c··link·not·install
 0003e130:·6564·0a69·6620·7465·7374·202d·6520·2f65··ed.if·test·-e·/e
0003e070:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003e080:·2d2d·6164·643d·6472·6163·7574·2d66·6970··--add=dracut-fip 
0003e090:·7320·2d2d·6164·643d·6472·6163·7574·2d66··s·--add=dracut-f 
0003e0a0:·6970·732d·6165·736e·690a·3c2f·636f·6465··ips-aesni.</code 
0003e0b0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003e0c0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003e0d0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003e0e0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003e0f0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003e100:·3639·3237·2220·7461·6269·6e64·6578·3d22··6927"·tabindex=" 
0003e110:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003e120:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003e130:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003e140:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003e150:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003e160:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003e170:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003e180:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003e190:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003e1a0:·7073·6522·2069·643d·2269·646d·3639·3237··pse"·id="idm6927 
0003e1b0:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R 
0003e1c0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003e1d0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003e1e0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
Max diff block lines reached; 224608/258886 bytes (86.76%) of diff not shown.
30.7 KB
html2text {}
    
Offset 79, 28 lines modifiedOffset 79, 28 lines modified
79 To·enable·FIPS,·the·system·requires·that·the·dracut-fips·package·be·installed.·The·dracut-fips·package·can·be·installed·with·the·following·command:79 To·enable·FIPS,·the·system·requires·that·the·dracut-fips·package·be·installed.·The·dracut-fips·package·can·be·installed·with·the·following·command:
80 $·sudo·yum·install·dracut-fips80 $·sudo·yum·install·dracut-fips
81 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.81 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
82 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.82 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
83 Severity: ················medium83 Severity: ················medium
84 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed84 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed
85 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-00159085 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590
86 Remediation_Anaconda_snippet_⇲ 
  
87 package·--add=dracut-fips 
88 Remediation_Shell_script_⇲86 Remediation_Shell_script_⇲
89 #·Remediation·is·applicable·only·in·certain·platforms87 #·Remediation·is·applicable·only·in·certain·platforms
90 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then88 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
91 if·!·rpm·-q·--quiet·"dracut-fips"·;·then89 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
92 ····yum·install·-y·"dracut-fips"90 ····yum·install·-y·"dracut-fips"
93 fi91 fi
  
94 else92 else
95 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'93 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
96 fi94 fi
 95 Remediation_Anaconda_snippet_⇲
  
 96 package·--add=dracut-fips
97 Remediation_Ansible_snippet_⇲97 Remediation_Ansible_snippet_⇲
98 Complexity:·low98 Complexity:·low
99 Disruption:·low99 Disruption:·low
100 Strategy:···enable100 Strategy:···enable
101 -·name:·Ensure·dracut-fips·is·installed101 -·name:·Ensure·dracut-fips·is·installed
102 ··package:102 ··package:
103 ····name:·dracut-fips103 ····name:·dracut-fips
Offset 142, 17 lines modifiedOffset 142, 14 lines modified
142 will·overwrite·the·existing·initramfs·file.142 will·overwrite·the·existing·initramfs·file.
143 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.143 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
144 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.144 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
145 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.145 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
146 Severity: ················high146 Severity: ················high
147 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode147 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
148 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule148 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule
149 Remediation_Anaconda_snippet_⇲ 
  
150 package·--add=dracut-fips·--add=dracut-fips-aesni 
151 Remediation_Shell_script_⇲149 Remediation_Shell_script_⇲
152 #·Remediation·is·applicable·only·in·certain·platforms150 #·Remediation·is·applicable·only·in·certain·platforms
153 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then151 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
154 #·prelink·not·installed152 #·prelink·not·installed
155 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then153 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
156 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink154 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 211, 14 lines modifiedOffset 208, 17 lines modified
211 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader208 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
212 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"209 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
213 fi210 fi
  
214 else211 else
215 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'212 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
216 fi213 fi
 214 Remediation_Anaconda_snippet_⇲
  
 215 package·--add=dracut-fips·--add=dracut-fips-aesni
217 Remediation_Ansible_snippet_⇲216 Remediation_Ansible_snippet_⇲
218 Complexity:·high217 Complexity:·high
219 Disruption:·medium218 Disruption:·medium
220 Reboot:·····true219 Reboot:·····true
221 Strategy:···restrict220 Strategy:···restrict
222 -·name:·Gather·the·package·facts221 -·name:·Gather·the·package·facts
223 ··package_facts:222 ··package_facts:
Offset 4787, 20 lines modifiedOffset 4787, 14 lines modified
4787 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_screen_installed4787 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_screen_installed
4788 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110,·OL07-00-0100904788 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110,·OL07-00-010090
4789 Remediation_OSBuild_Blueprint_snippet_⇲4789 Remediation_OSBuild_Blueprint_snippet_⇲
  
4790 [[packages]]4790 [[packages]]
4791 name·=·"screen"4791 name·=·"screen"
4792 version·=·"*"4792 version·=·"*"
4793 Remediation_Anaconda_snippet_⇲ 
4794 Complexity:·low 
4795 Disruption:·low 
4796 Strategy:···enable 
  
4797 package·--add=screen 
4798 Remediation_Puppet_snippet_⇲4793 Remediation_Puppet_snippet_⇲
4799 Complexity:·low4794 Complexity:·low
4800 Disruption:·low4795 Disruption:·low
4801 Strategy:···enable4796 Strategy:···enable
4802 include·install_screen4797 include·install_screen
  
4803 class·install_screen·{4798 class·install_screen·{
Offset 4818, 14 lines modifiedOffset 4812, 20 lines modified
4818 if·!·rpm·-q·--quiet·"screen"·;·then4812 if·!·rpm·-q·--quiet·"screen"·;·then
4819 ····yum·install·-y·"screen"4813 ····yum·install·-y·"screen"
4820 fi4814 fi
  
4821 else4815 else
4822 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4816 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4823 fi4817 fi
 4818 Remediation_Anaconda_snippet_⇲
 4819 Complexity:·low
 4820 Disruption:·low
 4821 Strategy:···enable
  
 4822 package·--add=screen
4824 Remediation_Ansible_snippet_⇲4823 Remediation_Ansible_snippet_⇲
4825 Complexity:·low4824 Complexity:·low
4826 Disruption:·low4825 Disruption:·low
4827 Strategy:···enable4826 Strategy:···enable
4828 -·name:·Ensure·screen·is·installed4827 -·name:·Ensure·screen·is·installed
4829 ··package:4828 ··package:
4830 ····name:·screen4829 ····name:·screen
Offset 5972, 15 lines modifiedOffset 5972, 15 lines modified
5972 flush·=·incremental_async5972 flush·=·incremental_async
5973 Rationale:·················Audit·data·should·be·synchronously·written·to·disk·to·ensure·log·integrity.·These·parameters·assure·that·all·audit·event·data·is·fully·synchronized·with·the·log·files·on·the·disk.5973 Rationale:·················Audit·data·should·be·synchronously·written·to·disk·to·ensure·log·integrity.·These·parameters·assure·that·all·audit·event·data·is·fully·synchronized·with·the·log·files·on·the·disk.
5974 Severity: ················medium5974 Severity: ················medium
5975 Rule·ID:···················xccdf_org.ssgproject.content_rule_auditd_data_retention_flush5975 Rule·ID:···················xccdf_org.ssgproject.content_rule_auditd_data_retention_flush
5976 Identifiers·and·References·References: ·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·CCI-001576,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·CIP-004-6_R2.2.3,·CIP-004-6_R3.3,·CIP-007-3_R5.2,·CIP-007-3_R5.3.1,·CIP-007-3_R5.3.2,·CIP-007-3_R5.3.3,·CIP-007-3_R6.5,·AU-11,·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·SRG-OS-000480-GPOS-002275976 Identifiers·and·References·References: ·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·CCI-001576,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·CIP-004-6_R2.2.3,·CIP-004-6_R3.3,·CIP-007-3_R5.2,·CIP-007-3_R5.3.1,·CIP-007-3_R5.3.2,·CIP-007-3_R5.3.3,·CIP-007-3_R6.5,·AU-11,·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·SRG-OS-000480-GPOS-00227
5977 Remediation_Shell_script_⇲5977 Remediation_Shell_script_⇲
5978 #·Remediation·is·applicable·only·in·certain·platforms5978 #·Remediation·is·applicable·only·in·certain·platforms
5979 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then5979 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
5980 var_auditd_flush='incremental_async'5980 var_auditd_flush='incremental_async'
  
  
5981 AUDITCONFIG=/etc/audit/auditd.conf5981 AUDITCONFIG=/etc/audit/auditd.conf
  
5982 #·if·flush·is·present,·flush·param·edited·to·var_auditd_flush5982 #·if·flush·is·present,·flush·param·edited·to·var_auditd_flush
Offset 6038, 16 lines modifiedOffset 6038, 16 lines modified
6038 ··lineinfile:6038 ··lineinfile:
Max diff block lines reached; 22383/31395 bytes (71.29%) of diff not shown.
675 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-pci-dss.html
    
Offset 17079, 116 lines modifiedOffset 17079, 116 lines modified
00042b60:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm600042b60:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
00042b70:·3238·3422·2074·6162·696e·6465·783d·2230··284"·tabindex="000042b70:·3238·3422·2074·6162·696e·6465·783d·2230··284"·tabindex="0
00042b80:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00042b80:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00042b90:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00042b90:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00042ba0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00042ba0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00042bb0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00042bb0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00042bc0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00042bc0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00042bd0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·00042bd0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
00042be0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><00042be0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
00042bf0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p00042bf0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
00042c00:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co00042c00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
00042c10:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm600042c10:·6170·7365·2220·6964·3d22·6964·6d36·3238··apse"·id="idm628
00042c20:·3238·3422·3e3c·7461·626c·6520·636c·6173··284"><table·clas00042c20:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
00042c30:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s00042c30:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
00042c40:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor00042c40:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
00042c50:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond00042c50:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
00042c60:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C00042c60:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
00042c70:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><00042c70:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
00042c80:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00042c80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00042c90:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti00042c90:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
00042ca0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<00042ca0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00042cb0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00042cb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00042cc0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><00042cc0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00042cd0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></00042cd0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
00042ce0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>00042ce0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
00042cf0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
00042d00:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code00042cf0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 00042d00:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 00042d10:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 00042d20:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 00042d30:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 00042d40:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 00042d50:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 00042d60:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00042d70:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00042d80:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 00042d90:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00042da0:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628
 00042db0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·
 00042dc0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 00042dd0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 00042de0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 00042df0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 00042e00:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00042e10:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 00042e20:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00042e30:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00042e40:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00042e50:·2220·6964·3d22·6964·6d36·3238·3522·3e3c··"·id="idm6285"><
 00042e60:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 00042e70:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00042e80:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00042e90:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 00042ea0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 00042eb0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 00042ec0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00042ed0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00042ee0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00042ef0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 00042f00:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 00042f10:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 00042f20:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00042f30:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 00042f40:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 00042f50:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 00042f60:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 00042f70:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 00042f80:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 00042f90:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 00042fa0:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 00042fb0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 00042fc0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 00042fd0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 00042fe0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 00042ff0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 00043000:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 00043010:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 00043020:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 00043030:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
00042d10:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·00043040:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
00042d20:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s00043050:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
00042d30:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog00043060:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
00042d40:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d00043070:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
00042d50:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00043080:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00042d60:·3632·3835·2220·7461·6269·6e64·6578·3d22··6285"·tabindex="00043090:·3632·3836·2220·7461·6269·6e64·6578·3d22··6286"·tabindex="
00042d70:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"000430a0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00042d80:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="000430b0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00042d90:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac000430c0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00042da0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal000430d0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00042db0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme000430e0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00042dc0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s000430f0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
00042dd0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b00043100:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
00042de0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00043110:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
00042df0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00043120:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
00042e00:·6c61·7073·6522·2069·643d·2269·646d·3632··lapse"·id="idm6200043130:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
00042e10:·3835·223e·3c74·6162·6c65·2063·6c61·7373··85"><table·class00043140:·3632·3836·223e·3c74·6162·6c65·2063·6c61··6286"><table·cla
00042e20:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00043150:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
00042e30:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00043160:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
00042e40:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00043170:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
00042e50:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00043180:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
00042e60:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00043190:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
00042e70:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><000431a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
00042e80:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio000431b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
00042e90:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</000431c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
00042ea0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>000431d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00042eb0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t000431e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
00042ec0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t000431f0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
00042ed0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><00043200:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 00043210:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 00043220:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
00042ee0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
00042ef0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
00042f00:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
00042f10:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
00042f20:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
00042f30:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
00042f40:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
00042f50:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00042f60:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00042f70:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00042f80:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
00042f90:·612d·7461·7267·6574·3d22·2369·646d·3632··a-target="#idm62 
00042fa0:·3836·2220·7461·6269·6e64·6578·3d22·3022··86"·tabindex="0" 
00042fb0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00042fc0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00042fd0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00042fe0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 476699/491355 bytes (97.02%) of diff not shown.
196 KB
html2text {}
    
Offset 386, 20 lines modifiedOffset 386, 14 lines modified
386 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed386 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
387 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule387 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule
388 Remediation_OSBuild_Blueprint_snippet_⇲388 Remediation_OSBuild_Blueprint_snippet_⇲
  
389 [[packages]]389 [[packages]]
390 name·=·"aide"390 name·=·"aide"
391 version·=·"*"391 version·=·"*"
392 Remediation_Anaconda_snippet_⇲ 
393 Complexity:·low 
394 Disruption:·low 
395 Strategy:···enable 
  
396 package·--add=aide 
397 Remediation_Puppet_snippet_⇲392 Remediation_Puppet_snippet_⇲
398 Complexity:·low393 Complexity:·low
399 Disruption:·low394 Disruption:·low
400 Strategy:···enable395 Strategy:···enable
401 include·install_aide396 include·install_aide
  
402 class·install_aide·{397 class·install_aide·{
Offset 417, 14 lines modifiedOffset 411, 20 lines modified
417 if·!·rpm·-q·--quiet·"aide"·;·then411 if·!·rpm·-q·--quiet·"aide"·;·then
418 ····yum·install·-y·"aide"412 ····yum·install·-y·"aide"
419 fi413 fi
  
420 else414 else
421 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'415 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
422 fi416 fi
 417 Remediation_Anaconda_snippet_⇲
 418 Complexity:·low
 419 Disruption:·low
 420 Strategy:···enable
  
 421 package·--add=aide
423 Remediation_Ansible_snippet_⇲422 Remediation_Ansible_snippet_⇲
424 Complexity:·low423 Complexity:·low
425 Disruption:·low424 Disruption:·low
426 Strategy:···enable425 Strategy:···enable
427 -·name:·Ensure·aide·is·installed426 -·name:·Ensure·aide·is·installed
428 ··package:427 ··package:
429 ····name:·aide428 ····name:·aide
Offset 5635, 17 lines modifiedOffset 5635, 14 lines modified
5635 ***·Rule  ·Enable·Smart·Card·Login·  [ref]·***5635 ***·Rule  ·Enable·Smart·Card·Login·  [ref]·***
5636 To·enable·smart·card·authentication,·consult·the·documentation·at:5636 To·enable·smart·card·authentication,·consult·the·documentation·at:
5637 ····*·https://docs.oracle.com/en/operating-systems/oracle-linux/7/userauth/userauth-AuthenticationConfiguration.html#ol7-s4-auth5637 ····*·https://docs.oracle.com/en/operating-systems/oracle-linux/7/userauth/userauth-AuthenticationConfiguration.html#ol7-s4-auth
5638 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.5638 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.
5639 Severity: ················medium5639 Severity: ················medium
5640 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth5640 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth
5641 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-010500,·SV-221703r818811_rule5641 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-010500,·SV-221703r818811_rule
5642 Remediation_Anaconda_snippet_⇲ 
  
5643 package·--add=pam_pkcs11·--add=esc 
5644 Remediation_Shell_script_⇲5642 Remediation_Shell_script_⇲
5645 #·Remediation·is·applicable·only·in·certain·platforms5643 #·Remediation·is·applicable·only·in·certain·platforms
5646 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·!·grep·-q·s390x·/proc/sys/kernel/osrelease;·};·then5644 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·!·grep·-q·s390x·/proc/sys/kernel/osrelease;·};·then
  
5647 #·Install·required·packages5645 #·Install·required·packages
5648 if·!·rpm·-q·--quiet·"esc"·;·then5646 if·!·rpm·-q·--quiet·"esc"·;·then
5649 ····yum·install·-y·"esc"5647 ····yum·install·-y·"esc"
Offset 5750, 14 lines modifiedOffset 5747, 17 lines modified
5750 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,5747 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,
5751 #·which·does·not·contain·it·yet5748 #·which·does·not·contain·it·yet
5752 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"5749 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"
  
5753 else5750 else
5754 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5751 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5755 fi5752 fi
 5753 Remediation_Anaconda_snippet_⇲
  
 5754 package·--add=pam_pkcs11·--add=esc
5756 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules5755 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules
5757 [ref]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.5756 [ref]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.
5758 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules5757 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules
5759 [ref]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:5758 [ref]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:
5760 $·sudo·chage·-I·NUM_DAYS·USER5759 $·sudo·chage·-I·NUM_DAYS·USER
5761 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.5760 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.
5762 Warning: ·This·will·only·apply·to·newly·created·accounts5761 Warning: ·This·will·only·apply·to·newly·created·accounts
Offset 6220, 15 lines modifiedOffset 6220, 15 lines modified
6220 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.6220 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
6221 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.6221 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
6222 Severity: ················medium6222 Severity: ················medium
6223 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod6223 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
6224 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule6224 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule
6225 Remediation_Shell_script_⇲6225 Remediation_Shell_script_⇲
6226 #·Remediation·is·applicable·only·in·certain·platforms6226 #·Remediation·is·applicable·only·in·certain·platforms
6227 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then6227 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
6228 #·First·perform·the·remediation·of·the·syscall·rule6228 #·First·perform·the·remediation·of·the·syscall·rule
6229 #·Retrieve·hardware·architecture·of·the·underlying·system6229 #·Retrieve·hardware·architecture·of·the·underlying·system
6230 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6230 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6231 for·ARCH·in·"${RULE_ARCHS[@]}"6231 for·ARCH·in·"${RULE_ARCHS[@]}"
6232 do6232 do
Offset 6575, 16 lines modifiedOffset 6575, 16 lines modified
6575 ··-·reboot_required6575 ··-·reboot_required
6576 ··-·restrict_strategy6576 ··-·restrict_strategy
  
6577 -·name:·Set·architecture·for·audit·chmod·tasks6577 -·name:·Set·architecture·for·audit·chmod·tasks
6578 ··set_fact:6578 ··set_fact:
6579 ····audit_arch:·b646579 ····audit_arch:·b64
6580 ··when:6580 ··when:
6581 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6582 ··-·'"audit"·in·ansible_facts.packages'6581 ··-·'"audit"·in·ansible_facts.packages'
 6582 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6583 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6583 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6584 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6584 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6585 ··tags:6585 ··tags:
6586 ··-·CJIS-5.4.1.16586 ··-·CJIS-5.4.1.1
6587 ··-·DISA-STIG-OL07-00-0304106587 ··-·DISA-STIG-OL07-00-030410
6588 ··-·NIST-800-171-3.1.76588 ··-·NIST-800-171-3.1.7
6589 ··-·NIST-800-53-AU-12(c)6589 ··-·NIST-800-53-AU-12(c)
Offset 6721, 16 lines modifiedOffset 6721, 16 lines modified
6721 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006721 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6722 ········-F·auid!=unset·-F·key=perm_mod6722 ········-F·auid!=unset·-F·key=perm_mod
6723 ······create:·true6723 ······create:·true
6724 ······mode:·o-rwx6724 ······mode:·o-rwx
6725 ······state:·present6725 ······state:·present
6726 ····when:·syscalls_found·|·length·==·06726 ····when:·syscalls_found·|·length·==·0
6727 ··when:6727 ··when:
6728 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6729 ··-·'"audit"·in·ansible_facts.packages'6728 ··-·'"audit"·in·ansible_facts.packages'
 6729 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6730 ··tags:6730 ··tags:
6731 ··-·CJIS-5.4.1.16731 ··-·CJIS-5.4.1.1
6732 ··-·DISA-STIG-OL07-00-0304106732 ··-·DISA-STIG-OL07-00-030410
6733 ··-·NIST-800-171-3.1.76733 ··-·NIST-800-171-3.1.7
6734 ··-·NIST-800-53-AU-12(c)6734 ··-·NIST-800-53-AU-12(c)
Max diff block lines reached; 190601/200171 bytes (95.22%) of diff not shown.
61.0 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-sap.html
    
Offset 14674, 104 lines modifiedOffset 14674, 104 lines modified
00039510:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00039510:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00039520:·6d39·3636·3822·2074·6162·696e·6465·783d··m9668"·tabindex=00039520:·6d39·3636·3822·2074·6162·696e·6465·783d··m9668"·tabindex=
00039530:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button00039530:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
00039540:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=00039540:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00039550:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A00039550:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
00039560:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea00039560:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
00039570:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem00039570:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
00039580:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond00039580:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
00039590:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a00039590:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
000395a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=000395a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
000395b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·000395b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000395c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id000395c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9
000395d0:·6d39·3636·3822·3e3c·7461·626c·6520·636c··m9668"><table·cl000395d0:·3636·3822·3e3c·7461·626c·6520·636c·6173··668"><table·clas
000395e0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table000395e0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
000395f0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b000395f0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
00039600:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co00039600:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00039610:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th00039610:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
00039620:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th00039620:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
00039630:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t00039630:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00039640:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup00039640:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
00039650:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo00039650:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
00039660:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00039660:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00039670:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th00039670:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00039680:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>00039680:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
00039690:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr00039690:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
000396a0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
000396b0:·202d·2d61·6464·3d67·6c69·6263·0a3c·2f63···--add=glibc.</c 
000396c0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
000396d0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
000396e0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
000396f0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00039700:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00039710:·6964·6d39·3636·3922·2074·6162·696e·6465··idm9669"·tabinde 
00039720:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00039730:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00039740:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00039750:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
00039760:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
00039770:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe 
00039780:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
00039790:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
000397a0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
000397b0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
000397c0:·6d39·3636·3922·3e3c·7461·626c·6520·636c··m9669"><table·cl 
000397d0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
000397e0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
000397f0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00039800:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00039810:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00039820:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00039830:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00039840:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
00039850:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00039860:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00039870:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00039880:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00039890:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·000396a0:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
000398a0:·696e·7374·616c·6c5f·676c·6962·630a·0a63··install_glibc..c000396b0:·7374·616c·6c5f·676c·6962·630a·0a63·6c61··stall_glibc..cla
000398b0:·6c61·7373·2069·6e73·7461·6c6c·5f67·6c69··lass·install_gli000396c0:·7373·2069·6e73·7461·6c6c·5f67·6c69·6263··ss·install_glibc
000398c0:·6263·207b·0a20·2070·6163·6b61·6765·207b··bc·{.··package·{000396d0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
000398d0:·2027·676c·6962·6327·3a0a·2020·2020·656e···'glibc':.····en000396e0:·676c·6962·6327·3a0a·2020·2020·656e·7375··glibc':.····ensu
000398e0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst000396f0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
000398f0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</00039700:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
00039900:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div00039710:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
00039910:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b00039720:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
00039920:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data00039730:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
00039930:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps00039740:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
00039940:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00039750:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
00039950:·2369·646d·3936·3730·2220·7461·6269·6e64··#idm9670"·tabind00039760:·646d·3936·3639·2220·7461·6269·6e64·6578··dm9669"·tabindex
00039960:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00039770:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00039970:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00039780:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00039980:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00039790:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00039990:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re000397a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
000399a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">000397b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
000399b0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel000397c0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
000399c0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>000397d0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
000399d0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="000397e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
000399e0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c000397f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
000399f0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm00039800:·6c61·7073·6522·2069·643d·2269·646d·3936··lapse"·id="idm96
00039a00:·3936·3730·223e·3c74·6162·6c65·2063·6c61··9670"><table·cla00039810:·3639·223e·3c74·6162·6c65·2063·6c61·7373··69"><table·class
00039a10:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-00039820:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
00039a20:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo00039830:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00039a30:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con00039840:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
00039a40:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>00039850:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
00039a50:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>00039860:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00039a60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr00039870:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00039a70:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt00039880:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00039a80:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low00039890:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00039a90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t000398a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00039aa0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>000398b0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00039ab0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><000398c0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
00039ac0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre000398d0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
00039ad0:·3e3c·636f·6465·3e0a·6966·2021·2072·706d··><code>.if·!·rpm000398e0:·636f·6465·3e0a·6966·2021·2072·706d·202d··code>.if·!·rpm·-
00039ae0:·202d·7120·2d2d·7175·6965·7420·2267·6c69···-q·--quiet·"gli000398f0:·7120·2d2d·7175·6965·7420·2267·6c69·6263··q·--quiet·"glibc
00039af0:·6263·2220·3b20·7468·656e·0a20·2020·2079··bc"·;·then.····y00039900:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
00039b00:·756d·2069·6e73·7461·6c6c·202d·7920·2267··um·install·-y·"g00039910:·2069·6e73·7461·6c6c·202d·7920·2267·6c69···install·-y·"gli
00039b10:·6c69·6263·220a·6669·0a3c·2f63·6f64·653e··libc".fi.</code>00039920:·6263·220a·6669·0a3c·2f63·6f64·653e·3c2f··bc".fi.</code></
 00039930:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00039940:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00039950:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 00039960:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00039970:·2d74·6172·6765·743d·2223·6964·6d39·3637··-target="#idm967
 00039980:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
 00039990:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 000399a0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 000399b0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 000399c0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 000399d0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 000399e0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
 000399f0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00039a00:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00039a10:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00039a20:·6170·7365·2220·6964·3d22·6964·6d39·3637··apse"·id="idm967
 00039a30:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
 00039a40:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 00039a50:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 00039a60:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 00039a70:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 00039a80:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 00039a90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00039aa0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 00039ab0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00039ac0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00039ad0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00039ae0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00039af0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00039b00:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
Max diff block lines reached; 44382/57382 bytes (77.34%) of diff not shown.
4.81 KB
html2text {}
    
Offset 70, 20 lines modifiedOffset 70, 14 lines modified
70 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_glibc_installed70 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_glibc_installed
71 Identifiers·and·References71 Identifiers·and·References
72 Remediation_OSBuild_Blueprint_snippet_⇲72 Remediation_OSBuild_Blueprint_snippet_⇲
  
73 [[packages]]73 [[packages]]
74 name·=·"glibc"74 name·=·"glibc"
75 version·=·"*"75 version·=·"*"
76 Remediation_Anaconda_snippet_⇲ 
77 Complexity:·low 
78 Disruption:·low 
79 Strategy:···enable 
  
80 package·--add=glibc 
81 Remediation_Puppet_snippet_⇲76 Remediation_Puppet_snippet_⇲
82 Complexity:·low77 Complexity:·low
83 Disruption:·low78 Disruption:·low
84 Strategy:···enable79 Strategy:···enable
85 include·install_glibc80 include·install_glibc
  
86 class·install_glibc·{81 class·install_glibc·{
Offset 95, 14 lines modifiedOffset 89, 20 lines modified
95 Complexity:·low89 Complexity:·low
96 Disruption:·low90 Disruption:·low
97 Strategy:···enable91 Strategy:···enable
  
98 if·!·rpm·-q·--quiet·"glibc"·;·then92 if·!·rpm·-q·--quiet·"glibc"·;·then
99 ····yum·install·-y·"glibc"93 ····yum·install·-y·"glibc"
100 fi94 fi
 95 Remediation_Anaconda_snippet_⇲
 96 Complexity:·low
 97 Disruption:·low
 98 Strategy:···enable
  
 99 package·--add=glibc
101 Remediation_Ansible_snippet_⇲100 Remediation_Ansible_snippet_⇲
102 Complexity:·low101 Complexity:·low
103 Disruption:·low102 Disruption:·low
104 Strategy:···enable103 Strategy:···enable
105 -·name:·Ensure·glibc·is·installed104 -·name:·Ensure·glibc·is·installed
106 ··package:105 ··package:
107 ····name:·glibc106 ····name:·glibc
Offset 124, 20 lines modifiedOffset 124, 14 lines modified
124 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_uuidd_installed124 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_uuidd_installed
125 Identifiers·and·References125 Identifiers·and·References
126 Remediation_OSBuild_Blueprint_snippet_⇲126 Remediation_OSBuild_Blueprint_snippet_⇲
  
127 [[packages]]127 [[packages]]
128 name·=·"uuidd"128 name·=·"uuidd"
129 version·=·"*"129 version·=·"*"
130 Remediation_Anaconda_snippet_⇲ 
131 Complexity:·low 
132 Disruption:·low 
133 Strategy:···enable 
  
134 package·--add=uuidd 
135 Remediation_Puppet_snippet_⇲130 Remediation_Puppet_snippet_⇲
136 Complexity:·low131 Complexity:·low
137 Disruption:·low132 Disruption:·low
138 Strategy:···enable133 Strategy:···enable
139 include·install_uuidd134 include·install_uuidd
  
140 class·install_uuidd·{135 class·install_uuidd·{
Offset 149, 14 lines modifiedOffset 143, 20 lines modified
149 Complexity:·low143 Complexity:·low
150 Disruption:·low144 Disruption:·low
151 Strategy:···enable145 Strategy:···enable
  
152 if·!·rpm·-q·--quiet·"uuidd"·;·then146 if·!·rpm·-q·--quiet·"uuidd"·;·then
153 ····yum·install·-y·"uuidd"147 ····yum·install·-y·"uuidd"
154 fi148 fi
 149 Remediation_Anaconda_snippet_⇲
 150 Complexity:·low
 151 Disruption:·low
 152 Strategy:···enable
  
 153 package·--add=uuidd
155 Remediation_Ansible_snippet_⇲154 Remediation_Ansible_snippet_⇲
156 Complexity:·low155 Complexity:·low
157 Disruption:·low156 Disruption:·low
158 Strategy:···enable157 Strategy:···enable
159 -·name:·Ensure·uuidd·is·installed158 -·name:·Ensure·uuidd·is·installed
160 ··package:159 ··package:
161 ····name:·uuidd160 ····name:·uuidd
Offset 368, 20 lines modifiedOffset 368, 14 lines modified
368 NIS·client·(ypbind)·was·used·to·bind·a·system·to·an·NIS·server·and·receive·the·distributed·configuration·files.368 NIS·client·(ypbind)·was·used·to·bind·a·system·to·an·NIS·server·and·receive·the·distributed·configuration·files.
369 ···························The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to·DOS·attacks,·buffer·overflows·and·has·poor·authentication·for369 ···························The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to·DOS·attacks,·buffer·overflows·and·has·poor·authentication·for
370 Rationale:·················querying·NIS·maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight·Directory·Access·Protocol·(LDAP).·It·is·recommended·that370 Rationale:·················querying·NIS·maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight·Directory·Access·Protocol·(LDAP).·It·is·recommended·that
371 ···························the·service·be·removed.371 ···························the·service·be·removed.
372 Severity: ················unknown372 Severity: ················unknown
373 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_ypbind_removed373 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_ypbind_removed
374 Identifiers·and·References·References: ·BP28(R1),·164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.310(b),·164.312(e)(1),·164.312(e)(2)(ii)374 Identifiers·and·References·References: ·BP28(R1),·164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.310(b),·164.312(e)(1),·164.312(e)(2)(ii)
375 Remediation_Anaconda_snippet_⇲ 
376 Complexity:·low 
377 Disruption:·low 
378 Strategy:···disable 
  
379 package·--remove=ypbind 
380 Remediation_Puppet_snippet_⇲375 Remediation_Puppet_snippet_⇲
381 Complexity:·low376 Complexity:·low
382 Disruption:·low377 Disruption:·low
383 Strategy:···disable378 Strategy:···disable
384 include·remove_ypbind379 include·remove_ypbind
  
385 class·remove_ypbind·{380 class·remove_ypbind·{
Offset 401, 14 lines modifiedOffset 395, 20 lines modified
401 #»      ···system!395 #»      ···system!
  
402 if·rpm·-q·--quiet·"ypbind"·;·then396 if·rpm·-q·--quiet·"ypbind"·;·then
  
403 ····yum·remove·-y·"ypbind"397 ····yum·remove·-y·"ypbind"
  
404 fi398 fi
 399 Remediation_Anaconda_snippet_⇲
 400 Complexity:·low
 401 Disruption:·low
 402 Strategy:···disable
  
 403 package·--remove=ypbind
405 Remediation_Ansible_snippet_⇲404 Remediation_Ansible_snippet_⇲
406 Complexity:·low405 Complexity:·low
407 Disruption:·low406 Disruption:·low
408 Strategy:···disable407 Strategy:···disable
409 -·name:·Ensure·ypbind·is·removed408 -·name:·Ensure·ypbind·is·removed
410 ··package:409 ··package:
411 ····name:·ypbind410 ····name:·ypbind
Offset 430, 20 lines modifiedOffset 430, 14 lines modified
430 ············References: ·BP28(R1),·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·CCI-000381,430 ············References: ·BP28(R1),·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·CCI-000381,
Max diff block lines reached; 1394/4903 bytes (28.43%) of diff not shown.
587 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-standard.html
    
Offset 23976, 21 lines modifiedOffset 23976, 21 lines modified
0005da70:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0005da70:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0005da80:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0005da80:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0005da90:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm20005da90:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
0005daa0:·3135·3531·223e·3c70·7265·3e3c·636f·6465··1551"><pre><code0005daa0:·3135·3531·223e·3c70·7265·3e3c·636f·6465··1551"><pre><code
0005dab0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i0005dab0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
0005dac0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl0005dac0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
0005dad0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla0005dad0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
0005dae0:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f0005dae0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
0005daf0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&0005daf0:·7175·6965·7420·2d71·2061·7564·6974·2026··quiet·-q·audit·&
0005db00:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f0005db00:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 0005db10:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 0005db20:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
0005db10:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container0005db30:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
0005db20:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp; 
0005db30:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0005db40:·6175·6469·743b·2074·6865·6e0a·0a23·2046··audit;·then..#·F0005db40:·656e·7620·5d3b·2074·6865·6e0a·0a23·2046··env·];·then..#·F
0005db50:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the0005db50:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the
0005db60:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·0005db60:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·
0005db70:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule0005db70:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule
0005db80:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard0005db80:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard
0005db90:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur0005db90:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur
0005dba0:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly0005dba0:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly
0005dbb0:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(0005dbb0:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(
Offset 24870, 23 lines modifiedOffset 24870, 23 lines modified
00061250:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_00061250:·6564·0a20·202d·2072·6573·7472·6963·745f··ed.··-·restrict_
00061260:·7374·7261·7465·6779·0a0a·2d20·6e61·6d65··strategy..-·name00061260:·7374·7261·7465·6779·0a0a·2d20·6e61·6d65··strategy..-·name
00061270:·3a20·5365·7420·6172·6368·6974·6563·7475··:·Set·architectu00061270:·3a20·5365·7420·6172·6368·6974·6563·7475··:·Set·architectu
00061280:·7265·2066·6f72·2061·7564·6974·2063·686d··re·for·audit·chm00061280:·7265·2066·6f72·2061·7564·6974·2063·686d··re·for·audit·chm
00061290:·6f64·2074·6173·6b73·0a20·2073·6574·5f66··od·tasks.··set_f00061290:·6f64·2074·6173·6b73·0a20·2073·6574·5f66··od·tasks.··set_f
000612a0:·6163·743a·0a20·2020·2061·7564·6974·5f61··act:.····audit_a000612a0:·6163·743a·0a20·2020·2061·7564·6974·5f61··act:.····audit_a
000612b0:·7263·683a·2062·3634·0a20·2077·6865·6e3a··rch:·b64.··when:000612b0:·7263·683a·2062·3634·0a20·2077·6865·6e3a··rch:·b64.··when:
000612c0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
000612d0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
000612e0:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
000612f0:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
00061300:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
00061310:·6f6e·7461·696e·6572·225d·0a20·202d·2027··ontainer"].··-·' 
00061320:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib 
00061330:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package000612c0:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 000612d0:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 000612e0:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans
 000612f0:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 00061300:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 00061310:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 00061320:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 00061330:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
00061340:·7327·0a20·202d·2061·6e73·6962·6c65·5f61··s'.··-·ansible_a00061340:·225d·0a20·202d·2061·6e73·6962·6c65·5f61··"].··-·ansible_a
00061350:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"00061350:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"
00061360:·6161·7263·6836·3422·206f·7220·616e·7369··aarch64"·or·ansi00061360:·6161·7263·6836·3422·206f·7220·616e·7369··aarch64"·or·ansi
00061370:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture00061370:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
00061380:·203d·3d20·2270·7063·3634·2220·6f72·2061···==·"ppc64"·or·a00061380:·203d·3d20·2270·7063·3634·2220·6f72·2061···==·"ppc64"·or·a
00061390:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect00061390:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
000613a0:·7572·650a·2020·2020·3d3d·2022·7070·6336··ure.····==·"ppc6000613a0:·7572·650a·2020·2020·3d3d·2022·7070·6336··ure.····==·"ppc6
000613b0:·346c·6522·206f·7220·616e·7369·626c·655f··4le"·or·ansible_000613b0:·346c·6522·206f·7220·616e·7369·626c·655f··4le"·or·ansible_
Offset 25193, 23 lines modifiedOffset 25193, 23 lines modified
00062680:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····00062680:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····
00062690:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··00062690:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··
000626a0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.000626a0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.
000626b0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre000626b0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre
000626c0:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s000626c0:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s
000626d0:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·000626d0:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·
000626e0:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh000626e0:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh
000626f0:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_ 
00062700:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
00062710:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
00062720:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
00062730:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
00062740:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].·· 
00062750:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an 
00062760:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack000626f0:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit"
 00062700:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 00062710:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·
 00062720:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 00062730:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 00062740:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 00062750:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 00062760:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
00062770:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··00062770:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··
00062780:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·00062780:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
00062790:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL000062790:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL0
000627a0:·372d·3030·2d30·3330·3431·300a·2020·2d20··7-00-030410.··-·000627a0:·372d·3030·2d30·3330·3431·300a·2020·2d20··7-00-030410.··-·
000627b0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1000627b0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
000627c0:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-000627c0:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-
000627d0:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·000627d0:·3533·2d41·552d·3132·2863·290a·2020·2d20··53-AU-12(c).··-·
000627e0:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-2000627e0:·4e49·5354·2d38·3030·2d35·332d·4155·2d32··NIST-800-53-AU-2
Offset 25505, 22 lines modifiedOffset 25505, 22 lines modified
00063a00:·5f6d·6f64·0a20·2020·2020·2063·7265·6174··_mod.······creat00063a00:·5f6d·6f64·0a20·2020·2020·2063·7265·6174··_mod.······creat
00063a10:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo00063a10:·653a·2074·7275·650a·2020·2020·2020·6d6f··e:·true.······mo
00063a20:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······00063a20:·6465·3a20·6f2d·7277·780a·2020·2020·2020··de:·o-rwx.······
00063a30:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·00063a30:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
00063a40:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall00063a40:·2020·2077·6865·6e3a·2073·7973·6361·6c6c·····when:·syscall
00063a50:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length00063a50:·735f·666f·756e·6420·7c20·6c65·6e67·7468··s_found·|·length
00063a60:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··00063a60:·203d·3d20·300a·2020·7768·656e·3a0a·2020···==·0.··when:.··
00063a70:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
00063a80:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
00063a90:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
00063aa0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
00063ab0:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont 
00063ac0:·6169·6e65·7222·5d0a·2020·2d20·2722·6175··ainer"].··-·'"au 
00063ad0:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
00063ae0:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'.00063a70:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 00063a80:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 00063a90:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl
 00063aa0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 00063ab0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 00063ac0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 00063ad0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 00063ae0:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
00063af0:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=00063af0:·2020·2d20·6175·6469·745f·6172·6368·203d····-·audit_arch·=
00063b00:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.00063b00:·3d20·2262·3634·220a·2020·7461·6773·3a0a··=·"b64".··tags:.
00063b10:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.100063b10:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1
00063b20:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O00063b20:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O
00063b30:·4c30·372d·3030·2d30·3330·3431·300a·2020··L07-00-030410.··00063b30:·4c30·372d·3030·2d30·3330·3431·300a·2020··L07-00-030410.··
00063b40:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-300063b40:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
00063b50:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-8000063b50:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80
Offset 26473, 20 lines modifiedOffset 26473, 20 lines modified
00067680:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00067680:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00067690:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00067690:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
000676a0:·2220·6964·3d22·6964·6d32·3137·3039·223e··"·id="idm21709">000676a0:·2220·6964·3d22·6964·6d32·3137·3039·223e··"·id="idm21709">
000676b0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem000676b0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
000676c0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl000676c0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
000676d0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c000676d0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
000676e0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms000676e0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 000676f0:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet·
 00067700:·2d71·2061·7564·6974·2026·616d·703b·2661··-q·audit·&amp;&a
000676f0:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc00067710:·6d70·3b20·5b20·2120·2d66·202f·2e64·6f63··mp;·[·!·-f·/.doc
00067700:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a00067720:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
Max diff block lines reached; 395455/405314 bytes (97.57%) of diff not shown.
191 KB
html2text {}
    
Offset 955, 15 lines modifiedOffset 955, 15 lines modified
955 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.955 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
956 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.956 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
957 Severity: ················medium957 Severity: ················medium
958 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod958 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
959 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule959 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030410,·SV-221782r810497_rule
960 Remediation_Shell_script_⇲960 Remediation_Shell_script_⇲
961 #·Remediation·is·applicable·only·in·certain·platforms961 #·Remediation·is·applicable·only·in·certain·platforms
962 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then962 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
963 #·First·perform·the·remediation·of·the·syscall·rule963 #·First·perform·the·remediation·of·the·syscall·rule
964 #·Retrieve·hardware·architecture·of·the·underlying·system964 #·Retrieve·hardware·architecture·of·the·underlying·system
965 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")965 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
966 for·ARCH·in·"${RULE_ARCHS[@]}"966 for·ARCH·in·"${RULE_ARCHS[@]}"
967 do967 do
Offset 1310, 16 lines modifiedOffset 1310, 16 lines modified
1310 ··-·reboot_required1310 ··-·reboot_required
1311 ··-·restrict_strategy1311 ··-·restrict_strategy
  
1312 -·name:·Set·architecture·for·audit·chmod·tasks1312 -·name:·Set·architecture·for·audit·chmod·tasks
1313 ··set_fact:1313 ··set_fact:
1314 ····audit_arch:·b641314 ····audit_arch:·b64
1315 ··when:1315 ··when:
1316 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1317 ··-·'"audit"·in·ansible_facts.packages'1316 ··-·'"audit"·in·ansible_facts.packages'
 1317 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1318 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1318 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1319 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1319 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1320 ··tags:1320 ··tags:
1321 ··-·CJIS-5.4.1.11321 ··-·CJIS-5.4.1.1
1322 ··-·DISA-STIG-OL07-00-0304101322 ··-·DISA-STIG-OL07-00-030410
1323 ··-·NIST-800-171-3.1.71323 ··-·NIST-800-171-3.1.7
1324 ··-·NIST-800-53-AU-12(c)1324 ··-·NIST-800-53-AU-12(c)
Offset 1456, 16 lines modifiedOffset 1456, 16 lines modified
1456 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001456 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1457 ········-F·auid!=unset·-F·key=perm_mod1457 ········-F·auid!=unset·-F·key=perm_mod
1458 ······create:·true1458 ······create:·true
1459 ······mode:·o-rwx1459 ······mode:·o-rwx
1460 ······state:·present1460 ······state:·present
1461 ····when:·syscalls_found·|·length·==·01461 ····when:·syscalls_found·|·length·==·0
1462 ··when:1462 ··when:
1463 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1464 ··-·'"audit"·in·ansible_facts.packages'1463 ··-·'"audit"·in·ansible_facts.packages'
 1464 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1465 ··tags:1465 ··tags:
1466 ··-·CJIS-5.4.1.11466 ··-·CJIS-5.4.1.1
1467 ··-·DISA-STIG-OL07-00-0304101467 ··-·DISA-STIG-OL07-00-030410
1468 ··-·NIST-800-171-3.1.71468 ··-·NIST-800-171-3.1.7
1469 ··-·NIST-800-53-AU-12(c)1469 ··-·NIST-800-53-AU-12(c)
1470 ··-·NIST-800-53-AU-2(d)1470 ··-·NIST-800-53-AU-2(d)
1471 ··-·NIST-800-53-CM-6(a)1471 ··-·NIST-800-53-CM-6(a)
Offset 1600, 16 lines modifiedOffset 1600, 16 lines modified
1600 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001600 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1601 ········-F·auid!=unset·-F·key=perm_mod1601 ········-F·auid!=unset·-F·key=perm_mod
1602 ······create:·true1602 ······create:·true
1603 ······mode:·o-rwx1603 ······mode:·o-rwx
1604 ······state:·present1604 ······state:·present
1605 ····when:·syscalls_found·|·length·==·01605 ····when:·syscalls_found·|·length·==·0
1606 ··when:1606 ··when:
1607 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1608 ··-·'"audit"·in·ansible_facts.packages'1607 ··-·'"audit"·in·ansible_facts.packages'
 1608 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1609 ··-·audit_arch·==·"b64"1609 ··-·audit_arch·==·"b64"
1610 ··tags:1610 ··tags:
1611 ··-·CJIS-5.4.1.11611 ··-·CJIS-5.4.1.1
1612 ··-·DISA-STIG-OL07-00-0304101612 ··-·DISA-STIG-OL07-00-030410
1613 ··-·NIST-800-171-3.1.71613 ··-·NIST-800-171-3.1.7
1614 ··-·NIST-800-53-AU-12(c)1614 ··-·NIST-800-53-AU-12(c)
1615 ··-·NIST-800-53-AU-2(d)1615 ··-·NIST-800-53-AU-2(d)
Offset 1633, 15 lines modifiedOffset 1633, 15 lines modified
1633 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1633 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1634 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1634 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1635 Severity: ················medium1635 Severity: ················medium
1636 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown1636 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
1637 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030370,·SV-221778r810481_rule1637 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL07-00-030370,·SV-221778r810481_rule
1638 Remediation_Shell_script_⇲1638 Remediation_Shell_script_⇲
1639 #·Remediation·is·applicable·only·in·certain·platforms1639 #·Remediation·is·applicable·only·in·certain·platforms
1640 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1640 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1641 #·First·perform·the·remediation·of·the·syscall·rule1641 #·First·perform·the·remediation·of·the·syscall·rule
1642 #·Retrieve·hardware·architecture·of·the·underlying·system1642 #·Retrieve·hardware·architecture·of·the·underlying·system
1643 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1643 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1644 for·ARCH·in·"${RULE_ARCHS[@]}"1644 for·ARCH·in·"${RULE_ARCHS[@]}"
1645 do1645 do
Offset 1988, 16 lines modifiedOffset 1988, 16 lines modified
1988 ··-·reboot_required1988 ··-·reboot_required
1989 ··-·restrict_strategy1989 ··-·restrict_strategy
  
1990 -·name:·Set·architecture·for·audit·chown·tasks1990 -·name:·Set·architecture·for·audit·chown·tasks
1991 ··set_fact:1991 ··set_fact:
1992 ····audit_arch:·b641992 ····audit_arch:·b64
1993 ··when:1993 ··when:
1994 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1995 ··-·'"audit"·in·ansible_facts.packages'1994 ··-·'"audit"·in·ansible_facts.packages'
 1995 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1996 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1996 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1997 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1997 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1998 ··tags:1998 ··tags:
1999 ··-·CJIS-5.4.1.11999 ··-·CJIS-5.4.1.1
2000 ··-·DISA-STIG-OL07-00-0303702000 ··-·DISA-STIG-OL07-00-030370
2001 ··-·NIST-800-171-3.1.72001 ··-·NIST-800-171-3.1.7
2002 ··-·NIST-800-53-AU-12(c)2002 ··-·NIST-800-53-AU-12(c)
Offset 2136, 16 lines modifiedOffset 2136, 16 lines modified
2136 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002136 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2137 ········-F·auid!=unset·-F·key=perm_mod2137 ········-F·auid!=unset·-F·key=perm_mod
2138 ······create:·true2138 ······create:·true
2139 ······mode:·o-rwx2139 ······mode:·o-rwx
2140 ······state:·present2140 ······state:·present
2141 ····when:·syscalls_found·|·length·==·02141 ····when:·syscalls_found·|·length·==·0
2142 ··when:2142 ··when:
2143 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2144 ··-·'"audit"·in·ansible_facts.packages'2143 ··-·'"audit"·in·ansible_facts.packages'
 2144 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2145 ··tags:2145 ··tags:
2146 ··-·CJIS-5.4.1.12146 ··-·CJIS-5.4.1.1
2147 ··-·DISA-STIG-OL07-00-0303702147 ··-·DISA-STIG-OL07-00-030370
2148 ··-·NIST-800-171-3.1.72148 ··-·NIST-800-171-3.1.7
2149 ··-·NIST-800-53-AU-12(c)2149 ··-·NIST-800-53-AU-12(c)
2150 ··-·NIST-800-53-AU-2(d)2150 ··-·NIST-800-53-AU-2(d)
2151 ··-·NIST-800-53-CM-6(a)2151 ··-·NIST-800-53-CM-6(a)
Offset 2282, 16 lines modifiedOffset 2282, 16 lines modified
2282 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002282 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2283 ········-F·auid!=unset·-F·key=perm_mod2283 ········-F·auid!=unset·-F·key=perm_mod
2284 ······create:·true2284 ······create:·true
2285 ······mode:·o-rwx2285 ······mode:·o-rwx
2286 ······state:·present2286 ······state:·present
Max diff block lines reached; 186557/195552 bytes (95.40%) of diff not shown.
1.13 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-stig.html
    
Offset 18035, 116 lines modifiedOffset 18035, 116 lines modified
00046720:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00046720:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00046730:·6964·6d36·3238·3422·2074·6162·696e·6465··idm6284"·tabinde00046730:·6964·6d36·3238·3422·2074·6162·696e·6465··idm6284"·tabinde
00046740:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00046740:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
00046750:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00046750:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
00046760:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00046760:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
00046770:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00046770:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
00046780:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00046780:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
00046790:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco00046790:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
000467a0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<000467a0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
000467b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas000467b0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
000467c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps000467c0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
000467d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="000467d0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
000467e0:·6964·6d36·3238·3422·3e3c·7461·626c·6520··idm6284"><table·000467e0:·6d36·3238·3422·3e3c·7461·626c·6520·636c··m6284"><table·cl
000467f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab000467f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
00046800:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00046800:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
00046810:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00046810:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
00046820:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00046820:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
00046830:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00046830:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
00046840:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00046840:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00046850:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00046850:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
00046860:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00046860:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
00046870:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00046870:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
00046880:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</00046880:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
00046890:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t00046890:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
000468a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><000468a0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
000468b0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
000468c0:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</000468b0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 000468c0:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 000468d0:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 000468e0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 000468f0:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 00046900:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 00046910:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 00046920:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00046930:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00046940:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 00046950:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 00046960:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00046970:·6d36·3238·3522·2074·6162·696e·6465·783d··m6285"·tabindex=
 00046980:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00046990:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 000469a0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 000469b0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 000469c0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 000469d0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 000469e0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 000469f0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00046a00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00046a10:·6170·7365·2220·6964·3d22·6964·6d36·3238··apse"·id="idm628
 00046a20:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=
 00046a30:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 00046a40:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 00046a50:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 00046a60:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 00046a70:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 00046a80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00046a90:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 00046aa0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00046ab0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00046ac0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00046ad0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00046ae0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00046af0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 00046b00:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 00046b10:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 00046b20:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
 00046b30:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
 00046b40:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
 00046b50:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 00046b60:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
 00046b70:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 00046b80:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 00046b90:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 00046ba0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 00046bb0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 00046bc0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 00046bd0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 00046be0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 00046bf0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
000468d0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div00046c00:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
000468e0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b00046c10:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
000468f0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data00046c20:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
00046900:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps00046c30:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
00046910:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00046c40:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00046920:·2369·646d·3632·3835·2220·7461·6269·6e64··#idm6285"·tabind00046c50:·2369·646d·3632·3836·2220·7461·6269·6e64··#idm6286"·tabind
00046930:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00046c60:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00046940:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00046c70:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
00046950:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00046c80:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00046960:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00046c90:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00046970:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00046ca0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00046980:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp00046cb0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
00046990:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</00046cc0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
000469a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class00046cd0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000469b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse00046ce0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000469c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i00046cf0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
000469d0:·646d·3632·3835·223e·3c74·6162·6c65·2063··dm6285"><table·c00046d00:·2269·646d·3632·3836·223e·3c74·6162·6c65··"idm6286"><table
000469e0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl00046d10:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
000469f0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-00046d20:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00046a00:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c00046d30:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00046a10:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t00046d40:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
00046a20:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t00046d50:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00046a30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00046d60:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00046a40:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru00046d70:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
00046a50:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l00046d80:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00046a60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00046d90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00046a70:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t00046da0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
00046a80:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td00046db0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
00046a90:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p00046dc0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00046dd0:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 00046de0:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
00046aa0:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
00046ab0:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
00046ac0:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
00046ad0:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
00046ae0:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
00046af0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
00046b00:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
00046b10:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00046b20:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00046b30:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00046b40:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
00046b50:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
00046b60:·646d·3632·3836·2220·7461·6269·6e64·6578··dm6286"·tabindex 
00046b70:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00046b80:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00046b90:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00046ba0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
Max diff block lines reached; 831115/845771 bytes (98.27%) of diff not shown.
327 KB
html2text {}
    
Offset 514, 20 lines modifiedOffset 514, 14 lines modified
514 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed514 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
515 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule515 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule
516 Remediation_OSBuild_Blueprint_snippet_⇲516 Remediation_OSBuild_Blueprint_snippet_⇲
  
517 [[packages]]517 [[packages]]
518 name·=·"aide"518 name·=·"aide"
519 version·=·"*"519 version·=·"*"
520 Remediation_Anaconda_snippet_⇲ 
521 Complexity:·low 
522 Disruption:·low 
523 Strategy:···enable 
  
524 package·--add=aide 
525 Remediation_Puppet_snippet_⇲520 Remediation_Puppet_snippet_⇲
526 Complexity:·low521 Complexity:·low
527 Disruption:·low522 Disruption:·low
528 Strategy:···enable523 Strategy:···enable
529 include·install_aide524 include·install_aide
  
530 class·install_aide·{525 class·install_aide·{
Offset 545, 14 lines modifiedOffset 539, 20 lines modified
545 if·!·rpm·-q·--quiet·"aide"·;·then539 if·!·rpm·-q·--quiet·"aide"·;·then
546 ····yum·install·-y·"aide"540 ····yum·install·-y·"aide"
547 fi541 fi
  
548 else542 else
549 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'543 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
550 fi544 fi
 545 Remediation_Anaconda_snippet_⇲
 546 Complexity:·low
 547 Disruption:·low
 548 Strategy:···enable
  
 549 package·--add=aide
551 Remediation_Ansible_snippet_⇲550 Remediation_Ansible_snippet_⇲
552 Complexity:·low551 Complexity:·low
553 Disruption:·low552 Disruption:·low
554 Strategy:···enable553 Strategy:···enable
555 -·name:·Ensure·aide·is·installed554 -·name:·Ensure·aide·is·installed
556 ··package:555 ··package:
557 ····name:·aide556 ····name:·aide
Offset 944, 17 lines modifiedOffset 944, 14 lines modified
944 will·overwrite·the·existing·initramfs·file.944 will·overwrite·the·existing·initramfs·file.
945 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.945 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
946 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.946 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
947 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.947 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
948 Severity: ················high948 Severity: ················high
949 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode949 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
950 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule950 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule
951 Remediation_Anaconda_snippet_⇲ 
  
952 package·--add=dracut-fips·--add=dracut-fips-aesni 
953 Remediation_Shell_script_⇲951 Remediation_Shell_script_⇲
954 #·Remediation·is·applicable·only·in·certain·platforms952 #·Remediation·is·applicable·only·in·certain·platforms
955 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then953 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
956 #·prelink·not·installed954 #·prelink·not·installed
957 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then955 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
958 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink956 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 1013, 14 lines modifiedOffset 1010, 17 lines modified
1013 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader1010 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
1014 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"1011 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
1015 fi1012 fi
  
1016 else1013 else
1017 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1014 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1018 fi1015 fi
 1016 Remediation_Anaconda_snippet_⇲
  
 1017 package·--add=dracut-fips·--add=dracut-fips-aesni
1019 Remediation_Ansible_snippet_⇲1018 Remediation_Ansible_snippet_⇲
1020 Complexity:·high1019 Complexity:·high
1021 Disruption:·medium1020 Disruption:·medium
1022 Reboot:·····true1021 Reboot:·····true
1023 Strategy:···restrict1022 Strategy:···restrict
1024 -·name:·Gather·the·package·facts1023 -·name:·Gather·the·package·facts
1025 ··package_facts:1024 ··package_facts:
Offset 11295, 20 lines modifiedOffset 11295, 14 lines modified
11295 Rule·ID:···················xccdf_org.ssgproject.content_rule_install_smartcard_packages11295 Rule·ID:···················xccdf_org.ssgproject.content_rule_install_smartcard_packages
11296 Identifiers·and·References·References: ·CCI-000765,·CCI-001948,·CCI-001953,·CCI-001954,·CM-6(a),·Req-8.3,·SRG-OS-000105-GPOS-00052,·SRG-OS-000375-GPOS-00160,·SRG-OS-000375-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-041001,·SV-221895r603260_rule11296 Identifiers·and·References·References: ·CCI-000765,·CCI-001948,·CCI-001953,·CCI-001954,·CM-6(a),·Req-8.3,·SRG-OS-000105-GPOS-00052,·SRG-OS-000375-GPOS-00160,·SRG-OS-000375-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-041001,·SV-221895r603260_rule
11297 Remediation_OSBuild_Blueprint_snippet_⇲11297 Remediation_OSBuild_Blueprint_snippet_⇲
  
11298 [[packages]]11298 [[packages]]
11299 name·=·"pam_pkcs11"11299 name·=·"pam_pkcs11"
11300 version·=·"*"11300 version·=·"*"
11301 Remediation_Anaconda_snippet_⇲ 
11302 Complexity:·low 
11303 Disruption:·low 
11304 Strategy:···enable 
  
11305 package·--add=pam_pkcs11 
11306 Remediation_Puppet_snippet_⇲11301 Remediation_Puppet_snippet_⇲
11307 Complexity:·low11302 Complexity:·low
11308 Disruption:·low11303 Disruption:·low
11309 Strategy:···enable11304 Strategy:···enable
11310 include·install_pam_pkcs1111305 include·install_pam_pkcs11
  
11311 class·install_pam_pkcs11·{11306 class·install_pam_pkcs11·{
Offset 11326, 14 lines modifiedOffset 11320, 20 lines modified
11326 if·!·rpm·-q·--quiet·"pam_pkcs11"·;·then11320 if·!·rpm·-q·--quiet·"pam_pkcs11"·;·then
11327 ····yum·install·-y·"pam_pkcs11"11321 ····yum·install·-y·"pam_pkcs11"
11328 fi11322 fi
  
11329 else11323 else
11330 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'11324 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
11331 fi11325 fi
 11326 Remediation_Anaconda_snippet_⇲
 11327 Complexity:·low
 11328 Disruption:·low
 11329 Strategy:···enable
  
 11330 package·--add=pam_pkcs11
11332 Remediation_Ansible_snippet_⇲11331 Remediation_Ansible_snippet_⇲
11333 Complexity:·low11332 Complexity:·low
11334 Disruption:·low11333 Disruption:·low
11335 Strategy:···enable11334 Strategy:···enable
11336 -·name:·Ensure·pam_pkcs11·is·installed11335 -·name:·Ensure·pam_pkcs11·is·installed
11337 ··package:11336 ··package:
11338 ····name:·pam_pkcs1111337 ····name:·pam_pkcs11
Offset 11354, 17 lines modifiedOffset 11354, 14 lines modified
11354 ***·Rule  ·Enable·Smart·Card·Login·  [ref]·***11354 ***·Rule  ·Enable·Smart·Card·Login·  [ref]·***
11355 To·enable·smart·card·authentication,·consult·the·documentation·at:11355 To·enable·smart·card·authentication,·consult·the·documentation·at:
11356 ····*·https://docs.oracle.com/en/operating-systems/oracle-linux/7/userauth/userauth-AuthenticationConfiguration.html#ol7-s4-auth11356 ····*·https://docs.oracle.com/en/operating-systems/oracle-linux/7/userauth/userauth-AuthenticationConfiguration.html#ol7-s4-auth
11357 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.11357 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.
11358 Severity: ················medium11358 Severity: ················medium
11359 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth11359 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth
11360 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-010500,·SV-221703r818811_rule11360 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-010500,·SV-221703r818811_rule
Max diff block lines reached; 326846/334479 bytes (97.72%) of diff not shown.
1.11 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-stig_gui.html
    
Offset 18054, 116 lines modifiedOffset 18054, 116 lines modified
00046850:·6574·3d22·2369·646d·3632·3834·2220·7461··et="#idm6284"·ta00046850:·6574·3d22·2369·646d·3632·3834·2220·7461··et="#idm6284"·ta
00046860:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00046860:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00046870:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00046870:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00046880:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00046880:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00046890:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00046890:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
000468a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="000468a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
000468b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·000468b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
000468c0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet000468c0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
000468d0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div000468d0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
000468e0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000468e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
000468f0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"000468f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00046900:·2069·643d·2269·646d·3632·3834·223e·3c74···id="idm6284"><t00046900:·643d·2269·646d·3632·3834·223e·3c74·6162··d="idm6284"><tab
00046910:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00046910:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00046920:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00046920:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00046930:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00046930:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00046940:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00046940:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00046950:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00046950:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00046960:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<00046960:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00046970:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00046970:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00046980:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th00046980:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00046990:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t00046990:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
000469a0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate000469a0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
000469b0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab000469b0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
000469c0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta000469c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
000469d0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.000469d0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
000469e0:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai000469e0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid
 000469f0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install
 00046a00:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag
 00046a10:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.····
 00046a20:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 00046a30:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 00046a40:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 00046a50:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 00046a60:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00046a70:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00046a80:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00046a90:·3d22·2369·646d·3632·3835·2220·7461·6269··="#idm6285"·tabi
 00046aa0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 00046ab0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 00046ac0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 00046ad0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 00046ae0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 00046af0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 00046b00:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 00046b10:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00046b20:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00046b30:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00046b40:·646d·3632·3835·223e·3c74·6162·6c65·2063··dm6285"><table·c
 00046b50:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 00046b60:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 00046b70:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 00046b80:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 00046b90:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 00046ba0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00046bb0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 00046bc0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 00046bd0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00046be0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00046bf0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 00046c00:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00046c10:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 00046c20:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 00046c30:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 00046c40:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 00046c50:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
 00046c60:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
 00046c70:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
 00046c80:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t
 00046c90:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 00046ca0:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"·
 00046cb0:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 00046cc0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 00046cd0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 00046ce0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 00046cf0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 00046d00:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 00046d10:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
000469f0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>00046d20:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
00046a00:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="00046d30:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
00046a10:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"00046d40:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
00046a20:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co00046d50:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
00046a30:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar00046d60:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
00046a40:·6765·743d·2223·6964·6d36·3238·3522·2074··get="#idm6285"·t00046d70:·6765·743d·2223·6964·6d36·3238·3622·2074··get="#idm6286"·t
00046a50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00046d80:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00046a60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00046d90:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00046a70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00046da0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00046a80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00046db0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00046a90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00046dc0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00046aa0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00046dd0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00046ab0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·00046de0:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
00046ac0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·00046df0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
00046ad0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col00046e00:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00046ae0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·00046e10:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
00046af0:·6964·3d22·6964·6d36·3238·3522·3e3c·7461··id="idm6285"><ta00046e20:·2220·6964·3d22·6964·6d36·3238·3622·3e3c··"·id="idm6286"><
00046b00:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table00046e30:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
00046b10:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t00046e40:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
00046b20:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta00046e50:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
00046b30:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><00046e60:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
00046b40:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit00046e70:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
00046b50:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</00046e80:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00046b60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00046e90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00046b70:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>00046ea0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
00046b80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr00046eb0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
00046b90:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg00046ec0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
00046ba0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl00046ed0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
00046bb0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab00046ee0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
00046bc0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in00046ef0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00046f00:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a
00046bd0:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai 
00046be0:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal 
00046bf0:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa 
00046c00:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.··· 
00046c10:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i 
00046c20:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.} 
00046c30:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
00046c40:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
00046c50:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
00046c60:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
00046c70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00046c80:·743d·2223·6964·6d36·3238·3622·2074·6162··t="#idm6286"·tab 
00046c90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
00046ca0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
00046cb0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
00046cc0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
00046cd0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
00046ce0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
00046cf0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
Max diff block lines reached; 821703/836359 bytes (98.25%) of diff not shown.
324 KB
html2text {}
    
Offset 518, 20 lines modifiedOffset 518, 14 lines modified
518 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed518 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
519 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule519 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL07-00-020029,·SV-251701r833031_rule
520 Remediation_OSBuild_Blueprint_snippet_⇲520 Remediation_OSBuild_Blueprint_snippet_⇲
  
521 [[packages]]521 [[packages]]
522 name·=·"aide"522 name·=·"aide"
523 version·=·"*"523 version·=·"*"
524 Remediation_Anaconda_snippet_⇲ 
525 Complexity:·low 
526 Disruption:·low 
527 Strategy:···enable 
  
528 package·--add=aide 
529 Remediation_Puppet_snippet_⇲524 Remediation_Puppet_snippet_⇲
530 Complexity:·low525 Complexity:·low
531 Disruption:·low526 Disruption:·low
532 Strategy:···enable527 Strategy:···enable
533 include·install_aide528 include·install_aide
  
534 class·install_aide·{529 class·install_aide·{
Offset 549, 14 lines modifiedOffset 543, 20 lines modified
549 if·!·rpm·-q·--quiet·"aide"·;·then543 if·!·rpm·-q·--quiet·"aide"·;·then
550 ····yum·install·-y·"aide"544 ····yum·install·-y·"aide"
551 fi545 fi
  
552 else546 else
553 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'547 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
554 fi548 fi
 549 Remediation_Anaconda_snippet_⇲
 550 Complexity:·low
 551 Disruption:·low
 552 Strategy:···enable
  
 553 package·--add=aide
555 Remediation_Ansible_snippet_⇲554 Remediation_Ansible_snippet_⇲
556 Complexity:·low555 Complexity:·low
557 Disruption:·low556 Disruption:·low
558 Strategy:···enable557 Strategy:···enable
559 -·name:·Ensure·aide·is·installed558 -·name:·Ensure·aide·is·installed
560 ··package:559 ··package:
561 ····name:·aide560 ····name:·aide
Offset 948, 17 lines modifiedOffset 948, 14 lines modified
948 will·overwrite·the·existing·initramfs·file.948 will·overwrite·the·existing·initramfs·file.
949 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.949 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
950 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.950 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
951 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.951 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
952 Severity: ················high952 Severity: ················high
953 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode953 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
954 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule954 Identifiers·and·References·References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·OL07-00-021350,·SV-221758r603260_rule
955 Remediation_Anaconda_snippet_⇲ 
  
956 package·--add=dracut-fips·--add=dracut-fips-aesni 
957 Remediation_Shell_script_⇲955 Remediation_Shell_script_⇲
958 #·Remediation·is·applicable·only·in·certain·platforms956 #·Remediation·is·applicable·only·in·certain·platforms
959 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then957 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
960 #·prelink·not·installed958 #·prelink·not·installed
961 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then959 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
962 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink960 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 1017, 14 lines modifiedOffset 1014, 17 lines modified
1017 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader1014 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
1018 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"1015 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
1019 fi1016 fi
  
1020 else1017 else
1021 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1018 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1022 fi1019 fi
 1020 Remediation_Anaconda_snippet_⇲
  
 1021 package·--add=dracut-fips·--add=dracut-fips-aesni
1023 Remediation_Ansible_snippet_⇲1022 Remediation_Ansible_snippet_⇲
1024 Complexity:·high1023 Complexity:·high
1025 Disruption:·medium1024 Disruption:·medium
1026 Reboot:·····true1025 Reboot:·····true
1027 Strategy:···restrict1026 Strategy:···restrict
1028 -·name:·Gather·the·package·facts1027 -·name:·Gather·the·package·facts
1029 ··package_facts:1028 ··package_facts:
Offset 11299, 20 lines modifiedOffset 11299, 14 lines modified
11299 Rule·ID:···················xccdf_org.ssgproject.content_rule_install_smartcard_packages11299 Rule·ID:···················xccdf_org.ssgproject.content_rule_install_smartcard_packages
11300 Identifiers·and·References·References: ·CCI-000765,·CCI-001948,·CCI-001953,·CCI-001954,·CM-6(a),·Req-8.3,·SRG-OS-000105-GPOS-00052,·SRG-OS-000375-GPOS-00160,·SRG-OS-000375-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-041001,·SV-221895r603260_rule11300 Identifiers·and·References·References: ·CCI-000765,·CCI-001948,·CCI-001953,·CCI-001954,·CM-6(a),·Req-8.3,·SRG-OS-000105-GPOS-00052,·SRG-OS-000375-GPOS-00160,·SRG-OS-000375-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-041001,·SV-221895r603260_rule
11301 Remediation_OSBuild_Blueprint_snippet_⇲11301 Remediation_OSBuild_Blueprint_snippet_⇲
  
11302 [[packages]]11302 [[packages]]
11303 name·=·"pam_pkcs11"11303 name·=·"pam_pkcs11"
11304 version·=·"*"11304 version·=·"*"
11305 Remediation_Anaconda_snippet_⇲ 
11306 Complexity:·low 
11307 Disruption:·low 
11308 Strategy:···enable 
  
11309 package·--add=pam_pkcs11 
11310 Remediation_Puppet_snippet_⇲11305 Remediation_Puppet_snippet_⇲
11311 Complexity:·low11306 Complexity:·low
11312 Disruption:·low11307 Disruption:·low
11313 Strategy:···enable11308 Strategy:···enable
11314 include·install_pam_pkcs1111309 include·install_pam_pkcs11
  
11315 class·install_pam_pkcs11·{11310 class·install_pam_pkcs11·{
Offset 11330, 14 lines modifiedOffset 11324, 20 lines modified
11330 if·!·rpm·-q·--quiet·"pam_pkcs11"·;·then11324 if·!·rpm·-q·--quiet·"pam_pkcs11"·;·then
11331 ····yum·install·-y·"pam_pkcs11"11325 ····yum·install·-y·"pam_pkcs11"
11332 fi11326 fi
  
11333 else11327 else
11334 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'11328 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
11335 fi11329 fi
 11330 Remediation_Anaconda_snippet_⇲
 11331 Complexity:·low
 11332 Disruption:·low
 11333 Strategy:···enable
  
 11334 package·--add=pam_pkcs11
11336 Remediation_Ansible_snippet_⇲11335 Remediation_Ansible_snippet_⇲
11337 Complexity:·low11336 Complexity:·low
11338 Disruption:·low11337 Disruption:·low
11339 Strategy:···enable11338 Strategy:···enable
11340 -·name:·Ensure·pam_pkcs11·is·installed11339 -·name:·Ensure·pam_pkcs11·is·installed
11341 ··package:11340 ··package:
11342 ····name:·pam_pkcs1111341 ····name:·pam_pkcs11
Offset 11358, 17 lines modifiedOffset 11358, 14 lines modified
11358 ***·Rule  ·Enable·Smart·Card·Login·  [ref]·***11358 ***·Rule  ·Enable·Smart·Card·Login·  [ref]·***
11359 To·enable·smart·card·authentication,·consult·the·documentation·at:11359 To·enable·smart·card·authentication,·consult·the·documentation·at:
11360 ····*·https://docs.oracle.com/en/operating-systems/oracle-linux/7/userauth/userauth-AuthenticationConfiguration.html#ol7-s4-auth11360 ····*·https://docs.oracle.com/en/operating-systems/oracle-linux/7/userauth/userauth-AuthenticationConfiguration.html#ol7-s4-auth
11361 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.11361 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.
11362 Severity: ················medium11362 Severity: ················medium
11363 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth11363 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth
11364 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-010500,·SV-221703r818811_rule11364 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·OL07-00-010500,·SV-221703r818811_rule
Max diff block lines reached; 324621/332254 bytes (97.70%) of diff not shown.
595 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_enhanced.html
    
Offset 15244, 116 lines modifiedOffset 15244, 116 lines modified
0003b8b0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b8b0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b8c0:·6d35·3935·3822·2074·6162·696e·6465·783d··m5958"·tabindex=0003b8c0:·6d35·3935·3822·2074·6162·696e·6465·783d··m5958"·tabindex=
0003b8d0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b8d0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b8e0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b8e0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b8f0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b8f0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b900:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b900:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b910:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b910:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b920:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003b920:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003b930:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003b930:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003b940:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b940:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b950:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b950:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b960:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b960:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
0003b970:·6d35·3935·3822·3e3c·7461·626c·6520·636c··m5958"><table·cl0003b970:·3935·3822·3e3c·7461·626c·6520·636c·6173··958"><table·clas
0003b980:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b980:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b990:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b990:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b9a0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b9a0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b9b0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b9b0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b9c0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b9c0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b9d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b9d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b9e0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b9e0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b9f0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003b9f0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003ba00:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003ba00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003ba10:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003ba10:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003ba20:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003ba20:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003ba30:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003ba30:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003ba40:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
0003ba50:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co0003ba40:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003ba50:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003ba60:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003ba70:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003ba80:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003ba90:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003baa0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003bab0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003bac0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003bad0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003bae0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003baf0:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 0003bb00:·3935·3922·2074·6162·696e·6465·783d·2230··959"·tabindex="0
 0003bb10:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003bb20:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003bb30:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003bb40:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003bb50:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003bb60:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 0003bb70:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003bb80:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003bb90:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003bba0:·7365·2220·6964·3d22·6964·6d35·3935·3922··se"·id="idm5959"
 0003bbb0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003bbc0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003bbd0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003bbe0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003bbf0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003bc00:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003bc10:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bc20:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003bc30:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003bc40:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003bc50:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003bc60:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003bc70:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003bc80:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 0003bc90:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 0003bca0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 0003bcb0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-
 0003bcc0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·
 0003bcd0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-
 0003bce0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe
 0003bcf0:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if
 0003bd00:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003bd10:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 0003bd20:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install·
 0003bd30:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 0003bd40:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003bd50:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003bd60:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003bd70:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003bd80:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
0003ba60:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003bd90:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003ba70:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003bda0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003ba80:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003bdb0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003ba90:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003bdc0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003baa0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003bdd0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003bab0:·646d·3539·3539·2220·7461·6269·6e64·6578··dm5959"·tabindex0003bde0:·646d·3539·3630·2220·7461·6269·6e64·6578··dm5960"·tabindex
0003bac0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003bdf0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003bad0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003be00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003bae0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003be10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003baf0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003be20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003bb00:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003be30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003bb10:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003be40:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003bb20:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003be50:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003bb30:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003be60:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003bb40:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003be70:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003bb50:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003be80:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003bb60:·3539·3539·223e·3c74·6162·6c65·2063·6c61··5959"><table·cla0003be90:·646d·3539·3630·223e·3c74·6162·6c65·2063··dm5960"><table·c
0003bb70:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003bea0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003bb80:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003beb0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003bb90:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003bec0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003bba0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003bed0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003bbb0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003bee0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003bbc0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bef0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003bbd0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003bf00:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bbe0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003bf10:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003bbf0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bf20:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bc00:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003bf30:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003bc10:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003bf40:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003bc20:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003bf50:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003bf60:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003bf70:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
0003bc30:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003bc40:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003bc50:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003bc60:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003bc70:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003bc80:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003bc90:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003bca0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bcb0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bcc0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bcd0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003bce0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bcf0:·3539·3630·2220·7461·6269·6e64·6578·3d22··5960"·tabindex=" 
0003bd00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bd10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003bd20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003bd30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
Max diff block lines reached; 553488/568144 bytes (97.42%) of diff not shown.
39.8 KB
html2text {}
    
Offset 107, 20 lines modifiedOffset 107, 14 lines modified
107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,
108 ············OL08-00-010359,·SV-252654r818758_rule108 ············OL08-00-010359,·SV-252654r818758_rule
109 Remediation_OSBuild_Blueprint_snippet_⇲109 Remediation_OSBuild_Blueprint_snippet_⇲
  
110 [[packages]]110 [[packages]]
111 name·=·"aide"111 name·=·"aide"
112 version·=·"*"112 version·=·"*"
113 Remediation_Anaconda_snippet_⇲ 
114 Complexity:·low 
115 Disruption:·low 
116 Strategy:···enable 
  
117 package·--add=aide 
118 Remediation_Puppet_snippet_⇲113 Remediation_Puppet_snippet_⇲
119 Complexity:·low114 Complexity:·low
120 Disruption:·low115 Disruption:·low
121 Strategy:···enable116 Strategy:···enable
122 include·install_aide117 include·install_aide
  
123 class·install_aide·{118 class·install_aide·{
Offset 138, 14 lines modifiedOffset 132, 20 lines modified
138 if·!·rpm·-q·--quiet·"aide"·;·then132 if·!·rpm·-q·--quiet·"aide"·;·then
139 ····yum·install·-y·"aide"133 ····yum·install·-y·"aide"
140 fi134 fi
  
141 else135 else
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
143 fi137 fi
 138 Remediation_Anaconda_snippet_⇲
 139 Complexity:·low
 140 Disruption:·low
 141 Strategy:···enable
  
 142 package·--add=aide
144 Remediation_Ansible_snippet_⇲143 Remediation_Ansible_snippet_⇲
145 Complexity:·low144 Complexity:·low
146 Disruption:·low145 Disruption:·low
147 Strategy:···enable146 Strategy:···enable
148 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
149 ··package:148 ··package:
150 ····name:·aide149 ····name:·aide
Offset 477, 20 lines modifiedOffset 477, 14 lines modified
477 and·········00125477 and·········00125
478 References478 References
479 Remediation_OSBuild_Blueprint_snippet_⇲479 Remediation_OSBuild_Blueprint_snippet_⇲
  
480 [[packages]]480 [[packages]]
481 name·=·"sudo"481 name·=·"sudo"
482 version·=·"*"482 version·=·"*"
483 Remediation_Anaconda_snippet_⇲ 
484 Complexity:·low 
485 Disruption:·low 
486 Strategy:···enable 
  
487 package·--add=sudo 
488 Remediation_Puppet_snippet_⇲483 Remediation_Puppet_snippet_⇲
489 Complexity:·low484 Complexity:·low
490 Disruption:·low485 Disruption:·low
491 Strategy:···enable486 Strategy:···enable
492 include·install_sudo487 include·install_sudo
  
493 class·install_sudo·{488 class·install_sudo·{
Offset 508, 14 lines modifiedOffset 502, 20 lines modified
508 if·!·rpm·-q·--quiet·"sudo"·;·then502 if·!·rpm·-q·--quiet·"sudo"·;·then
509 ····yum·install·-y·"sudo"503 ····yum·install·-y·"sudo"
510 fi504 fi
  
511 else505 else
512 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'506 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
513 fi507 fi
 508 Remediation_Anaconda_snippet_⇲
 509 Complexity:·low
 510 Disruption:·low
 511 Strategy:···enable
  
 512 package·--add=sudo
514 Remediation_Ansible_snippet_⇲513 Remediation_Ansible_snippet_⇲
515 Complexity:·low514 Complexity:·low
516 Disruption:·low515 Disruption:·low
517 Strategy:···enable516 Strategy:···enable
518 -·name:·Ensure·sudo·is·installed517 -·name:·Ensure·sudo·is·installed
519 ··package:518 ··package:
520 ····name:·sudo519 ····name:·sudo
Offset 1197, 20 lines modifiedOffset 1197, 14 lines modified
1197 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1197 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1198 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000801198 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1199 Remediation_OSBuild_Blueprint_snippet_⇲1199 Remediation_OSBuild_Blueprint_snippet_⇲
  
1200 [[packages]]1200 [[packages]]
1201 name·=·"dnf-automatic"1201 name·=·"dnf-automatic"
1202 version·=·"*"1202 version·=·"*"
1203 Remediation_Anaconda_snippet_⇲ 
1204 Complexity:·low 
1205 Disruption:·low 
1206 Strategy:···enable 
  
1207 package·--add=dnf-automatic 
1208 Remediation_Puppet_snippet_⇲1203 Remediation_Puppet_snippet_⇲
1209 Complexity:·low1204 Complexity:·low
1210 Disruption:·low1205 Disruption:·low
1211 Strategy:···enable1206 Strategy:···enable
1212 include·install_dnf-automatic1207 include·install_dnf-automatic
  
1213 class·install_dnf-automatic·{1208 class·install_dnf-automatic·{
Offset 1222, 14 lines modifiedOffset 1216, 20 lines modified
1222 Complexity:·low1216 Complexity:·low
1223 Disruption:·low1217 Disruption:·low
1224 Strategy:···enable1218 Strategy:···enable
  
1225 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1219 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1226 ····yum·install·-y·"dnf-automatic"1220 ····yum·install·-y·"dnf-automatic"
1227 fi1221 fi
 1222 Remediation_Anaconda_snippet_⇲
 1223 Complexity:·low
 1224 Disruption:·low
 1225 Strategy:···enable
  
 1226 package·--add=dnf-automatic
1228 Remediation_Ansible_snippet_⇲1227 Remediation_Ansible_snippet_⇲
1229 Complexity:·low1228 Complexity:·low
1230 Disruption:·low1229 Disruption:·low
1231 Strategy:···enable1230 Strategy:···enable
1232 -·name:·Ensure·dnf-automatic·is·installed1231 -·name:·Ensure·dnf-automatic·is·installed
1233 ··package:1232 ··package:
1234 ····name:·dnf-automatic1233 ····name:·dnf-automatic
Offset 8482, 15 lines modifiedOffset 8482, 15 lines modified
8482 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),8482 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
Max diff block lines reached; 37772/40741 bytes (92.71%) of diff not shown.
650 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_high.html
    
Offset 15243, 116 lines modifiedOffset 15243, 116 lines modified
0003b8a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b8a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b8b0:·6d35·3935·3822·2074·6162·696e·6465·783d··m5958"·tabindex=0003b8b0:·6d35·3935·3822·2074·6162·696e·6465·783d··m5958"·tabindex=
0003b8c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b8c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b8d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b8d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b8e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b8e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b8f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b8f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b900:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b900:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b910:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003b910:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003b920:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003b920:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003b930:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b930:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b940:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b940:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b950:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b950:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
0003b960:·6d35·3935·3822·3e3c·7461·626c·6520·636c··m5958"><table·cl0003b960:·3935·3822·3e3c·7461·626c·6520·636c·6173··958"><table·clas
0003b970:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b970:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b980:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b980:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b990:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b990:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b9a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b9a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b9b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b9b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b9c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b9c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b9d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b9d0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b9e0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003b9e0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b9f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b9f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003ba00:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003ba00:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003ba10:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003ba10:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003ba20:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003ba20:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003ba30:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
0003ba40:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co0003ba30:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003ba40:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003ba50:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003ba60:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003ba70:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003ba80:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003ba90:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003baa0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003bab0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003bac0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003bad0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003bae0:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 0003baf0:·3935·3922·2074·6162·696e·6465·783d·2230··959"·tabindex="0
 0003bb00:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003bb10:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003bb20:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003bb30:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003bb40:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003bb50:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 0003bb60:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003bb70:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003bb80:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003bb90:·7365·2220·6964·3d22·6964·6d35·3935·3922··se"·id="idm5959"
 0003bba0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003bbb0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003bbc0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003bbd0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003bbe0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003bbf0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003bc00:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bc10:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003bc20:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003bc30:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003bc40:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003bc50:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003bc60:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003bc70:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 0003bc80:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 0003bc90:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 0003bca0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-
 0003bcb0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·
 0003bcc0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-
 0003bcd0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe
 0003bce0:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if
 0003bcf0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003bd00:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 0003bd10:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install·
 0003bd20:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 0003bd30:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003bd40:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003bd50:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003bd60:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003bd70:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
0003ba50:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003bd80:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003ba60:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003bd90:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003ba70:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003bda0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003ba80:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003bdb0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003ba90:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003bdc0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003baa0:·646d·3539·3539·2220·7461·6269·6e64·6578··dm5959"·tabindex0003bdd0:·646d·3539·3630·2220·7461·6269·6e64·6578··dm5960"·tabindex
0003bab0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003bde0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003bac0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003bdf0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003bad0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003be00:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003bae0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003be10:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003baf0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003be20:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003bb00:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003be30:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003bb10:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003be40:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003bb20:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003be50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003bb30:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003be60:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003bb40:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003be70:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003bb50:·3539·3539·223e·3c74·6162·6c65·2063·6c61··5959"><table·cla0003be80:·646d·3539·3630·223e·3c74·6162·6c65·2063··dm5960"><table·c
0003bb60:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003be90:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003bb70:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003bea0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003bb80:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003beb0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003bb90:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003bec0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003bba0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003bed0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003bbb0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bee0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003bbc0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003bef0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bbd0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003bf00:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003bbe0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bf10:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bbf0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003bf20:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003bc00:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003bf30:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003bc10:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003bf40:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003bf50:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003bf60:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
0003bc20:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003bc30:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003bc40:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003bc50:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003bc60:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003bc70:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003bc80:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003bc90:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bca0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bcb0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bcc0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003bcd0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bce0:·3539·3630·2220·7461·6269·6e64·6578·3d22··5960"·tabindex=" 
0003bcf0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bd00:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003bd10:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003bd20:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
Max diff block lines reached; 606643/621299 bytes (97.64%) of diff not shown.
43.4 KB
html2text {}
    
Offset 107, 20 lines modifiedOffset 107, 14 lines modified
107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,
108 ············OL08-00-010359,·SV-252654r818758_rule108 ············OL08-00-010359,·SV-252654r818758_rule
109 Remediation_OSBuild_Blueprint_snippet_⇲109 Remediation_OSBuild_Blueprint_snippet_⇲
  
110 [[packages]]110 [[packages]]
111 name·=·"aide"111 name·=·"aide"
112 version·=·"*"112 version·=·"*"
113 Remediation_Anaconda_snippet_⇲ 
114 Complexity:·low 
115 Disruption:·low 
116 Strategy:···enable 
  
117 package·--add=aide 
118 Remediation_Puppet_snippet_⇲113 Remediation_Puppet_snippet_⇲
119 Complexity:·low114 Complexity:·low
120 Disruption:·low115 Disruption:·low
121 Strategy:···enable116 Strategy:···enable
122 include·install_aide117 include·install_aide
  
123 class·install_aide·{118 class·install_aide·{
Offset 138, 14 lines modifiedOffset 132, 20 lines modified
138 if·!·rpm·-q·--quiet·"aide"·;·then132 if·!·rpm·-q·--quiet·"aide"·;·then
139 ····yum·install·-y·"aide"133 ····yum·install·-y·"aide"
140 fi134 fi
  
141 else135 else
142 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
143 fi137 fi
 138 Remediation_Anaconda_snippet_⇲
 139 Complexity:·low
 140 Disruption:·low
 141 Strategy:···enable
  
 142 package·--add=aide
144 Remediation_Ansible_snippet_⇲143 Remediation_Ansible_snippet_⇲
145 Complexity:·low144 Complexity:·low
146 Disruption:·low145 Disruption:·low
147 Strategy:···enable146 Strategy:···enable
148 -·name:·Ensure·aide·is·installed147 -·name:·Ensure·aide·is·installed
149 ··package:148 ··package:
150 ····name:·aide149 ····name:·aide
Offset 821, 20 lines modifiedOffset 821, 14 lines modified
821 and·········00125821 and·········00125
822 References822 References
823 Remediation_OSBuild_Blueprint_snippet_⇲823 Remediation_OSBuild_Blueprint_snippet_⇲
  
824 [[packages]]824 [[packages]]
825 name·=·"sudo"825 name·=·"sudo"
826 version·=·"*"826 version·=·"*"
827 Remediation_Anaconda_snippet_⇲ 
828 Complexity:·low 
829 Disruption:·low 
830 Strategy:···enable 
  
831 package·--add=sudo 
832 Remediation_Puppet_snippet_⇲827 Remediation_Puppet_snippet_⇲
833 Complexity:·low828 Complexity:·low
834 Disruption:·low829 Disruption:·low
835 Strategy:···enable830 Strategy:···enable
836 include·install_sudo831 include·install_sudo
  
837 class·install_sudo·{832 class·install_sudo·{
Offset 852, 14 lines modifiedOffset 846, 20 lines modified
852 if·!·rpm·-q·--quiet·"sudo"·;·then846 if·!·rpm·-q·--quiet·"sudo"·;·then
853 ····yum·install·-y·"sudo"847 ····yum·install·-y·"sudo"
854 fi848 fi
  
855 else849 else
856 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'850 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
857 fi851 fi
 852 Remediation_Anaconda_snippet_⇲
 853 Complexity:·low
 854 Disruption:·low
 855 Strategy:···enable
  
 856 package·--add=sudo
858 Remediation_Ansible_snippet_⇲857 Remediation_Ansible_snippet_⇲
859 Complexity:·low858 Complexity:·low
860 Disruption:·low859 Disruption:·low
861 Strategy:···enable860 Strategy:···enable
862 -·name:·Ensure·sudo·is·installed861 -·name:·Ensure·sudo·is·installed
863 ··package:862 ··package:
864 ····name:·sudo863 ····name:·sudo
Offset 1541, 20 lines modifiedOffset 1541, 14 lines modified
1541 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1541 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1542 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000801542 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1543 Remediation_OSBuild_Blueprint_snippet_⇲1543 Remediation_OSBuild_Blueprint_snippet_⇲
  
1544 [[packages]]1544 [[packages]]
1545 name·=·"dnf-automatic"1545 name·=·"dnf-automatic"
1546 version·=·"*"1546 version·=·"*"
1547 Remediation_Anaconda_snippet_⇲ 
1548 Complexity:·low 
1549 Disruption:·low 
1550 Strategy:···enable 
  
1551 package·--add=dnf-automatic 
1552 Remediation_Puppet_snippet_⇲1547 Remediation_Puppet_snippet_⇲
1553 Complexity:·low1548 Complexity:·low
1554 Disruption:·low1549 Disruption:·low
1555 Strategy:···enable1550 Strategy:···enable
1556 include·install_dnf-automatic1551 include·install_dnf-automatic
  
1557 class·install_dnf-automatic·{1552 class·install_dnf-automatic·{
Offset 1566, 14 lines modifiedOffset 1560, 20 lines modified
1566 Complexity:·low1560 Complexity:·low
1567 Disruption:·low1561 Disruption:·low
1568 Strategy:···enable1562 Strategy:···enable
  
1569 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1563 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1570 ····yum·install·-y·"dnf-automatic"1564 ····yum·install·-y·"dnf-automatic"
1571 fi1565 fi
 1566 Remediation_Anaconda_snippet_⇲
 1567 Complexity:·low
 1568 Disruption:·low
 1569 Strategy:···enable
  
 1570 package·--add=dnf-automatic
1572 Remediation_Ansible_snippet_⇲1571 Remediation_Ansible_snippet_⇲
1573 Complexity:·low1572 Complexity:·low
1574 Disruption:·low1573 Disruption:·low
1575 Strategy:···enable1574 Strategy:···enable
1576 -·name:·Ensure·dnf-automatic·is·installed1575 -·name:·Ensure·dnf-automatic·is·installed
1577 ··package:1576 ··package:
1578 ····name:·dnf-automatic1577 ····name:·dnf-automatic
Offset 8826, 15 lines modifiedOffset 8826, 15 lines modified
8826 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),8826 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
Max diff block lines reached; 41401/44370 bytes (93.31%) of diff not shown.
595 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_intermediary.html
    
Offset 15238, 117 lines modifiedOffset 15238, 117 lines modified
0003b850:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b850:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b860:·743d·2223·6964·6d35·3935·3822·2074·6162··t="#idm5958"·tab0003b860:·743d·2223·6964·6d35·3935·3822·2074·6162··t="#idm5958"·tab
0003b870:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b870:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b880:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b880:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b890:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b890:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b8a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b8a0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b8b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b8b0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b8c0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003b8c0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003b8d0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003b8d0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0003b8e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b8e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b8f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b8f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b900:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b900:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b910:·6964·3d22·6964·6d35·3935·3822·3e3c·7461··id="idm5958"><ta0003b910:·3d22·6964·6d35·3935·3822·3e3c·7461·626c··="idm5958"><tabl
0003b920:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003b920:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b930:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003b930:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b940:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003b940:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b950:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003b950:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b960:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003b960:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b970:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003b970:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b980:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b980:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b990:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003b990:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b9a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b9a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b9b0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003b9b0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b9c0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003b9c0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b9d0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003b9d0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b9e0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0003b9e0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0003b9f0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid0003b9f0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003ba00:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003ba10:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003ba20:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003ba30:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003ba40:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003ba50:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003ba60:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003ba70:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003ba80:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003ba90:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003baa0:·2223·6964·6d35·3935·3922·2074·6162·696e··"#idm5959"·tabin
 0003bab0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003bac0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003bad0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003bae0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003baf0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003bb00:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003bb10:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003bb20:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003bb30:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003bb40:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003bb50:·6d35·3935·3922·3e3c·7461·626c·6520·636c··m5959"><table·cl
 0003bb60:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003bb70:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003bb80:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003bb90:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003bba0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003bbb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003bbc0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003bbd0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003bbe0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003bbf0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003bc00:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003bc10:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003bc20:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003bc30:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003bc40:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003bc50:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003bc60:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
 0003bc70:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 0003bc80:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
 0003bc90:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th
 0003bca0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003bcb0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003bcc0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003bcd0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003bce0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003bcf0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003bd00:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003bd10:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003bd20:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
0003ba00:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0003bd30:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
0003ba10:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003bd40:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003ba20:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003bd50:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003ba30:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003bd60:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003ba40:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003bd70:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003ba50:·6574·3d22·2369·646d·3539·3539·2220·7461··et="#idm5959"·ta0003bd80:·6574·3d22·2369·646d·3539·3630·2220·7461··et="#idm5960"·ta
0003ba60:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003bd90:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003ba70:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003bda0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003ba80:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003bdb0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003ba90:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003bdc0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003baa0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003bdd0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003bab0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003bde0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003bac0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003bdf0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003bad0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003be00:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bae0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003be10:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003baf0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003be20:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bb00:·643d·2269·646d·3539·3539·223e·3c74·6162··d="idm5959"><tab0003be30:·2069·643d·2269·646d·3539·3630·223e·3c74···id="idm5960"><t
0003bb10:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003be40:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bb20:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003be50:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bb30:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003be60:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bb40:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003be70:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bb50:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003be80:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bb60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003be90:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003bb70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003bea0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bb80:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003beb0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003bb90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bec0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bba0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bed0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bbb0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003bee0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bbc0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003bef0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bbd0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003bf00:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003bf10:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
0003bbe0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003bbf0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003bc00:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003bc10:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003bc20:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003bc30:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003bc40:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003bc50:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003bc60:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003bc70:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003bc80:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003bc90:·3d22·2369·646d·3539·3630·2220·7461·6269··="#idm5960"·tabi 
0003bca0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003bcb0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003bcc0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003bcd0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003bce0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003bcf0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
Max diff block lines reached; 553614/568408 bytes (97.40%) of diff not shown.
39.8 KB
html2text {}
    
Offset 106, 20 lines modifiedOffset 106, 14 lines modified
106 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,106 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,
107 ············OL08-00-010359,·SV-252654r818758_rule107 ············OL08-00-010359,·SV-252654r818758_rule
108 Remediation_OSBuild_Blueprint_snippet_⇲108 Remediation_OSBuild_Blueprint_snippet_⇲
  
109 [[packages]]109 [[packages]]
110 name·=·"aide"110 name·=·"aide"
111 version·=·"*"111 version·=·"*"
112 Remediation_Anaconda_snippet_⇲ 
113 Complexity:·low 
114 Disruption:·low 
115 Strategy:···enable 
  
116 package·--add=aide 
117 Remediation_Puppet_snippet_⇲112 Remediation_Puppet_snippet_⇲
118 Complexity:·low113 Complexity:·low
119 Disruption:·low114 Disruption:·low
120 Strategy:···enable115 Strategy:···enable
121 include·install_aide116 include·install_aide
  
122 class·install_aide·{117 class·install_aide·{
Offset 137, 14 lines modifiedOffset 131, 20 lines modified
137 if·!·rpm·-q·--quiet·"aide"·;·then131 if·!·rpm·-q·--quiet·"aide"·;·then
138 ····yum·install·-y·"aide"132 ····yum·install·-y·"aide"
139 fi133 fi
  
140 else134 else
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
142 fi136 fi
 137 Remediation_Anaconda_snippet_⇲
 138 Complexity:·low
 139 Disruption:·low
 140 Strategy:···enable
  
 141 package·--add=aide
143 Remediation_Ansible_snippet_⇲142 Remediation_Ansible_snippet_⇲
144 Complexity:·low143 Complexity:·low
145 Disruption:·low144 Disruption:·low
146 Strategy:···enable145 Strategy:···enable
147 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
148 ··package:147 ··package:
149 ····name:·aide148 ····name:·aide
Offset 476, 20 lines modifiedOffset 476, 14 lines modified
476 and·········00125476 and·········00125
477 References477 References
478 Remediation_OSBuild_Blueprint_snippet_⇲478 Remediation_OSBuild_Blueprint_snippet_⇲
  
479 [[packages]]479 [[packages]]
480 name·=·"sudo"480 name·=·"sudo"
481 version·=·"*"481 version·=·"*"
482 Remediation_Anaconda_snippet_⇲ 
483 Complexity:·low 
484 Disruption:·low 
485 Strategy:···enable 
  
486 package·--add=sudo 
487 Remediation_Puppet_snippet_⇲482 Remediation_Puppet_snippet_⇲
488 Complexity:·low483 Complexity:·low
489 Disruption:·low484 Disruption:·low
490 Strategy:···enable485 Strategy:···enable
491 include·install_sudo486 include·install_sudo
  
492 class·install_sudo·{487 class·install_sudo·{
Offset 507, 14 lines modifiedOffset 501, 20 lines modified
507 if·!·rpm·-q·--quiet·"sudo"·;·then501 if·!·rpm·-q·--quiet·"sudo"·;·then
508 ····yum·install·-y·"sudo"502 ····yum·install·-y·"sudo"
509 fi503 fi
  
510 else504 else
511 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'505 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
512 fi506 fi
 507 Remediation_Anaconda_snippet_⇲
 508 Complexity:·low
 509 Disruption:·low
 510 Strategy:···enable
  
 511 package·--add=sudo
513 Remediation_Ansible_snippet_⇲512 Remediation_Ansible_snippet_⇲
514 Complexity:·low513 Complexity:·low
515 Disruption:·low514 Disruption:·low
516 Strategy:···enable515 Strategy:···enable
517 -·name:·Ensure·sudo·is·installed516 -·name:·Ensure·sudo·is·installed
518 ··package:517 ··package:
519 ····name:·sudo518 ····name:·sudo
Offset 1196, 20 lines modifiedOffset 1196, 14 lines modified
1196 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1196 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1197 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000801197 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1198 Remediation_OSBuild_Blueprint_snippet_⇲1198 Remediation_OSBuild_Blueprint_snippet_⇲
  
1199 [[packages]]1199 [[packages]]
1200 name·=·"dnf-automatic"1200 name·=·"dnf-automatic"
1201 version·=·"*"1201 version·=·"*"
1202 Remediation_Anaconda_snippet_⇲ 
1203 Complexity:·low 
1204 Disruption:·low 
1205 Strategy:···enable 
  
1206 package·--add=dnf-automatic 
1207 Remediation_Puppet_snippet_⇲1202 Remediation_Puppet_snippet_⇲
1208 Complexity:·low1203 Complexity:·low
1209 Disruption:·low1204 Disruption:·low
1210 Strategy:···enable1205 Strategy:···enable
1211 include·install_dnf-automatic1206 include·install_dnf-automatic
  
1212 class·install_dnf-automatic·{1207 class·install_dnf-automatic·{
Offset 1221, 14 lines modifiedOffset 1215, 20 lines modified
1221 Complexity:·low1215 Complexity:·low
1222 Disruption:·low1216 Disruption:·low
1223 Strategy:···enable1217 Strategy:···enable
  
1224 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1218 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1225 ····yum·install·-y·"dnf-automatic"1219 ····yum·install·-y·"dnf-automatic"
1226 fi1220 fi
 1221 Remediation_Anaconda_snippet_⇲
 1222 Complexity:·low
 1223 Disruption:·low
 1224 Strategy:···enable
  
 1225 package·--add=dnf-automatic
1227 Remediation_Ansible_snippet_⇲1226 Remediation_Ansible_snippet_⇲
1228 Complexity:·low1227 Complexity:·low
1229 Disruption:·low1228 Disruption:·low
1230 Strategy:···enable1229 Strategy:···enable
1231 -·name:·Ensure·dnf-automatic·is·installed1230 -·name:·Ensure·dnf-automatic·is·installed
1232 ··package:1231 ··package:
1233 ····name:·dnf-automatic1232 ····name:·dnf-automatic
Offset 8035, 15 lines modifiedOffset 8035, 15 lines modified
8035 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),8035 References··A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
Max diff block lines reached; 37772/40741 bytes (92.71%) of diff not shown.
245 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_minimal.html
    
Offset 15906, 107 lines modifiedOffset 15906, 107 lines modified
0003e210:·2d74·6172·6765·743d·2223·6964·6d31·3038··-target="#idm1080003e210:·2d74·6172·6765·743d·2223·6964·6d31·3038··-target="#idm108
0003e220:·3139·2220·7461·6269·6e64·6578·3d22·3022··19"·tabindex="0"0003e220:·3139·2220·7461·6269·6e64·6578·3d22·3022··19"·tabindex="0"
0003e230:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003e230:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003e240:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003e240:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003e250:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003e250:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003e260:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003e260:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003e270:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003e270:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003e280:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0003e280:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003e290:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003e290:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003e2a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003e2a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003e2b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003e2b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003e2c0:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm100003e2c0:·7073·6522·2069·643d·2269·646d·3130·3831··pse"·id="idm1081
0003e2d0:·3831·3922·3e3c·7461·626c·6520·636c·6173··819"><table·clas0003e2d0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=
0003e2e0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003e2e0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003e2f0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003e2f0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003e300:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003e300:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003e310:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003e310:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003e320:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003e320:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003e330:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003e340:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003e350:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003e360:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003e370:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003e380:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003e390:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003e3a0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003e3b0:·616c·6c5f·646e·662d·6175·746f·6d61·7469··all_dnf-automati
 0003e3c0:·630a·0a63·6c61·7373·2069·6e73·7461·6c6c··c..class·install
 0003e3d0:·5f64·6e66·2d61·7574·6f6d·6174·6963·207b··_dnf-automatic·{
 0003e3e0:·0a20·2070·6163·6b61·6765·207b·2027·646e··.··package·{·'dn
 0003e3f0:·662d·6175·746f·6d61·7469·6327·3a0a·2020··f-automatic':.··
 0003e400:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003e410:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003e420:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003e430:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003e440:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003e450:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003e460:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003e470:·6574·3d22·2369·646d·3130·3832·3022·2074··et="#idm10820"·t
 0003e480:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003e490:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003e4a0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003e4b0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003e4c0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003e4d0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003e4e0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003e4f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003e500:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003e510:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003e520:·3d22·6964·6d31·3038·3230·223e·3c74·6162··="idm10820"><tab
 0003e530:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003e540:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003e550:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003e560:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003e570:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003e580:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003e590:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003e5a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003e330:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003e5b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003e340:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003e350:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003e360:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003e370:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003e380:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003e390:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003e3a0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003e3b0:·2d61·6464·3d64·6e66·2d61·7574·6f6d·6174··-add=dnf-automat0003e5c0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003e5d0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003e5e0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003e5f0:·653e·3c70·7265·3e3c·636f·6465·3e0a·6966··e><pre><code>.if
 0003e600:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003e610:·7420·2264·6e66·2d61·7574·6f6d·6174·6963··t·"dnf-automatic
 0003e620:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
 0003e630:·2069·6e73·7461·6c6c·202d·7920·2264·6e66···install·-y·"dnf
 0003e640:·2d61·7574·6f6d·6174·6963·220a·6669·0a3c··-automatic".fi.<
0003e3c0:·6963·0a3c·2f63·6f64·653e·3c2f·7072·653e··ic.</code></pre>0003e650:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003e3d0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003e660:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003e3e0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003e670:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003e3f0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003e680:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003e400:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003e690:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003e410:·6765·743d·2223·6964·6d31·3038·3230·2220··get="#idm10820"·0003e6a0:·2223·6964·6d31·3038·3231·2220·7461·6269··"#idm10821"·tabi
0003e420:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003e6b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003e430:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003e6c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003e440:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003e6d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003e450:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003e6e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003e460:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003e6f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003e470:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003e700:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003e480:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet0003e710:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003e490:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003e720:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003e4a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003e730:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003e4b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003e740:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003e4c0:·2069·643d·2269·646d·3130·3832·3022·3e3c···id="idm10820"><0003e750:·643d·2269·646d·3130·3832·3122·3e3c·7461··d="idm10821"><ta
0003e4d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003e760:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003e4e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003e770:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003e4f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003e780:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003e500:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003e790:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003e510:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003e7a0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003e520:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003e7b0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003e530:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003e7c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003e540:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003e7d0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003e550:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003e560:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003e570:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003e580:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003e590:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003e5a0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003e5b0:·646e·662d·6175·746f·6d61·7469·630a·0a63··dnf-automatic..c 
0003e5c0:·6c61·7373·2069·6e73·7461·6c6c·5f64·6e66··lass·install_dnf 
0003e5d0:·2d61·7574·6f6d·6174·6963·207b·0a20·2070··-automatic·{.··p 
0003e5e0:·6163·6b61·6765·207b·2027·646e·662d·6175··ackage·{·'dnf-au 
0003e5f0:·746f·6d61·7469·6327·3a0a·2020·2020·656e··tomatic':.····en 
0003e600:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003e610:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003e620:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003e630:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003e640:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003e650:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003e660:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003e670:·2369·646d·3130·3832·3122·2074·6162·696e··#idm10821"·tabin 
0003e680:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003e690:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003e6a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003e6b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003e6c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003e6d0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003e6e0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003e6f0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
Max diff block lines reached; 219122/232536 bytes (94.23%) of diff not shown.
17.4 KB
html2text {}
    
Offset 244, 20 lines modifiedOffset 244, 14 lines modified
244 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed244 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
245 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080245 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
246 Remediation_OSBuild_Blueprint_snippet_⇲246 Remediation_OSBuild_Blueprint_snippet_⇲
  
247 [[packages]]247 [[packages]]
248 name·=·"dnf-automatic"248 name·=·"dnf-automatic"
249 version·=·"*"249 version·=·"*"
250 Remediation_Anaconda_snippet_⇲ 
251 Complexity:·low 
252 Disruption:·low 
253 Strategy:···enable 
  
254 package·--add=dnf-automatic 
255 Remediation_Puppet_snippet_⇲250 Remediation_Puppet_snippet_⇲
256 Complexity:·low251 Complexity:·low
257 Disruption:·low252 Disruption:·low
258 Strategy:···enable253 Strategy:···enable
259 include·install_dnf-automatic254 include·install_dnf-automatic
  
260 class·install_dnf-automatic·{255 class·install_dnf-automatic·{
Offset 269, 14 lines modifiedOffset 263, 20 lines modified
269 Complexity:·low263 Complexity:·low
270 Disruption:·low264 Disruption:·low
271 Strategy:···enable265 Strategy:···enable
  
272 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then266 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
273 ····yum·install·-y·"dnf-automatic"267 ····yum·install·-y·"dnf-automatic"
274 fi268 fi
 269 Remediation_Anaconda_snippet_⇲
 270 Complexity:·low
 271 Disruption:·low
 272 Strategy:···enable
  
 273 package·--add=dnf-automatic
275 Remediation_Ansible_snippet_⇲274 Remediation_Ansible_snippet_⇲
276 Complexity:·low275 Complexity:·low
277 Disruption:·low276 Disruption:·low
278 Strategy:···enable277 Strategy:···enable
279 -·name:·Ensure·dnf-automatic·is·installed278 -·name:·Ensure·dnf-automatic·is·installed
280 ··package:279 ··package:
281 ····name:·dnf-automatic280 ····name:·dnf-automatic
Offset 6840, 20 lines modifiedOffset 6840, 14 lines modified
6840 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-6840 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
6841 ············00227,·OL08-00-030670,·SV-248812r780002_rule6841 ············00227,·OL08-00-030670,·SV-248812r780002_rule
6842 Remediation_OSBuild_Blueprint_snippet_⇲6842 Remediation_OSBuild_Blueprint_snippet_⇲
  
6843 [[packages]]6843 [[packages]]
6844 name·=·"rsyslog"6844 name·=·"rsyslog"
6845 version·=·"*"6845 version·=·"*"
6846 Remediation_Anaconda_snippet_⇲ 
6847 Complexity:·low 
6848 Disruption:·low 
6849 Strategy:···enable 
  
6850 package·--add=rsyslog 
6851 Remediation_Puppet_snippet_⇲6846 Remediation_Puppet_snippet_⇲
6852 Complexity:·low6847 Complexity:·low
6853 Disruption:·low6848 Disruption:·low
6854 Strategy:···enable6849 Strategy:···enable
6855 include·install_rsyslog6850 include·install_rsyslog
  
6856 class·install_rsyslog·{6851 class·install_rsyslog·{
Offset 6871, 14 lines modifiedOffset 6865, 20 lines modified
6871 if·!·rpm·-q·--quiet·"rsyslog"·;·then6865 if·!·rpm·-q·--quiet·"rsyslog"·;·then
6872 ····yum·install·-y·"rsyslog"6866 ····yum·install·-y·"rsyslog"
6873 fi6867 fi
  
6874 else6868 else
6875 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6869 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6876 fi6870 fi
 6871 Remediation_Anaconda_snippet_⇲
 6872 Complexity:·low
 6873 Disruption:·low
 6874 Strategy:···enable
  
 6875 package·--add=rsyslog
6877 Remediation_Ansible_snippet_⇲6876 Remediation_Ansible_snippet_⇲
6878 Complexity:·low6877 Complexity:·low
6879 Disruption:·low6878 Disruption:·low
6880 Strategy:···enable6879 Strategy:···enable
6881 -·name:·Ensure·rsyslog·is·installed6880 -·name:·Ensure·rsyslog·is·installed
6882 ··package:6881 ··package:
6883 ····name:·rsyslog6882 ····name:·rsyslog
Offset 7063, 20 lines modifiedOffset 7063, 14 lines modified
7063 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,7063 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,
7064 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7064 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
7065 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,7065 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
7066 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR7066 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
7067 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR7067 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
7068 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,7068 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
7069 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-37069 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3
7070 Remediation_Anaconda_snippet_⇲ 
7071 Complexity:·low 
7072 Disruption:·low 
7073 Strategy:···disable 
  
7074 package·--remove=dhcp 
7075 Remediation_Puppet_snippet_⇲7070 Remediation_Puppet_snippet_⇲
7076 Complexity:·low7071 Complexity:·low
7077 Disruption:·low7072 Disruption:·low
7078 Strategy:···disable7073 Strategy:···disable
7079 include·remove_dhcp7074 include·remove_dhcp
  
7080 class·remove_dhcp·{7075 class·remove_dhcp·{
Offset 7096, 14 lines modifiedOffset 7090, 20 lines modified
7096 #»      ···system!7090 #»      ···system!
  
7097 if·rpm·-q·--quiet·"dhcp"·;·then7091 if·rpm·-q·--quiet·"dhcp"·;·then
  
7098 ····yum·remove·-y·"dhcp"7092 ····yum·remove·-y·"dhcp"
  
7099 fi7093 fi
 7094 Remediation_Anaconda_snippet_⇲
 7095 Complexity:·low
 7096 Disruption:·low
 7097 Strategy:···disable
  
 7098 package·--remove=dhcp
7100 Remediation_Ansible_snippet_⇲7099 Remediation_Ansible_snippet_⇲
7101 Complexity:·low7100 Complexity:·low
7102 Disruption:·low7101 Disruption:·low
7103 Strategy:···disable7102 Strategy:···disable
7104 -·name:·Ensure·dhcp·is·removed7103 -·name:·Ensure·dhcp·is·removed
7105 ··package:7104 ··package:
7106 ····name:·dhcp7105 ····name:·dhcp
Offset 7150, 20 lines modifiedOffset 7150, 14 lines modified
7150 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7150 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
Max diff block lines reached; 14284/17755 bytes (80.45%) of diff not shown.
604 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-cjis.html
    
Offset 17036, 116 lines modifiedOffset 17036, 116 lines modified
000428b0:·2d74·6172·6765·743d·2223·6964·6d35·3935··-target="#idm595000428b0:·2d74·6172·6765·743d·2223·6964·6d35·3935··-target="#idm595
000428c0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·000428c0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
000428d0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar000428d0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
000428e0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal000428e0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
000428f0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ000428f0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00042900:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00042900:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00042910:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00042910:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00042920:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn00042920:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
00042930:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br00042930:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
00042940:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00042940:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00042950:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00042950:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00042960:·6170·7365·2220·6964·3d22·6964·6d35·3935··apse"·id="idm59500042960:·7365·2220·6964·3d22·6964·6d35·3935·3822··se"·id="idm5958"
00042970:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=00042970:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00042980:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str00042980:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00042990:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde00042990:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
000429a0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden000429a0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
000429b0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com000429b0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
000429c0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td000429c0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
000429d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t000429d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
000429e0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption000429e0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
000429f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t000429f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00042a00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00042a00:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
00042a10:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00042a10:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00042a20:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00042a20:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00042a30:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00042a30:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
00042a40:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
00042a50:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><00042a40:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 00042a50:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 00042a60:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 00042a70:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 00042a80:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 00042a90:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 00042aa0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 00042ab0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00042ac0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00042ad0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00042ae0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00042af0:·6172·6765·743d·2223·6964·6d35·3935·3922··arget="#idm5959"
 00042b00:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00042b10:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00042b20:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00042b30:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00042b40:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00042b50:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00042b60:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 00042b70:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00042b80:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00042b90:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00042ba0:·6964·3d22·6964·6d35·3935·3922·3e3c·7461··id="idm5959"><ta
 00042bb0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 00042bc0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 00042bd0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 00042be0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00042bf0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 00042c00:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 00042c10:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00042c20:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00042c30:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00042c40:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 00042c50:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 00042c60:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 00042c70:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 00042c80:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 00042c90:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 00042ca0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 00042cb0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
 00042cc0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
 00042cd0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
 00042ce0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 00042cf0:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r
 00042d00:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 00042d10:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 00042d20:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 00042d30:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 00042d40:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 00042d50:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 00042d60:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 00042d70:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 00042d80:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
00042a60:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl00042d90:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
00042a70:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc00042da0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
00042a80:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl00042db0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
00042a90:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat00042dc0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
00042aa0:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm5900042dd0:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm59
00042ab0:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0"00042de0:·3630·2220·7461·6269·6e64·6578·3d22·3022··60"·tabindex="0"
00042ac0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00042df0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00042ad0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00042e00:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00042ae0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00042e10:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00042af0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00042e20:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00042b00:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00042e30:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00042b10:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni00042e40:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
00042b20:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>00042e50:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00042b30:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane00042e60:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00042b40:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00042e70:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00042b50:·7073·6522·2069·643d·2269·646d·3539·3539··pse"·id="idm595900042e80:·6c61·7073·6522·2069·643d·2269·646d·3539··lapse"·id="idm59
00042b60:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="00042e90:·3630·223e·3c74·6162·6c65·2063·6c61·7373··60"><table·class
00042b70:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri00042ea0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
00042b80:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border00042eb0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00042b90:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens00042ec0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
00042ba0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp00042ed0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
00042bb0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>00042ee0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00042bc0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00042ef0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00042bd0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:00042f00:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00042be0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00042f10:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00042bf0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00042f20:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00042c00:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>00042f30:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00042c10:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>00042f40:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
00042c20:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co00042f50:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00042f60:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 00042f70:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
00042c30:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
00042c40:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
00042c50:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
00042c60:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
00042c70:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
00042c80:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
00042c90:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
00042ca0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
00042cb0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
00042cc0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
00042cd0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
00042ce0:·7461·7267·6574·3d22·2369·646d·3539·3630··target="#idm5960 
00042cf0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
00042d00:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
00042d10:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
00042d20:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
00042d30:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
Max diff block lines reached; 416402/431058 bytes (96.60%) of diff not shown.
183 KB
html2text {}
    
Offset 378, 20 lines modifiedOffset 378, 14 lines modified
378 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed378 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
379 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule379 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule
380 Remediation_OSBuild_Blueprint_snippet_⇲380 Remediation_OSBuild_Blueprint_snippet_⇲
  
381 [[packages]]381 [[packages]]
382 name·=·"aide"382 name·=·"aide"
383 version·=·"*"383 version·=·"*"
384 Remediation_Anaconda_snippet_⇲ 
385 Complexity:·low 
386 Disruption:·low 
387 Strategy:···enable 
  
388 package·--add=aide 
389 Remediation_Puppet_snippet_⇲384 Remediation_Puppet_snippet_⇲
390 Complexity:·low385 Complexity:·low
391 Disruption:·low386 Disruption:·low
392 Strategy:···enable387 Strategy:···enable
393 include·install_aide388 include·install_aide
  
394 class·install_aide·{389 class·install_aide·{
Offset 409, 14 lines modifiedOffset 403, 20 lines modified
409 if·!·rpm·-q·--quiet·"aide"·;·then403 if·!·rpm·-q·--quiet·"aide"·;·then
410 ····yum·install·-y·"aide"404 ····yum·install·-y·"aide"
411 fi405 fi
  
412 else406 else
413 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'407 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
414 fi408 fi
 409 Remediation_Anaconda_snippet_⇲
 410 Complexity:·low
 411 Disruption:·low
 412 Strategy:···enable
  
 413 package·--add=aide
415 Remediation_Ansible_snippet_⇲414 Remediation_Ansible_snippet_⇲
416 Complexity:·low415 Complexity:·low
417 Disruption:·low416 Disruption:·low
418 Strategy:···enable417 Strategy:···enable
419 -·name:·Ensure·aide·is·installed418 -·name:·Ensure·aide·is·installed
420 ··package:419 ··package:
421 ····name:·aide420 ····name:·aide
Offset 3794, 15 lines modifiedOffset 3794, 15 lines modified
3794 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.3794 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
3795 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.3795 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
3796 Severity: ················medium3796 Severity: ················medium
3797 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod3797 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
3798 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030490,·SV-248791r818684_rule3798 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030490,·SV-248791r818684_rule
3799 Remediation_Shell_script_⇲3799 Remediation_Shell_script_⇲
3800 #·Remediation·is·applicable·only·in·certain·platforms3800 #·Remediation·is·applicable·only·in·certain·platforms
3801 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then3801 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
3802 #·First·perform·the·remediation·of·the·syscall·rule3802 #·First·perform·the·remediation·of·the·syscall·rule
3803 #·Retrieve·hardware·architecture·of·the·underlying·system3803 #·Retrieve·hardware·architecture·of·the·underlying·system
3804 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3804 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3805 for·ARCH·in·"${RULE_ARCHS[@]}"3805 for·ARCH·in·"${RULE_ARCHS[@]}"
3806 do3806 do
Offset 4149, 16 lines modifiedOffset 4149, 16 lines modified
4149 ··-·reboot_required4149 ··-·reboot_required
4150 ··-·restrict_strategy4150 ··-·restrict_strategy
  
4151 -·name:·Set·architecture·for·audit·chmod·tasks4151 -·name:·Set·architecture·for·audit·chmod·tasks
4152 ··set_fact:4152 ··set_fact:
4153 ····audit_arch:·b644153 ····audit_arch:·b64
4154 ··when:4154 ··when:
4155 ··-·'"audit"·in·ansible_facts.packages' 
4156 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4155 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4156 ··-·'"audit"·in·ansible_facts.packages'
4157 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4157 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4158 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4158 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4159 ··tags:4159 ··tags:
4160 ··-·CJIS-5.4.1.14160 ··-·CJIS-5.4.1.1
4161 ··-·DISA-STIG-OL08-00-0304904161 ··-·DISA-STIG-OL08-00-030490
4162 ··-·NIST-800-171-3.1.74162 ··-·NIST-800-171-3.1.7
4163 ··-·NIST-800-53-AU-12(c)4163 ··-·NIST-800-53-AU-12(c)
Offset 4295, 16 lines modifiedOffset 4295, 16 lines modified
4295 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004295 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4296 ········-F·auid!=unset·-F·key=perm_mod4296 ········-F·auid!=unset·-F·key=perm_mod
4297 ······create:·true4297 ······create:·true
4298 ······mode:·o-rwx4298 ······mode:·o-rwx
4299 ······state:·present4299 ······state:·present
4300 ····when:·syscalls_found·|·length·==·04300 ····when:·syscalls_found·|·length·==·0
4301 ··when:4301 ··when:
4302 ··-·'"audit"·in·ansible_facts.packages' 
4303 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4302 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4303 ··-·'"audit"·in·ansible_facts.packages'
4304 ··tags:4304 ··tags:
4305 ··-·CJIS-5.4.1.14305 ··-·CJIS-5.4.1.1
4306 ··-·DISA-STIG-OL08-00-0304904306 ··-·DISA-STIG-OL08-00-030490
4307 ··-·NIST-800-171-3.1.74307 ··-·NIST-800-171-3.1.7
4308 ··-·NIST-800-53-AU-12(c)4308 ··-·NIST-800-53-AU-12(c)
4309 ··-·NIST-800-53-AU-2(d)4309 ··-·NIST-800-53-AU-2(d)
4310 ··-·NIST-800-53-CM-6(a)4310 ··-·NIST-800-53-CM-6(a)
Offset 4439, 16 lines modifiedOffset 4439, 16 lines modified
4439 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004439 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4440 ········-F·auid!=unset·-F·key=perm_mod4440 ········-F·auid!=unset·-F·key=perm_mod
4441 ······create:·true4441 ······create:·true
4442 ······mode:·o-rwx4442 ······mode:·o-rwx
4443 ······state:·present4443 ······state:·present
4444 ····when:·syscalls_found·|·length·==·04444 ····when:·syscalls_found·|·length·==·0
4445 ··when:4445 ··when:
4446 ··-·'"audit"·in·ansible_facts.packages' 
4447 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4446 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4447 ··-·'"audit"·in·ansible_facts.packages'
4448 ··-·audit_arch·==·"b64"4448 ··-·audit_arch·==·"b64"
4449 ··tags:4449 ··tags:
4450 ··-·CJIS-5.4.1.14450 ··-·CJIS-5.4.1.1
4451 ··-·DISA-STIG-OL08-00-0304904451 ··-·DISA-STIG-OL08-00-030490
4452 ··-·NIST-800-171-3.1.74452 ··-·NIST-800-171-3.1.7
4453 ··-·NIST-800-53-AU-12(c)4453 ··-·NIST-800-53-AU-12(c)
4454 ··-·NIST-800-53-AU-2(d)4454 ··-·NIST-800-53-AU-2(d)
Offset 4472, 15 lines modifiedOffset 4472, 15 lines modified
4472 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.4472 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
4473 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.4473 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
4474 Severity: ················medium4474 Severity: ················medium
4475 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown4475 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
4476 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030480,·SV-248790r818681_rule4476 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030480,·SV-248790r818681_rule
4477 Remediation_Shell_script_⇲4477 Remediation_Shell_script_⇲
4478 #·Remediation·is·applicable·only·in·certain·platforms4478 #·Remediation·is·applicable·only·in·certain·platforms
4479 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then4479 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
4480 #·First·perform·the·remediation·of·the·syscall·rule4480 #·First·perform·the·remediation·of·the·syscall·rule
4481 #·Retrieve·hardware·architecture·of·the·underlying·system4481 #·Retrieve·hardware·architecture·of·the·underlying·system
4482 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4482 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4483 for·ARCH·in·"${RULE_ARCHS[@]}"4483 for·ARCH·in·"${RULE_ARCHS[@]}"
4484 do4484 do
Max diff block lines reached; 178147/187051 bytes (95.24%) of diff not shown.
981 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-cui.html
    
Offset 15288, 116 lines modifiedOffset 15288, 116 lines modified
0003bb70:·2d74·6172·6765·743d·2223·6964·6d35·3935··-target="#idm5950003bb70:·2d74·6172·6765·743d·2223·6964·6d35·3935··-target="#idm595
0003bb80:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·0003bb80:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0003bb90:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003bb90:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bba0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003bba0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bbb0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003bbb0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003bbc0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003bbc0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bbd0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003bbd0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bbe0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003bbe0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003bbf0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003bbf0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003bc00:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003bc00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003bc10:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003bc10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bc20:·6170·7365·2220·6964·3d22·6964·6d35·3935··apse"·id="idm5950003bc20:·7365·2220·6964·3d22·6964·6d35·3935·3822··se"·id="idm5958"
0003bc30:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=0003bc30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bc40:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003bc40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bc50:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003bc50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bc60:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bc60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bc70:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003bc70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bc80:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003bc80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bc90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bc90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bca0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003bca0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bcb0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bcb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bcc0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003bcc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bcd0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003bcd0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bce0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003bce0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bcf0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003bcf0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003bd00:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003bd10:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><0003bd00:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 0003bd10:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 0003bd20:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 0003bd30:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 0003bd40:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 0003bd50:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 0003bd60:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 0003bd70:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003bd80:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003bd90:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003bda0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003bdb0:·6172·6765·743d·2223·6964·6d35·3935·3922··arget="#idm5959"
 0003bdc0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003bdd0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003bde0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003bdf0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003be00:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003be10:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003be20:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003be30:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003be40:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003be50:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003be60:·6964·3d22·6964·6d35·3935·3922·3e3c·7461··id="idm5959"><ta
 0003be70:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003be80:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003be90:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003bea0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003beb0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003bec0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003bed0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bee0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003bef0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003bf00:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003bf10:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003bf20:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003bf30:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003bf40:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003bf50:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003bf60:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003bf70:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
 0003bf80:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
 0003bf90:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
 0003bfa0:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 0003bfb0:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r
 0003bfc0:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 0003bfd0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 0003bfe0:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0003bff0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 0003c000:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003c010:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003c020:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0003c030:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0003c040:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
0003bd20:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003c050:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003bd30:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003c060:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003bd40:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003c070:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003bd50:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003c080:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003bd60:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm590003c090:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm59
0003bd70:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0"0003c0a0:·3630·2220·7461·6269·6e64·6578·3d22·3022··60"·tabindex="0"
0003bd80:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003c0b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003bd90:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003c0c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bda0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003c0d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003bdb0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003c0e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003bdc0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003c0f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003bdd0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003c100:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003bde0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003c110:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003bdf0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003c120:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003be00:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003c130:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003be10:·7073·6522·2069·643d·2269·646d·3539·3539··pse"·id="idm59590003c140:·6c61·7073·6522·2069·643d·2269·646d·3539··lapse"·id="idm59
0003be20:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003c150:·3630·223e·3c74·6162·6c65·2063·6c61·7373··60"><table·class
0003be30:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003c160:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003be40:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003c170:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003be50:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003c180:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003be60:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003c190:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003be70:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003c1a0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003be80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c1b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003be90:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003c1c0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003bea0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c1d0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003beb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003c1e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bec0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003c1f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003bed0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003c200:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003bee0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003c210:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c220:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 0003c230:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
0003bef0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003bf00:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
0003bf10:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
0003bf20:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
0003bf30:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0003bf40:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0003bf50:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0003bf60:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003bf70:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003bf80:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003bf90:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003bfa0:·7461·7267·6574·3d22·2369·646d·3539·3630··target="#idm5960 
0003bfb0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003bfc0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003bfd0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003bfe0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003bff0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
Max diff block lines reached; 900877/915533 bytes (98.40%) of diff not shown.
86.6 KB
html2text {}
    
Offset 96, 20 lines modifiedOffset 96, 14 lines modified
96 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed96 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
97 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule97 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule
98 Remediation_OSBuild_Blueprint_snippet_⇲98 Remediation_OSBuild_Blueprint_snippet_⇲
  
99 [[packages]]99 [[packages]]
100 name·=·"aide"100 name·=·"aide"
101 version·=·"*"101 version·=·"*"
102 Remediation_Anaconda_snippet_⇲ 
103 Complexity:·low 
104 Disruption:·low 
105 Strategy:···enable 
  
106 package·--add=aide 
107 Remediation_Puppet_snippet_⇲102 Remediation_Puppet_snippet_⇲
108 Complexity:·low103 Complexity:·low
109 Disruption:·low104 Disruption:·low
110 Strategy:···enable105 Strategy:···enable
111 include·install_aide106 include·install_aide
  
112 class·install_aide·{107 class·install_aide·{
Offset 127, 14 lines modifiedOffset 121, 20 lines modified
127 if·!·rpm·-q·--quiet·"aide"·;·then121 if·!·rpm·-q·--quiet·"aide"·;·then
128 ····yum·install·-y·"aide"122 ····yum·install·-y·"aide"
129 fi123 fi
  
130 else124 else
131 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'125 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
132 fi126 fi
 127 Remediation_Anaconda_snippet_⇲
 128 Complexity:·low
 129 Disruption:·low
 130 Strategy:···enable
  
 131 package·--add=aide
133 Remediation_Ansible_snippet_⇲132 Remediation_Ansible_snippet_⇲
134 Complexity:·low133 Complexity:·low
135 Disruption:·low134 Disruption:·low
136 Strategy:···enable135 Strategy:···enable
137 -·name:·Ensure·aide·is·installed136 -·name:·Ensure·aide·is·installed
138 ··package:137 ··package:
139 ····name:·aide138 ····name:·aide
Offset 399, 20 lines modifiedOffset 399, 14 lines modified
399 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed399 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
400 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174400 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
401 Remediation_OSBuild_Blueprint_snippet_⇲401 Remediation_OSBuild_Blueprint_snippet_⇲
  
402 [[packages]]402 [[packages]]
403 name·=·"crypto-policies"403 name·=·"crypto-policies"
404 version·=·"*"404 version·=·"*"
405 Remediation_Anaconda_snippet_⇲ 
406 Complexity:·low 
407 Disruption:·low 
408 Strategy:···enable 
  
409 package·--add=crypto-policies 
410 Remediation_Puppet_snippet_⇲405 Remediation_Puppet_snippet_⇲
411 Complexity:·low406 Complexity:·low
412 Disruption:·low407 Disruption:·low
413 Strategy:···enable408 Strategy:···enable
414 include·install_crypto-policies409 include·install_crypto-policies
  
415 class·install_crypto-policies·{410 class·install_crypto-policies·{
Offset 424, 14 lines modifiedOffset 418, 20 lines modified
424 Complexity:·low418 Complexity:·low
425 Disruption:·low419 Disruption:·low
426 Strategy:···enable420 Strategy:···enable
  
427 if·!·rpm·-q·--quiet·"crypto-policies"·;·then421 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
428 ····yum·install·-y·"crypto-policies"422 ····yum·install·-y·"crypto-policies"
429 fi423 fi
 424 Remediation_Anaconda_snippet_⇲
 425 Complexity:·low
 426 Disruption:·low
 427 Strategy:···enable
  
 428 package·--add=crypto-policies
430 Remediation_Ansible_snippet_⇲429 Remediation_Ansible_snippet_⇲
431 Complexity:·low430 Complexity:·low
432 Disruption:·low431 Disruption:·low
433 Strategy:···enable432 Strategy:···enable
434 -·name:·Ensure·crypto-policies·is·installed433 -·name:·Ensure·crypto-policies·is·installed
435 ··package:434 ··package:
436 ····name:·crypto-policies435 ····name:·crypto-policies
Offset 951, 20 lines modifiedOffset 951, 14 lines modified
951 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed951 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
952 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125952 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
953 Remediation_OSBuild_Blueprint_snippet_⇲953 Remediation_OSBuild_Blueprint_snippet_⇲
  
954 [[packages]]954 [[packages]]
955 name·=·"sudo"955 name·=·"sudo"
956 version·=·"*"956 version·=·"*"
957 Remediation_Anaconda_snippet_⇲ 
958 Complexity:·low 
959 Disruption:·low 
960 Strategy:···enable 
  
961 package·--add=sudo 
962 Remediation_Puppet_snippet_⇲957 Remediation_Puppet_snippet_⇲
963 Complexity:·low958 Complexity:·low
964 Disruption:·low959 Disruption:·low
965 Strategy:···enable960 Strategy:···enable
966 include·install_sudo961 include·install_sudo
  
967 class·install_sudo·{962 class·install_sudo·{
Offset 982, 14 lines modifiedOffset 976, 20 lines modified
982 if·!·rpm·-q·--quiet·"sudo"·;·then976 if·!·rpm·-q·--quiet·"sudo"·;·then
983 ····yum·install·-y·"sudo"977 ····yum·install·-y·"sudo"
984 fi978 fi
  
985 else979 else
986 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'980 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
987 fi981 fi
 982 Remediation_Anaconda_snippet_⇲
 983 Complexity:·low
 984 Disruption:·low
 985 Strategy:···enable
  
 986 package·--add=sudo
988 Remediation_Ansible_snippet_⇲987 Remediation_Ansible_snippet_⇲
989 Complexity:·low988 Complexity:·low
990 Disruption:·low989 Disruption:·low
991 Strategy:···enable990 Strategy:···enable
992 -·name:·Ensure·sudo·is·installed991 -·name:·Ensure·sudo·is·installed
993 ··package:992 ··package:
994 ····name:·sudo993 ····name:·sudo
Offset 1014, 20 lines modifiedOffset 1014, 14 lines modified
1014 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed1014 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed
Max diff block lines reached; 84749/88697 bytes (95.55%) of diff not shown.
629 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-e8.html
    
Offset 20400, 104 lines modifiedOffset 20400, 104 lines modified
0004faf0:·2d74·6172·6765·743d·2223·6964·6d31·3033··-target="#idm1030004faf0:·2d74·6172·6765·743d·2223·6964·6d31·3033··-target="#idm103
0004fb00:·3835·2220·7461·6269·6e64·6578·3d22·3022··85"·tabindex="0"0004fb00:·3835·2220·7461·6269·6e64·6578·3d22·3022··85"·tabindex="0"
0004fb10:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0004fb10:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0004fb20:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0004fb20:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0004fb30:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0004fb30:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0004fb40:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0004fb40:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0004fb50:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0004fb50:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0004fb60:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0004fb60:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0004fb70:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0004fb70:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0004fb80:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0004fb80:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0004fb90:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0004fb90:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0004fba0:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm100004fba0:·7073·6522·2069·643d·2269·646d·3130·3338··pse"·id="idm1038
0004fbb0:·3338·3522·3e3c·7461·626c·6520·636c·6173··385"><table·clas0004fbb0:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=
0004fbc0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0004fbc0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0004fbd0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0004fbd0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0004fbe0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0004fbe0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0004fbf0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0004fbf0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0004fc00:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0004fc00:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0004fc10:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0004fc10:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0004fc20:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0004fc20:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0004fc30:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0004fc30:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0004fc40:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0004fc40:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0004fc50:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0004fc50:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0004fc60:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0004fc60:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0004fc70:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0004fc70:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0004fc80:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0004fc90:·2d61·6464·3d72·6561·720a·3c2f·636f·6465··-add=rear.</code 
0004fca0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0004fcb0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0004fcc0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0004fcd0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0004fce0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0004fcf0:·3130·3338·3622·2074·6162·696e·6465·783d··10386"·tabindex= 
0004fd00:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0004fd10:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0004fd20:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0004fd30:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0004fd40:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0004fd50:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet· 
0004fd60:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0004fc80:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0004fc90:·616c·6c5f·7265·6172·0a0a·636c·6173·7320··all_rear..class·
 0004fca0:·696e·7374·616c·6c5f·7265·6172·207b·0a20··install_rear·{.·
 0004fcb0:·2070·6163·6b61·6765·207b·2027·7265·6172···package·{·'rear
 0004fcc0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0004fcd0:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0004fce0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0004fcf0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0004fd00:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0004fd10:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0004fd20:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0004fd30:·2d74·6172·6765·743d·2223·6964·6d31·3033··-target="#idm103
 0004fd40:·3836·2220·7461·6269·6e64·6578·3d22·3022··86"·tabindex="0"
 0004fd50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0004fd60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0004fd70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0004fd80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0004fd90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0004fda0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0004fdb0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0004fdc0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0004fdd0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0004fde0:·6522·2069·643d·2269·646d·3130·3338·3622··e"·id="idm10386"
0004fd70:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0004fdf0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0004fe00:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0004fe10:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0004fe20:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0004fe30:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0004fd80:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0004fd90:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0004fda0:·3033·3836·223e·3c74·6162·6c65·2063·6c61··0386"><table·cla 
0004fdb0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0004fdc0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0004fdd0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0004fde0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0004fdf0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0004fe00:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0004fe10:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0004fe20:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0004fe40:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0004fe30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0004fe50:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0004fe60:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0004fe70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0004fe80:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0004fe90:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0004fe40:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0004fe50:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0004fe60:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0004fe70:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0004fe80:·6e73·7461·6c6c·5f72·6561·720a·0a63·6c61··nstall_rear..cla 
0004fe90:·7373·2069·6e73·7461·6c6c·5f72·6561·7220··ss·install_rear· 
0004fea0:·7b0a·2020·7061·636b·6167·6520·7b20·2772··{.··package·{·'r 
0004feb0:·6561·7227·3a0a·2020·2020·656e·7375·7265··ear':.····ensure 
0004fec0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0004fed0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0004fee0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0004fef0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0004ff00:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0004ff10:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0004ff20:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0004ff30:·3130·3338·3722·2074·6162·696e·6465·783d··10387"·tabindex= 
0004ff40:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0004ff50:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0004ff60:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0004ff70:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0004ff80:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0004ff90:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0004ffa0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0004ffb0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0004ffc0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0004ffd0:·6170·7365·2220·6964·3d22·6964·6d31·3033··apse"·id="idm103 
0004ffe0:·3837·223e·3c74·6162·6c65·2063·6c61·7373··87"><table·class 
0004fff0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
00050000:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
00050010:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
00050020:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
00050030:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
00050040:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0004fea0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0004feb0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0004fec0:·653e·0a69·6620·2120·7270·6d20·2d71·202d··e>.if·!·rpm·-q·-
 0004fed0:·2d71·7569·6574·2022·7265·6172·2220·3b20··-quiet·"rear"·;·
 0004fee0:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 0004fef0:·7461·6c6c·202d·7920·2272·6561·7222·0a66··tall·-y·"rear".f
 0004ff00:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
 0004ff10:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0004ff20:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0004ff30:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0004ff40:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0004ff50:·6574·3d22·2369·646d·3130·3338·3722·2074··et="#idm10387"·t
Max diff block lines reached; 491610/504610 bytes (97.42%) of diff not shown.
136 KB
html2text {}
    
Offset 872, 20 lines modifiedOffset 872, 14 lines modified
872 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed872 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
873 Identifiers·and·References873 Identifiers·and·References
874 Remediation_OSBuild_Blueprint_snippet_⇲874 Remediation_OSBuild_Blueprint_snippet_⇲
  
875 [[packages]]875 [[packages]]
876 name·=·"rear"876 name·=·"rear"
877 version·=·"*"877 version·=·"*"
878 Remediation_Anaconda_snippet_⇲ 
879 Complexity:·low 
880 Disruption:·low 
881 Strategy:···enable 
  
882 package·--add=rear 
883 Remediation_Puppet_snippet_⇲878 Remediation_Puppet_snippet_⇲
884 Complexity:·low879 Complexity:·low
885 Disruption:·low880 Disruption:·low
886 Strategy:···enable881 Strategy:···enable
887 include·install_rear882 include·install_rear
  
888 class·install_rear·{883 class·install_rear·{
Offset 897, 14 lines modifiedOffset 891, 20 lines modified
897 Complexity:·low891 Complexity:·low
898 Disruption:·low892 Disruption:·low
899 Strategy:···enable893 Strategy:···enable
  
900 if·!·rpm·-q·--quiet·"rear"·;·then894 if·!·rpm·-q·--quiet·"rear"·;·then
901 ····yum·install·-y·"rear"895 ····yum·install·-y·"rear"
902 fi896 fi
 897 Remediation_Anaconda_snippet_⇲
 898 Complexity:·low
 899 Disruption:·low
 900 Strategy:···enable
  
 901 package·--add=rear
903 Remediation_Ansible_snippet_⇲902 Remediation_Ansible_snippet_⇲
904 Complexity:·low903 Complexity:·low
905 Disruption:·low904 Disruption:·low
906 Strategy:···enable905 Strategy:···enable
907 -·name:·Ensure·rear·is·installed906 -·name:·Ensure·rear·is·installed
908 ··package:907 ··package:
909 ····name:·rear908 ····name:·rear
Offset 1615, 15 lines modifiedOffset 1615, 15 lines modified
1615 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1615 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1616 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1616 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1617 Severity: ················medium1617 Severity: ················medium
1618 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1618 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1619 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030490,·SV-248791r818684_rule1619 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030490,·SV-248791r818684_rule
1620 Remediation_Shell_script_⇲1620 Remediation_Shell_script_⇲
1621 #·Remediation·is·applicable·only·in·certain·platforms1621 #·Remediation·is·applicable·only·in·certain·platforms
1622 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1622 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1623 #·First·perform·the·remediation·of·the·syscall·rule1623 #·First·perform·the·remediation·of·the·syscall·rule
1624 #·Retrieve·hardware·architecture·of·the·underlying·system1624 #·Retrieve·hardware·architecture·of·the·underlying·system
1625 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1625 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1626 for·ARCH·in·"${RULE_ARCHS[@]}"1626 for·ARCH·in·"${RULE_ARCHS[@]}"
1627 do1627 do
Offset 1970, 16 lines modifiedOffset 1970, 16 lines modified
1970 ··-·reboot_required1970 ··-·reboot_required
1971 ··-·restrict_strategy1971 ··-·restrict_strategy
  
1972 -·name:·Set·architecture·for·audit·chmod·tasks1972 -·name:·Set·architecture·for·audit·chmod·tasks
1973 ··set_fact:1973 ··set_fact:
1974 ····audit_arch:·b641974 ····audit_arch:·b64
1975 ··when:1975 ··when:
1976 ··-·'"audit"·in·ansible_facts.packages' 
1977 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1976 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1977 ··-·'"audit"·in·ansible_facts.packages'
1978 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1978 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1979 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1979 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1980 ··tags:1980 ··tags:
1981 ··-·CJIS-5.4.1.11981 ··-·CJIS-5.4.1.1
1982 ··-·DISA-STIG-OL08-00-0304901982 ··-·DISA-STIG-OL08-00-030490
1983 ··-·NIST-800-171-3.1.71983 ··-·NIST-800-171-3.1.7
1984 ··-·NIST-800-53-AU-12(c)1984 ··-·NIST-800-53-AU-12(c)
Offset 2116, 16 lines modifiedOffset 2116, 16 lines modified
2116 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002116 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2117 ········-F·auid!=unset·-F·key=perm_mod2117 ········-F·auid!=unset·-F·key=perm_mod
2118 ······create:·true2118 ······create:·true
2119 ······mode:·o-rwx2119 ······mode:·o-rwx
2120 ······state:·present2120 ······state:·present
2121 ····when:·syscalls_found·|·length·==·02121 ····when:·syscalls_found·|·length·==·0
2122 ··when:2122 ··when:
2123 ··-·'"audit"·in·ansible_facts.packages' 
2124 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2123 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2124 ··-·'"audit"·in·ansible_facts.packages'
2125 ··tags:2125 ··tags:
2126 ··-·CJIS-5.4.1.12126 ··-·CJIS-5.4.1.1
2127 ··-·DISA-STIG-OL08-00-0304902127 ··-·DISA-STIG-OL08-00-030490
2128 ··-·NIST-800-171-3.1.72128 ··-·NIST-800-171-3.1.7
2129 ··-·NIST-800-53-AU-12(c)2129 ··-·NIST-800-53-AU-12(c)
2130 ··-·NIST-800-53-AU-2(d)2130 ··-·NIST-800-53-AU-2(d)
2131 ··-·NIST-800-53-CM-6(a)2131 ··-·NIST-800-53-CM-6(a)
Offset 2260, 16 lines modifiedOffset 2260, 16 lines modified
2260 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002260 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2261 ········-F·auid!=unset·-F·key=perm_mod2261 ········-F·auid!=unset·-F·key=perm_mod
2262 ······create:·true2262 ······create:·true
2263 ······mode:·o-rwx2263 ······mode:·o-rwx
2264 ······state:·present2264 ······state:·present
2265 ····when:·syscalls_found·|·length·==·02265 ····when:·syscalls_found·|·length·==·0
2266 ··when:2266 ··when:
2267 ··-·'"audit"·in·ansible_facts.packages' 
2268 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2267 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2268 ··-·'"audit"·in·ansible_facts.packages'
2269 ··-·audit_arch·==·"b64"2269 ··-·audit_arch·==·"b64"
2270 ··tags:2270 ··tags:
2271 ··-·CJIS-5.4.1.12271 ··-·CJIS-5.4.1.1
2272 ··-·DISA-STIG-OL08-00-0304902272 ··-·DISA-STIG-OL08-00-030490
2273 ··-·NIST-800-171-3.1.72273 ··-·NIST-800-171-3.1.7
2274 ··-·NIST-800-53-AU-12(c)2274 ··-·NIST-800-53-AU-12(c)
2275 ··-·NIST-800-53-AU-2(d)2275 ··-·NIST-800-53-AU-2(d)
Offset 2293, 15 lines modifiedOffset 2293, 15 lines modified
2293 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2293 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2294 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2294 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2295 Severity: ················medium2295 Severity: ················medium
2296 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2296 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2297 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030480,·SV-248790r818681_rule2297 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030480,·SV-248790r818681_rule
2298 Remediation_Shell_script_⇲2298 Remediation_Shell_script_⇲
2299 #·Remediation·is·applicable·only·in·certain·platforms2299 #·Remediation·is·applicable·only·in·certain·platforms
2300 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2300 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2301 #·First·perform·the·remediation·of·the·syscall·rule2301 #·First·perform·the·remediation·of·the·syscall·rule
2302 #·Retrieve·hardware·architecture·of·the·underlying·system2302 #·Retrieve·hardware·architecture·of·the·underlying·system
2303 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2303 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2304 for·ARCH·in·"${RULE_ARCHS[@]}"2304 for·ARCH·in·"${RULE_ARCHS[@]}"
2305 do2305 do
Max diff block lines reached; 130926/139091 bytes (94.13%) of diff not shown.
1.13 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-hipaa.html
    
Offset 31579, 21 lines modifiedOffset 31579, 21 lines modified
0007b5a0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0007b5a0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0007b5b0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0007b5b0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0007b5c0:·6170·7365·2220·6964·3d22·6964·6d32·3236··apse"·id="idm2260007b5c0:·6170·7365·2220·6964·3d22·6964·6d32·3236··apse"·id="idm226
0007b5d0:·3638·223e·3c70·7265·3e3c·636f·6465·3e23··68"><pre><code>#0007b5d0:·3638·223e·3c70·7265·3e3c·636f·6465·3e23··68"><pre><code>#
0007b5e0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·0007b5e0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
0007b5f0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·0007b5f0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
0007b600:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf0007b600:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
0007b610:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu0007b610:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
0007b620:·6965·7420·2d71·2061·7564·6974·2026·616d··iet·-q·audit·&am0007b620:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
0007b630:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/0007b630:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
0007b640:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0007b650:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0007b660:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren0007b640:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 0007b650:·7620·5d20·2661·6d70·3b26·616d·703b·2072··v·]·&amp;&amp;·r
 0007b660:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au
0007b670:·7620·5d3b·2074·6865·6e0a·0a23·2046·6972··v·];·then..#·Fir0007b670:·6469·743b·2074·6865·6e0a·0a23·2046·6972··dit;·then..#·Fir
0007b680:·7374·2070·6572·666f·726d·2074·6865·2072··st·perform·the·r0007b680:·7374·2070·6572·666f·726d·2074·6865·2072··st·perform·the·r
0007b690:·656d·6564·6961·7469·6f6e·206f·6620·7468··emediation·of·th0007b690:·656d·6564·6961·7469·6f6e·206f·6620·7468··emediation·of·th
0007b6a0:·6520·7379·7363·616c·6c20·7275·6c65·0a23··e·syscall·rule.#0007b6a0:·6520·7379·7363·616c·6c20·7275·6c65·0a23··e·syscall·rule.#
0007b6b0:·2052·6574·7269·6576·6520·6861·7264·7761···Retrieve·hardwa0007b6b0:·2052·6574·7269·6576·6520·6861·7264·7761···Retrieve·hardwa
0007b6c0:·7265·2061·7263·6869·7465·6374·7572·6520··re·architecture·0007b6c0:·7265·2061·7263·6869·7465·6374·7572·6520··re·architecture·
0007b6d0:·6f66·2074·6865·2075·6e64·6572·6c79·696e··of·the·underlyin0007b6d0:·6f66·2074·6865·2075·6e64·6572·6c79·696e··of·the·underlyin
0007b6e0:·6720·7379·7374·656d·0a5b·2022·2428·6765··g·system.[·"$(ge0007b6e0:·6720·7379·7374·656d·0a5b·2022·2428·6765··g·system.[·"$(ge
Offset 32473, 22 lines modifiedOffset 32473, 22 lines modified
0007ed80:·0a20·202d·2072·6573·7472·6963·745f·7374··.··-·restrict_st0007ed80:·0a20·202d·2072·6573·7472·6963·745f·7374··.··-·restrict_st
0007ed90:·7261·7465·6779·0a0a·2d20·6e61·6d65·3a20··rategy..-·name:·0007ed90:·7261·7465·6779·0a0a·2d20·6e61·6d65·3a20··rategy..-·name:·
0007eda0:·5365·7420·6172·6368·6974·6563·7475·7265··Set·architecture0007eda0:·5365·7420·6172·6368·6974·6563·7475·7265··Set·architecture
0007edb0:·2066·6f72·2061·7564·6974·2063·686d·6f64···for·audit·chmod0007edb0:·2066·6f72·2061·7564·6974·2063·686d·6f64···for·audit·chmod
0007edc0:·2074·6173·6b73·0a20·2073·6574·5f66·6163···tasks.··set_fac0007edc0:·2074·6173·6b73·0a20·2073·6574·5f66·6163···tasks.··set_fac
0007edd0:·743a·0a20·2020·2061·7564·6974·5f61·7263··t:.····audit_arc0007edd0:·743a·0a20·2020·2061·7564·6974·5f61·7263··t:.····audit_arc
0007ede0:·683a·2062·3634·0a20·2077·6865·6e3a·0a20··h:·b64.··when:.·0007ede0:·683a·2062·3634·0a20·2077·6865·6e3a·0a20··h:·b64.··when:.·
0007edf0:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a 
0007ee00:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
0007ee10:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib 
0007ee20:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
0007ee30:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
0007ee40:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
0007ee50:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
0007ee60:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]0007edf0:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu
 0007ee00:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 0007ee10:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 0007ee20:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 0007ee30:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 0007ee40:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a
 0007ee50:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible
 0007ee60:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
0007ee70:·0a20·202d·2061·6e73·6962·6c65·5f61·7263··.··-·ansible_arc0007ee70:·0a20·202d·2061·6e73·6962·6c65·5f61·7263··.··-·ansible_arc
0007ee80:·6869·7465·6374·7572·6520·3d3d·2022·6161··hitecture·==·"aa0007ee80:·6869·7465·6374·7572·6520·3d3d·2022·6161··hitecture·==·"aa
0007ee90:·7263·6836·3422·206f·7220·616e·7369·626c··rch64"·or·ansibl0007ee90:·7263·6836·3422·206f·7220·616e·7369·626c··rch64"·or·ansibl
0007eea0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=0007eea0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=
0007eeb0:·3d20·2270·7063·3634·2220·6f72·2061·6e73··=·"ppc64"·or·ans0007eeb0:·3d20·2270·7063·3634·2220·6f72·2061·6e73··=·"ppc64"·or·ans
0007eec0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur0007eec0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
0007eed0:·650a·2020·2020·3d3d·2022·7070·6336·346c··e.····==·"ppc64l0007eed0:·650a·2020·2020·3d3d·2022·7070·6336·346c··e.····==·"ppc64l
Offset 32796, 23 lines modifiedOffset 32796, 23 lines modified
000801b0:·7065·726d·5f6d·6f64·0a20·2020·2020·2063··perm_mod.······c000801b0:·7065·726d·5f6d·6f64·0a20·2020·2020·2063··perm_mod.······c
000801c0:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····000801c0:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····
000801d0:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··000801d0:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··
000801e0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese000801e0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese
000801f0:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys000801f0:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys
00080200:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le00080200:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le
00080210:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when00080210:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when
00080220:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i 
00080230:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
00080240:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an 
00080250:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
00080260:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
00080270:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
00080280:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
00080290:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe00080220:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi
 00080230:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 00080240:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 00080250:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 00080260:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 00080270:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·
 00080280:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi
 00080290:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
000802a0:·7222·5d0a·2020·7461·6773·3a0a·2020·2d20··r"].··tags:.··-·000802a0:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·
000802b0:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-000802b0:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-
000802c0:·2044·4953·412d·5354·4947·2d4f·4c30·382d···DISA-STIG-OL08-000802c0:·2044·4953·412d·5354·4947·2d4f·4c30·382d···DISA-STIG-OL08-
000802d0:·3030·2d30·3330·3439·300a·2020·2d20·4e49··00-030490.··-·NI000802d0:·3030·2d30·3330·3439·300a·2020·2d20·4e49··00-030490.··-·NI
000802e0:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.7000802e0:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.7
000802f0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53000802f0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
00080300:·2d41·552d·3132·2863·290a·2020·2d20·4e49··-AU-12(c).··-·NI00080300:·2d41·552d·3132·2863·290a·2020·2d20·4e49··-AU-12(c).··-·NI
00080310:·5354·2d38·3030·2d35·332d·4155·2d32·2864··ST-800-53-AU-2(d00080310:·5354·2d38·3030·2d35·332d·4155·2d32·2864··ST-800-53-AU-2(d
Offset 33108, 22 lines modifiedOffset 33108, 22 lines modified
00081530:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:00081530:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:
00081540:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode00081540:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode
00081550:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st00081550:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st
00081560:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···00081560:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···
00081570:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_00081570:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_
00081580:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=00081580:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=
00081590:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·00081590:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·
000815a0:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi 
000815b0:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag 
000815c0:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_ 
000815d0:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
000815e0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
000815f0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
00081600:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
00081610:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··000815a0:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 000815b0:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 000815c0:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 000815d0:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 000815e0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
 000815f0:·6e65·7222·5d0a·2020·2d20·2722·6175·6469··ner"].··-·'"audi
 00081600:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa
 00081610:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
00081620:·2d20·6175·6469·745f·6172·6368·203d·3d20··-·audit_arch·==·00081620:·2d20·6175·6469·745f·6172·6368·203d·3d20··-·audit_arch·==·
00081630:·2262·3634·220a·2020·7461·6773·3a0a·2020··"b64".··tags:.··00081630:·2262·3634·220a·2020·7461·6773·3a0a·2020··"b64".··tags:.··
00081640:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·00081640:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
00081650:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL000081650:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL0
00081660:·382d·3030·2d30·3330·3439·300a·2020·2d20··8-00-030490.··-·00081660:·382d·3030·2d30·3330·3439·300a·2020·2d20··8-00-030490.··-·
00081670:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.100081670:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
00081680:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-00081680:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-
Offset 34076, 20 lines modifiedOffset 34076, 20 lines modified
000851b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000851b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
000851c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·000851c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
000851d0:·6964·3d22·6964·6d32·3238·3236·223e·3c70··id="idm22826"><p000851d0:·6964·3d22·6964·6d32·3238·3236·223e·3c70··id="idm22826"><p
000851e0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed000851e0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
000851f0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic000851f0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
00085200:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer00085200:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
00085210:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i00085210:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
00085220:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
00085230:·2061·7564·6974·2026·616d·703b·2661·6d70···audit·&amp;&amp 
00085240:·3b20·5b20·2120·2d66·202f·2e64·6f63·6b65··;·[·!·-f·/.docke00085220:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
00085250:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp00085230:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
00085260:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c00085240:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
Max diff block lines reached; 831163/840884 bytes (98.84%) of diff not shown.
338 KB
html2text {}
    
Offset 1966, 15 lines modifiedOffset 1966, 15 lines modified
1966 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1966 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1967 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1967 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1968 Severity: ················medium1968 Severity: ················medium
1969 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1969 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1970 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030490,·SV-248791r818684_rule1970 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030490,·SV-248791r818684_rule
1971 Remediation_Shell_script_⇲1971 Remediation_Shell_script_⇲
1972 #·Remediation·is·applicable·only·in·certain·platforms1972 #·Remediation·is·applicable·only·in·certain·platforms
1973 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1973 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1974 #·First·perform·the·remediation·of·the·syscall·rule1974 #·First·perform·the·remediation·of·the·syscall·rule
1975 #·Retrieve·hardware·architecture·of·the·underlying·system1975 #·Retrieve·hardware·architecture·of·the·underlying·system
1976 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1976 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1977 for·ARCH·in·"${RULE_ARCHS[@]}"1977 for·ARCH·in·"${RULE_ARCHS[@]}"
1978 do1978 do
Offset 2321, 16 lines modifiedOffset 2321, 16 lines modified
2321 ··-·reboot_required2321 ··-·reboot_required
2322 ··-·restrict_strategy2322 ··-·restrict_strategy
  
2323 -·name:·Set·architecture·for·audit·chmod·tasks2323 -·name:·Set·architecture·for·audit·chmod·tasks
2324 ··set_fact:2324 ··set_fact:
2325 ····audit_arch:·b642325 ····audit_arch:·b64
2326 ··when:2326 ··when:
2327 ··-·'"audit"·in·ansible_facts.packages' 
2328 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2327 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2328 ··-·'"audit"·in·ansible_facts.packages'
2329 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2329 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2330 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2330 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2331 ··tags:2331 ··tags:
2332 ··-·CJIS-5.4.1.12332 ··-·CJIS-5.4.1.1
2333 ··-·DISA-STIG-OL08-00-0304902333 ··-·DISA-STIG-OL08-00-030490
2334 ··-·NIST-800-171-3.1.72334 ··-·NIST-800-171-3.1.7
2335 ··-·NIST-800-53-AU-12(c)2335 ··-·NIST-800-53-AU-12(c)
Offset 2467, 16 lines modifiedOffset 2467, 16 lines modified
2467 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002467 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2468 ········-F·auid!=unset·-F·key=perm_mod2468 ········-F·auid!=unset·-F·key=perm_mod
2469 ······create:·true2469 ······create:·true
2470 ······mode:·o-rwx2470 ······mode:·o-rwx
2471 ······state:·present2471 ······state:·present
2472 ····when:·syscalls_found·|·length·==·02472 ····when:·syscalls_found·|·length·==·0
2473 ··when:2473 ··when:
2474 ··-·'"audit"·in·ansible_facts.packages' 
2475 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2474 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2475 ··-·'"audit"·in·ansible_facts.packages'
2476 ··tags:2476 ··tags:
2477 ··-·CJIS-5.4.1.12477 ··-·CJIS-5.4.1.1
2478 ··-·DISA-STIG-OL08-00-0304902478 ··-·DISA-STIG-OL08-00-030490
2479 ··-·NIST-800-171-3.1.72479 ··-·NIST-800-171-3.1.7
2480 ··-·NIST-800-53-AU-12(c)2480 ··-·NIST-800-53-AU-12(c)
2481 ··-·NIST-800-53-AU-2(d)2481 ··-·NIST-800-53-AU-2(d)
2482 ··-·NIST-800-53-CM-6(a)2482 ··-·NIST-800-53-CM-6(a)
Offset 2611, 16 lines modifiedOffset 2611, 16 lines modified
2611 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002611 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2612 ········-F·auid!=unset·-F·key=perm_mod2612 ········-F·auid!=unset·-F·key=perm_mod
2613 ······create:·true2613 ······create:·true
2614 ······mode:·o-rwx2614 ······mode:·o-rwx
2615 ······state:·present2615 ······state:·present
2616 ····when:·syscalls_found·|·length·==·02616 ····when:·syscalls_found·|·length·==·0
2617 ··when:2617 ··when:
2618 ··-·'"audit"·in·ansible_facts.packages' 
2619 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2618 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2619 ··-·'"audit"·in·ansible_facts.packages'
2620 ··-·audit_arch·==·"b64"2620 ··-·audit_arch·==·"b64"
2621 ··tags:2621 ··tags:
2622 ··-·CJIS-5.4.1.12622 ··-·CJIS-5.4.1.1
2623 ··-·DISA-STIG-OL08-00-0304902623 ··-·DISA-STIG-OL08-00-030490
2624 ··-·NIST-800-171-3.1.72624 ··-·NIST-800-171-3.1.7
2625 ··-·NIST-800-53-AU-12(c)2625 ··-·NIST-800-53-AU-12(c)
2626 ··-·NIST-800-53-AU-2(d)2626 ··-·NIST-800-53-AU-2(d)
Offset 2644, 15 lines modifiedOffset 2644, 15 lines modified
2644 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.2644 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
2645 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2645 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2646 Severity: ················medium2646 Severity: ················medium
2647 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2647 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2648 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030480,·SV-248790r818681_rule2648 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030480,·SV-248790r818681_rule
2649 Remediation_Shell_script_⇲2649 Remediation_Shell_script_⇲
2650 #·Remediation·is·applicable·only·in·certain·platforms2650 #·Remediation·is·applicable·only·in·certain·platforms
2651 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2651 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2652 #·First·perform·the·remediation·of·the·syscall·rule2652 #·First·perform·the·remediation·of·the·syscall·rule
2653 #·Retrieve·hardware·architecture·of·the·underlying·system2653 #·Retrieve·hardware·architecture·of·the·underlying·system
2654 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2654 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2655 for·ARCH·in·"${RULE_ARCHS[@]}"2655 for·ARCH·in·"${RULE_ARCHS[@]}"
2656 do2656 do
Offset 2999, 16 lines modifiedOffset 2999, 16 lines modified
2999 ··-·reboot_required2999 ··-·reboot_required
3000 ··-·restrict_strategy3000 ··-·restrict_strategy
  
3001 -·name:·Set·architecture·for·audit·chown·tasks3001 -·name:·Set·architecture·for·audit·chown·tasks
3002 ··set_fact:3002 ··set_fact:
3003 ····audit_arch:·b643003 ····audit_arch:·b64
3004 ··when:3004 ··when:
3005 ··-·'"audit"·in·ansible_facts.packages' 
3006 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3005 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3006 ··-·'"audit"·in·ansible_facts.packages'
3007 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3007 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3008 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3008 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3009 ··tags:3009 ··tags:
3010 ··-·CJIS-5.4.1.13010 ··-·CJIS-5.4.1.1
3011 ··-·DISA-STIG-OL08-00-0304803011 ··-·DISA-STIG-OL08-00-030480
3012 ··-·NIST-800-171-3.1.73012 ··-·NIST-800-171-3.1.7
3013 ··-·NIST-800-53-AU-12(c)3013 ··-·NIST-800-53-AU-12(c)
Offset 3147, 16 lines modifiedOffset 3147, 16 lines modified
3147 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003147 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3148 ········-F·auid!=unset·-F·key=perm_mod3148 ········-F·auid!=unset·-F·key=perm_mod
3149 ······create:·true3149 ······create:·true
3150 ······mode:·o-rwx3150 ······mode:·o-rwx
3151 ······state:·present3151 ······state:·present
3152 ····when:·syscalls_found·|·length·==·03152 ····when:·syscalls_found·|·length·==·0
3153 ··when:3153 ··when:
3154 ··-·'"audit"·in·ansible_facts.packages' 
3155 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3154 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3155 ··-·'"audit"·in·ansible_facts.packages'
3156 ··tags:3156 ··tags:
3157 ··-·CJIS-5.4.1.13157 ··-·CJIS-5.4.1.1
3158 ··-·DISA-STIG-OL08-00-0304803158 ··-·DISA-STIG-OL08-00-030480
3159 ··-·NIST-800-171-3.1.73159 ··-·NIST-800-171-3.1.7
3160 ··-·NIST-800-53-AU-12(c)3160 ··-·NIST-800-53-AU-12(c)
3161 ··-·NIST-800-53-AU-2(d)3161 ··-·NIST-800-53-AU-2(d)
3162 ··-·NIST-800-53-CM-6(a)3162 ··-·NIST-800-53-CM-6(a)
Offset 3293, 16 lines modifiedOffset 3293, 16 lines modified
3293 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003293 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3294 ········-F·auid!=unset·-F·key=perm_mod3294 ········-F·auid!=unset·-F·key=perm_mod
3295 ······create:·true3295 ······create:·true
3296 ······mode:·o-rwx3296 ······mode:·o-rwx
3297 ······state:·present3297 ······state:·present
Max diff block lines reached; 337016/345763 bytes (97.47%) of diff not shown.
981 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-ospp.html
    
Offset 15263, 116 lines modifiedOffset 15263, 116 lines modified
0003b9e0:·2d74·6172·6765·743d·2223·6964·6d35·3935··-target="#idm5950003b9e0:·2d74·6172·6765·743d·2223·6964·6d35·3935··-target="#idm595
0003b9f0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·0003b9f0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0003ba00:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003ba00:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003ba10:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003ba10:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003ba20:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003ba20:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003ba30:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003ba30:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003ba40:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003ba40:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003ba50:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003ba50:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003ba60:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003ba60:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003ba70:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003ba70:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003ba80:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003ba80:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003ba90:·6170·7365·2220·6964·3d22·6964·6d35·3935··apse"·id="idm5950003ba90:·7365·2220·6964·3d22·6964·6d35·3935·3822··se"·id="idm5958"
0003baa0:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=0003baa0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bab0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003bab0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bac0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003bac0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bad0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bad0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bae0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003bae0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003baf0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003baf0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bb00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bb00:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bb10:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003bb10:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bb20:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bb20:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bb30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003bb30:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bb40:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003bb40:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bb50:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003bb50:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bb60:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003bb60:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003bb70:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003bb80:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><0003bb70:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 0003bb80:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 0003bb90:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 0003bba0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 0003bbb0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 0003bbc0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 0003bbd0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 0003bbe0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003bbf0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003bc00:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003bc10:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003bc20:·6172·6765·743d·2223·6964·6d35·3935·3922··arget="#idm5959"
 0003bc30:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003bc40:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003bc50:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003bc60:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003bc70:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003bc80:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003bc90:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003bca0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003bcb0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003bcc0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003bcd0:·6964·3d22·6964·6d35·3935·3922·3e3c·7461··id="idm5959"><ta
 0003bce0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003bcf0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003bd00:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003bd10:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003bd20:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003bd30:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003bd40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bd50:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003bd60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003bd70:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003bd80:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003bd90:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003bda0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003bdb0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003bdc0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003bdd0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003bde0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
 0003bdf0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
 0003be00:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
 0003be10:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 0003be20:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r
 0003be30:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 0003be40:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 0003be50:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0003be60:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 0003be70:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003be80:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003be90:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0003bea0:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0003beb0:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
0003bb90:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003bec0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003bba0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003bed0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003bbb0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003bee0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003bbc0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003bef0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003bbd0:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm590003bf00:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm59
0003bbe0:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0"0003bf10:·3630·2220·7461·6269·6e64·6578·3d22·3022··60"·tabindex="0"
0003bbf0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bf20:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003bc00:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003bf30:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bc10:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003bf40:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003bc20:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003bf50:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003bc30:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003bf60:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003bc40:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003bf70:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003bc50:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003bf80:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003bc60:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003bf90:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003bc70:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003bfa0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003bc80:·7073·6522·2069·643d·2269·646d·3539·3539··pse"·id="idm59590003bfb0:·6c61·7073·6522·2069·643d·2269·646d·3539··lapse"·id="idm59
0003bc90:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003bfc0:·3630·223e·3c74·6162·6c65·2063·6c61·7373··60"><table·class
0003bca0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003bfd0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003bcb0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003bfe0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003bcc0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003bff0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003bcd0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003c000:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003bce0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003c010:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003bcf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c020:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003bd00:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003c030:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003bd10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c040:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003bd20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003c050:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bd30:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003c060:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003bd40:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003c070:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003bd50:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003c080:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c090:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 0003c0a0:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
0003bd60:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003bd70:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
0003bd80:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
0003bd90:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
0003bda0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0003bdb0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0003bdc0:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0003bdd0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003bde0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003bdf0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003be00:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003be10:·7461·7267·6574·3d22·2369·646d·3539·3630··target="#idm5960 
0003be20:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003be30:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003be40:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003be50:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003be60:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
Max diff block lines reached; 900877/915533 bytes (98.40%) of diff not shown.
86.6 KB
html2text {}
    
Offset 89, 20 lines modifiedOffset 89, 14 lines modified
89 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed89 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
90 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule90 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule
91 Remediation_OSBuild_Blueprint_snippet_⇲91 Remediation_OSBuild_Blueprint_snippet_⇲
  
92 [[packages]]92 [[packages]]
93 name·=·"aide"93 name·=·"aide"
94 version·=·"*"94 version·=·"*"
95 Remediation_Anaconda_snippet_⇲ 
96 Complexity:·low 
97 Disruption:·low 
98 Strategy:···enable 
  
99 package·--add=aide 
100 Remediation_Puppet_snippet_⇲95 Remediation_Puppet_snippet_⇲
101 Complexity:·low96 Complexity:·low
102 Disruption:·low97 Disruption:·low
103 Strategy:···enable98 Strategy:···enable
104 include·install_aide99 include·install_aide
  
105 class·install_aide·{100 class·install_aide·{
Offset 120, 14 lines modifiedOffset 114, 20 lines modified
120 if·!·rpm·-q·--quiet·"aide"·;·then114 if·!·rpm·-q·--quiet·"aide"·;·then
121 ····yum·install·-y·"aide"115 ····yum·install·-y·"aide"
122 fi116 fi
  
123 else117 else
124 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'118 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
125 fi119 fi
 120 Remediation_Anaconda_snippet_⇲
 121 Complexity:·low
 122 Disruption:·low
 123 Strategy:···enable
  
 124 package·--add=aide
126 Remediation_Ansible_snippet_⇲125 Remediation_Ansible_snippet_⇲
127 Complexity:·low126 Complexity:·low
128 Disruption:·low127 Disruption:·low
129 Strategy:···enable128 Strategy:···enable
130 -·name:·Ensure·aide·is·installed129 -·name:·Ensure·aide·is·installed
131 ··package:130 ··package:
132 ····name:·aide131 ····name:·aide
Offset 392, 20 lines modifiedOffset 392, 14 lines modified
392 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed392 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
393 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174393 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
394 Remediation_OSBuild_Blueprint_snippet_⇲394 Remediation_OSBuild_Blueprint_snippet_⇲
  
395 [[packages]]395 [[packages]]
396 name·=·"crypto-policies"396 name·=·"crypto-policies"
397 version·=·"*"397 version·=·"*"
398 Remediation_Anaconda_snippet_⇲ 
399 Complexity:·low 
400 Disruption:·low 
401 Strategy:···enable 
  
402 package·--add=crypto-policies 
403 Remediation_Puppet_snippet_⇲398 Remediation_Puppet_snippet_⇲
404 Complexity:·low399 Complexity:·low
405 Disruption:·low400 Disruption:·low
406 Strategy:···enable401 Strategy:···enable
407 include·install_crypto-policies402 include·install_crypto-policies
  
408 class·install_crypto-policies·{403 class·install_crypto-policies·{
Offset 417, 14 lines modifiedOffset 411, 20 lines modified
417 Complexity:·low411 Complexity:·low
418 Disruption:·low412 Disruption:·low
419 Strategy:···enable413 Strategy:···enable
  
420 if·!·rpm·-q·--quiet·"crypto-policies"·;·then414 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
421 ····yum·install·-y·"crypto-policies"415 ····yum·install·-y·"crypto-policies"
422 fi416 fi
 417 Remediation_Anaconda_snippet_⇲
 418 Complexity:·low
 419 Disruption:·low
 420 Strategy:···enable
  
 421 package·--add=crypto-policies
423 Remediation_Ansible_snippet_⇲422 Remediation_Ansible_snippet_⇲
424 Complexity:·low423 Complexity:·low
425 Disruption:·low424 Disruption:·low
426 Strategy:···enable425 Strategy:···enable
427 -·name:·Ensure·crypto-policies·is·installed426 -·name:·Ensure·crypto-policies·is·installed
428 ··package:427 ··package:
429 ····name:·crypto-policies428 ····name:·crypto-policies
Offset 944, 20 lines modifiedOffset 944, 14 lines modified
944 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed944 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
945 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125945 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
946 Remediation_OSBuild_Blueprint_snippet_⇲946 Remediation_OSBuild_Blueprint_snippet_⇲
  
947 [[packages]]947 [[packages]]
948 name·=·"sudo"948 name·=·"sudo"
949 version·=·"*"949 version·=·"*"
950 Remediation_Anaconda_snippet_⇲ 
951 Complexity:·low 
952 Disruption:·low 
953 Strategy:···enable 
  
954 package·--add=sudo 
955 Remediation_Puppet_snippet_⇲950 Remediation_Puppet_snippet_⇲
956 Complexity:·low951 Complexity:·low
957 Disruption:·low952 Disruption:·low
958 Strategy:···enable953 Strategy:···enable
959 include·install_sudo954 include·install_sudo
  
960 class·install_sudo·{955 class·install_sudo·{
Offset 975, 14 lines modifiedOffset 969, 20 lines modified
975 if·!·rpm·-q·--quiet·"sudo"·;·then969 if·!·rpm·-q·--quiet·"sudo"·;·then
976 ····yum·install·-y·"sudo"970 ····yum·install·-y·"sudo"
977 fi971 fi
  
978 else972 else
979 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'973 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
980 fi974 fi
 975 Remediation_Anaconda_snippet_⇲
 976 Complexity:·low
 977 Disruption:·low
 978 Strategy:···enable
  
 979 package·--add=sudo
981 Remediation_Ansible_snippet_⇲980 Remediation_Ansible_snippet_⇲
982 Complexity:·low981 Complexity:·low
983 Disruption:·low982 Disruption:·low
984 Strategy:···enable983 Strategy:···enable
985 -·name:·Ensure·sudo·is·installed984 -·name:·Ensure·sudo·is·installed
986 ··package:985 ··package:
987 ····name:·sudo986 ····name:·sudo
Offset 1007, 20 lines modifiedOffset 1007, 14 lines modified
1007 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed1007 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed
Max diff block lines reached; 84749/88697 bytes (95.55%) of diff not shown.
975 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-pci-dss.html
    
Offset 17043, 117 lines modifiedOffset 17043, 117 lines modified
00042920:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00042920:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00042930:·3d22·2369·646d·3539·3538·2220·7461·6269··="#idm5958"·tabi00042930:·3d22·2369·646d·3539·3538·2220·7461·6269··="#idm5958"·tabi
00042940:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00042940:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00042950:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00042950:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00042960:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00042960:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00042970:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00042970:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00042980:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00042980:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00042990:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An00042990:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
000429a0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.000429a0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
000429b0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c000429b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000429c0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000429c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000429d0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i000429d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
000429e0:·643d·2269·646d·3539·3538·223e·3c74·6162··d="idm5958"><tab000429e0:·2269·646d·3539·3538·223e·3c74·6162·6c65··"idm5958"><table
000429f0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·000429f0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
00042a00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00042a00:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00042a10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00042a10:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00042a20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00042a20:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
00042a30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00042a30:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00042a40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00042a40:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00042a50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00042a50:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
00042a60:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00042a60:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00042a70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00042a70:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00042a80:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy00042a80:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
00042a90:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable00042a90:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
00042aa0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl00042aa0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
00042ab0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa00042ab0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
00042ac0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide00042ac0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 00042ad0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 00042ae0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 00042af0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 00042b00:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 00042b10:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 00042b20:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 00042b30:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 00042b40:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 00042b50:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 00042b60:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 00042b70:·2369·646d·3539·3539·2220·7461·6269·6e64··#idm5959"·tabind
 00042b80:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 00042b90:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 00042ba0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 00042bb0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 00042bc0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 00042bd0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 00042be0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 00042bf0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 00042c00:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 00042c10:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 00042c20:·3539·3539·223e·3c74·6162·6c65·2063·6c61··5959"><table·cla
 00042c30:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 00042c40:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 00042c50:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 00042c60:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 00042c70:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 00042c80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00042c90:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 00042ca0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 00042cb0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00042cc0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 00042cd0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 00042ce0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 00042cf0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 00042d00:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 00042d10:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 00042d20:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 00042d30:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
 00042d40:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 00042d50:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
 00042d60:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the
 00042d70:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 00042d80:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 00042d90:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 00042da0:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 00042db0:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 00042dc0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 00042dd0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 00042de0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 00042df0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
00042ad0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></00042e00:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
00042ae0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt00042e10:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
00042af0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d00042e20:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
00042b00:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll00042e30:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
00042b10:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00042e40:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00042b20:·743d·2223·6964·6d35·3935·3922·2074·6162··t="#idm5959"·tab00042e50:·743d·2223·6964·6d35·3936·3022·2074·6162··t="#idm5960"·tab
00042b30:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00042e60:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00042b40:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00042e70:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00042b50:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00042e80:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00042b60:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00042e90:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00042b70:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00042ea0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00042b80:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P00042eb0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
00042b90:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..00042ec0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
00042ba0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl00042ed0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00042bb0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00042ee0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00042bc0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00042ef0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00042bd0:·3d22·6964·6d35·3935·3922·3e3c·7461·626c··="idm5959"><tabl00042f00:·6964·3d22·6964·6d35·3936·3022·3e3c·7461··id="idm5960"><ta
00042be0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00042f10:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
00042bf0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00042f20:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
00042c00:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00042f30:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
00042c10:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00042f40:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
00042c20:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00042f50:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
00042c30:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00042f60:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
00042c40:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00042f70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00042c50:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00042f80:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
00042c60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00042f90:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
00042c70:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00042fa0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
00042c80:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<00042fb0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
00042c90:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table00042fc0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
00042ca0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl00042fd0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 00042fe0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
00042cb0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
00042cc0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
00042cd0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
00042ce0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
00042cf0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
00042d00:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
00042d10:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00042d20:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
00042d30:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
00042d40:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00042d50:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00042d60:·2223·6964·6d35·3936·3022·2074·6162·696e··"#idm5960"·tabin 
00042d70:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00042d80:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00042d90:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00042da0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00042db0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
00042dc0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
Max diff block lines reached; 692478/707272 bytes (97.91%) of diff not shown.
284 KB
html2text {}
    
Offset 378, 20 lines modifiedOffset 378, 14 lines modified
378 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed378 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
379 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule379 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule
380 Remediation_OSBuild_Blueprint_snippet_⇲380 Remediation_OSBuild_Blueprint_snippet_⇲
  
381 [[packages]]381 [[packages]]
382 name·=·"aide"382 name·=·"aide"
383 version·=·"*"383 version·=·"*"
384 Remediation_Anaconda_snippet_⇲ 
385 Complexity:·low 
386 Disruption:·low 
387 Strategy:···enable 
  
388 package·--add=aide 
389 Remediation_Puppet_snippet_⇲384 Remediation_Puppet_snippet_⇲
390 Complexity:·low385 Complexity:·low
391 Disruption:·low386 Disruption:·low
392 Strategy:···enable387 Strategy:···enable
393 include·install_aide388 include·install_aide
  
394 class·install_aide·{389 class·install_aide·{
Offset 409, 14 lines modifiedOffset 403, 20 lines modified
409 if·!·rpm·-q·--quiet·"aide"·;·then403 if·!·rpm·-q·--quiet·"aide"·;·then
410 ····yum·install·-y·"aide"404 ····yum·install·-y·"aide"
411 fi405 fi
  
412 else406 else
413 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'407 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
414 fi408 fi
 409 Remediation_Anaconda_snippet_⇲
 410 Complexity:·low
 411 Disruption:·low
 412 Strategy:···enable
  
 413 package·--add=aide
415 Remediation_Ansible_snippet_⇲414 Remediation_Ansible_snippet_⇲
416 Complexity:·low415 Complexity:·low
417 Disruption:·low416 Disruption:·low
418 Strategy:···enable417 Strategy:···enable
419 -·name:·Ensure·aide·is·installed418 -·name:·Ensure·aide·is·installed
420 ··package:419 ··package:
421 ····name:·aide420 ····name:·aide
Offset 5908, 20 lines modifiedOffset 5908, 14 lines modified
5908 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed5908 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed
5909 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520,·OL08-00-010410,·SV-248588r779330_rule5909 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520,·OL08-00-010410,·SV-248588r779330_rule
5910 Remediation_OSBuild_Blueprint_snippet_⇲5910 Remediation_OSBuild_Blueprint_snippet_⇲
  
5911 [[packages]]5911 [[packages]]
5912 name·=·"opensc"5912 name·=·"opensc"
5913 version·=·"*"5913 version·=·"*"
5914 Remediation_Anaconda_snippet_⇲ 
5915 Complexity:·low 
5916 Disruption:·low 
5917 Strategy:···enable 
  
5918 package·--add=opensc 
5919 Remediation_Puppet_snippet_⇲5914 Remediation_Puppet_snippet_⇲
5920 Complexity:·low5915 Complexity:·low
5921 Disruption:·low5916 Disruption:·low
5922 Strategy:···enable5917 Strategy:···enable
5923 include·install_opensc5918 include·install_opensc
  
5924 class·install_opensc·{5919 class·install_opensc·{
Offset 5939, 14 lines modifiedOffset 5933, 20 lines modified
5939 if·!·rpm·-q·--quiet·"opensc"·;·then5933 if·!·rpm·-q·--quiet·"opensc"·;·then
5940 ····yum·install·-y·"opensc"5934 ····yum·install·-y·"opensc"
5941 fi5935 fi
  
5942 else5936 else
5943 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5937 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5944 fi5938 fi
 5939 Remediation_Anaconda_snippet_⇲
 5940 Complexity:·low
 5941 Disruption:·low
 5942 Strategy:···enable
  
 5943 package·--add=opensc
5945 Remediation_Ansible_snippet_⇲5944 Remediation_Ansible_snippet_⇲
5946 Complexity:·low5945 Complexity:·low
5947 Disruption:·low5946 Disruption:·low
5948 Strategy:···enable5947 Strategy:···enable
5949 -·name:·Ensure·opensc·is·installed5948 -·name:·Ensure·opensc·is·installed
5950 ··package:5949 ··package:
5951 ····name:·opensc5950 ····name:·opensc
Offset 5969, 20 lines modifiedOffset 5969, 14 lines modified
5969 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed5969 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
5970 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015305970 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
5971 Remediation_OSBuild_Blueprint_snippet_⇲5971 Remediation_OSBuild_Blueprint_snippet_⇲
  
5972 [[packages]]5972 [[packages]]
5973 name·=·"pcsc-lite"5973 name·=·"pcsc-lite"
5974 version·=·"*"5974 version·=·"*"
5975 Remediation_Anaconda_snippet_⇲ 
5976 Complexity:·low 
5977 Disruption:·low 
5978 Strategy:···enable 
  
5979 package·--add=pcsc-lite 
5980 Remediation_Puppet_snippet_⇲5975 Remediation_Puppet_snippet_⇲
5981 Complexity:·low5976 Complexity:·low
5982 Disruption:·low5977 Disruption:·low
5983 Strategy:···enable5978 Strategy:···enable
5984 include·install_pcsc-lite5979 include·install_pcsc-lite
  
5985 class·install_pcsc-lite·{5980 class·install_pcsc-lite·{
Offset 6000, 14 lines modifiedOffset 5994, 20 lines modified
6000 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then5994 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
6001 ····yum·install·-y·"pcsc-lite"5995 ····yum·install·-y·"pcsc-lite"
6002 fi5996 fi
  
6003 else5997 else
6004 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5998 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6005 fi5999 fi
 6000 Remediation_Anaconda_snippet_⇲
 6001 Complexity:·low
 6002 Disruption:·low
 6003 Strategy:···enable
  
 6004 package·--add=pcsc-lite
6006 Remediation_Ansible_snippet_⇲6005 Remediation_Ansible_snippet_⇲
6007 Complexity:·low6006 Complexity:·low
6008 Disruption:·low6007 Disruption:·low
6009 Strategy:···enable6008 Strategy:···enable
6010 -·name:·Ensure·pcsc-lite·is·installed6009 -·name:·Ensure·pcsc-lite·is·installed
6011 ··package:6010 ··package:
6012 ····name:·pcsc-lite6011 ····name:·pcsc-lite
Offset 6753, 15 lines modifiedOffset 6753, 15 lines modified
6753 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.6753 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
Max diff block lines reached; 286739/291059 bytes (98.52%) of diff not shown.
579 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-standard.html
    
Offset 26335, 20 lines modifiedOffset 26335, 20 lines modified
00066de0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col00066de0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00066df0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·00066df0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00066e00:·6964·3d22·6964·6d32·3236·3638·223e·3c70··id="idm22668"><p00066e00:·6964·3d22·6964·6d32·3236·3638·223e·3c70··id="idm22668"><p
00066e10:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed00066e10:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
00066e20:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic00066e20:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
00066e30:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer00066e30:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
00066e40:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i00066e40:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
00066e50:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
00066e60:·2061·7564·6974·2026·616d·703b·2661·6d70···audit·&amp;&amp 
00066e70:·3b20·5b20·2120·2d66·202f·2e64·6f63·6b65··;·[·!·-f·/.docke00066e50:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
00066e80:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp00066e60:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
00066e90:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c00066e70:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
00066ea0:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t00066e80:·6f6e·7461·696e·6572·656e·7620·5d20·2661··ontainerenv·]·&a
 00066e90:·6d70·3b26·616d·703b·2072·706d·202d·2d71··mp;&amp;·rpm·--q
 00066ea0:·7569·6574·202d·7120·6175·6469·743b·2074··uiet·-q·audit;·t
00066eb0:·6865·6e0a·0a23·2046·6972·7374·2070·6572··hen..#·First·per00066eb0:·6865·6e0a·0a23·2046·6972·7374·2070·6572··hen..#·First·per
00066ec0:·666f·726d·2074·6865·2072·656d·6564·6961··form·the·remedia00066ec0:·666f·726d·2074·6865·2072·656d·6564·6961··form·the·remedia
00066ed0:·7469·6f6e·206f·6620·7468·6520·7379·7363··tion·of·the·sysc00066ed0:·7469·6f6e·206f·6620·7468·6520·7379·7363··tion·of·the·sysc
00066ee0:·616c·6c20·7275·6c65·0a23·2052·6574·7269··all·rule.#·Retri00066ee0:·616c·6c20·7275·6c65·0a23·2052·6574·7269··all·rule.#·Retri
00066ef0:·6576·6520·6861·7264·7761·7265·2061·7263··eve·hardware·arc00066ef0:·6576·6520·6861·7264·7761·7265·2061·7263··eve·hardware·arc
00066f00:·6869·7465·6374·7572·6520·6f66·2074·6865··hitecture·of·the00066f00:·6869·7465·6374·7572·6520·6f66·2074·6865··hitecture·of·the
00066f10:·2075·6e64·6572·6c79·696e·6720·7379·7374···underlying·syst00066f10:·2075·6e64·6572·6c79·696e·6720·7379·7374···underlying·syst
Offset 27228, 23 lines modifiedOffset 27228, 23 lines modified
0006a5b0:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r0006a5b0:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r
0006a5c0:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy0006a5c0:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
0006a5d0:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar0006a5d0:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar
0006a5e0:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a0006a5e0:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a
0006a5f0:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks0006a5f0:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks
0006a600:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···0006a600:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
0006a610:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b640006a610:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b64
0006a620:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a0006a620:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans
0006a630:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
0006a640:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
0006a650:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
0006a660:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
0006a670:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
0006a680:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
0006a690:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
0006a6a0:·6f6e·7461·696e·6572·225d·0a20·202d·2061··ontainer"].··-·a0006a630:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 0006a640:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 0006a650:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 0006a660:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 0006a670:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
 0006a680:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"·
 0006a690:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 0006a6a0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
0006a6b0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect0006a6b0:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
0006a6c0:·7572·6520·3d3d·2022·6161·7263·6836·3422··ure·==·"aarch64"0006a6c0:·7572·6520·3d3d·2022·6161·7263·6836·3422··ure·==·"aarch64"
0006a6d0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch0006a6d0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch
0006a6e0:·6974·6563·7475·7265·203d·3d20·2270·7063··itecture·==·"ppc0006a6e0:·6974·6563·7475·7265·203d·3d20·2270·7063··itecture·==·"ppc
0006a6f0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a0006a6f0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a
0006a700:·7263·6869·7465·6374·7572·650a·2020·2020··rchitecture.····0006a700:·7263·6869·7465·6374·7572·650a·2020·2020··rchitecture.····
0006a710:·3d3d·2022·7070·6336·346c·6522·206f·7220··==·"ppc64le"·or·0006a710:·3d3d·2022·7070·6336·346c·6522·206f·7220··==·"ppc64le"·or·
Offset 27552, 22 lines modifiedOffset 27552, 22 lines modified
0006b9f0:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:0006b9f0:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:
0006ba00:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode0006ba00:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode
0006ba10:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st0006ba10:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st
0006ba20:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···0006ba20:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···
0006ba30:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_0006ba30:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_
0006ba40:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=0006ba40:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=
0006ba50:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·0006ba50:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·
0006ba60:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi 
0006ba70:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag 
0006ba80:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_ 
0006ba90:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
0006baa0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
0006bab0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
0006bac0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
0006bad0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··0006ba60:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 0006ba70:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 0006ba80:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 0006ba90:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 0006baa0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
 0006bab0:·6e65·7222·5d0a·2020·2d20·2722·6175·6469··ner"].··-·'"audi
 0006bac0:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa
 0006bad0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
0006bae0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50006bae0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0006baf0:·2e34·2e31·2e31·0a20·202d·2044·4953·412d··.4.1.1.··-·DISA-0006baf0:·2e34·2e31·2e31·0a20·202d·2044·4953·412d··.4.1.1.··-·DISA-
0006bb00:·5354·4947·2d4f·4c30·382d·3030·2d30·3330··STIG-OL08-00-0300006bb00:·5354·4947·2d4f·4c30·382d·3030·2d30·3330··STIG-OL08-00-030
0006bb10:·3439·300a·2020·2d20·4e49·5354·2d38·3030··490.··-·NIST-8000006bb10:·3439·300a·2020·2d20·4e49·5354·2d38·3030··490.··-·NIST-800
0006bb20:·2d31·3731·2d33·2e31·2e37·0a20·202d·204e··-171-3.1.7.··-·N0006bb20:·2d31·3731·2d33·2e31·2e37·0a20·202d·204e··-171-3.1.7.··-·N
0006bb30:·4953·542d·3830·302d·3533·2d41·552d·3132··IST-800-53-AU-120006bb30:·4953·542d·3830·302d·3533·2d41·552d·3132··IST-800-53-AU-12
0006bb40:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-8000006bb40:·2863·290a·2020·2d20·4e49·5354·2d38·3030··(c).··-·NIST-800
Offset 27863, 23 lines modifiedOffset 27863, 23 lines modified
0006cd60:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···0006cd60:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···
0006cd70:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.0006cd70:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.
0006cd80:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw0006cd80:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw
0006cd90:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p0006cd90:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p
0006cda0:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:0006cda0:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:
0006cdb0:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·0006cdb0:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·
0006cdc0:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··0006cdc0:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··
0006cdd0:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi0006cdd0:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
0006cde0:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
0006cdf0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
0006ce00:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
0006ce10:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
0006ce20:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
0006ce30:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
0006ce40:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont0006cde0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 0006cdf0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 0006ce00:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 0006ce10:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 0006ce20:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 0006ce30:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 0006ce40:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
0006ce50:·6169·6e65·7222·5d0a·2020·2d20·6175·6469··ainer"].··-·audi0006ce50:·636b·6167·6573·270a·2020·2d20·6175·6469··ckages'.··-·audi
0006ce60:·745f·6172·6368·203d·3d20·2262·3634·220a··t_arch·==·"b64".0006ce60:·745f·6172·6368·203d·3d20·2262·3634·220a··t_arch·==·"b64".
0006ce70:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS0006ce70:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS
0006ce80:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS0006ce80:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS
0006ce90:·412d·5354·4947·2d4f·4c30·382d·3030·2d30··A-STIG-OL08-00-00006ce90:·412d·5354·4947·2d4f·4c30·382d·3030·2d30··A-STIG-OL08-00-0
0006cea0:·3330·3439·300a·2020·2d20·4e49·5354·2d38··30490.··-·NIST-80006cea0:·3330·3439·300a·2020·2d20·4e49·5354·2d38··30490.··-·NIST-8
0006ceb0:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-0006ceb0:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-
0006cec0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-0006cec0:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
Offset 28831, 21 lines modifiedOffset 28831, 21 lines modified
000709e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=000709e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
000709f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·000709f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
00070a00:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id00070a00:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
00070a10:·6d32·3238·3236·223e·3c70·7265·3e3c·636f··m22826"><pre><co00070a10:·6d32·3238·3236·223e·3c70·7265·3e3c·636f··m22826"><pre><co
00070a20:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation00070a20:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
00070a30:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o00070a30:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
00070a40:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p00070a40:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
00070a50:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·00070a50:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
00070a60:·2d2d·7175·6965·7420·2d71·2061·7564·6974··--quiet·-q·audit00070a60:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
00070a70:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·00070a70:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
00070a80:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
00070a90:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
00070aa0:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain00070a80:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
Max diff block lines reached; 394927/404786 bytes (97.56%) of diff not shown.
184 KB
html2text {}
    
Offset 1277, 15 lines modifiedOffset 1277, 15 lines modified
1277 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1277 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1278 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1278 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1279 Severity: ················medium1279 Severity: ················medium
1280 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1280 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1281 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030490,·SV-248791r818684_rule1281 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030490,·SV-248791r818684_rule
1282 Remediation_Shell_script_⇲1282 Remediation_Shell_script_⇲
1283 #·Remediation·is·applicable·only·in·certain·platforms1283 #·Remediation·is·applicable·only·in·certain·platforms
1284 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1284 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1285 #·First·perform·the·remediation·of·the·syscall·rule1285 #·First·perform·the·remediation·of·the·syscall·rule
1286 #·Retrieve·hardware·architecture·of·the·underlying·system1286 #·Retrieve·hardware·architecture·of·the·underlying·system
1287 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1287 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1288 for·ARCH·in·"${RULE_ARCHS[@]}"1288 for·ARCH·in·"${RULE_ARCHS[@]}"
1289 do1289 do
Offset 1632, 16 lines modifiedOffset 1632, 16 lines modified
1632 ··-·reboot_required1632 ··-·reboot_required
1633 ··-·restrict_strategy1633 ··-·restrict_strategy
  
1634 -·name:·Set·architecture·for·audit·chmod·tasks1634 -·name:·Set·architecture·for·audit·chmod·tasks
1635 ··set_fact:1635 ··set_fact:
1636 ····audit_arch:·b641636 ····audit_arch:·b64
1637 ··when:1637 ··when:
1638 ··-·'"audit"·in·ansible_facts.packages' 
1639 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1638 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1639 ··-·'"audit"·in·ansible_facts.packages'
1640 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1640 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1641 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1641 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1642 ··tags:1642 ··tags:
1643 ··-·CJIS-5.4.1.11643 ··-·CJIS-5.4.1.1
1644 ··-·DISA-STIG-OL08-00-0304901644 ··-·DISA-STIG-OL08-00-030490
1645 ··-·NIST-800-171-3.1.71645 ··-·NIST-800-171-3.1.7
1646 ··-·NIST-800-53-AU-12(c)1646 ··-·NIST-800-53-AU-12(c)
Offset 1778, 16 lines modifiedOffset 1778, 16 lines modified
1778 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001778 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1779 ········-F·auid!=unset·-F·key=perm_mod1779 ········-F·auid!=unset·-F·key=perm_mod
1780 ······create:·true1780 ······create:·true
1781 ······mode:·o-rwx1781 ······mode:·o-rwx
1782 ······state:·present1782 ······state:·present
1783 ····when:·syscalls_found·|·length·==·01783 ····when:·syscalls_found·|·length·==·0
1784 ··when:1784 ··when:
1785 ··-·'"audit"·in·ansible_facts.packages' 
1786 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1785 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1786 ··-·'"audit"·in·ansible_facts.packages'
1787 ··tags:1787 ··tags:
1788 ··-·CJIS-5.4.1.11788 ··-·CJIS-5.4.1.1
1789 ··-·DISA-STIG-OL08-00-0304901789 ··-·DISA-STIG-OL08-00-030490
1790 ··-·NIST-800-171-3.1.71790 ··-·NIST-800-171-3.1.7
1791 ··-·NIST-800-53-AU-12(c)1791 ··-·NIST-800-53-AU-12(c)
1792 ··-·NIST-800-53-AU-2(d)1792 ··-·NIST-800-53-AU-2(d)
1793 ··-·NIST-800-53-CM-6(a)1793 ··-·NIST-800-53-CM-6(a)
Offset 1922, 16 lines modifiedOffset 1922, 16 lines modified
1922 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001922 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1923 ········-F·auid!=unset·-F·key=perm_mod1923 ········-F·auid!=unset·-F·key=perm_mod
1924 ······create:·true1924 ······create:·true
1925 ······mode:·o-rwx1925 ······mode:·o-rwx
1926 ······state:·present1926 ······state:·present
1927 ····when:·syscalls_found·|·length·==·01927 ····when:·syscalls_found·|·length·==·0
1928 ··when:1928 ··when:
1929 ··-·'"audit"·in·ansible_facts.packages' 
1930 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1929 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1930 ··-·'"audit"·in·ansible_facts.packages'
1931 ··-·audit_arch·==·"b64"1931 ··-·audit_arch·==·"b64"
1932 ··tags:1932 ··tags:
1933 ··-·CJIS-5.4.1.11933 ··-·CJIS-5.4.1.1
1934 ··-·DISA-STIG-OL08-00-0304901934 ··-·DISA-STIG-OL08-00-030490
1935 ··-·NIST-800-171-3.1.71935 ··-·NIST-800-171-3.1.7
1936 ··-·NIST-800-53-AU-12(c)1936 ··-·NIST-800-53-AU-12(c)
1937 ··-·NIST-800-53-AU-2(d)1937 ··-·NIST-800-53-AU-2(d)
Offset 1955, 15 lines modifiedOffset 1955, 15 lines modified
1955 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1955 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1956 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1956 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1957 Severity: ················medium1957 Severity: ················medium
1958 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown1958 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
1959 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030480,·SV-248790r818681_rule1959 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·OL08-00-030480,·SV-248790r818681_rule
1960 Remediation_Shell_script_⇲1960 Remediation_Shell_script_⇲
1961 #·Remediation·is·applicable·only·in·certain·platforms1961 #·Remediation·is·applicable·only·in·certain·platforms
1962 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1962 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1963 #·First·perform·the·remediation·of·the·syscall·rule1963 #·First·perform·the·remediation·of·the·syscall·rule
1964 #·Retrieve·hardware·architecture·of·the·underlying·system1964 #·Retrieve·hardware·architecture·of·the·underlying·system
1965 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1965 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1966 for·ARCH·in·"${RULE_ARCHS[@]}"1966 for·ARCH·in·"${RULE_ARCHS[@]}"
1967 do1967 do
Offset 2310, 16 lines modifiedOffset 2310, 16 lines modified
2310 ··-·reboot_required2310 ··-·reboot_required
2311 ··-·restrict_strategy2311 ··-·restrict_strategy
  
2312 -·name:·Set·architecture·for·audit·chown·tasks2312 -·name:·Set·architecture·for·audit·chown·tasks
2313 ··set_fact:2313 ··set_fact:
2314 ····audit_arch:·b642314 ····audit_arch:·b64
2315 ··when:2315 ··when:
2316 ··-·'"audit"·in·ansible_facts.packages' 
2317 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2316 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2317 ··-·'"audit"·in·ansible_facts.packages'
2318 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2318 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2319 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2319 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2320 ··tags:2320 ··tags:
2321 ··-·CJIS-5.4.1.12321 ··-·CJIS-5.4.1.1
2322 ··-·DISA-STIG-OL08-00-0304802322 ··-·DISA-STIG-OL08-00-030480
2323 ··-·NIST-800-171-3.1.72323 ··-·NIST-800-171-3.1.7
2324 ··-·NIST-800-53-AU-12(c)2324 ··-·NIST-800-53-AU-12(c)
Offset 2458, 16 lines modifiedOffset 2458, 16 lines modified
2458 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002458 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2459 ········-F·auid!=unset·-F·key=perm_mod2459 ········-F·auid!=unset·-F·key=perm_mod
2460 ······create:·true2460 ······create:·true
2461 ······mode:·o-rwx2461 ······mode:·o-rwx
2462 ······state:·present2462 ······state:·present
2463 ····when:·syscalls_found·|·length·==·02463 ····when:·syscalls_found·|·length·==·0
2464 ··when:2464 ··when:
2465 ··-·'"audit"·in·ansible_facts.packages' 
2466 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2465 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2466 ··-·'"audit"·in·ansible_facts.packages'
2467 ··tags:2467 ··tags:
2468 ··-·CJIS-5.4.1.12468 ··-·CJIS-5.4.1.1
2469 ··-·DISA-STIG-OL08-00-0304802469 ··-·DISA-STIG-OL08-00-030480
2470 ··-·NIST-800-171-3.1.72470 ··-·NIST-800-171-3.1.7
2471 ··-·NIST-800-53-AU-12(c)2471 ··-·NIST-800-53-AU-12(c)
2472 ··-·NIST-800-53-AU-2(d)2472 ··-·NIST-800-53-AU-2(d)
2473 ··-·NIST-800-53-CM-6(a)2473 ··-·NIST-800-53-CM-6(a)
Offset 2604, 16 lines modifiedOffset 2604, 16 lines modified
2604 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002604 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2605 ········-F·auid!=unset·-F·key=perm_mod2605 ········-F·auid!=unset·-F·key=perm_mod
2606 ······create:·true2606 ······create:·true
2607 ······mode:·o-rwx2607 ······mode:·o-rwx
2608 ······state:·present2608 ······state:·present
Max diff block lines reached; 179645/188392 bytes (95.36%) of diff not shown.
1.66 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-stig.html
    
Offset 15264, 116 lines modifiedOffset 15264, 116 lines modified
0003b9f0:·2d74·6172·6765·743d·2223·6964·6d35·3935··-target="#idm5950003b9f0:·2d74·6172·6765·743d·2223·6964·6d35·3935··-target="#idm595
0003ba00:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·0003ba00:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0003ba10:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003ba10:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003ba20:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003ba20:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003ba30:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003ba30:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003ba40:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003ba40:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003ba50:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003ba50:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003ba60:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003ba60:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003ba70:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003ba70:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003ba80:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003ba80:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003ba90:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003ba90:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003baa0:·6170·7365·2220·6964·3d22·6964·6d35·3935··apse"·id="idm5950003baa0:·7365·2220·6964·3d22·6964·6d35·3935·3822··se"·id="idm5958"
0003bab0:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=0003bab0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bac0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003bac0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bad0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003bad0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bae0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bae0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003baf0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003baf0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bb00:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003bb00:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bb10:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bb10:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bb20:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003bb20:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bb30:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bb30:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bb40:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003bb40:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bb50:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003bb50:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bb60:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003bb60:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bb70:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003bb70:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003bb80:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003bb90:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><0003bb80:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 0003bb90:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 0003bba0:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 0003bbb0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 0003bbc0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 0003bbd0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 0003bbe0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 0003bbf0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003bc00:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003bc10:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003bc20:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003bc30:·6172·6765·743d·2223·6964·6d35·3935·3922··arget="#idm5959"
 0003bc40:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003bc50:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003bc60:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003bc70:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003bc80:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003bc90:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003bca0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003bcb0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003bcc0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003bcd0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003bce0:·6964·3d22·6964·6d35·3935·3922·3e3c·7461··id="idm5959"><ta
 0003bcf0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003bd00:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003bd10:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003bd20:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003bd30:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003bd40:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003bd50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bd60:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003bd70:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003bd80:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003bd90:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003bda0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003bdb0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003bdc0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003bdd0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003bde0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003bdf0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
 0003be00:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
 0003be10:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
 0003be20:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 0003be30:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r
 0003be40:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 0003be50:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 0003be60:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0003be70:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 0003be80:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003be90:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003bea0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0003beb0:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0003bec0:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
0003bba0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003bed0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003bbb0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003bee0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003bbc0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003bef0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003bbd0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003bf00:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003bbe0:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm590003bf10:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm59
0003bbf0:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0"0003bf20:·3630·2220·7461·6269·6e64·6578·3d22·3022··60"·tabindex="0"
0003bc00:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bf30:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003bc10:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003bf40:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bc20:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003bf50:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003bc30:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003bf60:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003bc40:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003bf70:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003bc50:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003bf80:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003bc60:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003bf90:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003bc70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003bfa0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003bc80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003bfb0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003bc90:·7073·6522·2069·643d·2269·646d·3539·3539··pse"·id="idm59590003bfc0:·6c61·7073·6522·2069·643d·2269·646d·3539··lapse"·id="idm59
0003bca0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003bfd0:·3630·223e·3c74·6162·6c65·2063·6c61·7373··60"><table·class
0003bcb0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003bfe0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003bcc0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003bff0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003bcd0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003c000:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003bce0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003c010:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003bcf0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003c020:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003bd00:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c030:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003bd10:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003c040:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003bd20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c050:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003bd30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003c060:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bd40:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003c070:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003bd50:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003c080:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003bd60:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003c090:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c0a0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 0003c0b0:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
0003bd70:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003bd80:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
0003bd90:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
0003bda0:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
0003bdb0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0003bdc0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0003bdd0:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0003bde0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003bdf0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003be00:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003be10:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003be20:·7461·7267·6574·3d22·2369·646d·3539·3630··target="#idm5960 
0003be30:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003be40:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003be50:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003be60:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003be70:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
Max diff block lines reached; 1347609/1362265 bytes (98.92%) of diff not shown.
368 KB
html2text {}
    
Offset 88, 20 lines modifiedOffset 88, 14 lines modified
88 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed88 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
89 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule89 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule
90 Remediation_OSBuild_Blueprint_snippet_⇲90 Remediation_OSBuild_Blueprint_snippet_⇲
  
91 [[packages]]91 [[packages]]
92 name·=·"aide"92 name·=·"aide"
93 version·=·"*"93 version·=·"*"
94 Remediation_Anaconda_snippet_⇲ 
95 Complexity:·low 
96 Disruption:·low 
97 Strategy:···enable 
  
98 package·--add=aide 
99 Remediation_Puppet_snippet_⇲94 Remediation_Puppet_snippet_⇲
100 Complexity:·low95 Complexity:·low
101 Disruption:·low96 Disruption:·low
102 Strategy:···enable97 Strategy:···enable
103 include·install_aide98 include·install_aide
  
104 class·install_aide·{99 class·install_aide·{
Offset 119, 14 lines modifiedOffset 113, 20 lines modified
119 if·!·rpm·-q·--quiet·"aide"·;·then113 if·!·rpm·-q·--quiet·"aide"·;·then
120 ····yum·install·-y·"aide"114 ····yum·install·-y·"aide"
121 fi115 fi
  
122 else116 else
123 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'117 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
124 fi118 fi
 119 Remediation_Anaconda_snippet_⇲
 120 Complexity:·low
 121 Disruption:·low
 122 Strategy:···enable
  
 123 package·--add=aide
125 Remediation_Ansible_snippet_⇲124 Remediation_Ansible_snippet_⇲
126 Complexity:·low125 Complexity:·low
127 Disruption:·low126 Disruption:·low
128 Strategy:···enable127 Strategy:···enable
129 -·name:·Ensure·aide·is·installed128 -·name:·Ensure·aide·is·installed
130 ··package:129 ··package:
131 ····name:·aide130 ····name:·aide
Offset 4606, 20 lines modifiedOffset 4606, 14 lines modified
4606 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed4606 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed
4607 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·OL08-00-010472,·SV-248600r779366_rule4607 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·OL08-00-010472,·SV-248600r779366_rule
4608 Remediation_OSBuild_Blueprint_snippet_⇲4608 Remediation_OSBuild_Blueprint_snippet_⇲
  
4609 [[packages]]4609 [[packages]]
4610 name·=·"rng-tools"4610 name·=·"rng-tools"
4611 version·=·"*"4611 version·=·"*"
4612 Remediation_Anaconda_snippet_⇲ 
4613 Complexity:·low 
4614 Disruption:·low 
4615 Strategy:···enable 
  
4616 package·--add=rng-tools 
4617 Remediation_Puppet_snippet_⇲4612 Remediation_Puppet_snippet_⇲
4618 Complexity:·low4613 Complexity:·low
4619 Disruption:·low4614 Disruption:·low
4620 Strategy:···enable4615 Strategy:···enable
4621 include·install_rng-tools4616 include·install_rng-tools
  
4622 class·install_rng-tools·{4617 class·install_rng-tools·{
Offset 4631, 14 lines modifiedOffset 4625, 20 lines modified
4631 Complexity:·low4625 Complexity:·low
4632 Disruption:·low4626 Disruption:·low
4633 Strategy:···enable4627 Strategy:···enable
  
4634 if·!·rpm·-q·--quiet·"rng-tools"·;·then4628 if·!·rpm·-q·--quiet·"rng-tools"·;·then
4635 ····yum·install·-y·"rng-tools"4629 ····yum·install·-y·"rng-tools"
4636 fi4630 fi
 4631 Remediation_Anaconda_snippet_⇲
 4632 Complexity:·low
 4633 Disruption:·low
 4634 Strategy:···enable
  
 4635 package·--add=rng-tools
4637 Remediation_Ansible_snippet_⇲4636 Remediation_Ansible_snippet_⇲
4638 Complexity:·low4637 Complexity:·low
4639 Disruption:·low4638 Disruption:·low
4640 Strategy:···enable4639 Strategy:···enable
4641 -·name:·Ensure·rng-tools·is·installed4640 -·name:·Ensure·rng-tools·is·installed
4642 ··package:4641 ··package:
4643 ····name:·rng-tools4642 ····name:·rng-tools
Offset 4654, 20 lines modifiedOffset 4654, 14 lines modified
4654 ***·Rule  ·Uninstall·abrt-libs·Package·  [ref]·***4654 ***·Rule  ·Uninstall·abrt-libs·Package·  [ref]·***
4655 The·abrt-libs·package·can·be·removed·with·the·following·command:4655 The·abrt-libs·package·can·be·removed·with·the·following·command:
4656 $·sudo·yum·erase·abrt-libs4656 $·sudo·yum·erase·abrt-libs
4657 Rationale:·················abrt-libs·provides·libraries·for·the·ABRT·package.4657 Rationale:·················abrt-libs·provides·libraries·for·the·ABRT·package.
4658 Severity: ················medium4658 Severity: ················medium
4659 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-libs_removed4659 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-libs_removed
4660 Identifiers·and·References·References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·OL08-00-040001,·SV-248824r780038_rule4660 Identifiers·and·References·References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·OL08-00-040001,·SV-248824r780038_rule
4661 Remediation_Anaconda_snippet_⇲ 
4662 Complexity:·low 
4663 Disruption:·low 
4664 Strategy:···disable 
  
4665 package·--remove=abrt-libs 
4666 Remediation_Puppet_snippet_⇲4661 Remediation_Puppet_snippet_⇲
4667 Complexity:·low4662 Complexity:·low
4668 Disruption:·low4663 Disruption:·low
4669 Strategy:···disable4664 Strategy:···disable
4670 include·remove_abrt-libs4665 include·remove_abrt-libs
  
4671 class·remove_abrt-libs·{4666 class·remove_abrt-libs·{
Offset 4687, 14 lines modifiedOffset 4681, 20 lines modified
4687 #»      ···system!4681 #»      ···system!
  
4688 if·rpm·-q·--quiet·"abrt-libs"·;·then4682 if·rpm·-q·--quiet·"abrt-libs"·;·then
  
4689 ····yum·remove·-y·"abrt-libs"4683 ····yum·remove·-y·"abrt-libs"
  
4690 fi4684 fi
 4685 Remediation_Anaconda_snippet_⇲
 4686 Complexity:·low
 4687 Disruption:·low
 4688 Strategy:···disable
  
 4689 package·--remove=abrt-libs
4691 Remediation_Ansible_snippet_⇲4690 Remediation_Ansible_snippet_⇲
4692 Complexity:·low4691 Complexity:·low
4693 Disruption:·low4692 Disruption:·low
4694 Strategy:···disable4693 Strategy:···disable
4695 -·name:·Ensure·abrt-libs·is·removed4694 -·name:·Ensure·abrt-libs·is·removed
4696 ··package:4695 ··package:
4697 ····name:·abrt-libs4696 ····name:·abrt-libs
Offset 4710, 20 lines modifiedOffset 4710, 14 lines modified
4710 ***·Rule  ·Uninstall·abrt-server-info-page·Package·  [ref]·***4710 ***·Rule  ·Uninstall·abrt-server-info-page·Package·  [ref]·***
Max diff block lines reached; 372551/376449 bytes (98.96%) of diff not shown.
1.64 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-stig_gui.html
    
Offset 15282, 116 lines modifiedOffset 15282, 116 lines modified
0003bb10:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003bb10:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003bb20:·3539·3538·2220·7461·6269·6e64·6578·3d22··5958"·tabindex="0003bb20:·3539·3538·2220·7461·6269·6e64·6578·3d22··5958"·tabindex="
0003bb30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003bb30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003bb40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003bb40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003bb50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003bb50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003bb60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003bb60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003bb70:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003bb70:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003bb80:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003bb80:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003bb90:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003bb90:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003bba0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003bba0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003bbb0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003bbb0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003bbc0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003bbc0:·6c61·7073·6522·2069·643d·2269·646d·3539··lapse"·id="idm59
0003bbd0:·3539·3538·223e·3c74·6162·6c65·2063·6c61··5958"><table·cla0003bbd0:·3538·223e·3c74·6162·6c65·2063·6c61·7373··58"><table·class
0003bbe0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003bbe0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003bbf0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003bbf0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003bc00:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003bc00:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003bc10:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003bc10:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003bc20:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003bc20:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003bc30:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bc30:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003bc40:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003bc40:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003bc50:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003bc50:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003bc60:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bc60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bc70:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003bc70:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003bc80:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003bc80:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003bc90:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003bc90:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003bca0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003bcb0:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod0003bca0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003bcb0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003bcc0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003bcd0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003bce0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003bcf0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003bd00:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003bd10:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003bd20:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003bd30:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003bd40:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003bd50:·612d·7461·7267·6574·3d22·2369·646d·3539··a-target="#idm59
 0003bd60:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0"
 0003bd70:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003bd80:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003bd90:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003bda0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003bdb0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003bdc0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003bdd0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003bde0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bdf0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003be00:·6522·2069·643d·2269·646d·3539·3539·223e··e"·id="idm5959">
 0003be10:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003be20:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003be30:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003be40:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003be50:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003be60:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003be70:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003be80:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003be90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bea0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003beb0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003bec0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003bed0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bee0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003bef0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003bf00:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003bf10:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f
 0003bf20:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 0003bf30:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 0003bf40:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
 0003bf50:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if·
 0003bf60:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003bf70:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 0003bf80:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·-
 0003bf90:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 0003bfa0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003bfb0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003bfc0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003bfd0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003bfe0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
0003bcc0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003bff0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003bcd0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003c000:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003bce0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003c010:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003bcf0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003c020:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003bd00:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003c030:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bd10:·6d35·3935·3922·2074·6162·696e·6465·783d··m5959"·tabindex=0003c040:·6d35·3936·3022·2074·6162·696e·6465·783d··m5960"·tabindex=
0003bd20:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003c050:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bd30:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003c060:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bd40:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003c070:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bd50:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003c080:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bd60:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003c090:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003bd70:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003c0a0:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003bd80:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003c0b0:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003bd90:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003c0c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003bda0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003c0d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003bdb0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm50003c0e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003bdc0:·3935·3922·3e3c·7461·626c·6520·636c·6173··959"><table·clas0003c0f0:·6d35·3936·3022·3e3c·7461·626c·6520·636c··m5960"><table·cl
0003bdd0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003c100:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003bde0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003c110:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bdf0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003c120:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003be00:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003c130:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003be10:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003c140:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003be20:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c150:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003be30:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c160:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003be40:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c170:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003be50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c180:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003be60:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c190:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003be70:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c1a0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003be80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c1b0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c1c0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003c1d0:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co
0003be90:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003bea0:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas 
0003beb0:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{ 
0003bec0:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai 
0003bed0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure· 
0003bee0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0003bef0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0003bf00:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bf10:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bf20:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bf30:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bf40:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5 
0003bf50:·3936·3022·2074·6162·696e·6465·783d·2230··960"·tabindex="0 
0003bf60:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bf70:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bf80:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bf90:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
Max diff block lines reached; 1334471/1349127 bytes (98.91%) of diff not shown.
365 KB
html2text {}
    
Offset 92, 20 lines modifiedOffset 92, 14 lines modified
92 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed92 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
93 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule93 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·OL08-00-010359,·SV-252654r818758_rule
94 Remediation_OSBuild_Blueprint_snippet_⇲94 Remediation_OSBuild_Blueprint_snippet_⇲
  
95 [[packages]]95 [[packages]]
96 name·=·"aide"96 name·=·"aide"
97 version·=·"*"97 version·=·"*"
98 Remediation_Anaconda_snippet_⇲ 
99 Complexity:·low 
100 Disruption:·low 
101 Strategy:···enable 
  
102 package·--add=aide 
103 Remediation_Puppet_snippet_⇲98 Remediation_Puppet_snippet_⇲
104 Complexity:·low99 Complexity:·low
105 Disruption:·low100 Disruption:·low
106 Strategy:···enable101 Strategy:···enable
107 include·install_aide102 include·install_aide
  
108 class·install_aide·{103 class·install_aide·{
Offset 123, 14 lines modifiedOffset 117, 20 lines modified
123 if·!·rpm·-q·--quiet·"aide"·;·then117 if·!·rpm·-q·--quiet·"aide"·;·then
124 ····yum·install·-y·"aide"118 ····yum·install·-y·"aide"
125 fi119 fi
  
126 else120 else
127 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'121 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
128 fi122 fi
 123 Remediation_Anaconda_snippet_⇲
 124 Complexity:·low
 125 Disruption:·low
 126 Strategy:···enable
  
 127 package·--add=aide
129 Remediation_Ansible_snippet_⇲128 Remediation_Ansible_snippet_⇲
130 Complexity:·low129 Complexity:·low
131 Disruption:·low130 Disruption:·low
132 Strategy:···enable131 Strategy:···enable
133 -·name:·Ensure·aide·is·installed132 -·name:·Ensure·aide·is·installed
134 ··package:133 ··package:
135 ····name:·aide134 ····name:·aide
Offset 4610, 20 lines modifiedOffset 4610, 14 lines modified
4610 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed4610 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed
4611 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·OL08-00-010472,·SV-248600r779366_rule4611 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·OL08-00-010472,·SV-248600r779366_rule
4612 Remediation_OSBuild_Blueprint_snippet_⇲4612 Remediation_OSBuild_Blueprint_snippet_⇲
  
4613 [[packages]]4613 [[packages]]
4614 name·=·"rng-tools"4614 name·=·"rng-tools"
4615 version·=·"*"4615 version·=·"*"
4616 Remediation_Anaconda_snippet_⇲ 
4617 Complexity:·low 
4618 Disruption:·low 
4619 Strategy:···enable 
  
4620 package·--add=rng-tools 
4621 Remediation_Puppet_snippet_⇲4616 Remediation_Puppet_snippet_⇲
4622 Complexity:·low4617 Complexity:·low
4623 Disruption:·low4618 Disruption:·low
4624 Strategy:···enable4619 Strategy:···enable
4625 include·install_rng-tools4620 include·install_rng-tools
  
4626 class·install_rng-tools·{4621 class·install_rng-tools·{
Offset 4635, 14 lines modifiedOffset 4629, 20 lines modified
4635 Complexity:·low4629 Complexity:·low
4636 Disruption:·low4630 Disruption:·low
4637 Strategy:···enable4631 Strategy:···enable
  
4638 if·!·rpm·-q·--quiet·"rng-tools"·;·then4632 if·!·rpm·-q·--quiet·"rng-tools"·;·then
4639 ····yum·install·-y·"rng-tools"4633 ····yum·install·-y·"rng-tools"
4640 fi4634 fi
 4635 Remediation_Anaconda_snippet_⇲
 4636 Complexity:·low
 4637 Disruption:·low
 4638 Strategy:···enable
  
 4639 package·--add=rng-tools
4641 Remediation_Ansible_snippet_⇲4640 Remediation_Ansible_snippet_⇲
4642 Complexity:·low4641 Complexity:·low
4643 Disruption:·low4642 Disruption:·low
4644 Strategy:···enable4643 Strategy:···enable
4645 -·name:·Ensure·rng-tools·is·installed4644 -·name:·Ensure·rng-tools·is·installed
4646 ··package:4645 ··package:
4647 ····name:·rng-tools4646 ····name:·rng-tools
Offset 4658, 20 lines modifiedOffset 4658, 14 lines modified
4658 ***·Rule  ·Uninstall·abrt-libs·Package·  [ref]·***4658 ***·Rule  ·Uninstall·abrt-libs·Package·  [ref]·***
4659 The·abrt-libs·package·can·be·removed·with·the·following·command:4659 The·abrt-libs·package·can·be·removed·with·the·following·command:
4660 $·sudo·yum·erase·abrt-libs4660 $·sudo·yum·erase·abrt-libs
4661 Rationale:·················abrt-libs·provides·libraries·for·the·ABRT·package.4661 Rationale:·················abrt-libs·provides·libraries·for·the·ABRT·package.
4662 Severity: ················medium4662 Severity: ················medium
4663 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-libs_removed4663 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-libs_removed
4664 Identifiers·and·References·References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·OL08-00-040001,·SV-248824r780038_rule4664 Identifiers·and·References·References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·OL08-00-040001,·SV-248824r780038_rule
4665 Remediation_Anaconda_snippet_⇲ 
4666 Complexity:·low 
4667 Disruption:·low 
4668 Strategy:···disable 
  
4669 package·--remove=abrt-libs 
4670 Remediation_Puppet_snippet_⇲4665 Remediation_Puppet_snippet_⇲
4671 Complexity:·low4666 Complexity:·low
4672 Disruption:·low4667 Disruption:·low
4673 Strategy:···disable4668 Strategy:···disable
4674 include·remove_abrt-libs4669 include·remove_abrt-libs
  
4675 class·remove_abrt-libs·{4670 class·remove_abrt-libs·{
Offset 4691, 14 lines modifiedOffset 4685, 20 lines modified
4691 #»      ···system!4685 #»      ···system!
  
4692 if·rpm·-q·--quiet·"abrt-libs"·;·then4686 if·rpm·-q·--quiet·"abrt-libs"·;·then
  
4693 ····yum·remove·-y·"abrt-libs"4687 ····yum·remove·-y·"abrt-libs"
  
4694 fi4688 fi
 4689 Remediation_Anaconda_snippet_⇲
 4690 Complexity:·low
 4691 Disruption:·low
 4692 Strategy:···disable
  
 4693 package·--remove=abrt-libs
4695 Remediation_Ansible_snippet_⇲4694 Remediation_Ansible_snippet_⇲
4696 Complexity:·low4695 Complexity:·low
4697 Disruption:·low4696 Disruption:·low
4698 Strategy:···disable4697 Strategy:···disable
4699 -·name:·Ensure·abrt-libs·is·removed4698 -·name:·Ensure·abrt-libs·is·removed
4700 ··package:4699 ··package:
4701 ····name:·abrt-libs4700 ····name:·abrt-libs
Offset 4714, 20 lines modifiedOffset 4714, 14 lines modified
4714 ***·Rule  ·Uninstall·abrt-server-info-page·Package·  [ref]·***4714 ***·Rule  ·Uninstall·abrt-server-info-page·Package·  [ref]·***
Max diff block lines reached; 370204/374102 bytes (98.96%) of diff not shown.
557 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_enhanced.html
    
Offset 15231, 116 lines modifiedOffset 15231, 116 lines modified
0003b7e0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b7e0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b7f0:·3534·3033·2220·7461·6269·6e64·6578·3d22··5403"·tabindex="0003b7f0:·3534·3033·2220·7461·6269·6e64·6578·3d22··5403"·tabindex="
0003b800:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b800:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b810:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b810:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b820:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b820:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b830:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b830:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b840:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b840:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b850:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003b850:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003b860:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b860:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b870:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b870:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b880:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b880:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b890:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b890:·6c61·7073·6522·2069·643d·2269·646d·3534··lapse"·id="idm54
0003b8a0:·3534·3033·223e·3c74·6162·6c65·2063·6c61··5403"><table·cla0003b8a0:·3033·223e·3c74·6162·6c65·2063·6c61·7373··03"><table·class
0003b8b0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b8b0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b8c0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b8c0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b8d0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b8d0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b8e0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b8e0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b8f0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b8f0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b900:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b900:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b910:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b910:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b920:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b920:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b930:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b930:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b940:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003b940:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b950:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003b950:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003b960:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003b960:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003b970:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003b980:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod0003b970:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003b980:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003b990:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003b9a0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003b9b0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003b9c0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003b9d0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003b9e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b9f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003ba00:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003ba10:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003ba20:·612d·7461·7267·6574·3d22·2369·646d·3534··a-target="#idm54
 0003ba30:·3034·2220·7461·6269·6e64·6578·3d22·3022··04"·tabindex="0"
 0003ba40:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003ba50:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003ba60:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003ba70:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003ba80:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003ba90:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003baa0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003bab0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bac0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003bad0:·6522·2069·643d·2269·646d·3534·3034·223e··e"·id="idm5404">
 0003bae0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003baf0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003bb00:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003bb10:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003bb20:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003bb30:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003bb40:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003bb50:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003bb60:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bb70:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003bb80:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003bb90:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003bba0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bbb0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003bbc0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003bbd0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003bbe0:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f
 0003bbf0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 0003bc00:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 0003bc10:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
 0003bc20:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if·
 0003bc30:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003bc40:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 0003bc50:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·-
 0003bc60:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 0003bc70:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003bc80:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003bc90:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003bca0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003bcb0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
0003b990:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003bcc0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003b9a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003bcd0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003b9b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003bce0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003b9c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003bcf0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003b9d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003bd00:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b9e0:·6d35·3430·3422·2074·6162·696e·6465·783d··m5404"·tabindex=0003bd10:·6d35·3430·3522·2074·6162·696e·6465·783d··m5405"·tabindex=
0003b9f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003bd20:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003ba00:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bd30:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003ba10:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bd40:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003ba20:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003bd50:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003ba30:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bd60:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003ba40:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003bd70:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003ba50:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003bd80:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003ba60:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003bd90:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003ba70:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003bda0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003ba80:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm50003bdb0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003ba90:·3430·3422·3e3c·7461·626c·6520·636c·6173··404"><table·clas0003bdc0:·6d35·3430·3522·3e3c·7461·626c·6520·636c··m5405"><table·cl
0003baa0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003bdd0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003bab0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003bde0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bac0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003bdf0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003bad0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003be00:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003bae0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003be10:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003baf0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003be20:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bb00:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003be30:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bb10:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003be40:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003bb20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003be50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bb30:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003be60:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003bb40:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003be70:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003bb50:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003be80:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003be90:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003bea0:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co
0003bb60:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003bb70:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas 
0003bb80:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{ 
0003bb90:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai 
0003bba0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure· 
0003bbb0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0003bbc0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0003bbd0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bbe0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bbf0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bc00:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bc10:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5 
0003bc20:·3430·3522·2074·6162·696e·6465·783d·2230··405"·tabindex="0 
0003bc30:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bc40:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bc50:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bc60:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
Max diff block lines reached; 518310/532966 bytes (97.25%) of diff not shown.
36.1 KB
html2text {}
    
Offset 106, 20 lines modifiedOffset 106, 14 lines modified
106 ············A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,106 ············A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,
107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
108 Remediation_OSBuild_Blueprint_snippet_⇲108 Remediation_OSBuild_Blueprint_snippet_⇲
  
109 [[packages]]109 [[packages]]
110 name·=·"aide"110 name·=·"aide"
111 version·=·"*"111 version·=·"*"
112 Remediation_Anaconda_snippet_⇲ 
113 Complexity:·low 
114 Disruption:·low 
115 Strategy:···enable 
  
116 package·--add=aide 
117 Remediation_Puppet_snippet_⇲112 Remediation_Puppet_snippet_⇲
118 Complexity:·low113 Complexity:·low
119 Disruption:·low114 Disruption:·low
120 Strategy:···enable115 Strategy:···enable
121 include·install_aide116 include·install_aide
  
122 class·install_aide·{117 class·install_aide·{
Offset 137, 14 lines modifiedOffset 131, 20 lines modified
137 if·!·rpm·-q·--quiet·"aide"·;·then131 if·!·rpm·-q·--quiet·"aide"·;·then
138 ····yum·install·-y·"aide"132 ····yum·install·-y·"aide"
139 fi133 fi
  
140 else134 else
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
142 fi136 fi
 137 Remediation_Anaconda_snippet_⇲
 138 Complexity:·low
 139 Disruption:·low
 140 Strategy:···enable
  
 141 package·--add=aide
143 Remediation_Ansible_snippet_⇲142 Remediation_Ansible_snippet_⇲
144 Complexity:·low143 Complexity:·low
145 Disruption:·low144 Disruption:·low
146 Strategy:···enable145 Strategy:···enable
147 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
148 ··package:147 ··package:
149 ····name:·aide148 ····name:·aide
Offset 430, 20 lines modifiedOffset 430, 14 lines modified
430 and·········00125430 and·········00125
431 References431 References
432 Remediation_OSBuild_Blueprint_snippet_⇲432 Remediation_OSBuild_Blueprint_snippet_⇲
  
433 [[packages]]433 [[packages]]
434 name·=·"sudo"434 name·=·"sudo"
435 version·=·"*"435 version·=·"*"
436 Remediation_Anaconda_snippet_⇲ 
437 Complexity:·low 
438 Disruption:·low 
439 Strategy:···enable 
  
440 package·--add=sudo 
441 Remediation_Puppet_snippet_⇲436 Remediation_Puppet_snippet_⇲
442 Complexity:·low437 Complexity:·low
443 Disruption:·low438 Disruption:·low
444 Strategy:···enable439 Strategy:···enable
445 include·install_sudo440 include·install_sudo
  
446 class·install_sudo·{441 class·install_sudo·{
Offset 461, 14 lines modifiedOffset 455, 20 lines modified
461 if·!·rpm·-q·--quiet·"sudo"·;·then455 if·!·rpm·-q·--quiet·"sudo"·;·then
462 ····yum·install·-y·"sudo"456 ····yum·install·-y·"sudo"
463 fi457 fi
  
464 else458 else
465 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'459 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
466 fi460 fi
 461 Remediation_Anaconda_snippet_⇲
 462 Complexity:·low
 463 Disruption:·low
 464 Strategy:···enable
  
 465 package·--add=sudo
467 Remediation_Ansible_snippet_⇲466 Remediation_Ansible_snippet_⇲
468 Complexity:·low467 Complexity:·low
469 Disruption:·low468 Disruption:·low
470 Strategy:···enable469 Strategy:···enable
471 -·name:·Ensure·sudo·is·installed470 -·name:·Ensure·sudo·is·installed
472 ··package:471 ··package:
473 ····name:·sudo472 ····name:·sudo
Offset 859, 20 lines modifiedOffset 859, 14 lines modified
859 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed859 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
860 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080860 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
861 Remediation_OSBuild_Blueprint_snippet_⇲861 Remediation_OSBuild_Blueprint_snippet_⇲
  
862 [[packages]]862 [[packages]]
863 name·=·"dnf-automatic"863 name·=·"dnf-automatic"
864 version·=·"*"864 version·=·"*"
865 Remediation_Anaconda_snippet_⇲ 
866 Complexity:·low 
867 Disruption:·low 
868 Strategy:···enable 
  
869 package·--add=dnf-automatic 
870 Remediation_Puppet_snippet_⇲865 Remediation_Puppet_snippet_⇲
871 Complexity:·low866 Complexity:·low
872 Disruption:·low867 Disruption:·low
873 Strategy:···enable868 Strategy:···enable
874 include·install_dnf-automatic869 include·install_dnf-automatic
  
875 class·install_dnf-automatic·{870 class·install_dnf-automatic·{
Offset 884, 14 lines modifiedOffset 878, 20 lines modified
884 Complexity:·low878 Complexity:·low
885 Disruption:·low879 Disruption:·low
886 Strategy:···enable880 Strategy:···enable
  
887 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then881 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
888 ····yum·install·-y·"dnf-automatic"882 ····yum·install·-y·"dnf-automatic"
889 fi883 fi
 884 Remediation_Anaconda_snippet_⇲
 885 Complexity:·low
 886 Disruption:·low
 887 Strategy:···enable
  
 888 package·--add=dnf-automatic
890 Remediation_Ansible_snippet_⇲889 Remediation_Ansible_snippet_⇲
891 Complexity:·low890 Complexity:·low
892 Disruption:·low891 Disruption:·low
893 Strategy:···enable892 Strategy:···enable
894 -·name:·Ensure·dnf-automatic·is·installed893 -·name:·Ensure·dnf-automatic·is·installed
895 ··package:894 ··package:
896 ····name:·dnf-automatic895 ····name:·dnf-automatic
Offset 9200, 20 lines modifiedOffset 9200, 14 lines modified
9200 and·········000619200 and·········00061
Max diff block lines reached; 34089/36922 bytes (92.33%) of diff not shown.
613 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_high.html
    
Offset 15230, 116 lines modifiedOffset 15230, 116 lines modified
0003b7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b7e0:·3534·3033·2220·7461·6269·6e64·6578·3d22··5403"·tabindex="0003b7e0:·3534·3033·2220·7461·6269·6e64·6578·3d22··5403"·tabindex="
0003b7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b840:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003b840:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003b850:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003b850:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003b860:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b860:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b870:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b870:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b880:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b880:·6c61·7073·6522·2069·643d·2269·646d·3534··lapse"·id="idm54
0003b890:·3534·3033·223e·3c74·6162·6c65·2063·6c61··5403"><table·cla0003b890:·3033·223e·3c74·6162·6c65·2063·6c61·7373··03"><table·class
0003b8a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b8a0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b8b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b8b0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b8c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b8c0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b8d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b8d0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b8e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b8e0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b8f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b8f0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b900:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b900:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b910:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b910:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b920:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b920:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b930:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003b930:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b940:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003b940:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003b950:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003b950:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003b960:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003b970:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod0003b960:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003b970:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003b980:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003b990:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003b9a0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003b9b0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003b9c0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003b9d0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003b9e0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003b9f0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003ba00:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003ba10:·612d·7461·7267·6574·3d22·2369·646d·3534··a-target="#idm54
 0003ba20:·3034·2220·7461·6269·6e64·6578·3d22·3022··04"·tabindex="0"
 0003ba30:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003ba40:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003ba50:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003ba60:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003ba70:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003ba80:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003ba90:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003baa0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bab0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003bac0:·6522·2069·643d·2269·646d·3534·3034·223e··e"·id="idm5404">
 0003bad0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003bae0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003baf0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003bb00:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003bb10:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003bb20:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003bb30:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003bb40:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003bb50:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bb60:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003bb70:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003bb80:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003bb90:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bba0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003bbb0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003bbc0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003bbd0:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f
 0003bbe0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 0003bbf0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 0003bc00:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
 0003bc10:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if·
 0003bc20:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003bc30:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 0003bc40:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·-
 0003bc50:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 0003bc60:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003bc70:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003bc80:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003bc90:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003bca0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
0003b980:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003bcb0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003b990:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003bcc0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003b9a0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003bcd0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003b9b0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003bce0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003b9c0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003bcf0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b9d0:·6d35·3430·3422·2074·6162·696e·6465·783d··m5404"·tabindex=0003bd00:·6d35·3430·3522·2074·6162·696e·6465·783d··m5405"·tabindex=
0003b9e0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003bd10:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b9f0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bd20:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003ba00:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bd30:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003ba10:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003bd40:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003ba20:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bd50:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003ba30:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003bd60:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003ba40:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003bd70:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003ba50:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003bd80:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003ba60:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003bd90:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003ba70:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm50003bda0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003ba80:·3430·3422·3e3c·7461·626c·6520·636c·6173··404"><table·clas0003bdb0:·6d35·3430·3522·3e3c·7461·626c·6520·636c··m5405"><table·cl
0003ba90:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003bdc0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003baa0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003bdd0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bab0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003bde0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003bac0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003bdf0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003bad0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003be00:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003bae0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003be10:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003baf0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003be20:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bb00:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003be30:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003bb10:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003be40:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bb20:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003be50:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003bb30:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003be60:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003bb40:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003be70:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003be80:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003be90:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co
0003bb50:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003bb60:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas 
0003bb70:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{ 
0003bb80:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai 
0003bb90:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure· 
0003bba0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0003bbb0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0003bbc0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bbd0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bbe0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bbf0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bc00:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5 
0003bc10:·3430·3522·2074·6162·696e·6465·783d·2230··405"·tabindex="0 
0003bc20:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bc30:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bc40:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bc50:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
Max diff block lines reached; 572642/587298 bytes (97.50%) of diff not shown.
39.6 KB
html2text {}
    
Offset 106, 20 lines modifiedOffset 106, 14 lines modified
106 ············A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,106 ············A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,
107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199107 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
108 Remediation_OSBuild_Blueprint_snippet_⇲108 Remediation_OSBuild_Blueprint_snippet_⇲
  
109 [[packages]]109 [[packages]]
110 name·=·"aide"110 name·=·"aide"
111 version·=·"*"111 version·=·"*"
112 Remediation_Anaconda_snippet_⇲ 
113 Complexity:·low 
114 Disruption:·low 
115 Strategy:···enable 
  
116 package·--add=aide 
117 Remediation_Puppet_snippet_⇲112 Remediation_Puppet_snippet_⇲
118 Complexity:·low113 Complexity:·low
119 Disruption:·low114 Disruption:·low
120 Strategy:···enable115 Strategy:···enable
121 include·install_aide116 include·install_aide
  
122 class·install_aide·{117 class·install_aide·{
Offset 137, 14 lines modifiedOffset 131, 20 lines modified
137 if·!·rpm·-q·--quiet·"aide"·;·then131 if·!·rpm·-q·--quiet·"aide"·;·then
138 ····yum·install·-y·"aide"132 ····yum·install·-y·"aide"
139 fi133 fi
  
140 else134 else
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
142 fi136 fi
 137 Remediation_Anaconda_snippet_⇲
 138 Complexity:·low
 139 Disruption:·low
 140 Strategy:···enable
  
 141 package·--add=aide
143 Remediation_Ansible_snippet_⇲142 Remediation_Ansible_snippet_⇲
144 Complexity:·low143 Complexity:·low
145 Disruption:·low144 Disruption:·low
146 Strategy:···enable145 Strategy:···enable
147 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
148 ··package:147 ··package:
149 ····name:·aide148 ····name:·aide
Offset 725, 20 lines modifiedOffset 725, 14 lines modified
725 and·········00125725 and·········00125
726 References726 References
727 Remediation_OSBuild_Blueprint_snippet_⇲727 Remediation_OSBuild_Blueprint_snippet_⇲
  
728 [[packages]]728 [[packages]]
729 name·=·"sudo"729 name·=·"sudo"
730 version·=·"*"730 version·=·"*"
731 Remediation_Anaconda_snippet_⇲ 
732 Complexity:·low 
733 Disruption:·low 
734 Strategy:···enable 
  
735 package·--add=sudo 
736 Remediation_Puppet_snippet_⇲731 Remediation_Puppet_snippet_⇲
737 Complexity:·low732 Complexity:·low
738 Disruption:·low733 Disruption:·low
739 Strategy:···enable734 Strategy:···enable
740 include·install_sudo735 include·install_sudo
  
741 class·install_sudo·{736 class·install_sudo·{
Offset 756, 14 lines modifiedOffset 750, 20 lines modified
756 if·!·rpm·-q·--quiet·"sudo"·;·then750 if·!·rpm·-q·--quiet·"sudo"·;·then
757 ····yum·install·-y·"sudo"751 ····yum·install·-y·"sudo"
758 fi752 fi
  
759 else753 else
760 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'754 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
761 fi755 fi
 756 Remediation_Anaconda_snippet_⇲
 757 Complexity:·low
 758 Disruption:·low
 759 Strategy:···enable
  
 760 package·--add=sudo
762 Remediation_Ansible_snippet_⇲761 Remediation_Ansible_snippet_⇲
763 Complexity:·low762 Complexity:·low
764 Disruption:·low763 Disruption:·low
765 Strategy:···enable764 Strategy:···enable
766 -·name:·Ensure·sudo·is·installed765 -·name:·Ensure·sudo·is·installed
767 ··package:766 ··package:
768 ····name:·sudo767 ····name:·sudo
Offset 1154, 20 lines modifiedOffset 1154, 14 lines modified
1154 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1154 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1155 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-000801155 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1156 Remediation_OSBuild_Blueprint_snippet_⇲1156 Remediation_OSBuild_Blueprint_snippet_⇲
  
1157 [[packages]]1157 [[packages]]
1158 name·=·"dnf-automatic"1158 name·=·"dnf-automatic"
1159 version·=·"*"1159 version·=·"*"
1160 Remediation_Anaconda_snippet_⇲ 
1161 Complexity:·low 
1162 Disruption:·low 
1163 Strategy:···enable 
  
1164 package·--add=dnf-automatic 
1165 Remediation_Puppet_snippet_⇲1160 Remediation_Puppet_snippet_⇲
1166 Complexity:·low1161 Complexity:·low
1167 Disruption:·low1162 Disruption:·low
1168 Strategy:···enable1163 Strategy:···enable
1169 include·install_dnf-automatic1164 include·install_dnf-automatic
  
1170 class·install_dnf-automatic·{1165 class·install_dnf-automatic·{
Offset 1179, 14 lines modifiedOffset 1173, 20 lines modified
1179 Complexity:·low1173 Complexity:·low
1180 Disruption:·low1174 Disruption:·low
1181 Strategy:···enable1175 Strategy:···enable
  
1182 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1176 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1183 ····yum·install·-y·"dnf-automatic"1177 ····yum·install·-y·"dnf-automatic"
1184 fi1178 fi
 1179 Remediation_Anaconda_snippet_⇲
 1180 Complexity:·low
 1181 Disruption:·low
 1182 Strategy:···enable
  
 1183 package·--add=dnf-automatic
1185 Remediation_Ansible_snippet_⇲1184 Remediation_Ansible_snippet_⇲
1186 Complexity:·low1185 Complexity:·low
1187 Disruption:·low1186 Disruption:·low
1188 Strategy:···enable1187 Strategy:···enable
1189 -·name:·Ensure·dnf-automatic·is·installed1188 -·name:·Ensure·dnf-automatic·is·installed
1190 ··package:1189 ··package:
1191 ····name:·dnf-automatic1190 ····name:·dnf-automatic
Offset 9552, 20 lines modifiedOffset 9552, 14 lines modified
9552 and·········000619552 and·········00061
Max diff block lines reached; 37710/40547 bytes (93.00%) of diff not shown.
557 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_intermediary.html
    
Offset 15225, 117 lines modifiedOffset 15225, 117 lines modified
0003b780:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b780:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b790:·3d22·2369·646d·3534·3033·2220·7461·6269··="#idm5403"·tabi0003b790:·3d22·2369·646d·3534·3033·2220·7461·6269··="#idm5403"·tabi
0003b7a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b7a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b7b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b7b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b7c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b7c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b7d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b7d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b7e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b7e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b7f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b7f0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003b800:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003b800:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003b810:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b810:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b820:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b820:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b830:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b830:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b840:·643d·2269·646d·3534·3033·223e·3c74·6162··d="idm5403"><tab0003b840:·2269·646d·3534·3033·223e·3c74·6162·6c65··"idm5403"><table
0003b850:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b850:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b860:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b860:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b870:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b870:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b880:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b880:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b890:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b890:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b8a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b8a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b8b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b8b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b8c0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b8c0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b8d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b8d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b8e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b8e0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003b8f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003b8f0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003b900:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003b900:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003b910:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0003b910:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
0003b920:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide0003b920:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003b930:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003b940:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003b950:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003b960:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003b970:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003b980:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b990:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b9a0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b9b0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b9c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b9d0:·2369·646d·3534·3034·2220·7461·6269·6e64··#idm5404"·tabind
 0003b9e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b9f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003ba00:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003ba10:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003ba20:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003ba30:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003ba40:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003ba50:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003ba60:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003ba70:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003ba80:·3534·3034·223e·3c74·6162·6c65·2063·6c61··5404"><table·cla
 0003ba90:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003baa0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003bab0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003bac0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003bad0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003bae0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003baf0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003bb00:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003bb10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bb20:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003bb30:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003bb40:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003bb50:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003bb60:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003bb70:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003bb80:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003bb90:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
 0003bba0:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 0003bbb0:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
 0003bbc0:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the
 0003bbd0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003bbe0:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003bbf0:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 0003bc00:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003bc10:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003bc20:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003bc30:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003bc40:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003bc50:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
0003b930:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003bc60:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003b940:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003bc70:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003b950:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003bc80:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003b960:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003bc90:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003b970:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003bca0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b980:·743d·2223·6964·6d35·3430·3422·2074·6162··t="#idm5404"·tab0003bcb0:·743d·2223·6964·6d35·3430·3522·2074·6162··t="#idm5405"·tab
0003b990:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003bcc0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b9a0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bcd0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b9b0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bce0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b9c0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bcf0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b9d0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bd00:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b9e0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003bd10:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003b9f0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003bd20:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003ba00:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003bd30:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003ba10:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003bd40:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003ba20:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003bd50:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003ba30:·3d22·6964·6d35·3430·3422·3e3c·7461·626c··="idm5404"><tabl0003bd60:·6964·3d22·6964·6d35·3430·3522·3e3c·7461··id="idm5405"><ta
0003ba40:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003bd70:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003ba50:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003bd80:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003ba60:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003bd90:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003ba70:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003bda0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003ba80:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003bdb0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003ba90:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003bdc0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003baa0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003bdd0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bab0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003bde0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003bac0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003bdf0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003bad0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003be00:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003bae0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003be10:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003baf0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003be20:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003bb00:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003be30:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003be40:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
0003bb10:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003bb20:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003bb30:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003bb40:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003bb50:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003bb60:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003bb70:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003bb80:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003bb90:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003bba0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003bbb0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003bbc0:·2223·6964·6d35·3430·3522·2074·6162·696e··"#idm5405"·tabin 
0003bbd0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003bbe0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003bbf0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003bc00:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003bc10:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003bc20:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
Max diff block lines reached; 518860/533654 bytes (97.23%) of diff not shown.
36.1 KB
html2text {}
    
Offset 105, 20 lines modifiedOffset 105, 14 lines modified
105 ············A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,105 ············A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,
106 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199106 ············PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
107 Remediation_OSBuild_Blueprint_snippet_⇲107 Remediation_OSBuild_Blueprint_snippet_⇲
  
108 [[packages]]108 [[packages]]
109 name·=·"aide"109 name·=·"aide"
110 version·=·"*"110 version·=·"*"
111 Remediation_Anaconda_snippet_⇲ 
112 Complexity:·low 
113 Disruption:·low 
114 Strategy:···enable 
  
115 package·--add=aide 
116 Remediation_Puppet_snippet_⇲111 Remediation_Puppet_snippet_⇲
117 Complexity:·low112 Complexity:·low
118 Disruption:·low113 Disruption:·low
119 Strategy:···enable114 Strategy:···enable
120 include·install_aide115 include·install_aide
  
121 class·install_aide·{116 class·install_aide·{
Offset 136, 14 lines modifiedOffset 130, 20 lines modified
136 if·!·rpm·-q·--quiet·"aide"·;·then130 if·!·rpm·-q·--quiet·"aide"·;·then
137 ····yum·install·-y·"aide"131 ····yum·install·-y·"aide"
138 fi132 fi
  
139 else133 else
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
141 fi135 fi
 136 Remediation_Anaconda_snippet_⇲
 137 Complexity:·low
 138 Disruption:·low
 139 Strategy:···enable
  
 140 package·--add=aide
142 Remediation_Ansible_snippet_⇲141 Remediation_Ansible_snippet_⇲
143 Complexity:·low142 Complexity:·low
144 Disruption:·low143 Disruption:·low
145 Strategy:···enable144 Strategy:···enable
146 -·name:·Ensure·aide·is·installed145 -·name:·Ensure·aide·is·installed
147 ··package:146 ··package:
148 ····name:·aide147 ····name:·aide
Offset 429, 20 lines modifiedOffset 429, 14 lines modified
429 and·········00125429 and·········00125
430 References430 References
431 Remediation_OSBuild_Blueprint_snippet_⇲431 Remediation_OSBuild_Blueprint_snippet_⇲
  
432 [[packages]]432 [[packages]]
433 name·=·"sudo"433 name·=·"sudo"
434 version·=·"*"434 version·=·"*"
435 Remediation_Anaconda_snippet_⇲ 
436 Complexity:·low 
437 Disruption:·low 
438 Strategy:···enable 
  
439 package·--add=sudo 
440 Remediation_Puppet_snippet_⇲435 Remediation_Puppet_snippet_⇲
441 Complexity:·low436 Complexity:·low
442 Disruption:·low437 Disruption:·low
443 Strategy:···enable438 Strategy:···enable
444 include·install_sudo439 include·install_sudo
  
445 class·install_sudo·{440 class·install_sudo·{
Offset 460, 14 lines modifiedOffset 454, 20 lines modified
460 if·!·rpm·-q·--quiet·"sudo"·;·then454 if·!·rpm·-q·--quiet·"sudo"·;·then
461 ····yum·install·-y·"sudo"455 ····yum·install·-y·"sudo"
462 fi456 fi
  
463 else457 else
464 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'458 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
465 fi459 fi
 460 Remediation_Anaconda_snippet_⇲
 461 Complexity:·low
 462 Disruption:·low
 463 Strategy:···enable
  
 464 package·--add=sudo
466 Remediation_Ansible_snippet_⇲465 Remediation_Ansible_snippet_⇲
467 Complexity:·low466 Complexity:·low
468 Disruption:·low467 Disruption:·low
469 Strategy:···enable468 Strategy:···enable
470 -·name:·Ensure·sudo·is·installed469 -·name:·Ensure·sudo·is·installed
471 ··package:470 ··package:
472 ····name:·sudo471 ····name:·sudo
Offset 858, 20 lines modifiedOffset 858, 14 lines modified
858 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed858 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
859 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080859 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
860 Remediation_OSBuild_Blueprint_snippet_⇲860 Remediation_OSBuild_Blueprint_snippet_⇲
  
861 [[packages]]861 [[packages]]
862 name·=·"dnf-automatic"862 name·=·"dnf-automatic"
863 version·=·"*"863 version·=·"*"
864 Remediation_Anaconda_snippet_⇲ 
865 Complexity:·low 
866 Disruption:·low 
867 Strategy:···enable 
  
868 package·--add=dnf-automatic 
869 Remediation_Puppet_snippet_⇲864 Remediation_Puppet_snippet_⇲
870 Complexity:·low865 Complexity:·low
871 Disruption:·low866 Disruption:·low
872 Strategy:···enable867 Strategy:···enable
873 include·install_dnf-automatic868 include·install_dnf-automatic
  
874 class·install_dnf-automatic·{869 class·install_dnf-automatic·{
Offset 883, 14 lines modifiedOffset 877, 20 lines modified
883 Complexity:·low877 Complexity:·low
884 Disruption:·low878 Disruption:·low
885 Strategy:···enable879 Strategy:···enable
  
886 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then880 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
887 ····yum·install·-y·"dnf-automatic"881 ····yum·install·-y·"dnf-automatic"
888 fi882 fi
 883 Remediation_Anaconda_snippet_⇲
 884 Complexity:·low
 885 Disruption:·low
 886 Strategy:···enable
  
 887 package·--add=dnf-automatic
889 Remediation_Ansible_snippet_⇲888 Remediation_Ansible_snippet_⇲
890 Complexity:·low889 Complexity:·low
891 Disruption:·low890 Disruption:·low
892 Strategy:···enable891 Strategy:···enable
893 -·name:·Ensure·dnf-automatic·is·installed892 -·name:·Ensure·dnf-automatic·is·installed
894 ··package:893 ··package:
895 ····name:·dnf-automatic894 ····name:·dnf-automatic
Offset 8696, 20 lines modifiedOffset 8696, 14 lines modified
8696 and·········000618696 and·········00061
Max diff block lines reached; 34089/36922 bytes (92.33%) of diff not shown.
212 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_minimal.html
    
Offset 15872, 107 lines modifiedOffset 15872, 107 lines modified
0003dff0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003dff0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003e000:·2223·6964·6d38·3334·3822·2074·6162·696e··"#idm8348"·tabin0003e000:·2223·6964·6d38·3334·3822·2074·6162·696e··"#idm8348"·tabin
0003e010:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003e010:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003e020:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003e020:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003e030:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003e030:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003e040:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003e040:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003e050:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003e050:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003e060:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003e060:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
0003e070:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003e070:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
0003e080:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003e080:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003e090:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003e090:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003e0a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003e0a0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003e0b0:·3d22·6964·6d38·3334·3822·3e3c·7461·626c··="idm8348"><tabl0003e0b0:·6964·6d38·3334·3822·3e3c·7461·626c·6520··idm8348"><table·
0003e0c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003e0c0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003e0d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003e0d0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003e0e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003e0e0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003e0f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003e0f0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003e100:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003e100:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003e110:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003e110:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003e120:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003e120:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003e130:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003e130:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003e140:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003e140:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003e150:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003e150:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003e160:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003e160:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003e170:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003e170:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003e180:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac0003e180:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 0003e190:·6520·696e·7374·616c·6c5f·646e·662d·6175··e·install_dnf-au
 0003e1a0:·746f·6d61·7469·630a·0a63·6c61·7373·2069··tomatic..class·i
 0003e1b0:·6e73·7461·6c6c·5f64·6e66·2d61·7574·6f6d··nstall_dnf-autom
 0003e1c0:·6174·6963·207b·0a20·2070·6163·6b61·6765··atic·{.··package
0003e190:·6b61·6765·202d·2d61·6464·3d64·6e66·2d61··kage·--add=dnf-a 
0003e1a0:·7574·6f6d·6174·6963·0a3c·2f63·6f64·653e··utomatic.</code> 
0003e1b0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003e1c0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003e1d0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003e1e0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003e1f0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
0003e200:·3334·3922·2074·6162·696e·6465·783d·2230··349"·tabindex="0 
0003e210:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003e220:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003e230:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003e240:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003e250:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003e260:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn 
0003e270:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003e280:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003e290:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003e2a0:·6170·7365·2220·6964·3d22·6964·6d38·3334··apse"·id="idm834 
0003e2b0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class= 
0003e2c0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003e2d0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003e2e0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003e2f0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003e300:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003e310:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003e320:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003e330:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003e340:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003e350:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003e360:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003e370:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003e380:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
0003e390:·616c·6c5f·646e·662d·6175·746f·6d61·7469··all_dnf-automati0003e1d0:·207b·2027·646e·662d·6175·746f·6d61·7469···{·'dnf-automati
 0003e1e0:·6327·3a0a·2020·2020·656e·7375·7265·203d··c':.····ensure·=
 0003e1f0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003e200:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003e210:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003e220:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003e230:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003e3a0:·630a·0a63·6c61·7373·2069·6e73·7461·6c6c··c..class·install 
0003e3b0:·5f64·6e66·2d61·7574·6f6d·6174·6963·207b··_dnf-automatic·{ 
0003e3c0:·0a20·2070·6163·6b61·6765·207b·2027·646e··.··package·{·'dn 
0003e3d0:·662d·6175·746f·6d61·7469·6327·3a0a·2020··f-automatic':.·· 
0003e3e0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003e3f0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003e400:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003e410:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003e420:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003e430:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003e440:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003e450:·6574·3d22·2369·646d·3833·3530·2220·7461··et="#idm8350"·ta 
0003e460:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003e470:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003e480:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003e490:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003e4a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003e4b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003e4c0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003e4d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003e4e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003e4f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003e240:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003e500:·2269·646d·3833·3530·223e·3c74·6162·6c65··"idm8350"><table 
0003e510:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003e520:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003e530:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003e540:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003e550:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003e560:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003e570:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003e580:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003e250:·612d·7461·7267·6574·3d22·2369·646d·3833··a-target="#idm83
 0003e260:·3439·2220·7461·6269·6e64·6578·3d22·3022··49"·tabindex="0"
 0003e270:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003e280:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003e290:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003e2a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003e2b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003e2c0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003e2d0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003e2e0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003e2f0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003e300:·6522·2069·643d·2269·646d·3833·3439·223e··e"·id="idm8349">
 0003e310:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003e320:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003e330:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003e340:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003e350:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003e360:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003e370:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003e380:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003e390:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003e3a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003e3b0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003e590:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003e3c0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003e5a0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003e5b0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003e5c0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003e5d0:·3c70·7265·3e3c·636f·6465·3e0a·6966·2021··<pre><code>.if·! 
Max diff block lines reached; 188706/202120 bytes (93.36%) of diff not shown.
15.0 KB
html2text {}
    
Offset 241, 20 lines modifiedOffset 241, 14 lines modified
241 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed241 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
242 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080242 Identifiers·and·References·References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
243 Remediation_OSBuild_Blueprint_snippet_⇲243 Remediation_OSBuild_Blueprint_snippet_⇲
  
244 [[packages]]244 [[packages]]
245 name·=·"dnf-automatic"245 name·=·"dnf-automatic"
246 version·=·"*"246 version·=·"*"
247 Remediation_Anaconda_snippet_⇲ 
248 Complexity:·low 
249 Disruption:·low 
250 Strategy:···enable 
  
251 package·--add=dnf-automatic 
252 Remediation_Puppet_snippet_⇲247 Remediation_Puppet_snippet_⇲
253 Complexity:·low248 Complexity:·low
254 Disruption:·low249 Disruption:·low
255 Strategy:···enable250 Strategy:···enable
256 include·install_dnf-automatic251 include·install_dnf-automatic
  
257 class·install_dnf-automatic·{252 class·install_dnf-automatic·{
Offset 266, 14 lines modifiedOffset 260, 20 lines modified
266 Complexity:·low260 Complexity:·low
267 Disruption:·low261 Disruption:·low
268 Strategy:···enable262 Strategy:···enable
  
269 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then263 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
270 ····yum·install·-y·"dnf-automatic"264 ····yum·install·-y·"dnf-automatic"
271 fi265 fi
 266 Remediation_Anaconda_snippet_⇲
 267 Complexity:·low
 268 Disruption:·low
 269 Strategy:···enable
  
 270 package·--add=dnf-automatic
272 Remediation_Ansible_snippet_⇲271 Remediation_Ansible_snippet_⇲
273 Complexity:·low272 Complexity:·low
274 Disruption:·low273 Disruption:·low
275 Strategy:···enable274 Strategy:···enable
276 -·name:·Ensure·dnf-automatic·is·installed275 -·name:·Ensure·dnf-automatic·is·installed
277 ··package:276 ··package:
278 ····name:·dnf-automatic277 ····name:·dnf-automatic
Offset 6718, 20 lines modifiedOffset 6718, 14 lines modified
6718 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-6718 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
6719 ············002276719 ············00227
6720 Remediation_OSBuild_Blueprint_snippet_⇲6720 Remediation_OSBuild_Blueprint_snippet_⇲
  
6721 [[packages]]6721 [[packages]]
6722 name·=·"rsyslog"6722 name·=·"rsyslog"
6723 version·=·"*"6723 version·=·"*"
6724 Remediation_Anaconda_snippet_⇲ 
6725 Complexity:·low 
6726 Disruption:·low 
6727 Strategy:···enable 
  
6728 package·--add=rsyslog 
6729 Remediation_Puppet_snippet_⇲6724 Remediation_Puppet_snippet_⇲
6730 Complexity:·low6725 Complexity:·low
6731 Disruption:·low6726 Disruption:·low
6732 Strategy:···enable6727 Strategy:···enable
6733 include·install_rsyslog6728 include·install_rsyslog
  
6734 class·install_rsyslog·{6729 class·install_rsyslog·{
Offset 6749, 14 lines modifiedOffset 6743, 20 lines modified
6749 if·!·rpm·-q·--quiet·"rsyslog"·;·then6743 if·!·rpm·-q·--quiet·"rsyslog"·;·then
6750 ····yum·install·-y·"rsyslog"6744 ····yum·install·-y·"rsyslog"
6751 fi6745 fi
  
6752 else6746 else
6753 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6747 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6754 fi6748 fi
 6749 Remediation_Anaconda_snippet_⇲
 6750 Complexity:·low
 6751 Disruption:·low
 6752 Strategy:···enable
  
 6753 package·--add=rsyslog
6755 Remediation_Ansible_snippet_⇲6754 Remediation_Ansible_snippet_⇲
6756 Complexity:·low6755 Complexity:·low
6757 Disruption:·low6756 Disruption:·low
6758 Strategy:···enable6757 Strategy:···enable
6759 -·name:·Ensure·rsyslog·is·installed6758 -·name:·Ensure·rsyslog·is·installed
6760 ··package:6759 ··package:
6761 ····name:·rsyslog6760 ····name:·rsyslog
Offset 6939, 20 lines modifiedOffset 6939, 14 lines modified
6939 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,6939 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,
6940 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,6940 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
6941 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,6941 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
6942 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR6942 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
6943 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR6943 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
6944 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,6944 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
6945 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-36945 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3
6946 Remediation_Anaconda_snippet_⇲ 
6947 Complexity:·low 
6948 Disruption:·low 
6949 Strategy:···disable 
  
6950 package·--remove=dhcp 
6951 Remediation_Puppet_snippet_⇲6946 Remediation_Puppet_snippet_⇲
6952 Complexity:·low6947 Complexity:·low
6953 Disruption:·low6948 Disruption:·low
6954 Strategy:···disable6949 Strategy:···disable
6955 include·remove_dhcp6950 include·remove_dhcp
  
6956 class·remove_dhcp·{6951 class·remove_dhcp·{
Offset 6972, 14 lines modifiedOffset 6966, 20 lines modified
6972 #»      ···system!6966 #»      ···system!
  
6973 if·rpm·-q·--quiet·"dhcp"·;·then6967 if·rpm·-q·--quiet·"dhcp"·;·then
  
6974 ····yum·remove·-y·"dhcp"6968 ····yum·remove·-y·"dhcp"
  
6975 fi6969 fi
 6970 Remediation_Anaconda_snippet_⇲
 6971 Complexity:·low
 6972 Disruption:·low
 6973 Strategy:···disable
  
 6974 package·--remove=dhcp
6976 Remediation_Ansible_snippet_⇲6975 Remediation_Ansible_snippet_⇲
6977 Complexity:·low6976 Complexity:·low
6978 Disruption:·low6977 Disruption:·low
6979 Strategy:···disable6978 Strategy:···disable
6980 -·name:·Ensure·dhcp·is·removed6979 -·name:·Ensure·dhcp·is·removed
6981 ··package:6980 ··package:
6982 ····name:·dhcp6981 ····name:·dhcp
Offset 7026, 20 lines modifiedOffset 7026, 14 lines modified
7026 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7026 ············4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
Max diff block lines reached; 11878/15310 bytes (77.58%) of diff not shown.
828 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-cui.html
    
Offset 15271, 117 lines modifiedOffset 15271, 117 lines modified
0003ba60:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003ba60:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003ba70:·3d22·2369·646d·3534·3033·2220·7461·6269··="#idm5403"·tabi0003ba70:·3d22·2369·646d·3534·3033·2220·7461·6269··="#idm5403"·tabi
0003ba80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ba80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003ba90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003ba90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003baa0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003baa0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003bab0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003bab0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003bac0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003bac0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003bad0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003bad0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003bae0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003bae0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003baf0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003baf0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003bb00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003bb00:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003bb10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003bb10:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003bb20:·643d·2269·646d·3534·3033·223e·3c74·6162··d="idm5403"><tab0003bb20:·2269·646d·3534·3033·223e·3c74·6162·6c65··"idm5403"><table
0003bb30:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003bb30:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003bb40:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003bb40:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003bb50:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bb50:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003bb60:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bb60:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003bb70:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003bb70:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003bb80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bb80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bb90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003bb90:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003bba0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003bba0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003bbb0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bbb0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bbc0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bbc0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003bbd0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003bbd0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003bbe0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003bbe0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003bbf0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0003bbf0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
0003bc00:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide0003bc00:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003bc10:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003bc20:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003bc30:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003bc40:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003bc50:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003bc60:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bc70:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003bc80:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003bc90:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003bca0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003bcb0:·2369·646d·3534·3034·2220·7461·6269·6e64··#idm5404"·tabind
 0003bcc0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003bcd0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003bce0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003bcf0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003bd00:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003bd10:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003bd20:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003bd30:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003bd40:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003bd50:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003bd60:·3534·3034·223e·3c74·6162·6c65·2063·6c61··5404"><table·cla
 0003bd70:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003bd80:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003bd90:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003bda0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003bdb0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003bdc0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003bdd0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003bde0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003bdf0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003be00:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003be10:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003be20:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003be30:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003be40:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003be50:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003be60:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003be70:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
 0003be80:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 0003be90:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
 0003bea0:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the
 0003beb0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003bec0:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003bed0:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 0003bee0:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003bef0:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003bf00:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003bf10:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003bf20:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003bf30:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
0003bc10:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003bf40:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003bc20:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003bf50:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003bc30:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003bf60:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003bc40:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003bf70:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003bc50:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003bf80:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003bc60:·743d·2223·6964·6d35·3430·3422·2074·6162··t="#idm5404"·tab0003bf90:·743d·2223·6964·6d35·3430·3522·2074·6162··t="#idm5405"·tab
0003bc70:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003bfa0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003bc80:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bfb0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003bc90:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bfc0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bca0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bfd0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bcb0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bfe0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bcc0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003bff0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003bcd0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003c000:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003bce0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c010:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003bcf0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003c020:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003bd00:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003c030:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003bd10:·3d22·6964·6d35·3430·3422·3e3c·7461·626c··="idm5404"><tabl0003c040:·6964·3d22·6964·6d35·3430·3522·3e3c·7461··id="idm5405"><ta
0003bd20:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003c050:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003bd30:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003c060:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003bd40:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003c070:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003bd50:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003c080:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003bd60:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003c090:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003bd70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c0a0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003bd80:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003c0b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bd90:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003c0c0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003bda0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c0d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003bdb0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003c0e0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003bdc0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c0f0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003bdd0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003c100:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003bde0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003c110:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003c120:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
0003bdf0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003be00:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003be10:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003be20:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003be30:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003be40:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003be50:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003be60:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003be70:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003be80:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003be90:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003bea0:·2223·6964·6d35·3430·3522·2074·6162·696e··"#idm5405"·tabin 
0003beb0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003bec0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003bed0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003bee0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003bef0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003bf00:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
Max diff block lines reached; 763264/778058 bytes (98.10%) of diff not shown.
68.5 KB
html2text {}
    
Offset 95, 20 lines modifiedOffset 95, 14 lines modified
95 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed95 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
96 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019996 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
97 Remediation_OSBuild_Blueprint_snippet_⇲97 Remediation_OSBuild_Blueprint_snippet_⇲
  
98 [[packages]]98 [[packages]]
99 name·=·"aide"99 name·=·"aide"
100 version·=·"*"100 version·=·"*"
101 Remediation_Anaconda_snippet_⇲ 
102 Complexity:·low 
103 Disruption:·low 
104 Strategy:···enable 
  
105 package·--add=aide 
106 Remediation_Puppet_snippet_⇲101 Remediation_Puppet_snippet_⇲
107 Complexity:·low102 Complexity:·low
108 Disruption:·low103 Disruption:·low
109 Strategy:···enable104 Strategy:···enable
110 include·install_aide105 include·install_aide
  
111 class·install_aide·{106 class·install_aide·{
Offset 126, 14 lines modifiedOffset 120, 20 lines modified
126 if·!·rpm·-q·--quiet·"aide"·;·then120 if·!·rpm·-q·--quiet·"aide"·;·then
127 ····yum·install·-y·"aide"121 ····yum·install·-y·"aide"
128 fi122 fi
  
129 else123 else
130 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'124 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
131 fi125 fi
 126 Remediation_Anaconda_snippet_⇲
 127 Complexity:·low
 128 Disruption:·low
 129 Strategy:···enable
  
 130 package·--add=aide
132 Remediation_Ansible_snippet_⇲131 Remediation_Ansible_snippet_⇲
133 Complexity:·low132 Complexity:·low
134 Disruption:·low133 Disruption:·low
135 Strategy:···enable134 Strategy:···enable
136 -·name:·Ensure·aide·is·installed135 -·name:·Ensure·aide·is·installed
137 ··package:136 ··package:
138 ····name:·aide137 ····name:·aide
Offset 300, 20 lines modifiedOffset 300, 14 lines modified
300 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed300 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
301 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174301 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
302 Remediation_OSBuild_Blueprint_snippet_⇲302 Remediation_OSBuild_Blueprint_snippet_⇲
  
303 [[packages]]303 [[packages]]
304 name·=·"crypto-policies"304 name·=·"crypto-policies"
305 version·=·"*"305 version·=·"*"
306 Remediation_Anaconda_snippet_⇲ 
307 Complexity:·low 
308 Disruption:·low 
309 Strategy:···enable 
  
310 package·--add=crypto-policies 
311 Remediation_Puppet_snippet_⇲306 Remediation_Puppet_snippet_⇲
312 Complexity:·low307 Complexity:·low
313 Disruption:·low308 Disruption:·low
314 Strategy:···enable309 Strategy:···enable
315 include·install_crypto-policies310 include·install_crypto-policies
  
316 class·install_crypto-policies·{311 class·install_crypto-policies·{
Offset 325, 14 lines modifiedOffset 319, 20 lines modified
325 Complexity:·low319 Complexity:·low
326 Disruption:·low320 Disruption:·low
327 Strategy:···enable321 Strategy:···enable
  
328 if·!·rpm·-q·--quiet·"crypto-policies"·;·then322 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
329 ····yum·install·-y·"crypto-policies"323 ····yum·install·-y·"crypto-policies"
330 fi324 fi
 325 Remediation_Anaconda_snippet_⇲
 326 Complexity:·low
 327 Disruption:·low
 328 Strategy:···enable
  
 329 package·--add=crypto-policies
331 Remediation_Ansible_snippet_⇲330 Remediation_Ansible_snippet_⇲
332 Complexity:·low331 Complexity:·low
333 Disruption:·low332 Disruption:·low
334 Strategy:···enable333 Strategy:···enable
335 -·name:·Ensure·crypto-policies·is·installed334 -·name:·Ensure·crypto-policies·is·installed
336 ··package:335 ··package:
337 ····name:·crypto-policies336 ····name:·crypto-policies
Offset 734, 20 lines modifiedOffset 734, 14 lines modified
734 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed734 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
735 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125735 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
736 Remediation_OSBuild_Blueprint_snippet_⇲736 Remediation_OSBuild_Blueprint_snippet_⇲
  
737 [[packages]]737 [[packages]]
738 name·=·"sudo"738 name·=·"sudo"
739 version·=·"*"739 version·=·"*"
740 Remediation_Anaconda_snippet_⇲ 
741 Complexity:·low 
742 Disruption:·low 
743 Strategy:···enable 
  
744 package·--add=sudo 
745 Remediation_Puppet_snippet_⇲740 Remediation_Puppet_snippet_⇲
746 Complexity:·low741 Complexity:·low
747 Disruption:·low742 Disruption:·low
748 Strategy:···enable743 Strategy:···enable
749 include·install_sudo744 include·install_sudo
  
750 class·install_sudo·{745 class·install_sudo·{
Offset 765, 14 lines modifiedOffset 759, 20 lines modified
765 if·!·rpm·-q·--quiet·"sudo"·;·then759 if·!·rpm·-q·--quiet·"sudo"·;·then
766 ····yum·install·-y·"sudo"760 ····yum·install·-y·"sudo"
767 fi761 fi
  
768 else762 else
769 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'763 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
770 fi764 fi
 765 Remediation_Anaconda_snippet_⇲
 766 Complexity:·low
 767 Disruption:·low
 768 Strategy:···enable
  
 769 package·--add=sudo
771 Remediation_Ansible_snippet_⇲770 Remediation_Ansible_snippet_⇲
772 Complexity:·low771 Complexity:·low
773 Disruption:·low772 Disruption:·low
774 Strategy:···enable773 Strategy:···enable
775 -·name:·Ensure·sudo·is·installed774 -·name:·Ensure·sudo·is·installed
776 ··package:775 ··package:
777 ····name:·sudo776 ····name:·sudo
Offset 797, 20 lines modifiedOffset 797, 14 lines modified
797 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed797 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed
Max diff block lines reached; 66177/70084 bytes (94.43%) of diff not shown.
215 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-e8.html
    
Offset 20329, 116 lines modifiedOffset 20329, 116 lines modified
0004f680:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0004f680:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0004f690:·743d·2223·6964·6d38·3139·3922·2074·6162··t="#idm8199"·tab0004f690:·743d·2223·6964·6d38·3139·3922·2074·6162··t="#idm8199"·tab
0004f6a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0004f6a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0004f6b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0004f6b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0004f6c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0004f6c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0004f6d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0004f6d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0004f6e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0004f6e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0004f6f0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0004f6f0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0004f700:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0004f700:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0004f710:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0004f710:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0004f720:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0004f720:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0004f730:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0004f730:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0004f740:·6964·3d22·6964·6d38·3139·3922·3e3c·7461··id="idm8199"><ta0004f740:·3d22·6964·6d38·3139·3922·3e3c·7461·626c··="idm8199"><tabl
0004f750:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0004f750:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0004f760:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0004f760:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0004f770:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0004f770:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0004f780:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0004f780:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0004f790:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0004f790:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0004f7a0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0004f7a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0004f7b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0004f7b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0004f7c0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0004f7c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0004f7d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0004f7d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0004f7e0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0004f7e0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0004f7f0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0004f7f0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0004f800:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0004f800:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0004f810:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0004f810:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 0004f820:·7564·6520·696e·7374·616c·6c5f·7265·6172··ude·install_rear
 0004f830:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0004f840:·7265·6172·207b·0a20·2070·6163·6b61·6765··rear·{.··package
 0004f850:·207b·2027·7265·6172·273a·0a20·2020·2065···{·'rear':.····e
 0004f860:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0004f870:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0004f880:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0004f820:·6163·6b61·6765·202d·2d61·6464·3d72·6561··ackage·--add=rea 
0004f830:·720a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··r.</code></pre>< 
0004f840:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004f850:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004f860:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004f870:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004f880:·6574·3d22·2369·646d·3832·3030·2220·7461··et="#idm8200"·ta 
0004f890:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0004f8a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0004f8b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0004f8c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0004f8d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0004f8e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0004f8f0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·. 
0004f900:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0004f910:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0004f920:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0004f930:·643d·2269·646d·3832·3030·223e·3c74·6162··d="idm8200"><tab 
0004f940:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0004f890:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0004f950:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0004f960:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0004f970:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0004f980:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0004f990:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0004f9a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0004f9b0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0004f8a0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0004f8b0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0004f8c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0004f8d0:·2223·6964·6d38·3230·3022·2074·6162·696e··"#idm8200"·tabin
 0004f8e0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0004f8f0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0004f900:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0004f910:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0004f920:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0004f930:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0004f940:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0004f950:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0004f960:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0004f970:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0004f980:·6d38·3230·3022·3e3c·7461·626c·6520·636c··m8200"><table·cl
 0004f990:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0004f9a0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0004f9b0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0004f9c0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0004f9d0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0004f9c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0004f9e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0004f9d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0004f9e0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0004f9f0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0004fa00:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0004fa10:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0004fa20:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0004fa30:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0004fa40:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0004fa50:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0004fa60:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0004fa70:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0004fa80:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0004fa90:·2021·2067·7265·7020·2d71·2061·6172·6368···!·grep·-q·aarch
 0004faa0:·3634·202f·7072·6f63·2f73·7973·2f6b·6572··64·/proc/sys/ker
 0004fab0:·6e65·6c2f·6f73·7265·6c65·6173·653b·2074··nel/osrelease;·t
 0004fac0:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 0004fad0:·202d·2d71·7569·6574·2022·7265·6172·2220···--quiet·"rear"·
 0004fae0:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 0004faf0:·6e73·7461·6c6c·202d·7920·2272·6561·7222··nstall·-y·"rear"
 0004fb00:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 0004fb10:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 0004fb20:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 0004fb30:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 0004fb40:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0004fb50:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 0004fb60:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0004fb70:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0004fb80:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0004fb90:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0004fba0:·6765·743d·2223·6964·6d38·3230·3122·2074··get="#idm8201"·t
 0004fbb0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0004fbc0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0004fbd0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0004fbe0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0004fbf0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0004fc00:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0004fc10:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe
 0004fc20:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0004fc30:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0004fc40:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0004fc50:·2220·6964·3d22·6964·6d38·3230·3122·3e3c··"·id="idm8201"><
 0004fc60:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0004fc70:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0004fc80:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0004fc90:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0004fca0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0004fcb0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0004f9f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0004fcc0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0004fcd0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
Max diff block lines reached; 183336/197992 bytes (92.60%) of diff not shown.
21.9 KB
html2text {}
    
Offset 863, 20 lines modifiedOffset 863, 14 lines modified
863 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed863 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
864 Identifiers·and·References864 Identifiers·and·References
865 Remediation_OSBuild_Blueprint_snippet_⇲865 Remediation_OSBuild_Blueprint_snippet_⇲
  
866 [[packages]]866 [[packages]]
867 name·=·"rear"867 name·=·"rear"
868 version·=·"*"868 version·=·"*"
869 Remediation_Anaconda_snippet_⇲ 
870 Complexity:·low 
871 Disruption:·low 
872 Strategy:···enable 
  
873 package·--add=rear 
874 Remediation_Puppet_snippet_⇲869 Remediation_Puppet_snippet_⇲
875 Complexity:·low870 Complexity:·low
876 Disruption:·low871 Disruption:·low
877 Strategy:···enable872 Strategy:···enable
878 include·install_rear873 include·install_rear
  
879 class·install_rear·{874 class·install_rear·{
Offset 894, 14 lines modifiedOffset 888, 20 lines modified
894 if·!·rpm·-q·--quiet·"rear"·;·then888 if·!·rpm·-q·--quiet·"rear"·;·then
895 ····yum·install·-y·"rear"889 ····yum·install·-y·"rear"
896 fi890 fi
  
897 else891 else
898 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'892 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
899 fi893 fi
 894 Remediation_Anaconda_snippet_⇲
 895 Complexity:·low
 896 Disruption:·low
 897 Strategy:···enable
  
 898 package·--add=rear
900 Remediation_Ansible_snippet_⇲899 Remediation_Ansible_snippet_⇲
901 Complexity:·low900 Complexity:·low
902 Disruption:·low901 Disruption:·low
903 Strategy:···enable902 Strategy:···enable
904 -·name:·Ensure·rear·is·installed903 -·name:·Ensure·rear·is·installed
905 ··package:904 ··package:
906 ····name:·rear905 ····name:·rear
Offset 14766, 26 lines modifiedOffset 14766, 14 lines modified
14766 $·sudo·systemctl·enable·auditd.service14766 $·sudo·systemctl·enable·auditd.service
14767 ···························Without·establishing·what·type·of·events·occurred,·it·would·be·difficult·to·establish,·correlate,·and·investigate·the·events·leading·up·to·an·outage·or·attack.·Ensuring·the·auditd·service·is·active·ensures·audit·records·generated·by·the·kernel·are·appropriately·recorded.14767 ···························Without·establishing·what·type·of·events·occurred,·it·would·be·difficult·to·establish,·correlate,·and·investigate·the·events·leading·up·to·an·outage·or·attack.·Ensuring·the·auditd·service·is·active·ensures·audit·records·generated·by·the·kernel·are·appropriately·recorded.
14768 Rationale:14768 Rationale:
14769 ···························Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of·individual·system·users·can·be·uniquely·traced·to·those·users·so·they·can·be·held·accountable·for·their·actions.14769 ···························Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of·individual·system·users·can·be·uniquely·traced·to·those·users·so·they·can·be·held·accountable·for·their·actions.
14770 Severity: ················medium14770 Severity: ················medium
14771 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_auditd_enabled14771 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_auditd_enabled
14772 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·3.3.2,·3.3.6,·CCI-000126,·CCI-000130,·CCI-000131,·CCI-000132,·CCI-000133,·CCI-000134,·CCI-000135,·CCI-000154,·CCI-000158,·CCI-000172,·CCI-000366,·CCI-001464,·CCI-001487,·CCI-001814,·CCI-001875,·CCI-001876,·CCI-001877,·CCI-002884,·CCI-001878,·CCI-001879,·CCI-001880,·CCI-001881,·CCI-001882,·CCI-001889,·CCI-001914,·CCI-000169,·164.308(a)(1)(ii)(D),·164.308(a)(5)(ii)(C),·164.310(a)(2)(iv),·164.310(d)(2)(iii),·164.312(b),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·CIP-004-6_R3.3,·CIP-007-3_R6.5,·AC-2(g),·AU-3,·AU-10,·AU-2(d),·AU-12(c),·AU-14(1),·AC-6(9),·CM-6(a),·SI-4(23),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1,·Req-10.1,·SRG-OS-000062-GPOS-00031,·SRG-OS-000037-GPOS-00015,·SRG-OS-000038-GPOS-00016,·SRG-OS-000039-GPOS-00017,·SRG-OS-000040-GPOS-00018,·SRG-OS-000041-GPOS-00019,·SRG-OS-000042-GPOS-00021,·SRG-OS-000051-GPOS-00024,·SRG-OS-000054-GPOS-00025,·SRG-OS-000122-GPOS-00063,·SRG-OS-000254-GPOS-00095,·SRG-OS-000255-GPOS-00096,·SRG-OS-000337-GPOS-00129,·SRG-OS-000348-GPOS-00136,·SRG-OS-000349-GPOS-00137,·SRG-OS-000350-GPOS-00138,·SRG-OS-000351-GPOS-00139,·SRG-OS-000352-GPOS-00140,·SRG-OS-000353-GPOS-00141,·SRG-OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,·SRG-OS-000365-GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-00220,·SRG-OS-000037-VMM-000150,·SRG-OS-000063-VMM-000310,·SRG-OS-000038-VMM-000160,·SRG-OS-000039-VMM-000170,·SRG-OS-000040-VMM-000180,·SRG-OS-000041-VMM-00019014772 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·3.3.2,·3.3.6,·CCI-000126,·CCI-000130,·CCI-000131,·CCI-000132,·CCI-000133,·CCI-000134,·CCI-000135,·CCI-000154,·CCI-000158,·CCI-000172,·CCI-000366,·CCI-001464,·CCI-001487,·CCI-001814,·CCI-001875,·CCI-001876,·CCI-001877,·CCI-002884,·CCI-001878,·CCI-001879,·CCI-001880,·CCI-001881,·CCI-001882,·CCI-001889,·CCI-001914,·CCI-000169,·164.308(a)(1)(ii)(D),·164.308(a)(5)(ii)(C),·164.310(a)(2)(iv),·164.310(d)(2)(iii),·164.312(b),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·CIP-004-6_R3.3,·CIP-007-3_R6.5,·AC-2(g),·AU-3,·AU-10,·AU-2(d),·AU-12(c),·AU-14(1),·AC-6(9),·CM-6(a),·SI-4(23),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1,·Req-10.1,·SRG-OS-000062-GPOS-00031,·SRG-OS-000037-GPOS-00015,·SRG-OS-000038-GPOS-00016,·SRG-OS-000039-GPOS-00017,·SRG-OS-000040-GPOS-00018,·SRG-OS-000041-GPOS-00019,·SRG-OS-000042-GPOS-00021,·SRG-OS-000051-GPOS-00024,·SRG-OS-000054-GPOS-00025,·SRG-OS-000122-GPOS-00063,·SRG-OS-000254-GPOS-00095,·SRG-OS-000255-GPOS-00096,·SRG-OS-000337-GPOS-00129,·SRG-OS-000348-GPOS-00136,·SRG-OS-000349-GPOS-00137,·SRG-OS-000350-GPOS-00138,·SRG-OS-000351-GPOS-00139,·SRG-OS-000352-GPOS-00140,·SRG-OS-000353-GPOS-00141,·SRG-OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,·SRG-OS-000365-GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-00220,·SRG-OS-000037-VMM-000150,·SRG-OS-000063-VMM-000310,·SRG-OS-000038-VMM-000160,·SRG-OS-000039-VMM-000170,·SRG-OS-000040-VMM-000180,·SRG-OS-000041-VMM-000190
14773 Remediation_Kubernetes_snippet_⇲ 
14774 --- 
14775 apiVersion:·machineconfiguration.openshift.io/v1 
14776 kind:·MachineConfig 
14777 spec: 
14778 ··config: 
14779 ····ignition: 
14780 ······version:·3.1.0 
14781 ····systemd: 
14782 ······units: 
14783 ······-·name:·auditd.service 
14784 ········enabled:·true 
14785 Remediation_OSBuild_Blueprint_snippet_⇲14773 Remediation_OSBuild_Blueprint_snippet_⇲
  
14786 [customizations.services]14774 [customizations.services]
14787 enabled·=·["auditd"]14775 enabled·=·["auditd"]
14788 Remediation_Puppet_snippet_⇲14776 Remediation_Puppet_snippet_⇲
14789 Complexity:·low14777 Complexity:·low
14790 Disruption:·low14778 Disruption:·low
Offset 14794, 14 lines modifiedOffset 14782, 26 lines modified
  
14794 class·enable_auditd·{14782 class·enable_auditd·{
14795 ··service·{'auditd':14783 ··service·{'auditd':
14796 ····enable·=>·true,14784 ····enable·=>·true,
14797 ····ensure·=>·'running',14785 ····ensure·=>·'running',
14798 ··}14786 ··}
14799 }14787 }
 14788 Remediation_Kubernetes_snippet_⇲
 14789 ---
 14790 apiVersion:·machineconfiguration.openshift.io/v1
 14791 kind:·MachineConfig
 14792 spec:
 14793 ··config:
 14794 ····ignition:
 14795 ······version:·3.1.0
 14796 ····systemd:
 14797 ······units:
 14798 ······-·name:·auditd.service
 14799 ········enabled:·true
14800 Remediation_Shell_script_⇲14800 Remediation_Shell_script_⇲
14801 Complexity:·low14801 Complexity:·low
14802 Disruption:·low14802 Disruption:·low
14803 Strategy:···enable14803 Strategy:···enable
14804 #·Remediation·is·applicable·only·in·certain·platforms14804 #·Remediation·is·applicable·only·in·certain·platforms
14805 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·audit;·};·then14805 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·audit;·};·then
  
Offset 14893, 20 lines modifiedOffset 14893, 14 lines modified
14893 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rsyslog_installed14893 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rsyslog_installed
14894 Identifiers·and·References·References: ·BP28(R5),·NT28(R46),·1,·14,·15,·16,·3,·5,·6,·APO11.04,·BAI03.05,·DSS05.04,·DSS05.07,·MEA02.01,·CCI-001311,·CCI-001312,·CCI-000366,·164.312(a)(2)(ii),·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-0022714894 Identifiers·and·References·References: ·BP28(R5),·NT28(R46),·1,·14,·15,·16,·3,·5,·6,·APO11.04,·BAI03.05,·DSS05.04,·DSS05.07,·MEA02.01,·CCI-001311,·CCI-001312,·CCI-000366,·164.312(a)(2)(ii),·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
14895 Remediation_OSBuild_Blueprint_snippet_⇲14895 Remediation_OSBuild_Blueprint_snippet_⇲
  
14896 [[packages]]14896 [[packages]]
14897 name·=·"rsyslog"14897 name·=·"rsyslog"
14898 version·=·"*"14898 version·=·"*"
14899 Remediation_Anaconda_snippet_⇲ 
14900 Complexity:·low 
14901 Disruption:·low 
14902 Strategy:···enable 
  
14903 package·--add=rsyslog 
14904 Remediation_Puppet_snippet_⇲14899 Remediation_Puppet_snippet_⇲
14905 Complexity:·low14900 Complexity:·low
14906 Disruption:·low14901 Disruption:·low
14907 Strategy:···enable14902 Strategy:···enable
14908 include·install_rsyslog14903 include·install_rsyslog
  
14909 class·install_rsyslog·{14904 class·install_rsyslog·{
Offset 14924, 14 lines modifiedOffset 14918, 20 lines modified
14924 if·!·rpm·-q·--quiet·"rsyslog"·;·then14918 if·!·rpm·-q·--quiet·"rsyslog"·;·then
14925 ····yum·install·-y·"rsyslog"14919 ····yum·install·-y·"rsyslog"
14926 fi14920 fi
  
14927 else14921 else
14928 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'14922 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
14929 fi14923 fi
 14924 Remediation_Anaconda_snippet_⇲
 14925 Complexity:·low
 14926 Disruption:·low
Max diff block lines reached; 16331/22415 bytes (72.86%) of diff not shown.
139 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-hipaa.html
    
Offset 187743, 92 lines modifiedOffset 187743, 92 lines modified
002dd5e0:·6172·6765·743d·2223·6964·6d31·3533·3133··arget="#idm15313002dd5e0:·6172·6765·743d·2223·6964·6d31·3533·3133··arget="#idm15313
002dd5f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r002dd5f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
002dd600:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari002dd600:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
002dd610:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals002dd610:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
002dd620:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa002dd620:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
002dd630:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr002dd630:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
002dd640:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat002dd640:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 002dd650:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue
 002dd660:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·..
 002dd670:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 002dd680:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 002dd690:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 002dd6a0:·3d22·6964·6d31·3533·3133·223e·3c70·7265··="idm15313"><pre
 002dd6b0:·3e3c·636f·6465·3e0a·5b63·7573·746f·6d69··><code>.[customi
 002dd6c0:·7a61·7469·6f6e·732e·7365·7276·6963·6573··zations.services
 002dd6d0:·5d0a·656e·6162·6c65·6420·3d20·5b22·6175··].enabled·=·["au
 002dd6e0:·6469·7464·225d·0a3c·2f63·6f64·653e·3c2f··ditd"].</code></
002dd650:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s 
002dd660:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
002dd670:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
002dd680:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
002dd690:·6c61·7073·6522·2069·643d·2269·646d·3135··lapse"·id="idm15 
002dd6a0:·3331·3322·3e3c·7072·653e·3c63·6f64·653e··313"><pre><code> 
002dd6b0:·2d2d·2d0a·6170·6956·6572·7369·6f6e·3a20··---.apiVersion:· 
002dd6c0:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura 
002dd6d0:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i 
002dd6e0:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi 
002dd6f0:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.· 
002dd700:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign 
002dd710:·6974·696f·6e3a·0a20·2020·2020·2076·6572··ition:.······ver 
002dd720:·7369·6f6e·3a20·332e·312e·300a·2020·2020··sion:·3.1.0.···· 
002dd730:·7379·7374·656d·643a·0a20·2020·2020·2075··systemd:.······u 
002dd740:·6e69·7473·3a0a·2020·2020·2020·2d20·6e61··nits:.······-·na 
002dd750:·6d65·3a20·6175·6469·7464·2e73·6572·7669··me:·auditd.servi 
002dd760:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl 
002dd770:·6564·3a20·7472·7565·0a3c·2f63·6f64·653e··ed:·true.</code> 
002dd780:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c002dd6f0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
002dd790:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su002dd700:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
002dd7a0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg002dd710:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
002dd7b0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da002dd720:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
002dd7c0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1002dd730:·2d74·6172·6765·743d·2223·6964·6d31·3533··-target="#idm153
002dd7d0:·3533·3134·2220·7461·6269·6e64·6578·3d22··5314"·tabindex="002dd740:·3134·2220·7461·6269·6e64·6578·3d22·3022··14"·tabindex="0"
002dd7e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"002dd750:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
002dd7f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="002dd760:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
002dd800:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac002dd770:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
002dd810:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal002dd780:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
002dd820:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme002dd790:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
002dd830:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild· 
002dd840:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
002dd850:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
002dd860:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
002dd870:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
002dd880:·2220·6964·3d22·6964·6d31·3533·3134·223e··"·id="idm15314"> 
002dd890:·3c70·7265·3e3c·636f·6465·3e0a·5b63·7573··<pre><code>.[cus 
002dd8a0:·746f·6d69·7a61·7469·6f6e·732e·7365·7276··tomizations.serv 
002dd8b0:·6963·6573·5d0a·656e·6162·6c65·6420·3d20··ices].enabled·=· 
002dd8c0:·5b22·6175·6469·7464·225d·0a3c·2f63·6f64··["auditd"].</cod 
002dd8d0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
002dd8e0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
002dd8f0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
002dd900:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
002dd910:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
002dd920:·6d31·3533·3135·2220·7461·6269·6e64·6578··m15315"·tabindex 
002dd930:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
002dd940:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
002dd950:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
002dd960:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
002dd970:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
002dd980:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet002dd7a0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
002dd990:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>002dd7b0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
002dd9a0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="002dd7c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
002dd9b0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c002dd7d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
002dd9c0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm002dd7e0:·7073·6522·2069·643d·2269·646d·3135·3331··pse"·id="idm1531
002dd9d0:·3135·3331·3522·3e3c·7461·626c·6520·636c··15315"><table·cl002dd7f0:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
002dd9e0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table002dd800:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
002dd9f0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b002dd810:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
002dda00:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co002dd820:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
002dda10:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th002dd830:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
002dda20:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th002dd840:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
002dda30:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t002dd850:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
002dda40:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup002dd860:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
002dda50:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo002dd870:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
002dda60:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><002dd880:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
002dda70:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th002dd890:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
002dda80:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>002dd8a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
002dda90:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr002dd8b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
002ddaa0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·002dd8c0:·6f64·653e·696e·636c·7564·6520·656e·6162··ode>include·enab
002ddab0:·656e·6162·6c65·5f61·7564·6974·640a·0a63··enable_auditd..c002dd8d0:·6c65·5f61·7564·6974·640a·0a63·6c61·7373··le_auditd..class
002ddac0:·6c61·7373·2065·6e61·626c·655f·6175·6469··lass·enable_audi002dd8e0:·2065·6e61·626c·655f·6175·6469·7464·207b···enable_auditd·{
002ddad0:·7464·207b·0a20·2073·6572·7669·6365·207b··td·{.··service·{002dd8f0:·0a20·2073·6572·7669·6365·207b·2761·7564··.··service·{'aud
002ddae0:·2761·7564·6974·6427·3a0a·2020·2020·656e··'auditd':.····en002dd900:·6974·6427·3a0a·2020·2020·656e·6162·6c65··itd':.····enable
002ddaf0:·6162·6c65·203d·2667·743b·2074·7275·652c··able·=&gt;·true,002dd910:·203d·2667·743b·2074·7275·652c·0a20·2020···=&gt;·true,.···
002ddb00:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt002dd920:·2065·6e73·7572·6520·3d26·6774·3b20·2772···ensure·=&gt;·'r
002ddb10:·3b20·2772·756e·6e69·6e67·272c·0a20·207d··;·'running',.··}002dd930:·756e·6e69·6e67·272c·0a20·207d·0a7d·0a3c··unning',.··}.}.<
 002dd940:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 002dd950:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 002dd960:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 002dd970:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 002dd980:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 002dd990:·2223·6964·6d31·3533·3135·2220·7461·6269··"#idm15315"·tabi
 002dd9a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 002dd9b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 002dd9c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 002dd9d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 002dd9e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 002dd9f0:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
 002dda00:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 002dda10:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 002dda20:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 002dda30:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 002dda40:·2069·643d·2269·646d·3135·3331·3522·3e3c···id="idm15315"><
 002dda50:·7072·653e·3c63·6f64·653e·2d2d·2d0a·6170··pre><code>---.ap
 002dda60:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin
 002dda70:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o
 002dda80:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k
 002dda90:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf
 002ddaa0:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi
 002ddab0:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:
 002ddac0:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·
 002ddad0:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system
 002ddae0:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:.
 002ddaf0:·2020·2020·2020·2d20·6e61·6d65·3a20·6175········-·name:·au
 002ddb00:·6469·7464·2e73·6572·7669·6365·0a20·2020··ditd.service.···
 002ddb10:·2020·2020·2065·6e61·626c·6564·3a20·7472·······enabled:·tr
002ddb20:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>002ddb20:·7565·0a3c·2f63·6f64·653e·3c2f·7072·653e··ue.</code></pre>
002ddb30:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="002ddb30:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
002ddb40:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"002ddb40:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
Max diff block lines reached; 113094/124576 bytes (90.78%) of diff not shown.
17.0 KB
html2text {}
    
Offset 43813, 26 lines modifiedOffset 43813, 14 lines modified
43813 $·sudo·systemctl·enable·auditd.service43813 $·sudo·systemctl·enable·auditd.service
43814 ···························Without·establishing·what·type·of·events·occurred,·it·would·be·difficult·to·establish,·correlate,·and·investigate·the·events·leading·up·to·an·outage·or·attack.·Ensuring·the·auditd·service·is·active·ensures·audit·records·generated·by·the·kernel·are·appropriately·recorded.43814 ···························Without·establishing·what·type·of·events·occurred,·it·would·be·difficult·to·establish,·correlate,·and·investigate·the·events·leading·up·to·an·outage·or·attack.·Ensuring·the·auditd·service·is·active·ensures·audit·records·generated·by·the·kernel·are·appropriately·recorded.
43815 Rationale:43815 Rationale:
43816 ···························Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of·individual·system·users·can·be·uniquely·traced·to·those·users·so·they·can·be·held·accountable·for·their·actions.43816 ···························Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of·individual·system·users·can·be·uniquely·traced·to·those·users·so·they·can·be·held·accountable·for·their·actions.
43817 Severity: ················medium43817 Severity: ················medium
43818 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_auditd_enabled43818 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_auditd_enabled
43819 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·3.3.2,·3.3.6,·CCI-000126,·CCI-000130,·CCI-000131,·CCI-000132,·CCI-000133,·CCI-000134,·CCI-000135,·CCI-000154,·CCI-000158,·CCI-000172,·CCI-000366,·CCI-001464,·CCI-001487,·CCI-001814,·CCI-001875,·CCI-001876,·CCI-001877,·CCI-002884,·CCI-001878,·CCI-001879,·CCI-001880,·CCI-001881,·CCI-001882,·CCI-001889,·CCI-001914,·CCI-000169,·164.308(a)(1)(ii)(D),·164.308(a)(5)(ii)(C),·164.310(a)(2)(iv),·164.310(d)(2)(iii),·164.312(b),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·CIP-004-6_R3.3,·CIP-007-3_R6.5,·AC-2(g),·AU-3,·AU-10,·AU-2(d),·AU-12(c),·AU-14(1),·AC-6(9),·CM-6(a),·SI-4(23),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1,·Req-10.1,·SRG-OS-000062-GPOS-00031,·SRG-OS-000037-GPOS-00015,·SRG-OS-000038-GPOS-00016,·SRG-OS-000039-GPOS-00017,·SRG-OS-000040-GPOS-00018,·SRG-OS-000041-GPOS-00019,·SRG-OS-000042-GPOS-00021,·SRG-OS-000051-GPOS-00024,·SRG-OS-000054-GPOS-00025,·SRG-OS-000122-GPOS-00063,·SRG-OS-000254-GPOS-00095,·SRG-OS-000255-GPOS-00096,·SRG-OS-000337-GPOS-00129,·SRG-OS-000348-GPOS-00136,·SRG-OS-000349-GPOS-00137,·SRG-OS-000350-GPOS-00138,·SRG-OS-000351-GPOS-00139,·SRG-OS-000352-GPOS-00140,·SRG-OS-000353-GPOS-00141,·SRG-OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,·SRG-OS-000365-GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-00220,·SRG-OS-000037-VMM-000150,·SRG-OS-000063-VMM-000310,·SRG-OS-000038-VMM-000160,·SRG-OS-000039-VMM-000170,·SRG-OS-000040-VMM-000180,·SRG-OS-000041-VMM-00019043819 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·3.3.2,·3.3.6,·CCI-000126,·CCI-000130,·CCI-000131,·CCI-000132,·CCI-000133,·CCI-000134,·CCI-000135,·CCI-000154,·CCI-000158,·CCI-000172,·CCI-000366,·CCI-001464,·CCI-001487,·CCI-001814,·CCI-001875,·CCI-001876,·CCI-001877,·CCI-002884,·CCI-001878,·CCI-001879,·CCI-001880,·CCI-001881,·CCI-001882,·CCI-001889,·CCI-001914,·CCI-000169,·164.308(a)(1)(ii)(D),·164.308(a)(5)(ii)(C),·164.310(a)(2)(iv),·164.310(d)(2)(iii),·164.312(b),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·CIP-004-6_R3.3,·CIP-007-3_R6.5,·AC-2(g),·AU-3,·AU-10,·AU-2(d),·AU-12(c),·AU-14(1),·AC-6(9),·CM-6(a),·SI-4(23),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1,·Req-10.1,·SRG-OS-000062-GPOS-00031,·SRG-OS-000037-GPOS-00015,·SRG-OS-000038-GPOS-00016,·SRG-OS-000039-GPOS-00017,·SRG-OS-000040-GPOS-00018,·SRG-OS-000041-GPOS-00019,·SRG-OS-000042-GPOS-00021,·SRG-OS-000051-GPOS-00024,·SRG-OS-000054-GPOS-00025,·SRG-OS-000122-GPOS-00063,·SRG-OS-000254-GPOS-00095,·SRG-OS-000255-GPOS-00096,·SRG-OS-000337-GPOS-00129,·SRG-OS-000348-GPOS-00136,·SRG-OS-000349-GPOS-00137,·SRG-OS-000350-GPOS-00138,·SRG-OS-000351-GPOS-00139,·SRG-OS-000352-GPOS-00140,·SRG-OS-000353-GPOS-00141,·SRG-OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,·SRG-OS-000365-GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-00220,·SRG-OS-000037-VMM-000150,·SRG-OS-000063-VMM-000310,·SRG-OS-000038-VMM-000160,·SRG-OS-000039-VMM-000170,·SRG-OS-000040-VMM-000180,·SRG-OS-000041-VMM-000190
43820 Remediation_Kubernetes_snippet_⇲ 
43821 --- 
43822 apiVersion:·machineconfiguration.openshift.io/v1 
43823 kind:·MachineConfig 
43824 spec: 
43825 ··config: 
43826 ····ignition: 
43827 ······version:·3.1.0 
43828 ····systemd: 
43829 ······units: 
43830 ······-·name:·auditd.service 
43831 ········enabled:·true 
43832 Remediation_OSBuild_Blueprint_snippet_⇲43820 Remediation_OSBuild_Blueprint_snippet_⇲
  
43833 [customizations.services]43821 [customizations.services]
43834 enabled·=·["auditd"]43822 enabled·=·["auditd"]
43835 Remediation_Puppet_snippet_⇲43823 Remediation_Puppet_snippet_⇲
43836 Complexity:·low43824 Complexity:·low
43837 Disruption:·low43825 Disruption:·low
Offset 43841, 14 lines modifiedOffset 43829, 26 lines modified
  
43841 class·enable_auditd·{43829 class·enable_auditd·{
43842 ··service·{'auditd':43830 ··service·{'auditd':
43843 ····enable·=>·true,43831 ····enable·=>·true,
43844 ····ensure·=>·'running',43832 ····ensure·=>·'running',
43845 ··}43833 ··}
43846 }43834 }
 43835 Remediation_Kubernetes_snippet_⇲
 43836 ---
 43837 apiVersion:·machineconfiguration.openshift.io/v1
 43838 kind:·MachineConfig
 43839 spec:
 43840 ··config:
 43841 ····ignition:
 43842 ······version:·3.1.0
 43843 ····systemd:
 43844 ······units:
 43845 ······-·name:·auditd.service
 43846 ········enabled:·true
43847 Remediation_Shell_script_⇲43847 Remediation_Shell_script_⇲
43848 Complexity:·low43848 Complexity:·low
43849 Disruption:·low43849 Disruption:·low
43850 Strategy:···enable43850 Strategy:···enable
43851 #·Remediation·is·applicable·only·in·certain·platforms43851 #·Remediation·is·applicable·only·in·certain·platforms
43852 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·audit;·};·then43852 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·audit;·};·then
  
Offset 45563, 17 lines modifiedOffset 45563, 14 lines modified
45563 Severity: ················medium45563 Severity: ················medium
45564 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_kdump_disabled45564 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_kdump_disabled
45565 Identifiers·and·References·References: ·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·CCI-000366,·CCI-001665,·164.308(a)(1)(ii)(D),·164.308(a)(3),·164.308(a)(4),·164.310(b),·164.310(c),·164.312(a),·164.312(e),·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4,·FMT_SMF_EXT.1.1,·SRG-OS-000269-GPOS-00103,·SRG-OS-000480-GPOS-0022745565 Identifiers·and·References·References: ·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·CCI-000366,·CCI-001665,·164.308(a)(1)(ii)(D),·164.308(a)(3),·164.308(a)(4),·164.310(b),·164.310(c),·164.312(a),·164.312(e),·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4,·FMT_SMF_EXT.1.1,·SRG-OS-000269-GPOS-00103,·SRG-OS-000480-GPOS-00227
45566 Remediation_OSBuild_Blueprint_snippet_⇲45566 Remediation_OSBuild_Blueprint_snippet_⇲
  
45567 [customizations.services]45567 [customizations.services]
45568 disabled·=·["kdump"]45568 disabled·=·["kdump"]
45569 Remediation_Anaconda_snippet_⇲ 
  
45570 kdump·--disable 
45571 Remediation_Puppet_snippet_⇲45569 Remediation_Puppet_snippet_⇲
45572 Complexity:·low45570 Complexity:·low
45573 Disruption:·low45571 Disruption:·low
45574 Strategy:···enable45572 Strategy:···enable
45575 include·disable_kdump45573 include·disable_kdump
  
45576 class·disable_kdump·{45574 class·disable_kdump·{
Offset 45602, 14 lines modifiedOffset 45599, 17 lines modified
45602 #·so·let's·reset·the·state·so·OVAL·checks·pass.45599 #·so·let's·reset·the·state·so·OVAL·checks·pass.
45603 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.45600 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
45604 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true45601 "$SYSTEMCTL_EXEC"·reset-failed·'kdump.service'·||·true
  
45605 else45602 else
45606 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'45603 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
45607 fi45604 fi
 45605 Remediation_Anaconda_snippet_⇲
  
 45606 kdump·--disable
45608 Remediation_Ansible_snippet_⇲45607 Remediation_Ansible_snippet_⇲
45609 Complexity:·low45608 Complexity:·low
45610 Disruption:·low45609 Disruption:·low
45611 Strategy:···disable45610 Strategy:···disable
45612 -·name:·Disable·service·kdump45611 -·name:·Disable·service·kdump
45613 ··block:45612 ··block:
  
Offset 45818, 20 lines modifiedOffset 45818, 14 lines modified
45818 ***·Rule  ·Uninstall·xinetd·Package·  [ref]·***45818 ***·Rule  ·Uninstall·xinetd·Package·  [ref]·***
45819 The·xinetd·package·can·be·removed·with·the·following·command:45819 The·xinetd·package·can·be·removed·with·the·following·command:
45820 $·sudo·yum·erase·xinetd45820 $·sudo·yum·erase·xinetd
45821 Rationale:·················Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's·accidental·(or·intentional)·activation.45821 Rationale:·················Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's·accidental·(or·intentional)·activation.
45822 Severity: ················low45822 Severity: ················low
45823 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_xinetd_removed45823 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_xinetd_removed
45824 Identifiers·and·References·References: ·BP28(R1),·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·CCI-000305,·164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.310(b),·164.312(e)(1),·164.312(e)(2)(ii),·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-445824 Identifiers·and·References·References: ·BP28(R1),·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·CCI-000305,·164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.310(b),·164.312(e)(1),·164.312(e)(2)(ii),·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
45825 Remediation_Anaconda_snippet_⇲ 
45826 Complexity:·low 
45827 Disruption:·low 
45828 Strategy:···disable 
  
45829 package·--remove=xinetd 
45830 Remediation_Puppet_snippet_⇲45825 Remediation_Puppet_snippet_⇲
45831 Complexity:·low45826 Complexity:·low
45832 Disruption:·low45827 Disruption:·low
45833 Strategy:···disable45828 Strategy:···disable
45834 include·remove_xinetd45829 include·remove_xinetd
  
45835 class·remove_xinetd·{45830 class·remove_xinetd·{
Offset 45857, 14 lines modifiedOffset 45851, 20 lines modified
45857 ····yum·remove·-y·"xinetd"45851 ····yum·remove·-y·"xinetd"
  
45858 fi45852 fi
  
45859 else45853 else
45860 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'45854 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
45861 fi45855 fi
 45856 Remediation_Anaconda_snippet_⇲
 45857 Complexity:·low
 45858 Disruption:·low
 45859 Strategy:···disable
  
 45860 package·--remove=xinetd
45862 Remediation_Ansible_snippet_⇲45861 Remediation_Ansible_snippet_⇲
45863 Complexity:·low45862 Complexity:·low
45864 Disruption:·low45863 Disruption:·low
Max diff block lines reached; 9468/17338 bytes (54.61%) of diff not shown.
828 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ospp.html
    
Offset 15240, 116 lines modifiedOffset 15240, 116 lines modified
0003b870:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm50003b870:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
0003b880:·3430·3322·2074·6162·696e·6465·783d·2230··403"·tabindex="00003b880:·3430·3322·2074·6162·696e·6465·783d·2230··403"·tabindex="0
0003b890:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b890:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b8a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b8a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b8b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b8b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b8c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b8c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b8d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b8d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b8e0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003b8e0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003b8f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003b8f0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003b900:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b900:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b910:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b910:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b920:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm50003b920:·6170·7365·2220·6964·3d22·6964·6d35·3430··apse"·id="idm540
0003b930:·3430·3322·3e3c·7461·626c·6520·636c·6173··403"><table·clas0003b930:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
0003b940:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b940:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003b950:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b950:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003b960:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b960:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003b970:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b970:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003b980:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b980:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003b990:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b990:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b9a0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003b9a0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003b9b0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003b9b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b9c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b9c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b9d0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b9d0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b9e0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b9e0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003b9f0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b9f0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003ba00:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003ba10:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003ba00:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003ba10:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003ba20:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003ba30:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003ba40:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003ba50:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003ba60:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003ba70:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003ba80:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003ba90:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003baa0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003bab0:·2d74·6172·6765·743d·2223·6964·6d35·3430··-target="#idm540
 0003bac0:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·
 0003bad0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003bae0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003baf0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003bb00:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003bb10:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003bb20:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003bb30:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003bb40:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003bb50:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003bb60:·2220·6964·3d22·6964·6d35·3430·3422·3e3c··"·id="idm5404"><
 0003bb70:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003bb80:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003bb90:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003bba0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003bbb0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003bbc0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003bbd0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bbe0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003bbf0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bc00:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bc10:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003bc20:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003bc30:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bc40:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003bc50:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003bc60:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003bc70:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003bc80:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003bc90:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003bca0:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003bcb0:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003bcc0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003bcd0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003bce0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 0003bcf0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003bd00:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003bd10:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003bd20:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003bd30:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003bd40:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003ba20:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003bd50:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003ba30:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003bd60:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003ba40:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003bd70:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003ba50:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003bd80:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003ba60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003bd90:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003ba70:·3534·3034·2220·7461·6269·6e64·6578·3d22··5404"·tabindex="0003bda0:·3534·3035·2220·7461·6269·6e64·6578·3d22··5405"·tabindex="
0003ba80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003bdb0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003ba90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003bdc0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003baa0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003bdd0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003bab0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003bde0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003bac0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003bdf0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003bad0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003be00:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003bae0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003be10:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003baf0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003be20:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003bb00:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003be30:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003bb10:·6c61·7073·6522·2069·643d·2269·646d·3534··lapse"·id="idm540003be40:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003bb20:·3034·223e·3c74·6162·6c65·2063·6c61·7373··04"><table·class0003be50:·3534·3035·223e·3c74·6162·6c65·2063·6c61··5405"><table·cla
0003bb30:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003be60:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003bb40:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003be70:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003bb50:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003be80:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003bb60:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003be90:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003bb70:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003bea0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003bb80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003beb0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003bb90:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003bec0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003bba0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003bed0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003bbb0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bee0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003bbc0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003bef0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003bbd0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003bf00:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003bbe0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003bf10:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003bf20:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003bf30:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003bbf0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003bc00:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003bc10:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003bc20:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003bc30:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003bc40:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003bc50:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003bc60:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003bc70:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003bc80:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003bc90:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003bca0:·612d·7461·7267·6574·3d22·2369·646d·3534··a-target="#idm54 
0003bcb0:·3035·2220·7461·6269·6e64·6578·3d22·3022··05"·tabindex="0" 
0003bcc0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003bcd0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003bce0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003bcf0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 763264/777920 bytes (98.12%) of diff not shown.
68.5 KB
html2text {}
    
Offset 87, 20 lines modifiedOffset 87, 14 lines modified
87 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed87 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
88 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019988 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
89 Remediation_OSBuild_Blueprint_snippet_⇲89 Remediation_OSBuild_Blueprint_snippet_⇲
  
90 [[packages]]90 [[packages]]
91 name·=·"aide"91 name·=·"aide"
92 version·=·"*"92 version·=·"*"
93 Remediation_Anaconda_snippet_⇲ 
94 Complexity:·low 
95 Disruption:·low 
96 Strategy:···enable 
  
97 package·--add=aide 
98 Remediation_Puppet_snippet_⇲93 Remediation_Puppet_snippet_⇲
99 Complexity:·low94 Complexity:·low
100 Disruption:·low95 Disruption:·low
101 Strategy:···enable96 Strategy:···enable
102 include·install_aide97 include·install_aide
  
103 class·install_aide·{98 class·install_aide·{
Offset 118, 14 lines modifiedOffset 112, 20 lines modified
118 if·!·rpm·-q·--quiet·"aide"·;·then112 if·!·rpm·-q·--quiet·"aide"·;·then
119 ····yum·install·-y·"aide"113 ····yum·install·-y·"aide"
120 fi114 fi
  
121 else115 else
122 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'116 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
123 fi117 fi
 118 Remediation_Anaconda_snippet_⇲
 119 Complexity:·low
 120 Disruption:·low
 121 Strategy:···enable
  
 122 package·--add=aide
124 Remediation_Ansible_snippet_⇲123 Remediation_Ansible_snippet_⇲
125 Complexity:·low124 Complexity:·low
126 Disruption:·low125 Disruption:·low
127 Strategy:···enable126 Strategy:···enable
128 -·name:·Ensure·aide·is·installed127 -·name:·Ensure·aide·is·installed
129 ··package:128 ··package:
130 ····name:·aide129 ····name:·aide
Offset 292, 20 lines modifiedOffset 292, 14 lines modified
292 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed292 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
293 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174293 Identifiers·and·References·References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
294 Remediation_OSBuild_Blueprint_snippet_⇲294 Remediation_OSBuild_Blueprint_snippet_⇲
  
295 [[packages]]295 [[packages]]
296 name·=·"crypto-policies"296 name·=·"crypto-policies"
297 version·=·"*"297 version·=·"*"
298 Remediation_Anaconda_snippet_⇲ 
299 Complexity:·low 
300 Disruption:·low 
301 Strategy:···enable 
  
302 package·--add=crypto-policies 
303 Remediation_Puppet_snippet_⇲298 Remediation_Puppet_snippet_⇲
304 Complexity:·low299 Complexity:·low
305 Disruption:·low300 Disruption:·low
306 Strategy:···enable301 Strategy:···enable
307 include·install_crypto-policies302 include·install_crypto-policies
  
308 class·install_crypto-policies·{303 class·install_crypto-policies·{
Offset 317, 14 lines modifiedOffset 311, 20 lines modified
317 Complexity:·low311 Complexity:·low
318 Disruption:·low312 Disruption:·low
319 Strategy:···enable313 Strategy:···enable
  
320 if·!·rpm·-q·--quiet·"crypto-policies"·;·then314 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
321 ····yum·install·-y·"crypto-policies"315 ····yum·install·-y·"crypto-policies"
322 fi316 fi
 317 Remediation_Anaconda_snippet_⇲
 318 Complexity:·low
 319 Disruption:·low
 320 Strategy:···enable
  
 321 package·--add=crypto-policies
323 Remediation_Ansible_snippet_⇲322 Remediation_Ansible_snippet_⇲
324 Complexity:·low323 Complexity:·low
325 Disruption:·low324 Disruption:·low
326 Strategy:···enable325 Strategy:···enable
327 -·name:·Ensure·crypto-policies·is·installed326 -·name:·Ensure·crypto-policies·is·installed
328 ··package:327 ··package:
329 ····name:·crypto-policies328 ····name:·crypto-policies
Offset 726, 20 lines modifiedOffset 726, 14 lines modified
726 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed726 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_sudo_installed
727 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125727 Identifiers·and·References·References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
728 Remediation_OSBuild_Blueprint_snippet_⇲728 Remediation_OSBuild_Blueprint_snippet_⇲
  
729 [[packages]]729 [[packages]]
730 name·=·"sudo"730 name·=·"sudo"
731 version·=·"*"731 version·=·"*"
732 Remediation_Anaconda_snippet_⇲ 
733 Complexity:·low 
734 Disruption:·low 
735 Strategy:···enable 
  
736 package·--add=sudo 
737 Remediation_Puppet_snippet_⇲732 Remediation_Puppet_snippet_⇲
738 Complexity:·low733 Complexity:·low
739 Disruption:·low734 Disruption:·low
740 Strategy:···enable735 Strategy:···enable
741 include·install_sudo736 include·install_sudo
  
742 class·install_sudo·{737 class·install_sudo·{
Offset 757, 14 lines modifiedOffset 751, 20 lines modified
757 if·!·rpm·-q·--quiet·"sudo"·;·then751 if·!·rpm·-q·--quiet·"sudo"·;·then
758 ····yum·install·-y·"sudo"752 ····yum·install·-y·"sudo"
759 fi753 fi
  
760 else754 else
761 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'755 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
762 fi756 fi
 757 Remediation_Anaconda_snippet_⇲
 758 Complexity:·low
 759 Disruption:·low
 760 Strategy:···enable
  
 761 package·--add=sudo
763 Remediation_Ansible_snippet_⇲762 Remediation_Ansible_snippet_⇲
764 Complexity:·low763 Complexity:·low
765 Disruption:·low764 Disruption:·low
766 Strategy:···enable765 Strategy:···enable
767 -·name:·Ensure·sudo·is·installed766 -·name:·Ensure·sudo·is·installed
768 ··package:767 ··package:
769 ····name:·sudo768 ····name:·sudo
Offset 789, 20 lines modifiedOffset 789, 14 lines modified
789 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed789 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed
Max diff block lines reached; 66177/70084 bytes (94.43%) of diff not shown.
94.7 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-pci-dss.html
    
Offset 17029, 117 lines modifiedOffset 17029, 117 lines modified
00042840:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00042840:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00042850:·743d·2223·6964·6d35·3430·3322·2074·6162··t="#idm5403"·tab00042850:·743d·2223·6964·6d35·3430·3322·2074·6162··t="#idm5403"·tab
00042860:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00042860:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00042870:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00042870:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00042880:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00042880:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00042890:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00042890:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
000428a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#000428a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
000428b0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A000428b0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
000428c0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·000428c0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
000428d0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·000428d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
000428e0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000428e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
000428f0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·000428f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
00042900:·6964·3d22·6964·6d35·3430·3322·3e3c·7461··id="idm5403"><ta00042900:·3d22·6964·6d35·3430·3322·3e3c·7461·626c··="idm5403"><tabl
00042910:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table00042910:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
00042920:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t00042920:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
00042930:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta00042930:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
00042940:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><00042940:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
00042950:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit00042950:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00042960:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</00042960:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00042970:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00042970:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
00042980:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>00042980:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
00042990:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr00042990:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
000429a0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg000429a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
000429b0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl000429b0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
000429c0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab000429c0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
000429d0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p000429d0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
000429e0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid000429e0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 000429f0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 00042a00:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 00042a10:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 00042a20:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 00042a30:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 00042a40:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00042a50:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00042a60:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00042a70:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00042a80:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00042a90:·2223·6964·6d35·3430·3422·2074·6162·696e··"#idm5404"·tabin
 00042aa0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00042ab0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00042ac0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00042ad0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00042ae0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00042af0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 00042b00:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 00042b10:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00042b20:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00042b30:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00042b40:·6d35·3430·3422·3e3c·7461·626c·6520·636c··m5404"><table·cl
 00042b50:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00042b60:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00042b70:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00042b80:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00042b90:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00042ba0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00042bb0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00042bc0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00042bd0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00042be0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 00042bf0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 00042c00:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00042c10:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 00042c20:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 00042c30:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 00042c40:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 00042c50:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
 00042c60:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 00042c70:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
 00042c80:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th
 00042c90:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 00042ca0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 00042cb0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 00042cc0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 00042cd0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 00042ce0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 00042cf0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 00042d00:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 00042d10:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
000429f0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><00042d20:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
00042a00:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b00042d30:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
00042a10:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·00042d40:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
00042a20:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col00042d50:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
00042a30:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ00042d60:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
00042a40:·6574·3d22·2369·646d·3534·3034·2220·7461··et="#idm5404"·ta00042d70:·6574·3d22·2369·646d·3534·3035·2220·7461··et="#idm5405"·ta
00042a50:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00042d80:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00042a60:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00042d90:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00042a70:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00042da0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00042a80:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00042db0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00042a90:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00042dc0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00042aa0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00042dd0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00042ab0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.00042de0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
00042ac0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00042df0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00042ad0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00042e00:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00042ae0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00042e10:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00042af0:·643d·2269·646d·3534·3034·223e·3c74·6162··d="idm5404"><tab00042e20:·2069·643d·2269·646d·3534·3035·223e·3c74···id="idm5405"><t
00042b00:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00042e30:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
00042b10:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00042e40:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
00042b20:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00042e50:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
00042b30:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00042e60:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
00042b40:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00042e70:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00042b50:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00042e80:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
00042b60:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00042e90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00042b70:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00042ea0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
00042b80:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00042eb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00042b90:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy00042ec0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
00042ba0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable00042ed0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
00042bb0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl00042ee0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
00042bc0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc00042ef0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 00042f00:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
00042bd0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
00042be0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
00042bf0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
00042c00:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
00042c10:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
00042c20:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
00042c30:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
00042c40:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
00042c50:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00042c60:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00042c70:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00042c80:·3d22·2369·646d·3534·3035·2220·7461·6269··="#idm5405"·tabi 
00042c90:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00042ca0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00042cb0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00042cc0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00042cd0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00042ce0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
Max diff block lines reached; 72042/86836 bytes (82.96%) of diff not shown.
9.81 KB
html2text {}
    
Offset 377, 20 lines modifiedOffset 377, 14 lines modified
377 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed377 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
378 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199378 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
379 Remediation_OSBuild_Blueprint_snippet_⇲379 Remediation_OSBuild_Blueprint_snippet_⇲
  
380 [[packages]]380 [[packages]]
381 name·=·"aide"381 name·=·"aide"
382 version·=·"*"382 version·=·"*"
383 Remediation_Anaconda_snippet_⇲ 
384 Complexity:·low 
385 Disruption:·low 
386 Strategy:···enable 
  
387 package·--add=aide 
388 Remediation_Puppet_snippet_⇲383 Remediation_Puppet_snippet_⇲
389 Complexity:·low384 Complexity:·low
390 Disruption:·low385 Disruption:·low
391 Strategy:···enable386 Strategy:···enable
392 include·install_aide387 include·install_aide
  
393 class·install_aide·{388 class·install_aide·{
Offset 408, 14 lines modifiedOffset 402, 20 lines modified
408 if·!·rpm·-q·--quiet·"aide"·;·then402 if·!·rpm·-q·--quiet·"aide"·;·then
409 ····yum·install·-y·"aide"403 ····yum·install·-y·"aide"
410 fi404 fi
  
411 else405 else
412 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'406 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
413 fi407 fi
 408 Remediation_Anaconda_snippet_⇲
 409 Complexity:·low
 410 Disruption:·low
 411 Strategy:···enable
  
 412 package·--add=aide
414 Remediation_Ansible_snippet_⇲413 Remediation_Ansible_snippet_⇲
415 Complexity:·low414 Complexity:·low
416 Disruption:·low415 Disruption:·low
417 Strategy:···enable416 Strategy:···enable
418 -·name:·Ensure·aide·is·installed417 -·name:·Ensure·aide·is·installed
419 ··package:418 ··package:
420 ····name:·aide419 ····name:·aide
Offset 6186, 20 lines modifiedOffset 6186, 14 lines modified
6186 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed6186 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed
6187 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-0015206187 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520
6188 Remediation_OSBuild_Blueprint_snippet_⇲6188 Remediation_OSBuild_Blueprint_snippet_⇲
  
6189 [[packages]]6189 [[packages]]
6190 name·=·"opensc"6190 name·=·"opensc"
6191 version·=·"*"6191 version·=·"*"
6192 Remediation_Anaconda_snippet_⇲ 
6193 Complexity:·low 
6194 Disruption:·low 
6195 Strategy:···enable 
  
6196 package·--add=opensc 
6197 Remediation_Puppet_snippet_⇲6192 Remediation_Puppet_snippet_⇲
6198 Complexity:·low6193 Complexity:·low
6199 Disruption:·low6194 Disruption:·low
6200 Strategy:···enable6195 Strategy:···enable
6201 include·install_opensc6196 include·install_opensc
  
6202 class·install_opensc·{6197 class·install_opensc·{
Offset 6217, 14 lines modifiedOffset 6211, 20 lines modified
6217 if·!·rpm·-q·--quiet·"opensc"·;·then6211 if·!·rpm·-q·--quiet·"opensc"·;·then
6218 ····yum·install·-y·"opensc"6212 ····yum·install·-y·"opensc"
6219 fi6213 fi
  
6220 else6214 else
6221 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6215 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6222 fi6216 fi
 6217 Remediation_Anaconda_snippet_⇲
 6218 Complexity:·low
 6219 Disruption:·low
 6220 Strategy:···enable
  
 6221 package·--add=opensc
6223 Remediation_Ansible_snippet_⇲6222 Remediation_Ansible_snippet_⇲
6224 Complexity:·low6223 Complexity:·low
6225 Disruption:·low6224 Disruption:·low
6226 Strategy:···enable6225 Strategy:···enable
6227 -·name:·Ensure·opensc·is·installed6226 -·name:·Ensure·opensc·is·installed
6228 ··package:6227 ··package:
6229 ····name:·opensc6228 ····name:·opensc
Offset 6246, 20 lines modifiedOffset 6246, 14 lines modified
6246 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed6246 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
6247 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015306247 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
6248 Remediation_OSBuild_Blueprint_snippet_⇲6248 Remediation_OSBuild_Blueprint_snippet_⇲
  
6249 [[packages]]6249 [[packages]]
6250 name·=·"pcsc-lite"6250 name·=·"pcsc-lite"
6251 version·=·"*"6251 version·=·"*"
6252 Remediation_Anaconda_snippet_⇲ 
6253 Complexity:·low 
6254 Disruption:·low 
6255 Strategy:···enable 
  
6256 package·--add=pcsc-lite 
6257 Remediation_Puppet_snippet_⇲6252 Remediation_Puppet_snippet_⇲
6258 Complexity:·low6253 Complexity:·low
6259 Disruption:·low6254 Disruption:·low
6260 Strategy:···enable6255 Strategy:···enable
6261 include·install_pcsc-lite6256 include·install_pcsc-lite
  
6262 class·install_pcsc-lite·{6257 class·install_pcsc-lite·{
Offset 6277, 14 lines modifiedOffset 6271, 20 lines modified
6277 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then6271 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
6278 ····yum·install·-y·"pcsc-lite"6272 ····yum·install·-y·"pcsc-lite"
6279 fi6273 fi
  
6280 else6274 else
6281 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6275 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6282 fi6276 fi
 6277 Remediation_Anaconda_snippet_⇲
 6278 Complexity:·low
 6279 Disruption:·low
 6280 Strategy:···enable
  
 6281 package·--add=pcsc-lite
6283 Remediation_Ansible_snippet_⇲6282 Remediation_Ansible_snippet_⇲
6284 Complexity:·low6283 Complexity:·low
6285 Disruption:·low6284 Disruption:·low
6286 Strategy:···enable6285 Strategy:···enable
6287 -·name:·Ensure·pcsc-lite·is·installed6286 -·name:·Ensure·pcsc-lite·is·installed
6288 ··package:6287 ··package:
6289 ····name:·pcsc-lite6288 ····name:·pcsc-lite
Offset 40150, 20 lines modifiedOffset 40150, 14 lines modified
40150 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_audispd-plugins_installed40150 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_audispd-plugins_installed
Max diff block lines reached; 6175/10017 bytes (61.65%) of diff not shown.
16.4 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-standard.html
    
Offset 127563, 118 lines modifiedOffset 127563, 118 lines modified
001f24a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target001f24a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
001f24b0:·3d22·2369·646d·3331·3532·3922·2074·6162··="#idm31529"·tab001f24b0:·3d22·2369·646d·3331·3532·3922·2074·6162··="#idm31529"·tab
001f24c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="001f24c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
001f24d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp001f24d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
001f24e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti001f24e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
001f24f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to001f24f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
001f2500:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#001f2500:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
001f2510:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A001f2510:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
001f2520:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·001f2520:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
001f2530:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·001f2530:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
001f2540:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col001f2540:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
001f2550:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·001f2550:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
001f2560:·6964·3d22·6964·6d33·3135·3239·223e·3c74··id="idm31529"><t001f2560:·3d22·6964·6d33·3135·3239·223e·3c74·6162··="idm31529"><tab
001f2570:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl001f2570:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
001f2580:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·001f2580:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
001f2590:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t001f2590:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
001f25a0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">001f25a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
001f25b0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi001f25b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
001f25c0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<001f25c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
001f25d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th001f25d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
001f25e0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th001f25e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
001f25f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t001f25f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
001f2600:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate001f2600:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
001f2610:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab001f2610:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
001f2620:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta001f2620:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
001f2630:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.001f2630:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
001f2640:·7061·636b·6167·6520·2d2d·6164·643d·7273··package·--add=rs 
001f2650:·7973·6c6f·670a·3c2f·636f·6465·3e3c·2f70··yslog.</code></p001f2640:·6c75·6465·2069·6e73·7461·6c6c·5f72·7379··lude·install_rsy
 001f2650:·736c·6f67·0a0a·636c·6173·7320·696e·7374··slog..class·inst
 001f2660:·616c·6c5f·7273·7973·6c6f·6720·7b0a·2020··all_rsyslog·{.··
 001f2670:·7061·636b·6167·6520·7b20·2772·7379·736c··package·{·'rsysl
 001f2680:·6f67·273a·0a20·2020·2065·6e73·7572·6520··og':.····ensure·
 001f2690:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 001f26a0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 001f26b0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 001f26c0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 001f26d0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 001f26e0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 001f26f0:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3
 001f2700:·3135·3330·2220·7461·6269·6e64·6578·3d22··1530"·tabindex="
 001f2710:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 001f2720:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 001f2730:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 001f2740:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 001f2750:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 001f2760:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 001f2770:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 001f2780:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 001f2790:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 001f27a0:·7073·6522·2069·643d·2269·646d·3331·3533··pse"·id="idm3153
 001f27b0:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
 001f27c0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 001f27d0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 001f27e0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 001f27f0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 001f2800:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 001f2810:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 001f2820:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 001f2830:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 001f2840:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 001f2850:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 001f2860:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 001f2870:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 001f2880:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 001f2890:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 001f28a0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 001f28b0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
 001f28c0:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
 001f28d0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
 001f28e0:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 001f28f0:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
 001f2900:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 001f2910:·6965·7420·2272·7379·736c·6f67·2220·3b20··iet·"rsyslog"·;·
 001f2920:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 001f2930:·7461·6c6c·202d·7920·2272·7379·736c·6f67··tall·-y·"rsyslog
 001f2940:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 001f2950:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 001f2960:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 001f2970:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 001f2980:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 001f2990:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
001f2660:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas001f29a0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
001f2670:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe001f29b0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
001f2680:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=001f29c0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
001f2690:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-001f29d0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
001f26a0:·7461·7267·6574·3d22·2369·646d·3331·3533··target="#idm3153001f29e0:·7267·6574·3d22·2369·646d·3331·3533·3122··rget="#idm31531"
001f26b0:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·001f29f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
001f26c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar001f2a00:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
001f26d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal001f2a10:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
001f26e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ001f2a20:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
001f26f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h001f2a30:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
001f2700:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia001f2a40:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
001f2710:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip001f2a50:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
001f2720:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><001f2a60:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
001f2730:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel001f2a70:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
001f2740:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap001f2a80:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
001f2750:·7365·2220·6964·3d22·6964·6d33·3135·3330··se"·id="idm31530001f2a90:·7365·2220·6964·3d22·6964·6d33·3135·3331··se"·id="idm31531
001f2760:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="001f2aa0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
001f2770:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri001f2ab0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
001f2780:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border001f2ac0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
001f2790:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens001f2ad0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
001f27a0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp001f2ae0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
001f27b0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>001f2af0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
001f27c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr001f2b00:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
001f27d0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:001f2b10:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
001f27e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td001f2b20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
001f27f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St001f2b30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
001f2800:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>001f2b40:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
001f2810:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>001f2b50:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
001f2820:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co001f2b60:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 001f2b70:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
 001f2b80:·643d·7273·7973·6c6f·670a·3c2f·636f·6465··d=rsyslog.</code
001f2830:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
001f2840:·6c6c·5f72·7379·736c·6f67·0a0a·636c·6173··ll_rsyslog..clas 
001f2850:·7320·696e·7374·616c·6c5f·7273·7973·6c6f··s·install_rsyslo 
001f2860:·6720·7b0a·2020·7061·636b·6167·6520·7b20··g·{.··package·{· 
001f2870:·2772·7379·736c·6f67·273a·0a20·2020·2065··'rsyslog':.····e 
001f2880:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
001f2890:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
001f28a0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
001f28b0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
001f28c0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
001f28d0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
001f28e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
001f28f0:·2223·6964·6d33·3135·3331·2220·7461·6269··"#idm31531"·tabi 
001f2900:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
001f2910:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
Max diff block lines reached; 414/15348 bytes (2.70%) of diff not shown.
1.34 KB
html2text {}
    
Offset 28720, 20 lines modifiedOffset 28720, 14 lines modified
28720 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rsyslog_installed28720 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rsyslog_installed
28721 Identifiers·and·References·References: ·BP28(R5),·NT28(R46),·1,·14,·15,·16,·3,·5,·6,·APO11.04,·BAI03.05,·DSS05.04,·DSS05.07,·MEA02.01,·CCI-001311,·CCI-001312,·CCI-000366,·164.312(a)(2)(ii),·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-0022728721 Identifiers·and·References·References: ·BP28(R5),·NT28(R46),·1,·14,·15,·16,·3,·5,·6,·APO11.04,·BAI03.05,·DSS05.04,·DSS05.07,·MEA02.01,·CCI-001311,·CCI-001312,·CCI-000366,·164.312(a)(2)(ii),·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·CM-6(a),·PR.PT-1,·FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
28722 Remediation_OSBuild_Blueprint_snippet_⇲28722 Remediation_OSBuild_Blueprint_snippet_⇲
  
28723 [[packages]]28723 [[packages]]
28724 name·=·"rsyslog"28724 name·=·"rsyslog"
28725 version·=·"*"28725 version·=·"*"
28726 Remediation_Anaconda_snippet_⇲ 
28727 Complexity:·low 
28728 Disruption:·low 
28729 Strategy:···enable 
  
28730 package·--add=rsyslog 
28731 Remediation_Puppet_snippet_⇲28726 Remediation_Puppet_snippet_⇲
28732 Complexity:·low28727 Complexity:·low
28733 Disruption:·low28728 Disruption:·low
28734 Strategy:···enable28729 Strategy:···enable
28735 include·install_rsyslog28730 include·install_rsyslog
  
28736 class·install_rsyslog·{28731 class·install_rsyslog·{
Offset 28751, 14 lines modifiedOffset 28745, 20 lines modified
28751 if·!·rpm·-q·--quiet·"rsyslog"·;·then28745 if·!·rpm·-q·--quiet·"rsyslog"·;·then
28752 ····yum·install·-y·"rsyslog"28746 ····yum·install·-y·"rsyslog"
28753 fi28747 fi
  
28754 else28748 else
28755 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'28749 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
28756 fi28750 fi
 28751 Remediation_Anaconda_snippet_⇲
 28752 Complexity:·low
 28753 Disruption:·low
 28754 Strategy:···enable
  
 28755 package·--add=rsyslog
28757 Remediation_Ansible_snippet_⇲28756 Remediation_Ansible_snippet_⇲
28758 Complexity:·low28757 Complexity:·low
28759 Disruption:·low28758 Disruption:·low
28760 Strategy:···enable28759 Strategy:···enable
28761 -·name:·Ensure·rsyslog·is·installed28760 -·name:·Ensure·rsyslog·is·installed
28762 ··package:28761 ··package:
28763 ····name:·rsyslog28762 ····name:·rsyslog
737 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-stig.html
    
Offset 15252, 117 lines modifiedOffset 15252, 117 lines modified
0003b930:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b930:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b940:·743d·2223·6964·6d35·3430·3322·2074·6162··t="#idm5403"·tab0003b940:·743d·2223·6964·6d35·3430·3322·2074·6162··t="#idm5403"·tab
0003b950:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b950:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b960:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b960:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b970:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b970:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b980:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b980:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b990:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b990:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b9a0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003b9a0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003b9b0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003b9b0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0003b9c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b9c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b9d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b9d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b9e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b9e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b9f0:·6964·3d22·6964·6d35·3430·3322·3e3c·7461··id="idm5403"><ta0003b9f0:·3d22·6964·6d35·3430·3322·3e3c·7461·626c··="idm5403"><tabl
0003ba00:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003ba00:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003ba10:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003ba10:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003ba20:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003ba20:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003ba30:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003ba30:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003ba40:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003ba40:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003ba50:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003ba50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003ba60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003ba60:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003ba70:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003ba70:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003ba80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003ba80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003ba90:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003ba90:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003baa0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003baa0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003bab0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003bab0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003bac0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0003bac0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0003bad0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid0003bad0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003bae0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003baf0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003bb00:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003bb10:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003bb20:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003bb30:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003bb40:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003bb50:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003bb60:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003bb70:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003bb80:·2223·6964·6d35·3430·3422·2074·6162·696e··"#idm5404"·tabin
 0003bb90:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003bba0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003bbb0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003bbc0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003bbd0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003bbe0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003bbf0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003bc00:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003bc10:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003bc20:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003bc30:·6d35·3430·3422·3e3c·7461·626c·6520·636c··m5404"><table·cl
 0003bc40:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003bc50:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003bc60:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003bc70:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003bc80:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003bc90:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003bca0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003bcb0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003bcc0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003bcd0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003bce0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003bcf0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003bd00:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003bd10:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003bd20:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003bd30:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003bd40:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
 0003bd50:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 0003bd60:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
 0003bd70:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th
 0003bd80:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003bd90:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003bda0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003bdb0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003bdc0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003bdd0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003bde0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003bdf0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003be00:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
0003bae0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0003be10:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
0003baf0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003be20:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003bb00:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003be30:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003bb10:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003be40:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003bb20:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003be50:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003bb30:·6574·3d22·2369·646d·3534·3034·2220·7461··et="#idm5404"·ta0003be60:·6574·3d22·2369·646d·3534·3035·2220·7461··et="#idm5405"·ta
0003bb40:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003be70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003bb50:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003be80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003bb60:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003be90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003bb70:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003bea0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003bb80:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003beb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003bb90:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003bec0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003bba0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003bed0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003bbb0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003bee0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bbc0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003bef0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bbd0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003bf00:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bbe0:·643d·2269·646d·3534·3034·223e·3c74·6162··d="idm5404"><tab0003bf10:·2069·643d·2269·646d·3534·3035·223e·3c74···id="idm5405"><t
0003bbf0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003bf20:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bc00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003bf30:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bc10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bf40:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bc20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bf50:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bc30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003bf60:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bc40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bf70:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003bc50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003bf80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bc60:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003bf90:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003bc70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bfa0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bc80:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bfb0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bc90:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003bfc0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bca0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003bfd0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bcb0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003bfe0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003bff0:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
0003bcc0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003bcd0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003bce0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003bcf0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003bd00:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003bd10:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003bd20:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003bd30:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003bd40:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003bd50:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003bd60:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003bd70:·3d22·2369·646d·3534·3035·2220·7461·6269··="#idm5405"·tabi 
0003bd80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003bd90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003bda0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003bdb0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003bdc0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003bdd0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
Max diff block lines reached; 670036/684830 bytes (97.84%) of diff not shown.
68.5 KB
html2text {}
    
Offset 88, 20 lines modifiedOffset 88, 14 lines modified
88 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed88 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
89 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019989 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
90 Remediation_OSBuild_Blueprint_snippet_⇲90 Remediation_OSBuild_Blueprint_snippet_⇲
  
91 [[packages]]91 [[packages]]
92 name·=·"aide"92 name·=·"aide"
93 version·=·"*"93 version·=·"*"
94 Remediation_Anaconda_snippet_⇲ 
95 Complexity:·low 
96 Disruption:·low 
97 Strategy:···enable 
  
98 package·--add=aide 
99 Remediation_Puppet_snippet_⇲94 Remediation_Puppet_snippet_⇲
100 Complexity:·low95 Complexity:·low
101 Disruption:·low96 Disruption:·low
102 Strategy:···enable97 Strategy:···enable
103 include·install_aide98 include·install_aide
  
104 class·install_aide·{99 class·install_aide·{
Offset 119, 14 lines modifiedOffset 113, 20 lines modified
119 if·!·rpm·-q·--quiet·"aide"·;·then113 if·!·rpm·-q·--quiet·"aide"·;·then
120 ····yum·install·-y·"aide"114 ····yum·install·-y·"aide"
121 fi115 fi
  
122 else116 else
123 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'117 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
124 fi118 fi
 119 Remediation_Anaconda_snippet_⇲
 120 Complexity:·low
 121 Disruption:·low
 122 Strategy:···enable
  
 123 package·--add=aide
125 Remediation_Ansible_snippet_⇲124 Remediation_Ansible_snippet_⇲
126 Complexity:·low125 Complexity:·low
127 Disruption:·low126 Disruption:·low
128 Strategy:···enable127 Strategy:···enable
129 -·name:·Ensure·aide·is·installed128 -·name:·Ensure·aide·is·installed
130 ··package:129 ··package:
131 ····name:·aide130 ····name:·aide
Offset 3349, 20 lines modifiedOffset 3349, 14 lines modified
3349 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed3349 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed
3350 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-002273350 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227
3351 Remediation_OSBuild_Blueprint_snippet_⇲3351 Remediation_OSBuild_Blueprint_snippet_⇲
  
3352 [[packages]]3352 [[packages]]
3353 name·=·"rng-tools"3353 name·=·"rng-tools"
3354 version·=·"*"3354 version·=·"*"
3355 Remediation_Anaconda_snippet_⇲ 
3356 Complexity:·low 
3357 Disruption:·low 
3358 Strategy:···enable 
  
3359 package·--add=rng-tools 
3360 Remediation_Puppet_snippet_⇲3355 Remediation_Puppet_snippet_⇲
3361 Complexity:·low3356 Complexity:·low
3362 Disruption:·low3357 Disruption:·low
3363 Strategy:···enable3358 Strategy:···enable
3364 include·install_rng-tools3359 include·install_rng-tools
  
3365 class·install_rng-tools·{3360 class·install_rng-tools·{
Offset 3374, 14 lines modifiedOffset 3368, 20 lines modified
3374 Complexity:·low3368 Complexity:·low
3375 Disruption:·low3369 Disruption:·low
3376 Strategy:···enable3370 Strategy:···enable
  
3377 if·!·rpm·-q·--quiet·"rng-tools"·;·then3371 if·!·rpm·-q·--quiet·"rng-tools"·;·then
3378 ····yum·install·-y·"rng-tools"3372 ····yum·install·-y·"rng-tools"
3379 fi3373 fi
 3374 Remediation_Anaconda_snippet_⇲
 3375 Complexity:·low
 3376 Disruption:·low
 3377 Strategy:···enable
  
 3378 package·--add=rng-tools
3380 Remediation_Ansible_snippet_⇲3379 Remediation_Ansible_snippet_⇲
3381 Complexity:·low3380 Complexity:·low
3382 Disruption:·low3381 Disruption:·low
3383 Strategy:···enable3382 Strategy:···enable
3384 -·name:·Ensure·rng-tools·is·installed3383 -·name:·Ensure·rng-tools·is·installed
3385 ··package:3384 ··package:
3386 ····name:·rng-tools3385 ····name:·rng-tools
Offset 3445, 20 lines modifiedOffset 3445, 14 lines modified
3445 ***·Rule  ·Uninstall·iprutils·Package·  [ref]·***3445 ***·Rule  ·Uninstall·iprutils·Package·  [ref]·***
3446 The·iprutils·package·can·be·removed·with·the·following·command:3446 The·iprutils·package·can·be·removed·with·the·following·command:
3447 $·sudo·yum·erase·iprutils3447 $·sudo·yum·erase·iprutils
3448 Rationale:·················iprutils·provides·a·suite·of·utlilities·to·manage·and·configure·SCSI·devices·supported·by·the·ipr·SCSI·storage·device·driver.3448 Rationale:·················iprutils·provides·a·suite·of·utlilities·to·manage·and·configure·SCSI·devices·supported·by·the·ipr·SCSI·storage·device·driver.
3449 Severity: ················medium3449 Severity: ················medium
3450 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_iprutils_removed3450 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_iprutils_removed
3451 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000095-GPOS-00049,·SRG-OS-000480-GPOS-002273451 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000095-GPOS-00049,·SRG-OS-000480-GPOS-00227
3452 Remediation_Anaconda_snippet_⇲ 
3453 Complexity:·low 
3454 Disruption:·low 
3455 Strategy:···disable 
  
3456 package·--remove=iprutils 
3457 Remediation_Puppet_snippet_⇲3452 Remediation_Puppet_snippet_⇲
3458 Complexity:·low3453 Complexity:·low
3459 Disruption:·low3454 Disruption:·low
3460 Strategy:···disable3455 Strategy:···disable
3461 include·remove_iprutils3456 include·remove_iprutils
  
3462 class·remove_iprutils·{3457 class·remove_iprutils·{
Offset 3478, 14 lines modifiedOffset 3472, 20 lines modified
3478 #»      ···system!3472 #»      ···system!
  
3479 if·rpm·-q·--quiet·"iprutils"·;·then3473 if·rpm·-q·--quiet·"iprutils"·;·then
  
3480 ····yum·remove·-y·"iprutils"3474 ····yum·remove·-y·"iprutils"
  
3481 fi3475 fi
 3476 Remediation_Anaconda_snippet_⇲
 3477 Complexity:·low
 3478 Disruption:·low
 3479 Strategy:···disable
  
 3480 package·--remove=iprutils
3482 Remediation_Ansible_snippet_⇲3481 Remediation_Ansible_snippet_⇲
3483 Complexity:·low3482 Complexity:·low
3484 Disruption:·low3483 Disruption:·low
3485 Strategy:···disable3484 Strategy:···disable
3486 -·name:·Ensure·iprutils·is·removed3485 -·name:·Ensure·iprutils·is·removed
3487 ··package:3486 ··package:
3488 ····name:·iprutils3487 ····name:·iprutils
Offset 3500, 20 lines modifiedOffset 3500, 14 lines modified
3500 ***·Rule  ·Uninstall·tuned·Package·  [ref]·***3500 ***·Rule  ·Uninstall·tuned·Package·  [ref]·***
Max diff block lines reached; 66232/70070 bytes (94.52%) of diff not shown.
725 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-stig_gui.html
    
Offset 15270, 116 lines modifiedOffset 15270, 116 lines modified
0003ba50:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003ba50:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003ba60:·6964·6d35·3430·3322·2074·6162·696e·6465··idm5403"·tabinde0003ba60:·6964·6d35·3430·3322·2074·6162·696e·6465··idm5403"·tabinde
0003ba70:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003ba70:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003ba80:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003ba80:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003ba90:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003ba90:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003baa0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003baa0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003bab0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bab0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003bac0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003bac0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
0003bad0:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003bad0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003bae0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003bae0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003baf0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003baf0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003bb00:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003bb00:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003bb10:·6964·6d35·3430·3322·3e3c·7461·626c·6520··idm5403"><table·0003bb10:·6d35·3430·3322·3e3c·7461·626c·6520·636c··m5403"><table·cl
0003bb20:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003bb20:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003bb30:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003bb30:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bb40:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003bb40:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003bb50:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003bb50:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003bb60:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003bb60:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003bb70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bb70:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bb80:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003bb80:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bb90:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003bb90:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003bba0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bba0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bbb0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003bbb0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003bbc0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003bbc0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003bbd0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003bbd0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003bbe0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003bbf0:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</0003bbe0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003bbf0:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003bc00:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003bc10:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003bc20:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003bc30:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003bc40:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003bc50:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003bc60:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003bc70:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003bc80:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003bc90:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003bca0:·6d35·3430·3422·2074·6162·696e·6465·783d··m5404"·tabindex=
 0003bcb0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003bcc0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003bcd0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003bce0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003bcf0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003bd00:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003bd10:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003bd20:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003bd30:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003bd40:·6170·7365·2220·6964·3d22·6964·6d35·3430··apse"·id="idm540
 0003bd50:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
 0003bd60:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003bd70:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003bd80:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003bd90:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003bda0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003bdb0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003bdc0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003bdd0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003bde0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003bdf0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003be00:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003be10:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003be20:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 0003be30:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 0003be40:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 0003be50:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
 0003be60:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
 0003be70:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
 0003be80:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 0003be90:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
 0003bea0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003beb0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003bec0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 0003bed0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003bee0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003bef0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003bf00:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003bf10:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003bf20:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
0003bc00:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003bf30:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003bc10:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003bf40:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003bc20:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003bf50:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003bc30:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003bf60:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003bc40:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bf70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bc50:·2369·646d·3534·3034·2220·7461·6269·6e64··#idm5404"·tabind0003bf80:·2369·646d·3534·3035·2220·7461·6269·6e64··#idm5405"·tabind
0003bc60:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bf90:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bc70:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003bfa0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bc80:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003bfb0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003bc90:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003bfc0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003bca0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bfd0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003bcb0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003bfe0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003bcc0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003bff0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003bcd0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c000:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003bce0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c010:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003bcf0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003c020:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003bd00:·646d·3534·3034·223e·3c74·6162·6c65·2063··dm5404"><table·c0003c030:·2269·646d·3534·3035·223e·3c74·6162·6c65··"idm5405"><table
0003bd10:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003c040:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003bd20:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003c050:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003bd30:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003c060:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003bd40:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003c070:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003bd50:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003c080:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003bd60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c090:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bd70:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003c0a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003bd80:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003c0b0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003bd90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c0c0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bda0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003c0d0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003bdb0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003c0e0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003bdc0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003c0f0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003c100:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003c110:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
0003bdd0:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003bde0:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003bdf0:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003be00:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003be10:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003be20:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003be30:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003be40:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003be50:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003be60:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003be70:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003be80:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003be90:·646d·3534·3035·2220·7461·6269·6e64·6578··dm5405"·tabindex 
0003bea0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003beb0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003bec0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003bed0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
Max diff block lines reached; 659658/674314 bytes (97.83%) of diff not shown.
66.1 KB
html2text {}
    
Offset 92, 20 lines modifiedOffset 92, 14 lines modified
92 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed92 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
93 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019993 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
94 Remediation_OSBuild_Blueprint_snippet_⇲94 Remediation_OSBuild_Blueprint_snippet_⇲
  
95 [[packages]]95 [[packages]]
96 name·=·"aide"96 name·=·"aide"
97 version·=·"*"97 version·=·"*"
98 Remediation_Anaconda_snippet_⇲ 
99 Complexity:·low 
100 Disruption:·low 
101 Strategy:···enable 
  
102 package·--add=aide 
103 Remediation_Puppet_snippet_⇲98 Remediation_Puppet_snippet_⇲
104 Complexity:·low99 Complexity:·low
105 Disruption:·low100 Disruption:·low
106 Strategy:···enable101 Strategy:···enable
107 include·install_aide102 include·install_aide
  
108 class·install_aide·{103 class·install_aide·{
Offset 123, 14 lines modifiedOffset 117, 20 lines modified
123 if·!·rpm·-q·--quiet·"aide"·;·then117 if·!·rpm·-q·--quiet·"aide"·;·then
124 ····yum·install·-y·"aide"118 ····yum·install·-y·"aide"
125 fi119 fi
  
126 else120 else
127 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'121 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
128 fi122 fi
 123 Remediation_Anaconda_snippet_⇲
 124 Complexity:·low
 125 Disruption:·low
 126 Strategy:···enable
  
 127 package·--add=aide
129 Remediation_Ansible_snippet_⇲128 Remediation_Ansible_snippet_⇲
130 Complexity:·low129 Complexity:·low
131 Disruption:·low130 Disruption:·low
132 Strategy:···enable131 Strategy:···enable
133 -·name:·Ensure·aide·is·installed132 -·name:·Ensure·aide·is·installed
134 ··package:133 ··package:
135 ····name:·aide134 ····name:·aide
Offset 3353, 20 lines modifiedOffset 3353, 14 lines modified
3353 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed3353 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rng-tools_installed
3354 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-002273354 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000480-GPOS-00227
3355 Remediation_OSBuild_Blueprint_snippet_⇲3355 Remediation_OSBuild_Blueprint_snippet_⇲
  
3356 [[packages]]3356 [[packages]]
3357 name·=·"rng-tools"3357 name·=·"rng-tools"
3358 version·=·"*"3358 version·=·"*"
3359 Remediation_Anaconda_snippet_⇲ 
3360 Complexity:·low 
3361 Disruption:·low 
3362 Strategy:···enable 
  
3363 package·--add=rng-tools 
3364 Remediation_Puppet_snippet_⇲3359 Remediation_Puppet_snippet_⇲
3365 Complexity:·low3360 Complexity:·low
3366 Disruption:·low3361 Disruption:·low
3367 Strategy:···enable3362 Strategy:···enable
3368 include·install_rng-tools3363 include·install_rng-tools
  
3369 class·install_rng-tools·{3364 class·install_rng-tools·{
Offset 3378, 14 lines modifiedOffset 3372, 20 lines modified
3378 Complexity:·low3372 Complexity:·low
3379 Disruption:·low3373 Disruption:·low
3380 Strategy:···enable3374 Strategy:···enable
  
3381 if·!·rpm·-q·--quiet·"rng-tools"·;·then3375 if·!·rpm·-q·--quiet·"rng-tools"·;·then
3382 ····yum·install·-y·"rng-tools"3376 ····yum·install·-y·"rng-tools"
3383 fi3377 fi
 3378 Remediation_Anaconda_snippet_⇲
 3379 Complexity:·low
 3380 Disruption:·low
 3381 Strategy:···enable
  
 3382 package·--add=rng-tools
3384 Remediation_Ansible_snippet_⇲3383 Remediation_Ansible_snippet_⇲
3385 Complexity:·low3384 Complexity:·low
3386 Disruption:·low3385 Disruption:·low
3387 Strategy:···enable3386 Strategy:···enable
3388 -·name:·Ensure·rng-tools·is·installed3387 -·name:·Ensure·rng-tools·is·installed
3389 ··package:3388 ··package:
3390 ····name:·rng-tools3389 ····name:·rng-tools
Offset 3449, 20 lines modifiedOffset 3449, 14 lines modified
3449 ***·Rule  ·Uninstall·iprutils·Package·  [ref]·***3449 ***·Rule  ·Uninstall·iprutils·Package·  [ref]·***
3450 The·iprutils·package·can·be·removed·with·the·following·command:3450 The·iprutils·package·can·be·removed·with·the·following·command:
3451 $·sudo·yum·erase·iprutils3451 $·sudo·yum·erase·iprutils
3452 Rationale:·················iprutils·provides·a·suite·of·utlilities·to·manage·and·configure·SCSI·devices·supported·by·the·ipr·SCSI·storage·device·driver.3452 Rationale:·················iprutils·provides·a·suite·of·utlilities·to·manage·and·configure·SCSI·devices·supported·by·the·ipr·SCSI·storage·device·driver.
3453 Severity: ················medium3453 Severity: ················medium
3454 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_iprutils_removed3454 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_iprutils_removed
3455 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000095-GPOS-00049,·SRG-OS-000480-GPOS-002273455 Identifiers·and·References·References: ·CCI-000366,·SRG-OS-000095-GPOS-00049,·SRG-OS-000480-GPOS-00227
3456 Remediation_Anaconda_snippet_⇲ 
3457 Complexity:·low 
3458 Disruption:·low 
3459 Strategy:···disable 
  
3460 package·--remove=iprutils 
3461 Remediation_Puppet_snippet_⇲3456 Remediation_Puppet_snippet_⇲
3462 Complexity:·low3457 Complexity:·low
3463 Disruption:·low3458 Disruption:·low
3464 Strategy:···disable3459 Strategy:···disable
3465 include·remove_iprutils3460 include·remove_iprutils
  
3466 class·remove_iprutils·{3461 class·remove_iprutils·{
Offset 3482, 14 lines modifiedOffset 3476, 20 lines modified
3482 #»      ···system!3476 #»      ···system!
  
3483 if·rpm·-q·--quiet·"iprutils"·;·then3477 if·rpm·-q·--quiet·"iprutils"·;·then
  
3484 ····yum·remove·-y·"iprutils"3478 ····yum·remove·-y·"iprutils"
  
3485 fi3479 fi
 3480 Remediation_Anaconda_snippet_⇲
 3481 Complexity:·low
 3482 Disruption:·low
 3483 Strategy:···disable
  
 3484 package·--remove=iprutils
3486 Remediation_Ansible_snippet_⇲3485 Remediation_Ansible_snippet_⇲
3487 Complexity:·low3486 Complexity:·low
3488 Disruption:·low3487 Disruption:·low
3489 Strategy:···disable3488 Strategy:···disable
3490 -·name:·Ensure·iprutils·is·removed3489 -·name:·Ensure·iprutils·is·removed
3491 ··package:3490 ··package:
3492 ····name:·iprutils3491 ····name:·iprutils
Offset 3504, 20 lines modifiedOffset 3504, 14 lines modified
3504 ***·Rule  ·Uninstall·tuned·Package·  [ref]·***3504 ***·Rule  ·Uninstall·tuned·Package·  [ref]·***
Max diff block lines reached; 63818/67656 bytes (94.33%) of diff not shown.
56.0 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-high.html
    
Offset 19640, 84 lines modifiedOffset 19640, 84 lines modified
0004cb70:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0004cb70:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0004cb80:·646d·3632·3135·2220·7461·6269·6e64·6578··dm6215"·tabindex0004cb80:·646d·3632·3135·2220·7461·6269·6e64·6578··dm6215"·tabindex
0004cb90:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0004cb90:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0004cba0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0004cba0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0004cbb0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0004cbb0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0004cbc0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0004cbc0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0004cbd0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0004cbd0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0004cbe0:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern0004cbe0:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
0004cbf0:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·... 
0004cc00:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0004cbf0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0004cc10:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0004cc00:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0004cc20:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0004cc10:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0004cc30:·2269·646d·3632·3135·223e·3c70·7265·3e3c··"idm6215"><pre><0004cc20:·2069·643d·2269·646d·3632·3135·223e·3c74···id="idm6215"><t
 0004cc30:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0004cc40:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0004cc50:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0004cc60:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0004cc70:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0004cc80:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0004cc90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0004cca0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0004ccb0:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>
 0004ccc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0004ccd0:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru
 0004cce0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0004ccf0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0004cd00:·3e3c·7464·3e64·6973·6162·6c65·3c2f·7464··><td>disable</td
 0004cd10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0004cc40:·636f·6465·3e2d·2d2d·0a61·7069·5665·7273··code>---.apiVers0004cd20:·7265·3e3c·636f·6465·3e61·7069·5665·7273··re><code>apiVers
0004cc50:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf0004cd30:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf
0004cc60:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh0004cd40:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh
0004cc70:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:·0004cd50:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:·
0004cc80:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp0004cd60:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp
0004cc90:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.··0004cd70:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.··
0004cca0:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.····0004cd80:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.····
0004ccb0:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.00004cd90:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.0
0004ccc0:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.··0004cda0:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.··
0004ccd0:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.·····0004cdb0:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.·····
 0004cdc0:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s
 0004cdd0:·6865·6c6c·2e73·6572·7669·6365·0a20·2020··hell.service.···
0004cce0:·202d·2065·6e61·626c·6564·3a20·6661·6c73···-·enabled:·fals0004cde0:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa
0004ccf0:·650a·2020·2020·2020·2020·6e61·6d65·3a20··e.········name:·0004cdf0:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask
0004cd00:·6465·6275·672d·7368·656c·6c2e·7365·7276··debug-shell.serv0004ce00:·3a20·7472·7565·0a20·2020·2020·202d·206e··:·true.······-·n
 0004ce10:·616d·653a·2064·6562·7567·2d73·6865·6c6c··ame:·debug-shell
 0004ce20:·2e73·6f63·6b65·740a·2020·2020·2020·2020··.socket.········
 0004ce30:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.·
 0004ce40:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru
0004cd10:·6963·650a·3c2f·636f·6465·3e3c·2f70·7265··ice.</code></pre0004ce50:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
0004cd20:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0004ce60:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0004cd30:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0004ce70:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0004cd40:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0004ce80:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0004cd50:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0004ce90:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0004cd60:·7267·6574·3d22·2369·646d·3632·3136·2220··rget="#idm6216"·0004cea0:·6574·3d22·2369·646d·3632·3136·2220·7461··et="#idm6216"·ta
0004cd70:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0004ceb0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0004cd80:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0004cec0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0004cd90:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0004ced0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0004cda0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0004cee0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0004cdb0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0004cef0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0004cdc0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0004cf00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0004cf10:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp
 0004cf20:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0004cf30:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0004cf40:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0004cf50:·6522·2069·643d·2269·646d·3632·3136·223e··e"·id="idm6216">
 0004cf60:·3c70·7265·3e3c·636f·6465·3e2d·2d2d·0a61··<pre><code>---.a
0004cdd0:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a> 
0004cde0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0004cdf0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0004ce00:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0004ce10:·3632·3136·223e·3c74·6162·6c65·2063·6c61··6216"><table·cla 
0004ce20:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0004ce30:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0004ce40:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0004ce50:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0004ce60:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0004ce70:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0004ce80:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0004ce90:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med 
0004cea0:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr 
0004ceb0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0004cec0:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></ 
0004ced0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0004cee0:·6567·793a·3c2f·7468·3e3c·7464·3e64·6973··egy:</th><td>dis 
0004cef0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0004cf00:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0004cf10:·3e61·7069·5665·7273·696f·6e3a·206d·6163··>apiVersion:·mac0004cf70:·7069·5665·7273·696f·6e3a·206d·6163·6869··piVersion:·machi
0004cf20:·6869·6e65·636f·6e66·6967·7572·6174·696f··hineconfiguratio0004cf80:·6e65·636f·6e66·6967·7572·6174·696f·6e2e··neconfiguration.
0004cf30:·6e2e·6f70·656e·7368·6966·742e·696f·2f76··n.openshift.io/v0004cf90:·6f70·656e·7368·6966·742e·696f·2f76·310a··openshift.io/v1.
0004cf40:·310a·6b69·6e64·3a20·4d61·6368·696e·6543··1.kind:·MachineC0004cfa0:·6b69·6e64·3a20·4d61·6368·696e·6543·6f6e··kind:·MachineCon
0004cf50:·6f6e·6669·670a·7370·6563·3a0a·2020·636f··onfig.spec:.··co0004cfb0:·6669·670a·7370·6563·3a0a·2020·636f·6e66··fig.spec:.··conf
0004cf60:·6e66·6967·3a0a·2020·2020·6967·6e69·7469··nfig:.····igniti0004cfc0:·6967·3a0a·2020·2020·6967·6e69·7469·6f6e··ig:.····ignition
0004cf70:·6f6e·3a0a·2020·2020·2020·7665·7273·696f··on:.······versio0004cfd0:·3a0a·2020·2020·2020·7665·7273·696f·6e3a··:.······version:
0004cf80:·6e3a·2033·2e31·2e30·0a20·2020·2073·7973··n:·3.1.0.····sys0004cfe0:·2033·2e31·2e30·0a20·2020·2073·7973·7465···3.1.0.····syste
0004cf90:·7465·6d64·3a0a·2020·2020·2020·756e·6974··temd:.······unit0004cff0:·6d64·3a0a·2020·2020·2020·756e·6974·733a··md:.······units:
0004cfa0:·733a·0a20·2020·2020·202d·206e·616d·653a··s:.······-·name:0004d000:·0a20·2020·2020·202d·2065·6e61·626c·6564··.······-·enabled
0004cfb0:·2064·6562·7567·2d73·6865·6c6c·2e73·6572···debug-shell.ser 
0004cfc0:·7669·6365·0a20·2020·2020·2020·2065·6e61··vice.········ena 
0004cfd0:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.···· 
0004cfe0:·2020·2020·6d61·736b·3a20·7472·7565·0a20······mask:·true.· 
0004cff0:·2020·2020·202d·206e·616d·653a·2064·6562·······-·name:·deb 
0004d000:·7567·2d73·6865·6c6c·2e73·6f63·6b65·740a··ug-shell.socket. 
0004d010:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled: 
0004d020:·2066·616c·7365·0a20·2020·2020·2020·206d···false.········m0004d010:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
0004d030:·6173·6b3a·2074·7275·650a·3c2f·636f·6465··ask:·true.</code0004d020:·6e61·6d65·3a20·6465·6275·672d·7368·656c··name:·debug-shel
 0004d030:·6c2e·7365·7276·6963·650a·3c2f·636f·6465··l.service.</code
0004d040:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d0004d040:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d
0004d050:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t0004d050:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t
0004d060:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t0004d060:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t
0004d070:·643e·3c2f·7472·3e3c·7472·2064·6174·612d··d></tr><tr·data-0004d070:·643e·3c2f·7472·3e3c·7472·2064·6174·612d··d></tr><tr·data-
0004d080:·7474·2d69·643d·2278·6363·6466·5f6f·7267··tt-id="xccdf_org0004d080:·7474·2d69·643d·2278·6363·6466·5f6f·7267··tt-id="xccdf_org
0004d090:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont0004d090:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
0004d0a0:·656e·745f·7275·6c65·5f63·6f72·656f·735f··ent_rule_coreos_0004d0a0:·656e·745f·7275·6c65·5f63·6f72·656f·735f··ent_rule_coreos_
Offset 152433, 67 lines modifiedOffset 152433, 67 lines modified
00253700:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00253700:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00253710:·2369·646d·3332·3337·3422·2074·6162·696e··#idm32374"·tabin00253710:·2369·646d·3332·3337·3422·2074·6162·696e··#idm32374"·tabin
00253720:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00253720:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00253730:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00253730:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00253740:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00253740:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00253750:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00253750:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00253760:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00253760:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00253770:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub00253770:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
00253780:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet· 
00253790:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·00253780:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
002537a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col00253790:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
002537b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·002537a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
002537c0:·6964·3d22·6964·6d33·3233·3734·223e·3c74··id="idm32374"><t002537b0:·7365·2220·6964·3d22·6964·6d33·3233·3734··se"·id="idm32374
002537d0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl002537c0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
Max diff block lines reached; 27408/45954 bytes (59.64%) of diff not shown.
11.0 KB
html2text {}
    
Offset 334, 26 lines modifiedOffset 334, 14 lines modified
334 Note·that·this·needs·to·be·done·for·each·MachineConfigPool334 Note·that·this·needs·to·be·done·for·each·MachineConfigPool
335 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.335 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.
336 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.336 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
337 Severity: ················medium337 Severity: ················medium
338 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled338 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
339 Identifiers·and·References·Identifiers: ·CCE-82496-1339 Identifiers·and·References·Identifiers: ·CCE-82496-1
340 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227340 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
341 Remediation_Kubernetes_snippet_⇲ 
342 --- 
343 apiVersion:·machineconfiguration.openshift.io/v1 
344 kind:·MachineConfig 
345 spec: 
346 ··config: 
347 ····ignition: 
348 ······version:·3.1.0 
349 ····systemd: 
350 ······units: 
351 ······-·enabled:·false 
352 ········name:·debug-shell.service 
353 Remediation_script_⇲341 Remediation_script_⇲
354 Complexity:·low342 Complexity:·low
355 Disruption:·medium343 Disruption:·medium
356 Reboot:·····true344 Reboot:·····true
357 Strategy:···disable345 Strategy:···disable
358 apiVersion:·machineconfiguration.openshift.io/v1346 apiVersion:·machineconfiguration.openshift.io/v1
359 kind:·MachineConfig347 kind:·MachineConfig
Offset 365, 14 lines modifiedOffset 353, 26 lines modified
365 ······units:353 ······units:
366 ······-·name:·debug-shell.service354 ······-·name:·debug-shell.service
367 ········enabled:·false355 ········enabled:·false
368 ········mask:·true356 ········mask:·true
369 ······-·name:·debug-shell.socket357 ······-·name:·debug-shell.socket
370 ········enabled:·false358 ········enabled:·false
371 ········mask:·true359 ········mask:·true
 360 Remediation_Kubernetes_snippet_⇲
 361 ---
 362 apiVersion:·machineconfiguration.openshift.io/v1
 363 kind:·MachineConfig
 364 spec:
 365 ··config:
 366 ····ignition:
 367 ······version:·3.1.0
 368 ····systemd:
 369 ······units:
 370 ······-·enabled:·false
 371 ········name:·debug-shell.service
372 ***·Rule  ·Verify·that·Interactive·Boot·is·Disabled·  [ref]·***372 ***·Rule  ·Verify·that·Interactive·Boot·is·Disabled·  [ref]·***
373 Red·Hat·Enterprise·Linux·CoreOS·4·systems·support·an·"interactive·boot"·option·that·can·be·used·to·prevent·services·from·being·started.·On·a·Red·Hat·Enterprise·Linux·CoreOS·4·system,·interactive·boot·can·be·enabled·by·providing·a·1,·yes,·true,·or·on·value·to·the·systemd.confirm_spawn·kernel·argument.373 Red·Hat·Enterprise·Linux·CoreOS·4·systems·support·an·"interactive·boot"·option·that·can·be·used·to·prevent·services·from·being·started.·On·a·Red·Hat·Enterprise·Linux·CoreOS·4·system,·interactive·boot·can·be·enabled·by·providing·a·1,·yes,·true,·or·on·value·to·the·systemd.confirm_spawn·kernel·argument.
374 Rationale:·················Using·interactive·boot,·the·console·user·could·disable·auditing,·firewalls,·or·other·services,·weakening·system·security.374 Rationale:·················Using·interactive·boot,·the·console·user·could·disable·auditing,·firewalls,·or·other·services,·weakening·system·security.
375 Severity: ················medium375 Severity: ················medium
376 Rule·ID:···················xccdf_org.ssgproject.content_rule_coreos_disable_interactive_boot376 Rule·ID:···················xccdf_org.ssgproject.content_rule_coreos_disable_interactive_boot
377 Identifiers·and·References·Identifiers: ·CCE-83548-8377 Identifiers·and·References·Identifiers: ·CCE-83548-8
378 ···························References: ·11,·12,·14,·15,·16,·18,·3,·5,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·DSS06.03,·DSS06.06,·3.1.2,·3.4.5,·CCI-000213,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·A.6.1.2,·A.7.1.1,·A.9.1.2,·A.9.2.1,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·SC-2(1),·CM-6(a),·PR.AC-4,·PR.AC-6,·PR.PT-3,·FIA_UAU.1,·SRG-OS-000480-GPOS-00227378 ···························References: ·11,·12,·14,·15,·16,·18,·3,·5,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·DSS06.03,·DSS06.06,·3.1.2,·3.4.5,·CCI-000213,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·A.6.1.2,·A.7.1.1,·A.9.1.2,·A.9.2.1,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·SC-2(1),·CM-6(a),·PR.AC-4,·PR.AC-6,·PR.PT-3,·FIA_UAU.1,·SRG-OS-000480-GPOS-00227
Offset 5632, 15 lines modifiedOffset 5632, 15 lines modified
5632 Note·that·this·needs·to·be·done·for·each·MachineConfigPool5632 Note·that·this·needs·to·be·done·for·each·MachineConfigPool
5633 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.5633 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.
5634 $·sudo·service·bluetooth·stop5634 $·sudo·service·bluetooth·stop
5635 Rationale:·················Disabling·the·bluetooth·service·prevents·the·system·from·attempting·connections·to·Bluetooth·devices,·which·entails·some·security·risk.·Nevertheless,·variation·in·this·risk·decision·may·be·expected·due·to·the·utility·of·Bluetooth·connectivity·and·its·limited·range.5635 Rationale:·················Disabling·the·bluetooth·service·prevents·the·system·from·attempting·connections·to·Bluetooth·devices,·which·entails·some·security·risk.·Nevertheless,·variation·in·this·risk·decision·may·be·expected·due·to·the·utility·of·Bluetooth·connectivity·and·its·limited·range.
5636 Severity: ················medium5636 Severity: ················medium
5637 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_bluetooth_disabled5637 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_bluetooth_disabled
5638 Identifiers·and·References·References: ·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·3.1.16,·CCI-000085,·CCI-001551,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-45638 Identifiers·and·References·References: ·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·3.1.16,·CCI-000085,·CCI-001551,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
5639 Remediation_Kubernetes_snippet_⇲5639 Remediation_script_⇲
5640 Complexity:·low5640 Complexity:·low
5641 Disruption:·medium5641 Disruption:·medium
5642 Reboot:·····true5642 Reboot:·····true
5643 Strategy:···disable5643 Strategy:···disable
5644 apiVersion:·machineconfiguration.openshift.io/v15644 apiVersion:·machineconfiguration.openshift.io/v1
5645 kind:·MachineConfig5645 kind:·MachineConfig
5646 spec:5646 spec:
Offset 5651, 15 lines modifiedOffset 5651, 15 lines modified
5651 ······units:5651 ······units:
5652 ······-·name:·bluetooth.service5652 ······-·name:·bluetooth.service
5653 ········enabled:·false5653 ········enabled:·false
5654 ········mask:·true5654 ········mask:·true
5655 ······-·name:·bluetooth.socket5655 ······-·name:·bluetooth.socket
5656 ········enabled:·false5656 ········enabled:·false
5657 ········mask:·true5657 ········mask:·true
5658 Remediation_script_⇲5658 Remediation_Kubernetes_snippet_⇲
5659 Complexity:·low5659 Complexity:·low
5660 Disruption:·medium5660 Disruption:·medium
5661 Reboot:·····true5661 Reboot:·····true
5662 Strategy:···disable5662 Strategy:···disable
5663 apiVersion:·machineconfiguration.openshift.io/v15663 apiVersion:·machineconfiguration.openshift.io/v1
5664 kind:·MachineConfig5664 kind:·MachineConfig
5665 spec:5665 spec:
Offset 5917, 26 lines modifiedOffset 5917, 14 lines modified
5917 ···························Disabling·the·automounter·permits·the·administrator·to·statically·control·filesystem·mounting·through·/etc/fstab.5917 ···························Disabling·the·automounter·permits·the·administrator·to·statically·control·filesystem·mounting·through·/etc/fstab.
5918 Rationale:5918 Rationale:
5919 ···························Additionally,·automatically·mounting·filesystems·permits·easy·introduction·of·unknown·devices,·thereby·facilitating·malicious·activity.5919 ···························Additionally,·automatically·mounting·filesystems·permits·easy·introduction·of·unknown·devices,·thereby·facilitating·malicious·activity.
5920 Severity: ················medium5920 Severity: ················medium
5921 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_autofs_disabled5921 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_autofs_disabled
5922 Identifiers·and·References·Identifiers: ·CCE-82663-65922 Identifiers·and·References·Identifiers: ·CCE-82663-6
5923 ···························References: ·1,·12,·15,·16,·5,·APO13.01,·DSS01.04,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·3.4.6,·CCI-000366,·CCI-000778,·CCI-001958,·164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7,·SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002275923 ···························References: ·1,·12,·15,·16,·5,·APO13.01,·DSS01.04,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·3.4.6,·CCI-000366,·CCI-000778,·CCI-001958,·164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7,·SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
5924 Remediation_Kubernetes_snippet_⇲ 
5925 --- 
5926 apiVersion:·machineconfiguration.openshift.io/v1 
5927 kind:·MachineConfig 
5928 spec: 
5929 ··config: 
5930 ····ignition: 
5931 ······version:·3.1.0 
5932 ····systemd: 
5933 ······units: 
5934 ······-·enabled:·false 
5935 ········name:·autofs.service 
5936 Remediation_script_⇲5924 Remediation_script_⇲
5937 Complexity:·low5925 Complexity:·low
5938 Disruption:·medium5926 Disruption:·medium
5939 Reboot:·····true5927 Reboot:·····true
5940 Strategy:···disable5928 Strategy:···disable
5941 apiVersion:·machineconfiguration.openshift.io/v15929 apiVersion:·machineconfiguration.openshift.io/v1
5942 kind:·MachineConfig5930 kind:·MachineConfig
Offset 5948, 14 lines modifiedOffset 5936, 26 lines modified
5948 ······units:5936 ······units:
5949 ······-·name:·autofs.service5937 ······-·name:·autofs.service
5950 ········enabled:·false5938 ········enabled:·false
5951 ········mask:·true5939 ········mask:·true
5952 ······-·name:·autofs.socket5940 ······-·name:·autofs.socket
5953 ········enabled:·false5941 ········enabled:·false
5954 ········mask:·true5942 ········mask:·true
 5943 Remediation_Kubernetes_snippet_⇲
 5944 ---
 5945 apiVersion:·machineconfiguration.openshift.io/v1
 5946 kind:·MachineConfig
 5947 spec:
 5948 ··config:
 5949 ····ignition:
Max diff block lines reached; 3385/11224 bytes (30.16%) of diff not shown.
46.8 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-moderate.html
    
Offset 19641, 84 lines modifiedOffset 19641, 84 lines modified
0004cb80:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0004cb80:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0004cb90:·3d22·2369·646d·3632·3135·2220·7461·6269··="#idm6215"·tabi0004cb90:·3d22·2369·646d·3632·3135·2220·7461·6269··="#idm6215"·tabi
0004cba0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0004cba0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0004cbb0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0004cbb0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0004cbc0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0004cbc0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0004cbd0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0004cbd0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0004cbe0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0004cbe0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0004cbf0:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku0004cbf0:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
0004cc00:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet 
0004cc10:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0004cc00:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
0004cc20:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0004cc10:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0004cc30:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0004cc20:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0004cc40:·2069·643d·2269·646d·3632·3135·223e·3c70···id="idm6215"><p0004cc30:·7073·6522·2069·643d·2269·646d·3632·3135··pse"·id="idm6215
 0004cc40:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0004cc50:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0004cc60:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0004cc70:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0004cc80:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0004cc90:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0004cca0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0004ccb0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0004ccc0:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
 0004ccd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0004cce0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0004ccf0:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><
 0004cd00:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0004cd10:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable
 0004cd20:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0004cc50:·7265·3e3c·636f·6465·3e2d·2d2d·0a61·7069··re><code>---.api0004cd30:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api
0004cc60:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine0004cd40:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine
0004cc70:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op0004cd50:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op
0004cc80:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki0004cd60:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki
0004cc90:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi0004cd70:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi
0004cca0:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config0004cd80:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config
0004ccb0:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.0004cd90:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.
0004ccc0:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·30004cda0:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3
0004ccd0:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd0004cdb0:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd
0004cce0:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·0004cdc0:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·
 0004cdd0:·2020·2020·202d·206e·616d·653a·2064·6562·······-·name:·deb
 0004cde0:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service
0004ccf0:·2020·2020·202d·2065·6e61·626c·6564·3a20·······-·enabled:·0004cdf0:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled
0004cd00:·6661·6c73·650a·2020·2020·2020·2020·6e61··false.········na0004ce00:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
0004cd10:·6d65·3a20·6465·6275·672d·7368·656c·6c2e··me:·debug-shell.0004ce10:·6d61·736b·3a20·7472·7565·0a20·2020·2020··mask:·true.·····
 0004ce20:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s
 0004ce30:·6865·6c6c·2e73·6f63·6b65·740a·2020·2020··hell.socket.····
 0004ce40:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal
 0004ce50:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask:
0004cd20:·7365·7276·6963·650a·3c2f·636f·6465·3e3c··service.</code><0004ce60:·2074·7275·650a·3c2f·636f·6465·3e3c·2f70···true.</code></p
0004cd30:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0004ce70:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0004cd40:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0004ce80:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0004cd50:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0004ce90:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0004cd60:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0004cea0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0004cd70:·612d·7461·7267·6574·3d22·2369·646d·3632··a-target="#idm620004ceb0:·7461·7267·6574·3d22·2369·646d·3632·3136··target="#idm6216
0004cd80:·3136·2220·7461·6269·6e64·6578·3d22·3022··16"·tabindex="0"0004cec0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0004cd90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0004ced0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0004cda0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0004cee0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0004cdb0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0004cef0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0004cdc0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0004cf00:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0004cdd0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0004cf10:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0004cf20:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s
 0004cf30:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0004cf40:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0004cf50:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0004cf60:·6c61·7073·6522·2069·643d·2269·646d·3632··lapse"·id="idm62
 0004cf70:·3136·223e·3c70·7265·3e3c·636f·6465·3e2d··16"><pre><code>-
 0004cf80:·2d2d·0a61·7069·5665·7273·696f·6e3a·206d··--.apiVersion:·m
0004cde0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·... 
0004cdf0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0004ce00:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0004ce10:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0004ce20:·2269·646d·3632·3136·223e·3c74·6162·6c65··"idm6216"><table 
0004ce30:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0004ce40:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0004ce50:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0004ce60:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0004ce70:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0004ce80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0004ce90:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0004cea0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0004ceb0:·3e6d·6564·6975·6d3c·2f74·643e·3c2f·7472··>medium</td></tr 
0004cec0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0004ced0:·3c2f·7468·3e3c·7464·3e74·7275·653c·2f74··</th><td>true</t 
0004cee0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0004cef0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0004cf00:·3e64·6973·6162·6c65·3c2f·7464·3e3c·2f74··>disable</td></t 
0004cf10:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0004cf20:·636f·6465·3e61·7069·5665·7273·696f·6e3a··code>apiVersion: 
0004cf30:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur0004cf90:·6163·6869·6e65·636f·6e66·6967·7572·6174··achineconfigurat
0004cf40:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift.0004cfa0:·696f·6e2e·6f70·656e·7368·6966·742e·696f··ion.openshift.io
0004cf50:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach0004cfb0:·2f76·310a·6b69·6e64·3a20·4d61·6368·696e··/v1.kind:·Machin
0004cf60:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:.0004cfc0:·6543·6f6e·6669·670a·7370·6563·3a0a·2020··eConfig.spec:.··
0004cf70:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig0004cfd0:·636f·6e66·6967·3a0a·2020·2020·6967·6e69··config:.····igni
0004cf80:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve0004cfe0:·7469·6f6e·3a0a·2020·2020·2020·7665·7273··tion:.······vers
0004cf90:·7273·696f·6e3a·2033·2e31·2e30·0a20·2020··rsion:·3.1.0.···0004cff0:·696f·6e3a·2033·2e31·2e30·0a20·2020·2073··ion:·3.1.0.····s
0004cfa0:·2073·7973·7465·6d64·3a0a·2020·2020·2020···systemd:.······0004d000:·7973·7465·6d64·3a0a·2020·2020·2020·756e··ystemd:.······un
0004cfb0:·756e·6974·733a·0a20·2020·2020·202d·206e··units:.······-·n0004d010:·6974·733a·0a20·2020·2020·202d·2065·6e61··its:.······-·ena
0004cfc0:·616d·653a·2064·6562·7567·2d73·6865·6c6c··ame:·debug-shell 
0004cfd0:·2e73·6572·7669·6365·0a20·2020·2020·2020··.service.······· 
0004cfe0:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false.0004d020:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.····
 0004d030:·2020·2020·6e61·6d65·3a20·6465·6275·672d······name:·debug-
 0004d040:·7368·656c·6c2e·7365·7276·6963·650a·3c2f··shell.service.</
0004cff0:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr 
0004d000:·7565·0a20·2020·2020·202d·206e·616d·653a··ue.······-·name: 
0004d010:·2064·6562·7567·2d73·6865·6c6c·2e73·6f63···debug-shell.soc 
0004d020:·6b65·740a·2020·2020·2020·2020·656e·6162··ket.········enab 
0004d030:·6c65·643a·2066·616c·7365·0a20·2020·2020··led:·false.····· 
0004d040:·2020·206d·6173·6b3a·2074·7275·650a·3c2f·····mask:·true.</ 
0004d050:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0004d050:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0004d060:·3e3c·2f64·6976·3e3c·2f74·643e·3c2f·7472··></div></td></tr0004d060:·3e3c·2f64·6976·3e3c·2f74·643e·3c2f·7472··></div></td></tr
0004d070:·3e3c·2f74·626f·6479·3e3c·2f74·6162·6c65··></tbody></table0004d070:·3e3c·2f74·626f·6479·3e3c·2f74·6162·6c65··></tbody></table
0004d080:·3e3c·2f74·643e·3c2f·7472·3e3c·7472·2064··></td></tr><tr·d0004d080:·3e3c·2f74·643e·3c2f·7472·3e3c·7472·2064··></td></tr><tr·d
0004d090:·6174·612d·7474·2d69·643d·2278·6363·6466··ata-tt-id="xccdf0004d090:·6174·612d·7474·2d69·643d·2278·6363·6466··ata-tt-id="xccdf
0004d0a0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.0004d0a0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.
0004d0b0:·636f·6e74·656e·745f·7275·6c65·5f63·6f72··content_rule_cor0004d0b0:·636f·6e74·656e·745f·7275·6c65·5f63·6f72··content_rule_cor
Offset 152435, 66 lines modifiedOffset 152435, 66 lines modified
00253720:·6574·3d22·2369·646d·3332·3337·3422·2074··et="#idm32374"·t00253720:·6574·3d22·2369·646d·3332·3337·3422·2074··et="#idm32374"·t
00253730:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00253730:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00253740:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00253740:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00253750:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00253750:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00253760:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00253760:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00253770:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00253770:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00253780:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00253780:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00253790:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip 
002537a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
002537b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
002537c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
002537d0:·7365·2220·6964·3d22·6964·6d33·3233·3734··se"·id="idm32374 
Max diff block lines reached; 19238/37646 bytes (51.10%) of diff not shown.
9.93 KB
html2text {}
    
Offset 334, 26 lines modifiedOffset 334, 14 lines modified
334 Note·that·this·needs·to·be·done·for·each·MachineConfigPool334 Note·that·this·needs·to·be·done·for·each·MachineConfigPool
335 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.335 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.
336 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.336 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
337 Severity: ················medium337 Severity: ················medium
338 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled338 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
339 Identifiers·and·References·Identifiers: ·CCE-82496-1339 Identifiers·and·References·Identifiers: ·CCE-82496-1
340 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227340 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
341 Remediation_Kubernetes_snippet_⇲ 
342 --- 
343 apiVersion:·machineconfiguration.openshift.io/v1 
344 kind:·MachineConfig 
345 spec: 
346 ··config: 
347 ····ignition: 
348 ······version:·3.1.0 
349 ····systemd: 
350 ······units: 
351 ······-·enabled:·false 
352 ········name:·debug-shell.service 
353 Remediation_script_⇲341 Remediation_script_⇲
354 Complexity:·low342 Complexity:·low
355 Disruption:·medium343 Disruption:·medium
356 Reboot:·····true344 Reboot:·····true
357 Strategy:···disable345 Strategy:···disable
358 apiVersion:·machineconfiguration.openshift.io/v1346 apiVersion:·machineconfiguration.openshift.io/v1
359 kind:·MachineConfig347 kind:·MachineConfig
Offset 365, 14 lines modifiedOffset 353, 26 lines modified
365 ······units:353 ······units:
366 ······-·name:·debug-shell.service354 ······-·name:·debug-shell.service
367 ········enabled:·false355 ········enabled:·false
368 ········mask:·true356 ········mask:·true
369 ······-·name:·debug-shell.socket357 ······-·name:·debug-shell.socket
370 ········enabled:·false358 ········enabled:·false
371 ········mask:·true359 ········mask:·true
 360 Remediation_Kubernetes_snippet_⇲
 361 ---
 362 apiVersion:·machineconfiguration.openshift.io/v1
 363 kind:·MachineConfig
 364 spec:
 365 ··config:
 366 ····ignition:
 367 ······version:·3.1.0
 368 ····systemd:
 369 ······units:
 370 ······-·enabled:·false
 371 ········name:·debug-shell.service
372 ***·Rule  ·Verify·that·Interactive·Boot·is·Disabled·  [ref]·***372 ***·Rule  ·Verify·that·Interactive·Boot·is·Disabled·  [ref]·***
373 Red·Hat·Enterprise·Linux·CoreOS·4·systems·support·an·"interactive·boot"·option·that·can·be·used·to·prevent·services·from·being·started.·On·a·Red·Hat·Enterprise·Linux·CoreOS·4·system,·interactive·boot·can·be·enabled·by·providing·a·1,·yes,·true,·or·on·value·to·the·systemd.confirm_spawn·kernel·argument.373 Red·Hat·Enterprise·Linux·CoreOS·4·systems·support·an·"interactive·boot"·option·that·can·be·used·to·prevent·services·from·being·started.·On·a·Red·Hat·Enterprise·Linux·CoreOS·4·system,·interactive·boot·can·be·enabled·by·providing·a·1,·yes,·true,·or·on·value·to·the·systemd.confirm_spawn·kernel·argument.
374 Rationale:·················Using·interactive·boot,·the·console·user·could·disable·auditing,·firewalls,·or·other·services,·weakening·system·security.374 Rationale:·················Using·interactive·boot,·the·console·user·could·disable·auditing,·firewalls,·or·other·services,·weakening·system·security.
375 Severity: ················medium375 Severity: ················medium
376 Rule·ID:···················xccdf_org.ssgproject.content_rule_coreos_disable_interactive_boot376 Rule·ID:···················xccdf_org.ssgproject.content_rule_coreos_disable_interactive_boot
377 Identifiers·and·References·Identifiers: ·CCE-83548-8377 Identifiers·and·References·Identifiers: ·CCE-83548-8
378 ···························References: ·11,·12,·14,·15,·16,·18,·3,·5,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·DSS06.03,·DSS06.06,·3.1.2,·3.4.5,·CCI-000213,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·A.6.1.2,·A.7.1.1,·A.9.1.2,·A.9.2.1,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·SC-2(1),·CM-6(a),·PR.AC-4,·PR.AC-6,·PR.PT-3,·FIA_UAU.1,·SRG-OS-000480-GPOS-00227378 ···························References: ·11,·12,·14,·15,·16,·18,·3,·5,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·DSS06.03,·DSS06.06,·3.1.2,·3.4.5,·CCI-000213,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·A.6.1.2,·A.7.1.1,·A.9.1.2,·A.9.2.1,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·SC-2(1),·CM-6(a),·PR.AC-4,·PR.AC-6,·PR.PT-3,·FIA_UAU.1,·SRG-OS-000480-GPOS-00227
Offset 5632, 15 lines modifiedOffset 5632, 15 lines modified
5632 Note·that·this·needs·to·be·done·for·each·MachineConfigPool5632 Note·that·this·needs·to·be·done·for·each·MachineConfigPool
5633 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.5633 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.
5634 $·sudo·service·bluetooth·stop5634 $·sudo·service·bluetooth·stop
5635 Rationale:·················Disabling·the·bluetooth·service·prevents·the·system·from·attempting·connections·to·Bluetooth·devices,·which·entails·some·security·risk.·Nevertheless,·variation·in·this·risk·decision·may·be·expected·due·to·the·utility·of·Bluetooth·connectivity·and·its·limited·range.5635 Rationale:·················Disabling·the·bluetooth·service·prevents·the·system·from·attempting·connections·to·Bluetooth·devices,·which·entails·some·security·risk.·Nevertheless,·variation·in·this·risk·decision·may·be·expected·due·to·the·utility·of·Bluetooth·connectivity·and·its·limited·range.
5636 Severity: ················medium5636 Severity: ················medium
5637 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_bluetooth_disabled5637 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_bluetooth_disabled
5638 Identifiers·and·References·References: ·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·3.1.16,·CCI-000085,·CCI-001551,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-45638 Identifiers·and·References·References: ·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·3.1.16,·CCI-000085,·CCI-001551,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
5639 Remediation_Kubernetes_snippet_⇲5639 Remediation_script_⇲
5640 Complexity:·low5640 Complexity:·low
5641 Disruption:·medium5641 Disruption:·medium
5642 Reboot:·····true5642 Reboot:·····true
5643 Strategy:···disable5643 Strategy:···disable
5644 apiVersion:·machineconfiguration.openshift.io/v15644 apiVersion:·machineconfiguration.openshift.io/v1
5645 kind:·MachineConfig5645 kind:·MachineConfig
5646 spec:5646 spec:
Offset 5651, 15 lines modifiedOffset 5651, 15 lines modified
5651 ······units:5651 ······units:
5652 ······-·name:·bluetooth.service5652 ······-·name:·bluetooth.service
5653 ········enabled:·false5653 ········enabled:·false
5654 ········mask:·true5654 ········mask:·true
5655 ······-·name:·bluetooth.socket5655 ······-·name:·bluetooth.socket
5656 ········enabled:·false5656 ········enabled:·false
5657 ········mask:·true5657 ········mask:·true
5658 Remediation_script_⇲5658 Remediation_Kubernetes_snippet_⇲
5659 Complexity:·low5659 Complexity:·low
5660 Disruption:·medium5660 Disruption:·medium
5661 Reboot:·····true5661 Reboot:·····true
5662 Strategy:···disable5662 Strategy:···disable
5663 apiVersion:·machineconfiguration.openshift.io/v15663 apiVersion:·machineconfiguration.openshift.io/v1
5664 kind:·MachineConfig5664 kind:·MachineConfig
5665 spec:5665 spec:
Offset 5917, 26 lines modifiedOffset 5917, 14 lines modified
5917 ···························Disabling·the·automounter·permits·the·administrator·to·statically·control·filesystem·mounting·through·/etc/fstab.5917 ···························Disabling·the·automounter·permits·the·administrator·to·statically·control·filesystem·mounting·through·/etc/fstab.
5918 Rationale:5918 Rationale:
5919 ···························Additionally,·automatically·mounting·filesystems·permits·easy·introduction·of·unknown·devices,·thereby·facilitating·malicious·activity.5919 ···························Additionally,·automatically·mounting·filesystems·permits·easy·introduction·of·unknown·devices,·thereby·facilitating·malicious·activity.
5920 Severity: ················medium5920 Severity: ················medium
5921 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_autofs_disabled5921 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_autofs_disabled
5922 Identifiers·and·References·Identifiers: ·CCE-82663-65922 Identifiers·and·References·Identifiers: ·CCE-82663-6
5923 ···························References: ·1,·12,·15,·16,·5,·APO13.01,·DSS01.04,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·3.4.6,·CCI-000366,·CCI-000778,·CCI-001958,·164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7,·SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002275923 ···························References: ·1,·12,·15,·16,·5,·APO13.01,·DSS01.04,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·3.4.6,·CCI-000366,·CCI-000778,·CCI-001958,·164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7,·SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
5924 Remediation_Kubernetes_snippet_⇲ 
5925 --- 
5926 apiVersion:·machineconfiguration.openshift.io/v1 
5927 kind:·MachineConfig 
5928 spec: 
5929 ··config: 
5930 ····ignition: 
5931 ······version:·3.1.0 
5932 ····systemd: 
5933 ······units: 
5934 ······-·enabled:·false 
5935 ········name:·autofs.service 
5936 Remediation_script_⇲5924 Remediation_script_⇲
5937 Complexity:·low5925 Complexity:·low
5938 Disruption:·medium5926 Disruption:·medium
5939 Reboot:·····true5927 Reboot:·····true
5940 Strategy:···disable5928 Strategy:···disable
5941 apiVersion:·machineconfiguration.openshift.io/v15929 apiVersion:·machineconfiguration.openshift.io/v1
5942 kind:·MachineConfig5930 kind:·MachineConfig
Offset 5948, 14 lines modifiedOffset 5936, 26 lines modified
5948 ······units:5936 ······units:
5949 ······-·name:·autofs.service5937 ······-·name:·autofs.service
5950 ········enabled:·false5938 ········enabled:·false
5951 ········mask:·true5939 ········mask:·true
5952 ······-·name:·autofs.socket5940 ······-·name:·autofs.socket
5953 ········enabled:·false5941 ········enabled:·false
5954 ········mask:·true5942 ········mask:·true
 5943 Remediation_Kubernetes_snippet_⇲
 5944 ---
 5945 apiVersion:·machineconfiguration.openshift.io/v1
 5946 kind:·MachineConfig
 5947 spec:
 5948 ··config:
 5949 ····ignition:
Max diff block lines reached; 2307/10146 bytes (22.74%) of diff not shown.
46.9 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-nerc-cip.html
    
Offset 19600, 84 lines modifiedOffset 19600, 84 lines modified
0004c8f0:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm60004c8f0:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
0004c900:·3231·3522·2074·6162·696e·6465·783d·2230··215"·tabindex="00004c900:·3231·3522·2074·6162·696e·6465·783d·2230··215"·tabindex="0
0004c910:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0004c910:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0004c920:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0004c920:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0004c930:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0004c930:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0004c940:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0004c940:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0004c950:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0004c950:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0004c960:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
0004c960:·6961·7469·6f6e·204b·7562·6572·6e65·7465··iation·Kubernete 
0004c970:·7320·736e·6970·7065·7420·e287·b23c·2f61··s·snippet·...</a 
0004c980:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0004c970:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0004c990:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0004c980:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0004c9a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0004c990:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0004c9b0:·6d36·3231·3522·3e3c·7072·653e·3c63·6f64··m6215"><pre><cod0004c9a0:·3d22·6964·6d36·3231·3522·3e3c·7461·626c··="idm6215"><tabl
 0004c9b0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0004c9c0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0004c9d0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0004c9e0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0004c9f0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0004ca00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0004ca10:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0004ca20:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0004ca30:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
 0004ca40:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0004ca50:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
 0004ca60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0004ca70:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0004ca80:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></
 0004ca90:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0004c9c0:·653e·2d2d·2d0a·6170·6956·6572·7369·6f6e··e>---.apiVersion0004caa0:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion
0004c9d0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu0004cab0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
0004c9e0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift0004cac0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
0004c9f0:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac0004cad0:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
0004ca00:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:0004cae0:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
0004ca10:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i0004caf0:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i
0004ca20:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v0004cb00:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v
0004ca30:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··0004cb10:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··
0004ca40:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····0004cb20:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····
0004ca50:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·0004cb30:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·
 0004cb40:·6e61·6d65·3a20·6465·6275·672d·7368·656c··name:·debug-shel
 0004cb50:·6c2e·7365·7276·6963·650a·2020·2020·2020··l.service.······
0004ca60:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.·0004cb60:·2020·656e·6162·6c65·643a·2066·616c·7365····enabled:·false
0004ca70:·2020·2020·2020·206e·616d·653a·2064·6562·········name:·deb 
0004ca80:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service0004cb70:·0a20·2020·2020·2020·206d·6173·6b3a·2074··.········mask:·t
 0004cb80:·7275·650a·2020·2020·2020·2d20·6e61·6d65··rue.······-·name
 0004cb90:·3a20·6465·6275·672d·7368·656c·6c2e·736f··:·debug-shell.so
 0004cba0:·636b·6574·0a20·2020·2020·2020·2065·6e61··cket.········ena
 0004cbb0:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.····
 0004cbc0:·2020·2020·6d61·736b·3a20·7472·7565·0a3c······mask:·true.<
0004ca90:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0004cbd0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0004caa0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0004cbe0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0004cab0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0004cbf0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0004cac0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0004cc00:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0004cad0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0004cc10:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0004cae0:·743d·2223·6964·6d36·3231·3622·2074·6162··t="#idm6216"·tab0004cc20:·2223·6964·6d36·3231·3622·2074·6162·696e··"#idm6216"·tabin
0004caf0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0004cc30:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0004cb00:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0004cc40:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0004cb10:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0004cc50:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0004cb20:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0004cc60:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0004cb30:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0004cc70:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0004cb40:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s0004cc80:·3e52·656d·6564·6961·7469·6f6e·204b·7562··>Remediation·Kub
 0004cc90:·6572·6e65·7465·7320·736e·6970·7065·7420··ernetes·snippet·
 0004cca0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0004ccb0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0004ccc0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0004ccd0:·6964·3d22·6964·6d36·3231·3622·3e3c·7072··id="idm6216"><pr
 0004cce0:·653e·3c63·6f64·653e·2d2d·2d0a·6170·6956··e><code>---.apiV
0004cb50:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0004cb60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0004cb70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0004cb80:·6170·7365·2220·6964·3d22·6964·6d36·3231··apse"·id="idm621 
0004cb90:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class= 
0004cba0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0004cbb0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0004cbc0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0004cbd0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0004cbe0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0004cbf0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0004cc00:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0004cc10:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium 
0004cc20:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0004cc30:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0004cc40:·643e·7472·7565·3c2f·7464·3e3c·2f74·723e··d>true</td></tr> 
0004cc50:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0004cc60:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl 
0004cc70:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0004cc80:·6c65·3e3c·7072·653e·3c63·6f64·653e·6170··le><pre><code>ap 
0004cc90:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin0004ccf0:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec
0004cca0:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o0004cd00:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope
0004ccb0:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k0004cd10:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin
0004ccc0:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf0004cd20:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig
0004ccd0:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi0004cd30:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:
0004cce0:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:0004cd40:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·
0004ccf0:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·0004cd50:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3.
0004cd00:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system0004cd60:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd:
0004cd10:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:.0004cd70:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.··
0004cd20:·2020·2020·2020·2d20·6e61·6d65·3a20·6465········-·name:·de0004cd80:·2020·2020·2d20·656e·6162·6c65·643a·2066······-·enabled:·f
0004cd30:·6275·672d·7368·656c·6c2e·7365·7276·6963··bug-shell.servic 
0004cd40:·650a·2020·2020·2020·2020·656e·6162·6c65··e.········enable 
0004cd50:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······0004cd90:·616c·7365·0a20·2020·2020·2020·206e·616d··alse.········nam
 0004cda0:·653a·2064·6562·7567·2d73·6865·6c6c·2e73··e:·debug-shell.s
0004cd60:·206d·6173·6b3a·2074·7275·650a·2020·2020···mask:·true.···· 
0004cd70:·2020·2d20·6e61·6d65·3a20·6465·6275·672d····-·name:·debug- 
0004cd80:·7368·656c·6c2e·736f·636b·6574·0a20·2020··shell.socket.··· 
0004cd90:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa 
0004cda0:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask 
0004cdb0:·3a20·7472·7565·0a3c·2f63·6f64·653e·3c2f··:·true.</code></0004cdb0:·6572·7669·6365·0a3c·2f63·6f64·653e·3c2f··ervice.</code></
0004cdc0:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>0004cdc0:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>
0004cdd0:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod0004cdd0:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod
0004cde0:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><0004cde0:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><
0004cdf0:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-0004cdf0:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-
0004ce00:·6964·3d22·7863·6364·665f·6f72·672e·7373··id="xccdf_org.ss0004ce00:·6964·3d22·7863·6364·665f·6f72·672e·7373··id="xccdf_org.ss
0004ce10:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content0004ce10:·6770·726f·6a65·6374·2e63·6f6e·7465·6e74··gproject.content
0004ce20:·5f72·756c·655f·636f·7265·6f73·5f64·6973··_rule_coreos_dis0004ce20:·5f72·756c·655f·636f·7265·6f73·5f64·6973··_rule_coreos_dis
Offset 152393, 66 lines modifiedOffset 152393, 66 lines modified
00253480:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00253480:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00253490:·6d33·3233·3734·2220·7461·6269·6e64·6578··m32374"·tabindex00253490:·6d33·3233·3734·2220·7461·6269·6e64·6578··m32374"·tabindex
002534a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto002534a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
002534b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded002534b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
002534c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="002534c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
002534d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve002534d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
002534e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re002534e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
002534f0:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern 
00253500:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·... 
00253510:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00253520:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00253530:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
Max diff block lines reached; 19376/37784 bytes (51.28%) of diff not shown.
9.93 KB
html2text {}
    
Offset 323, 26 lines modifiedOffset 323, 14 lines modified
323 Note·that·this·needs·to·be·done·for·each·MachineConfigPool323 Note·that·this·needs·to·be·done·for·each·MachineConfigPool
324 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.324 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.
325 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.325 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
326 Severity: ················medium326 Severity: ················medium
327 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled327 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
328 Identifiers·and·References·Identifiers: ·CCE-82496-1328 Identifiers·and·References·Identifiers: ·CCE-82496-1
329 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227329 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
330 Remediation_Kubernetes_snippet_⇲ 
331 --- 
332 apiVersion:·machineconfiguration.openshift.io/v1 
333 kind:·MachineConfig 
334 spec: 
335 ··config: 
336 ····ignition: 
337 ······version:·3.1.0 
338 ····systemd: 
339 ······units: 
340 ······-·enabled:·false 
341 ········name:·debug-shell.service 
342 Remediation_script_⇲330 Remediation_script_⇲
343 Complexity:·low331 Complexity:·low
344 Disruption:·medium332 Disruption:·medium
345 Reboot:·····true333 Reboot:·····true
346 Strategy:···disable334 Strategy:···disable
347 apiVersion:·machineconfiguration.openshift.io/v1335 apiVersion:·machineconfiguration.openshift.io/v1
348 kind:·MachineConfig336 kind:·MachineConfig
Offset 354, 14 lines modifiedOffset 342, 26 lines modified
354 ······units:342 ······units:
355 ······-·name:·debug-shell.service343 ······-·name:·debug-shell.service
356 ········enabled:·false344 ········enabled:·false
357 ········mask:·true345 ········mask:·true
358 ······-·name:·debug-shell.socket346 ······-·name:·debug-shell.socket
359 ········enabled:·false347 ········enabled:·false
360 ········mask:·true348 ········mask:·true
 349 Remediation_Kubernetes_snippet_⇲
 350 ---
 351 apiVersion:·machineconfiguration.openshift.io/v1
 352 kind:·MachineConfig
 353 spec:
 354 ··config:
 355 ····ignition:
 356 ······version:·3.1.0
 357 ····systemd:
 358 ······units:
 359 ······-·enabled:·false
 360 ········name:·debug-shell.service
361 ***·Rule  ·Verify·that·Interactive·Boot·is·Disabled·  [ref]·***361 ***·Rule  ·Verify·that·Interactive·Boot·is·Disabled·  [ref]·***
362 Red·Hat·Enterprise·Linux·CoreOS·4·systems·support·an·"interactive·boot"·option·that·can·be·used·to·prevent·services·from·being·started.·On·a·Red·Hat·Enterprise·Linux·CoreOS·4·system,·interactive·boot·can·be·enabled·by·providing·a·1,·yes,·true,·or·on·value·to·the·systemd.confirm_spawn·kernel·argument.362 Red·Hat·Enterprise·Linux·CoreOS·4·systems·support·an·"interactive·boot"·option·that·can·be·used·to·prevent·services·from·being·started.·On·a·Red·Hat·Enterprise·Linux·CoreOS·4·system,·interactive·boot·can·be·enabled·by·providing·a·1,·yes,·true,·or·on·value·to·the·systemd.confirm_spawn·kernel·argument.
363 Rationale:·················Using·interactive·boot,·the·console·user·could·disable·auditing,·firewalls,·or·other·services,·weakening·system·security.363 Rationale:·················Using·interactive·boot,·the·console·user·could·disable·auditing,·firewalls,·or·other·services,·weakening·system·security.
364 Severity: ················medium364 Severity: ················medium
365 Rule·ID:···················xccdf_org.ssgproject.content_rule_coreos_disable_interactive_boot365 Rule·ID:···················xccdf_org.ssgproject.content_rule_coreos_disable_interactive_boot
366 Identifiers·and·References·Identifiers: ·CCE-83548-8366 Identifiers·and·References·Identifiers: ·CCE-83548-8
367 ···························References: ·11,·12,·14,·15,·16,·18,·3,·5,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·DSS06.03,·DSS06.06,·3.1.2,·3.4.5,·CCI-000213,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·A.6.1.2,·A.7.1.1,·A.9.1.2,·A.9.2.1,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·SC-2(1),·CM-6(a),·PR.AC-4,·PR.AC-6,·PR.PT-3,·FIA_UAU.1,·SRG-OS-000480-GPOS-00227367 ···························References: ·11,·12,·14,·15,·16,·18,·3,·5,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·DSS06.03,·DSS06.06,·3.1.2,·3.4.5,·CCI-000213,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·A.6.1.2,·A.7.1.1,·A.9.1.2,·A.9.2.1,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·SC-2(1),·CM-6(a),·PR.AC-4,·PR.AC-6,·PR.PT-3,·FIA_UAU.1,·SRG-OS-000480-GPOS-00227
Offset 5621, 15 lines modifiedOffset 5621, 15 lines modified
5621 Note·that·this·needs·to·be·done·for·each·MachineConfigPool5621 Note·that·this·needs·to·be·done·for·each·MachineConfigPool
5622 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.5622 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·the_relevant_documentation.
5623 $·sudo·service·bluetooth·stop5623 $·sudo·service·bluetooth·stop
5624 Rationale:·················Disabling·the·bluetooth·service·prevents·the·system·from·attempting·connections·to·Bluetooth·devices,·which·entails·some·security·risk.·Nevertheless,·variation·in·this·risk·decision·may·be·expected·due·to·the·utility·of·Bluetooth·connectivity·and·its·limited·range.5624 Rationale:·················Disabling·the·bluetooth·service·prevents·the·system·from·attempting·connections·to·Bluetooth·devices,·which·entails·some·security·risk.·Nevertheless,·variation·in·this·risk·decision·may·be·expected·due·to·the·utility·of·Bluetooth·connectivity·and·its·limited·range.
5625 Severity: ················medium5625 Severity: ················medium
5626 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_bluetooth_disabled5626 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_bluetooth_disabled
5627 Identifiers·and·References·References: ·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·3.1.16,·CCI-000085,·CCI-001551,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-45627 Identifiers·and·References·References: ·11,·12,·14,·15,·3,·8,·9,·APO13.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.04,·DSS05.02,·DSS05.03,·DSS05.05,·DSS06.06,·3.1.16,·CCI-000085,·CCI-001551,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR_2.6,·SR_2.7,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2,·AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
5628 Remediation_Kubernetes_snippet_⇲5628 Remediation_script_⇲
5629 Complexity:·low5629 Complexity:·low
5630 Disruption:·medium5630 Disruption:·medium
5631 Reboot:·····true5631 Reboot:·····true
5632 Strategy:···disable5632 Strategy:···disable
5633 apiVersion:·machineconfiguration.openshift.io/v15633 apiVersion:·machineconfiguration.openshift.io/v1
5634 kind:·MachineConfig5634 kind:·MachineConfig
5635 spec:5635 spec:
Offset 5640, 15 lines modifiedOffset 5640, 15 lines modified
5640 ······units:5640 ······units:
5641 ······-·name:·bluetooth.service5641 ······-·name:·bluetooth.service
5642 ········enabled:·false5642 ········enabled:·false
5643 ········mask:·true5643 ········mask:·true
5644 ······-·name:·bluetooth.socket5644 ······-·name:·bluetooth.socket
5645 ········enabled:·false5645 ········enabled:·false
5646 ········mask:·true5646 ········mask:·true
5647 Remediation_script_⇲5647 Remediation_Kubernetes_snippet_⇲
5648 Complexity:·low5648 Complexity:·low
5649 Disruption:·medium5649 Disruption:·medium
5650 Reboot:·····true5650 Reboot:·····true
5651 Strategy:···disable5651 Strategy:···disable
5652 apiVersion:·machineconfiguration.openshift.io/v15652 apiVersion:·machineconfiguration.openshift.io/v1
5653 kind:·MachineConfig5653 kind:·MachineConfig
5654 spec:5654 spec:
Offset 5906, 26 lines modifiedOffset 5906, 14 lines modified
5906 ···························Disabling·the·automounter·permits·the·administrator·to·statically·control·filesystem·mounting·through·/etc/fstab.5906 ···························Disabling·the·automounter·permits·the·administrator·to·statically·control·filesystem·mounting·through·/etc/fstab.
5907 Rationale:5907 Rationale:
5908 ···························Additionally,·automatically·mounting·filesystems·permits·easy·introduction·of·unknown·devices,·thereby·facilitating·malicious·activity.5908 ···························Additionally,·automatically·mounting·filesystems·permits·easy·introduction·of·unknown·devices,·thereby·facilitating·malicious·activity.
5909 Severity: ················medium5909 Severity: ················medium
5910 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_autofs_disabled5910 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_autofs_disabled
5911 Identifiers·and·References·Identifiers: ·CCE-82663-65911 Identifiers·and·References·Identifiers: ·CCE-82663-6
5912 ···························References: ·1,·12,·15,·16,·5,·APO13.01,·DSS01.04,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·3.4.6,·CCI-000366,·CCI-000778,·CCI-001958,·164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7,·SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002275912 ···························References: ·1,·12,·15,·16,·5,·APO13.01,·DSS01.04,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·3.4.6,·CCI-000366,·CCI-000778,·CCI-001958,·164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b),·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.13,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-7(a),·CM-7(b),·CM-6(a),·MP-7,·PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7,·SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
5913 Remediation_Kubernetes_snippet_⇲ 
5914 --- 
5915 apiVersion:·machineconfiguration.openshift.io/v1 
5916 kind:·MachineConfig 
5917 spec: 
5918 ··config: 
5919 ····ignition: 
5920 ······version:·3.1.0 
5921 ····systemd: 
5922 ······units: 
5923 ······-·enabled:·false 
5924 ········name:·autofs.service 
5925 Remediation_script_⇲5913 Remediation_script_⇲
5926 Complexity:·low5914 Complexity:·low
5927 Disruption:·medium5915 Disruption:·medium
5928 Reboot:·····true5916 Reboot:·····true
5929 Strategy:···disable5917 Strategy:···disable
5930 apiVersion:·machineconfiguration.openshift.io/v15918 apiVersion:·machineconfiguration.openshift.io/v1
5931 kind:·MachineConfig5919 kind:·MachineConfig
Offset 5937, 14 lines modifiedOffset 5925, 26 lines modified
5937 ······units:5925 ······units:
5938 ······-·name:·autofs.service5926 ······-·name:·autofs.service
5939 ········enabled:·false5927 ········enabled:·false
5940 ········mask:·true5928 ········mask:·true
5941 ······-·name:·autofs.socket5929 ······-·name:·autofs.socket
5942 ········enabled:·false5930 ········enabled:·false
5943 ········mask:·true5931 ········mask:·true
 5932 Remediation_Kubernetes_snippet_⇲
 5933 ---
 5934 apiVersion:·machineconfiguration.openshift.io/v1
 5935 kind:·MachineConfig
 5936 spec:
 5937 ··config:
 5938 ····ignition:
Max diff block lines reached; 2307/10146 bytes (22.74%) of diff not shown.
1.54 MB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-C2S.html
    
Offset 15409, 117 lines modifiedOffset 15409, 117 lines modified
0003c300:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003c300:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003c310:·3d22·2369·646d·3935·3637·2220·7461·6269··="#idm9567"·tabi0003c310:·3d22·2369·646d·3935·3637·2220·7461·6269··="#idm9567"·tabi
0003c320:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003c320:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003c330:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003c330:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003c340:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003c340:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003c350:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003c350:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003c360:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003c360:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003c370:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003c370:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003c380:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003c380:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003c390:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c390:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003c3a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c3a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003c3b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c3b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003c3c0:·643d·2269·646d·3935·3637·223e·3c74·6162··d="idm9567"><tab0003c3c0:·2269·646d·3935·3637·223e·3c74·6162·6c65··"idm9567"><table
0003c3d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c3d0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003c3e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c3e0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003c3f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c3f0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003c400:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c400:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003c410:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c410:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003c420:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c420:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c430:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c430:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003c440:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c440:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003c450:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c450:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c460:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c460:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003c470:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003c470:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003c480:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003c480:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003c490:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0003c490:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
0003c4a0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide0003c4a0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003c4b0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003c4c0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003c4d0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003c4e0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003c4f0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003c500:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003c510:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003c520:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003c530:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003c540:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003c550:·2369·646d·3935·3638·2220·7461·6269·6e64··#idm9568"·tabind
 0003c560:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003c570:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003c580:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003c590:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003c5a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003c5b0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003c5c0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003c5d0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003c5e0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003c5f0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003c600:·3935·3638·223e·3c74·6162·6c65·2063·6c61··9568"><table·cla
 0003c610:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003c620:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003c630:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003c640:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003c650:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003c660:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c670:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003c680:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003c690:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c6a0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003c6b0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003c6c0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c6d0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003c6e0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003c6f0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003c700:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003c710:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
 0003c720:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 0003c730:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
 0003c740:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the
 0003c750:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003c760:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003c770:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 0003c780:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003c790:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003c7a0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003c7b0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003c7c0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003c7d0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
0003c4b0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003c7e0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003c4c0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003c7f0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003c4d0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003c800:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003c4e0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003c810:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003c4f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003c820:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c500:·743d·2223·6964·6d39·3536·3822·2074·6162··t="#idm9568"·tab0003c830:·743d·2223·6964·6d39·3536·3922·2074·6162··t="#idm9569"·tab
0003c510:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003c840:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c520:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003c850:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c530:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003c860:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c540:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003c870:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c550:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003c880:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c560:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003c890:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003c570:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003c8a0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003c580:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c8b0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003c590:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003c8c0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003c5a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003c8d0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003c5b0:·3d22·6964·6d39·3536·3822·3e3c·7461·626c··="idm9568"><tabl0003c8e0:·6964·3d22·6964·6d39·3536·3922·3e3c·7461··id="idm9569"><ta
0003c5c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003c8f0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003c5d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003c900:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003c5e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003c910:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003c5f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003c920:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003c600:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003c930:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003c610:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c940:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003c620:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003c950:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c630:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003c960:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003c640:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c970:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c650:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003c980:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003c660:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c990:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003c670:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003c9a0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003c680:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003c9b0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003c9c0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
0003c690:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003c6a0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003c6b0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003c6c0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003c6d0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003c6e0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003c6f0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c700:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c710:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c720:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c730:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c740:·2223·6964·6d39·3536·3922·2074·6162·696e··"#idm9569"·tabin 
0003c750:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c760:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c770:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c780:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c790:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c7a0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
Max diff block lines reached; 1257099/1271893 bytes (98.84%) of diff not shown.
340 KB
html2text {}
    
Offset 105, 20 lines modifiedOffset 105, 14 lines modified
105 Identifiers·and·References·Identifiers: ·CCE-27096-7105 Identifiers·and·References·Identifiers: ·CCE-27096-7
106 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule106 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
107 Remediation_OSBuild_Blueprint_snippet_⇲107 Remediation_OSBuild_Blueprint_snippet_⇲
  
108 [[packages]]108 [[packages]]
109 name·=·"aide"109 name·=·"aide"
110 version·=·"*"110 version·=·"*"
111 Remediation_Anaconda_snippet_⇲ 
112 Complexity:·low 
113 Disruption:·low 
114 Strategy:···enable 
  
115 package·--add=aide 
116 Remediation_Puppet_snippet_⇲111 Remediation_Puppet_snippet_⇲
117 Complexity:·low112 Complexity:·low
118 Disruption:·low113 Disruption:·low
119 Strategy:···enable114 Strategy:···enable
120 include·install_aide115 include·install_aide
  
121 class·install_aide·{116 class·install_aide·{
Offset 136, 14 lines modifiedOffset 130, 20 lines modified
136 if·!·rpm·-q·--quiet·"aide"·;·then130 if·!·rpm·-q·--quiet·"aide"·;·then
137 ····yum·install·-y·"aide"131 ····yum·install·-y·"aide"
138 fi132 fi
  
139 else133 else
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
141 fi135 fi
 136 Remediation_Anaconda_snippet_⇲
 137 Complexity:·low
 138 Disruption:·low
 139 Strategy:···enable
  
 140 package·--add=aide
142 Remediation_Ansible_snippet_⇲141 Remediation_Ansible_snippet_⇲
143 Complexity:·low142 Complexity:·low
144 Disruption:·low143 Disruption:·low
145 Strategy:···enable144 Strategy:···enable
146 -·name:·Ensure·aide·is·installed145 -·name:·Ensure·aide·is·installed
147 ··package:146 ··package:
148 ····name:·aide147 ····name:·aide
Offset 5391, 15 lines modifiedOffset 5391, 15 lines modified
5391 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.5391 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
5392 Severity: ················medium5392 Severity: ················medium
5393 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod5393 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
5394 Identifiers·and·References·Identifiers: ·CCE-27339-15394 Identifiers·and·References·Identifiers: ·CCE-27339-1
5395 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule5395 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
5396 Remediation_Shell_script_⇲5396 Remediation_Shell_script_⇲
5397 #·Remediation·is·applicable·only·in·certain·platforms5397 #·Remediation·is·applicable·only·in·certain·platforms
5398 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then5398 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
5399 #·First·perform·the·remediation·of·the·syscall·rule5399 #·First·perform·the·remediation·of·the·syscall·rule
5400 #·Retrieve·hardware·architecture·of·the·underlying·system5400 #·Retrieve·hardware·architecture·of·the·underlying·system
5401 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")5401 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
5402 for·ARCH·in·"${RULE_ARCHS[@]}"5402 for·ARCH·in·"${RULE_ARCHS[@]}"
5403 do5403 do
Offset 5747, 16 lines modifiedOffset 5747, 16 lines modified
5747 ··-·reboot_required5747 ··-·reboot_required
5748 ··-·restrict_strategy5748 ··-·restrict_strategy
  
5749 -·name:·Set·architecture·for·audit·chmod·tasks5749 -·name:·Set·architecture·for·audit·chmod·tasks
5750 ··set_fact:5750 ··set_fact:
5751 ····audit_arch:·b645751 ····audit_arch:·b64
5752 ··when:5752 ··when:
5753 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5754 ··-·'"audit"·in·ansible_facts.packages'5753 ··-·'"audit"·in·ansible_facts.packages'
 5754 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5755 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5755 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5756 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5756 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5757 ··tags:5757 ··tags:
5758 ··-·CCE-27339-15758 ··-·CCE-27339-1
5759 ··-·CJIS-5.4.1.15759 ··-·CJIS-5.4.1.1
5760 ··-·DISA-STIG-RHEL-07-0304105760 ··-·DISA-STIG-RHEL-07-030410
5761 ··-·NIST-800-171-3.1.75761 ··-·NIST-800-171-3.1.7
Offset 5894, 16 lines modifiedOffset 5894, 16 lines modified
5894 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005894 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
5895 ········-F·auid!=unset·-F·key=perm_mod5895 ········-F·auid!=unset·-F·key=perm_mod
5896 ······create:·true5896 ······create:·true
5897 ······mode:·o-rwx5897 ······mode:·o-rwx
5898 ······state:·present5898 ······state:·present
5899 ····when:·syscalls_found·|·length·==·05899 ····when:·syscalls_found·|·length·==·0
5900 ··when:5900 ··when:
5901 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5902 ··-·'"audit"·in·ansible_facts.packages'5901 ··-·'"audit"·in·ansible_facts.packages'
 5902 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5903 ··tags:5903 ··tags:
5904 ··-·CCE-27339-15904 ··-·CCE-27339-1
5905 ··-·CJIS-5.4.1.15905 ··-·CJIS-5.4.1.1
5906 ··-·DISA-STIG-RHEL-07-0304105906 ··-·DISA-STIG-RHEL-07-030410
5907 ··-·NIST-800-171-3.1.75907 ··-·NIST-800-171-3.1.7
5908 ··-·NIST-800-53-AU-12(c)5908 ··-·NIST-800-53-AU-12(c)
5909 ··-·NIST-800-53-AU-2(d)5909 ··-·NIST-800-53-AU-2(d)
Offset 6039, 16 lines modifiedOffset 6039, 16 lines modified
6039 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006039 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6040 ········-F·auid!=unset·-F·key=perm_mod6040 ········-F·auid!=unset·-F·key=perm_mod
6041 ······create:·true6041 ······create:·true
6042 ······mode:·o-rwx6042 ······mode:·o-rwx
6043 ······state:·present6043 ······state:·present
6044 ····when:·syscalls_found·|·length·==·06044 ····when:·syscalls_found·|·length·==·0
6045 ··when:6045 ··when:
6046 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6047 ··-·'"audit"·in·ansible_facts.packages'6046 ··-·'"audit"·in·ansible_facts.packages'
 6047 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6048 ··-·audit_arch·==·"b64"6048 ··-·audit_arch·==·"b64"
6049 ··tags:6049 ··tags:
6050 ··-·CCE-27339-16050 ··-·CCE-27339-1
6051 ··-·CJIS-5.4.1.16051 ··-·CJIS-5.4.1.1
6052 ··-·DISA-STIG-RHEL-07-0304106052 ··-·DISA-STIG-RHEL-07-030410
6053 ··-·NIST-800-171-3.1.76053 ··-·NIST-800-171-3.1.7
6054 ··-·NIST-800-53-AU-12(c)6054 ··-·NIST-800-53-AU-12(c)
Offset 6074, 15 lines modifiedOffset 6074, 15 lines modified
6074 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.6074 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
6075 Severity: ················medium6075 Severity: ················medium
6076 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown6076 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
6077 Identifiers·and·References·Identifiers: ·CCE-27364-96077 Identifiers·and·References·Identifiers: ·CCE-27364-9
6078 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030370,·4.1.9,·SV-204517r809570_rule6078 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030370,·4.1.9,·SV-204517r809570_rule
6079 Remediation_Shell_script_⇲6079 Remediation_Shell_script_⇲
6080 #·Remediation·is·applicable·only·in·certain·platforms6080 #·Remediation·is·applicable·only·in·certain·platforms
6081 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then6081 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
6082 #·First·perform·the·remediation·of·the·syscall·rule6082 #·First·perform·the·remediation·of·the·syscall·rule
6083 #·Retrieve·hardware·architecture·of·the·underlying·system6083 #·Retrieve·hardware·architecture·of·the·underlying·system
6084 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6084 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6085 for·ARCH·in·"${RULE_ARCHS[@]}"6085 for·ARCH·in·"${RULE_ARCHS[@]}"
6086 do6086 do
Max diff block lines reached; 339295/347856 bytes (97.54%) of diff not shown.
641 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-anssi_nt28_enhanced.html
    
Offset 15337, 117 lines modifiedOffset 15337, 117 lines modified
0003be80:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003be80:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003be90:·743d·2223·6964·6d39·3536·3722·2074·6162··t="#idm9567"·tab0003be90:·743d·2223·6964·6d39·3536·3722·2074·6162··t="#idm9567"·tab
0003bea0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003bea0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003beb0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003beb0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003bec0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bec0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bed0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bed0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bee0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bee0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bef0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003bef0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003bf00:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003bf00:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0003bf10:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003bf10:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003bf20:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003bf20:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003bf30:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003bf30:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003bf40:·6964·3d22·6964·6d39·3536·3722·3e3c·7461··id="idm9567"><ta0003bf40:·3d22·6964·6d39·3536·3722·3e3c·7461·626c··="idm9567"><tabl
0003bf50:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003bf50:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003bf60:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003bf60:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003bf70:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003bf70:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003bf80:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003bf80:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003bf90:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003bf90:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003bfa0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003bfa0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bfb0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bfb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003bfc0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003bfc0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003bfd0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bfd0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003bfe0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003bfe0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003bff0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003bff0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003c000:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003c000:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003c010:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0003c010:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0003c020:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid0003c020:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003c030:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003c040:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003c050:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003c060:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003c070:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003c080:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003c090:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003c0a0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003c0b0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003c0c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003c0d0:·2223·6964·6d39·3536·3822·2074·6162·696e··"#idm9568"·tabin
 0003c0e0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003c0f0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003c100:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003c110:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003c120:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003c130:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003c140:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003c150:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003c160:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003c170:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003c180:·6d39·3536·3822·3e3c·7461·626c·6520·636c··m9568"><table·cl
 0003c190:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003c1a0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003c1b0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003c1c0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003c1d0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003c1e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003c1f0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003c200:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003c210:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003c220:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003c230:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003c240:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c250:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003c260:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003c270:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003c280:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003c290:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
 0003c2a0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 0003c2b0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
 0003c2c0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th
 0003c2d0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003c2e0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003c2f0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003c300:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003c310:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003c320:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003c330:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003c340:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003c350:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
0003c030:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0003c360:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
0003c040:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003c370:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003c050:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003c380:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003c060:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003c390:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003c070:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003c3a0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003c080:·6574·3d22·2369·646d·3935·3638·2220·7461··et="#idm9568"·ta0003c3b0:·6574·3d22·2369·646d·3935·3639·2220·7461··et="#idm9569"·ta
0003c090:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c3c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c0a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c3d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c0b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c3e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c0c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c3f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c0d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c400:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c0e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c410:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c0f0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003c420:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003c100:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c430:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c110:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c440:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c120:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c450:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c130:·643d·2269·646d·3935·3638·223e·3c74·6162··d="idm9568"><tab0003c460:·2069·643d·2269·646d·3935·3639·223e·3c74···id="idm9569"><t
0003c140:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c470:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c150:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c480:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c160:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c490:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c170:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c4a0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c180:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c4b0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c190:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c4c0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003c1a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c4d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c1b0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c4e0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003c1c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c4f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c1d0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c500:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003c1e0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003c510:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003c1f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003c520:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003c200:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003c530:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003c540:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
0003c210:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003c220:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003c230:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003c240:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003c250:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003c260:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003c270:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003c280:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003c290:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003c2a0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003c2b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003c2c0:·3d22·2369·646d·3935·3639·2220·7461·6269··="#idm9569"·tabi 
0003c2d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003c2e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003c2f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003c300:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003c310:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003c320:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
Max diff block lines reached; 583886/598680 bytes (97.53%) of diff not shown.
56.1 KB
html2text {}
    
Offset 93, 20 lines modifiedOffset 93, 14 lines modified
93 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,93 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
94 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule94 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
95 Remediation_OSBuild_Blueprint_snippet_⇲95 Remediation_OSBuild_Blueprint_snippet_⇲
  
96 [[packages]]96 [[packages]]
97 name·=·"aide"97 name·=·"aide"
98 version·=·"*"98 version·=·"*"
99 Remediation_Anaconda_snippet_⇲ 
100 Complexity:·low 
101 Disruption:·low 
102 Strategy:···enable 
  
103 package·--add=aide 
104 Remediation_Puppet_snippet_⇲99 Remediation_Puppet_snippet_⇲
105 Complexity:·low100 Complexity:·low
106 Disruption:·low101 Disruption:·low
107 Strategy:···enable102 Strategy:···enable
108 include·install_aide103 include·install_aide
  
109 class·install_aide·{104 class·install_aide·{
Offset 124, 14 lines modifiedOffset 118, 20 lines modified
124 if·!·rpm·-q·--quiet·"aide"·;·then118 if·!·rpm·-q·--quiet·"aide"·;·then
125 ····yum·install·-y·"aide"119 ····yum·install·-y·"aide"
126 fi120 fi
  
127 else121 else
128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'122 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
129 fi123 fi
 124 Remediation_Anaconda_snippet_⇲
 125 Complexity:·low
 126 Disruption:·low
 127 Strategy:···enable
  
 128 package·--add=aide
130 Remediation_Ansible_snippet_⇲129 Remediation_Ansible_snippet_⇲
131 Complexity:·low130 Complexity:·low
132 Disruption:·low131 Disruption:·low
133 Strategy:···enable132 Strategy:···enable
134 -·name:·Ensure·aide·is·installed133 -·name:·Ensure·aide·is·installed
135 ··package:134 ··package:
136 ····name:·aide135 ····name:·aide
Offset 452, 20 lines modifiedOffset 452, 14 lines modified
452 Identifiers·and·References·Identifiers: ·CCE-82213-0452 Identifiers·and·References·Identifiers: ·CCE-82213-0
453 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1453 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1
454 Remediation_OSBuild_Blueprint_snippet_⇲454 Remediation_OSBuild_Blueprint_snippet_⇲
  
455 [[packages]]455 [[packages]]
456 name·=·"sudo"456 name·=·"sudo"
457 version·=·"*"457 version·=·"*"
458 Remediation_Anaconda_snippet_⇲ 
459 Complexity:·low 
460 Disruption:·low 
461 Strategy:···enable 
  
462 package·--add=sudo 
463 Remediation_Puppet_snippet_⇲458 Remediation_Puppet_snippet_⇲
464 Complexity:·low459 Complexity:·low
465 Disruption:·low460 Disruption:·low
466 Strategy:···enable461 Strategy:···enable
467 include·install_sudo462 include·install_sudo
  
468 class·install_sudo·{463 class·install_sudo·{
Offset 483, 14 lines modifiedOffset 477, 20 lines modified
483 if·!·rpm·-q·--quiet·"sudo"·;·then477 if·!·rpm·-q·--quiet·"sudo"·;·then
484 ····yum·install·-y·"sudo"478 ····yum·install·-y·"sudo"
485 fi479 fi
  
486 else480 else
487 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'481 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
488 fi482 fi
 483 Remediation_Anaconda_snippet_⇲
 484 Complexity:·low
 485 Disruption:·low
 486 Strategy:···enable
  
 487 package·--add=sudo
489 Remediation_Ansible_snippet_⇲488 Remediation_Ansible_snippet_⇲
490 Complexity:·low489 Complexity:·low
491 Disruption:·low490 Disruption:·low
492 Strategy:···enable491 Strategy:···enable
493 -·name:·Ensure·sudo·is·installed492 -·name:·Ensure·sudo·is·installed
494 ··package:493 ··package:
495 ····name:·sudo494 ····name:·sudo
Offset 7836, 15 lines modifiedOffset 7836, 15 lines modified
7836 Severity: ·medium7836 Severity: ·medium
7837 Rule·ID:····xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo7837 Rule·ID:····xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo
7838 Identifiers·Identifiers: ·CCE-80401-37838 Identifiers·Identifiers: ·CCE-80401-3
7839 and·········References: ·BP28(R19),·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR7839 and·········References: ·BP28(R19),·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR
7840 References··2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·RHEL-07-030690,·SV-204548r861044_rule7840 References··2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·RHEL-07-030690,·SV-204548r861044_rule
7841 Remediation_Shell_script_⇲7841 Remediation_Shell_script_⇲
7842 #·Remediation·is·applicable·only·in·certain·platforms7842 #·Remediation·is·applicable·only·in·certain·platforms
7843 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then7843 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
7844 ACTION_ARCH_FILTERS="-a·always,exit"7844 ACTION_ARCH_FILTERS="-a·always,exit"
7845 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"7845 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
7846 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"7846 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
7847 SYSCALL=""7847 SYSCALL=""
7848 KEY="privileged"7848 KEY="privileged"
7849 SYSCALL_GROUPING=""7849 SYSCALL_GROUPING=""
Offset 8297, 16 lines modifiedOffset 8297, 16 lines modified
8297 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x8297 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
8298 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged8298 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
8299 ······create:·true8299 ······create:·true
8300 ······mode:·o-rwx8300 ······mode:·o-rwx
8301 ······state:·present8301 ······state:·present
8302 ····when:·syscalls_found·|·length·==·08302 ····when:·syscalls_found·|·length·==·0
8303 ··when:8303 ··when:
8304 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8305 ··-·'"audit"·in·ansible_facts.packages'8304 ··-·'"audit"·in·ansible_facts.packages'
 8305 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8306 ··tags:8306 ··tags:
8307 ··-·CCE-80401-38307 ··-·CCE-80401-3
8308 ··-·DISA-STIG-RHEL-07-0306908308 ··-·DISA-STIG-RHEL-07-030690
8309 ··-·NIST-800-171-3.1.78309 ··-·NIST-800-171-3.1.7
8310 ··-·NIST-800-53-AC-6(9)8310 ··-·NIST-800-53-AC-6(9)
8311 ··-·NIST-800-53-AU-12(c)8311 ··-·NIST-800-53-AU-12(c)
8312 ··-·NIST-800-53-AU-2(d)8312 ··-·NIST-800-53-AU-2(d)
Offset 8987, 20 lines modifiedOffset 8987, 14 lines modified
8987 Identifiers·and·References·Identifiers: ·CCE-86724-28987 Identifiers·and·References·Identifiers: ·CCE-86724-2
8988 ···························References: ·BP28(R43),·CCI-000366,·FTP_ITC_EXT.1.1,·SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-000618988 ···························References: ·BP28(R43),·CCI-000366,·FTP_ITC_EXT.1.1,·SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-00061
8989 Remediation_OSBuild_Blueprint_snippet_⇲8989 Remediation_OSBuild_Blueprint_snippet_⇲
  
8990 [[packages]]8990 [[packages]]
8991 name·=·"rsyslog-gnutls"8991 name·=·"rsyslog-gnutls"
8992 version·=·"*"8992 version·=·"*"
8993 Remediation_Anaconda_snippet_⇲ 
8994 Complexity:·low 
Max diff block lines reached; 52241/57447 bytes (90.94%) of diff not shown.
698 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-anssi_nt28_high.html
    
Offset 15336, 117 lines modifiedOffset 15336, 117 lines modified
0003be70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003be70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003be80:·743d·2223·6964·6d39·3536·3722·2074·6162··t="#idm9567"·tab0003be80:·743d·2223·6964·6d39·3536·3722·2074·6162··t="#idm9567"·tab
0003be90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003be90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003bea0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bea0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003beb0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003beb0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bec0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bec0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bed0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bed0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bee0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003bee0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003bef0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003bef0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0003bf00:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003bf00:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003bf10:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003bf10:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003bf20:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003bf20:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003bf30:·6964·3d22·6964·6d39·3536·3722·3e3c·7461··id="idm9567"><ta0003bf30:·3d22·6964·6d39·3536·3722·3e3c·7461·626c··="idm9567"><tabl
0003bf40:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003bf40:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003bf50:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003bf50:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003bf60:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003bf60:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003bf70:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003bf70:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003bf80:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003bf80:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003bf90:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003bf90:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bfa0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bfa0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003bfb0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003bfb0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003bfc0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bfc0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003bfd0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003bfd0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003bfe0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003bfe0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003bff0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003bff0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003c000:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0003c000:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0003c010:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid0003c010:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003c020:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003c030:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003c040:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003c050:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003c060:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003c070:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003c080:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003c090:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003c0a0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003c0b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003c0c0:·2223·6964·6d39·3536·3822·2074·6162·696e··"#idm9568"·tabin
 0003c0d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003c0e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003c0f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003c100:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003c110:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003c120:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003c130:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003c140:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003c150:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003c160:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003c170:·6d39·3536·3822·3e3c·7461·626c·6520·636c··m9568"><table·cl
 0003c180:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003c190:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003c1a0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003c1b0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003c1c0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003c1d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003c1e0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003c1f0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003c200:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003c210:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003c220:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003c230:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c240:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003c250:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003c260:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003c270:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003c280:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
 0003c290:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 0003c2a0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
 0003c2b0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th
 0003c2c0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003c2d0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003c2e0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003c2f0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003c300:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003c310:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003c320:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003c330:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003c340:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
0003c020:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0003c350:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
0003c030:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003c360:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003c040:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003c370:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003c050:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003c380:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003c060:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003c390:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003c070:·6574·3d22·2369·646d·3935·3638·2220·7461··et="#idm9568"·ta0003c3a0:·6574·3d22·2369·646d·3935·3639·2220·7461··et="#idm9569"·ta
0003c080:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c3b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c090:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c3c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c0a0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c3d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c0b0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c3e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c0c0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c3f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c0d0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c400:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c0e0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003c410:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003c0f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c420:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c100:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c430:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c110:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c440:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c120:·643d·2269·646d·3935·3638·223e·3c74·6162··d="idm9568"><tab0003c450:·2069·643d·2269·646d·3935·3639·223e·3c74···id="idm9569"><t
0003c130:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c460:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c140:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c470:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c150:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c480:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c160:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c490:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c170:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c4a0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c180:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c4b0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003c190:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c4c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c1a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c4d0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003c1b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c4e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c1c0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c4f0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003c1d0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003c500:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003c1e0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003c510:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003c1f0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003c520:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003c530:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
0003c200:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003c210:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003c220:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003c230:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003c240:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003c250:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003c260:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003c270:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003c280:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003c290:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003c2a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003c2b0:·3d22·2369·646d·3935·3639·2220·7461·6269··="#idm9569"·tabi 
0003c2c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003c2d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003c2e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003c2f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003c300:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003c310:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
Max diff block lines reached; 638350/653144 bytes (97.73%) of diff not shown.
60.3 KB
html2text {}
    
Offset 93, 20 lines modifiedOffset 93, 14 lines modified
93 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,93 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
94 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule94 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
95 Remediation_OSBuild_Blueprint_snippet_⇲95 Remediation_OSBuild_Blueprint_snippet_⇲
  
96 [[packages]]96 [[packages]]
97 name·=·"aide"97 name·=·"aide"
98 version·=·"*"98 version·=·"*"
99 Remediation_Anaconda_snippet_⇲ 
100 Complexity:·low 
101 Disruption:·low 
102 Strategy:···enable 
  
103 package·--add=aide 
104 Remediation_Puppet_snippet_⇲99 Remediation_Puppet_snippet_⇲
105 Complexity:·low100 Complexity:·low
106 Disruption:·low101 Disruption:·low
107 Strategy:···enable102 Strategy:···enable
108 include·install_aide103 include·install_aide
  
109 class·install_aide·{104 class·install_aide·{
Offset 124, 14 lines modifiedOffset 118, 20 lines modified
124 if·!·rpm·-q·--quiet·"aide"·;·then118 if·!·rpm·-q·--quiet·"aide"·;·then
125 ····yum·install·-y·"aide"119 ····yum·install·-y·"aide"
126 fi120 fi
  
127 else121 else
128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'122 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
129 fi123 fi
 124 Remediation_Anaconda_snippet_⇲
 125 Complexity:·low
 126 Disruption:·low
 127 Strategy:···enable
  
 128 package·--add=aide
130 Remediation_Ansible_snippet_⇲129 Remediation_Ansible_snippet_⇲
131 Complexity:·low130 Complexity:·low
132 Disruption:·low131 Disruption:·low
133 Strategy:···enable132 Strategy:···enable
134 -·name:·Ensure·aide·is·installed133 -·name:·Ensure·aide·is·installed
135 ··package:134 ··package:
136 ····name:·aide135 ····name:·aide
Offset 770, 20 lines modifiedOffset 770, 14 lines modified
770 Identifiers·and·References·Identifiers: ·CCE-82213-0770 Identifiers·and·References·Identifiers: ·CCE-82213-0
771 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1771 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1
772 Remediation_OSBuild_Blueprint_snippet_⇲772 Remediation_OSBuild_Blueprint_snippet_⇲
  
773 [[packages]]773 [[packages]]
774 name·=·"sudo"774 name·=·"sudo"
775 version·=·"*"775 version·=·"*"
776 Remediation_Anaconda_snippet_⇲ 
777 Complexity:·low 
778 Disruption:·low 
779 Strategy:···enable 
  
780 package·--add=sudo 
781 Remediation_Puppet_snippet_⇲776 Remediation_Puppet_snippet_⇲
782 Complexity:·low777 Complexity:·low
783 Disruption:·low778 Disruption:·low
784 Strategy:···enable779 Strategy:···enable
785 include·install_sudo780 include·install_sudo
  
786 class·install_sudo·{781 class·install_sudo·{
Offset 801, 14 lines modifiedOffset 795, 20 lines modified
801 if·!·rpm·-q·--quiet·"sudo"·;·then795 if·!·rpm·-q·--quiet·"sudo"·;·then
802 ····yum·install·-y·"sudo"796 ····yum·install·-y·"sudo"
803 fi797 fi
  
804 else798 else
805 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'799 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
806 fi800 fi
 801 Remediation_Anaconda_snippet_⇲
 802 Complexity:·low
 803 Disruption:·low
 804 Strategy:···enable
  
 805 package·--add=sudo
807 Remediation_Ansible_snippet_⇲806 Remediation_Ansible_snippet_⇲
808 Complexity:·low807 Complexity:·low
809 Disruption:·low808 Disruption:·low
810 Strategy:···enable809 Strategy:···enable
811 -·name:·Ensure·sudo·is·installed810 -·name:·Ensure·sudo·is·installed
812 ··package:811 ··package:
813 ····name:·sudo812 ····name:·sudo
Offset 8154, 15 lines modifiedOffset 8154, 15 lines modified
8154 Severity: ·medium8154 Severity: ·medium
8155 Rule·ID:····xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo8155 Rule·ID:····xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo
8156 Identifiers·Identifiers: ·CCE-80401-38156 Identifiers·Identifiers: ·CCE-80401-3
8157 and·········References: ·BP28(R19),·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR8157 and·········References: ·BP28(R19),·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR
8158 References··2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·RHEL-07-030690,·SV-204548r861044_rule8158 References··2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·RHEL-07-030690,·SV-204548r861044_rule
8159 Remediation_Shell_script_⇲8159 Remediation_Shell_script_⇲
8160 #·Remediation·is·applicable·only·in·certain·platforms8160 #·Remediation·is·applicable·only·in·certain·platforms
8161 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then8161 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
8162 ACTION_ARCH_FILTERS="-a·always,exit"8162 ACTION_ARCH_FILTERS="-a·always,exit"
8163 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"8163 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
8164 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"8164 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
8165 SYSCALL=""8165 SYSCALL=""
8166 KEY="privileged"8166 KEY="privileged"
8167 SYSCALL_GROUPING=""8167 SYSCALL_GROUPING=""
Offset 8615, 16 lines modifiedOffset 8615, 16 lines modified
8615 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x8615 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
8616 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged8616 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
8617 ······create:·true8617 ······create:·true
8618 ······mode:·o-rwx8618 ······mode:·o-rwx
8619 ······state:·present8619 ······state:·present
8620 ····when:·syscalls_found·|·length·==·08620 ····when:·syscalls_found·|·length·==·0
8621 ··when:8621 ··when:
8622 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8623 ··-·'"audit"·in·ansible_facts.packages'8622 ··-·'"audit"·in·ansible_facts.packages'
 8623 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8624 ··tags:8624 ··tags:
8625 ··-·CCE-80401-38625 ··-·CCE-80401-3
8626 ··-·DISA-STIG-RHEL-07-0306908626 ··-·DISA-STIG-RHEL-07-030690
8627 ··-·NIST-800-171-3.1.78627 ··-·NIST-800-171-3.1.7
8628 ··-·NIST-800-53-AC-6(9)8628 ··-·NIST-800-53-AC-6(9)
8629 ··-·NIST-800-53-AU-12(c)8629 ··-·NIST-800-53-AU-12(c)
8630 ··-·NIST-800-53-AU-2(d)8630 ··-·NIST-800-53-AU-2(d)
Offset 9418, 20 lines modifiedOffset 9418, 14 lines modified
9418 Identifiers·and·References·Identifiers: ·CCE-86724-29418 Identifiers·and·References·Identifiers: ·CCE-86724-2
9419 ···························References: ·BP28(R43),·CCI-000366,·FTP_ITC_EXT.1.1,·SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-000619419 ···························References: ·BP28(R43),·CCI-000366,·FTP_ITC_EXT.1.1,·SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-00061
9420 Remediation_OSBuild_Blueprint_snippet_⇲9420 Remediation_OSBuild_Blueprint_snippet_⇲
  
9421 [[packages]]9421 [[packages]]
9422 name·=·"rsyslog-gnutls"9422 name·=·"rsyslog-gnutls"
9423 version·=·"*"9423 version·=·"*"
9424 Remediation_Anaconda_snippet_⇲ 
9425 Complexity:·low 
Max diff block lines reached; 56511/61717 bytes (91.56%) of diff not shown.
641 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-anssi_nt28_intermediary.html
    
Offset 15332, 116 lines modifiedOffset 15332, 116 lines modified
0003be30:·2d74·6172·6765·743d·2223·6964·6d39·3536··-target="#idm9560003be30:·2d74·6172·6765·743d·2223·6964·6d39·3536··-target="#idm956
0003be40:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·0003be40:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·
0003be50:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003be50:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003be60:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003be60:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003be70:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003be70:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003be80:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003be80:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003be90:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003be90:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bea0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003bea0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003beb0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003beb0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003bec0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003bec0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003bed0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003bed0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bee0:·6170·7365·2220·6964·3d22·6964·6d39·3536··apse"·id="idm9560003bee0:·7365·2220·6964·3d22·6964·6d39·3536·3722··se"·id="idm9567"
0003bef0:·3722·3e3c·7461·626c·6520·636c·6173·733d··7"><table·class=0003bef0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bf00:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003bf00:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bf10:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003bf10:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bf20:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bf20:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bf30:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003bf30:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bf40:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003bf40:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bf50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bf50:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bf60:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003bf60:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bf70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bf70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bf80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003bf80:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bf90:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003bf90:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bfa0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003bfa0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bfb0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003bfb0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003bfc0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003bfd0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><0003bfc0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 0003bfd0:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 0003bfe0:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 0003bff0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 0003c000:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 0003c010:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 0003c020:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 0003c030:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003c040:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003c050:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003c060:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003c070:·6172·6765·743d·2223·6964·6d39·3536·3822··arget="#idm9568"
 0003c080:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003c090:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003c0a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003c0b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003c0c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003c0d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003c0e0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003c0f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003c100:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003c110:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003c120:·6964·3d22·6964·6d39·3536·3822·3e3c·7461··id="idm9568"><ta
 0003c130:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003c140:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003c150:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003c160:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003c170:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003c180:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003c190:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003c1a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003c1b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c1c0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003c1d0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003c1e0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003c1f0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003c200:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003c210:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003c220:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003c230:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
 0003c240:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
 0003c250:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
 0003c260:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 0003c270:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r
 0003c280:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 0003c290:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 0003c2a0:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0003c2b0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 0003c2c0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003c2d0:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003c2e0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0003c2f0:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0003c300:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
0003bfe0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003c310:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003bff0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003c320:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003c000:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003c330:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003c010:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003c340:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003c020:·612d·7461·7267·6574·3d22·2369·646d·3935··a-target="#idm950003c350:·612d·7461·7267·6574·3d22·2369·646d·3935··a-target="#idm95
0003c030:·3638·2220·7461·6269·6e64·6578·3d22·3022··68"·tabindex="0"0003c360:·3639·2220·7461·6269·6e64·6578·3d22·3022··69"·tabindex="0"
0003c040:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003c370:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003c050:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003c380:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003c060:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003c390:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003c070:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003c3a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003c080:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003c3b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003c090:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni0003c3c0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
0003c0a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003c3d0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003c0b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003c3e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003c0c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003c3f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003c0d0:·7073·6522·2069·643d·2269·646d·3935·3638··pse"·id="idm95680003c400:·6c61·7073·6522·2069·643d·2269·646d·3935··lapse"·id="idm95
0003c0e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003c410:·3639·223e·3c74·6162·6c65·2063·6c61·7373··69"><table·class
0003c0f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003c420:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003c100:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003c430:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003c110:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003c440:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003c120:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003c450:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003c130:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003c460:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003c140:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c470:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c150:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003c480:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003c160:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c490:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003c170:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003c4a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c180:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003c4b0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003c190:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003c4c0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003c1a0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003c4d0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c4e0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 0003c4f0:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
0003c1b0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
0003c1c0:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
0003c1d0:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
0003c1e0:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
0003c1f0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
0003c200:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
0003c210:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
0003c220:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c230:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c240:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c250:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c260:·7461·7267·6574·3d22·2369·646d·3935·3639··target="#idm9569 
0003c270:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c280:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c290:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c2a0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c2b0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
Max diff block lines reached; 584566/599222 bytes (97.55%) of diff not shown.
56.1 KB
html2text {}
    
Offset 92, 20 lines modifiedOffset 92, 14 lines modified
92 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,92 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
93 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule93 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
94 Remediation_OSBuild_Blueprint_snippet_⇲94 Remediation_OSBuild_Blueprint_snippet_⇲
  
95 [[packages]]95 [[packages]]
96 name·=·"aide"96 name·=·"aide"
97 version·=·"*"97 version·=·"*"
98 Remediation_Anaconda_snippet_⇲ 
99 Complexity:·low 
100 Disruption:·low 
101 Strategy:···enable 
  
102 package·--add=aide 
103 Remediation_Puppet_snippet_⇲98 Remediation_Puppet_snippet_⇲
104 Complexity:·low99 Complexity:·low
105 Disruption:·low100 Disruption:·low
106 Strategy:···enable101 Strategy:···enable
107 include·install_aide102 include·install_aide
  
108 class·install_aide·{103 class·install_aide·{
Offset 123, 14 lines modifiedOffset 117, 20 lines modified
123 if·!·rpm·-q·--quiet·"aide"·;·then117 if·!·rpm·-q·--quiet·"aide"·;·then
124 ····yum·install·-y·"aide"118 ····yum·install·-y·"aide"
125 fi119 fi
  
126 else120 else
127 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'121 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
128 fi122 fi
 123 Remediation_Anaconda_snippet_⇲
 124 Complexity:·low
 125 Disruption:·low
 126 Strategy:···enable
  
 127 package·--add=aide
129 Remediation_Ansible_snippet_⇲128 Remediation_Ansible_snippet_⇲
130 Complexity:·low129 Complexity:·low
131 Disruption:·low130 Disruption:·low
132 Strategy:···enable131 Strategy:···enable
133 -·name:·Ensure·aide·is·installed132 -·name:·Ensure·aide·is·installed
134 ··package:133 ··package:
135 ····name:·aide134 ····name:·aide
Offset 451, 20 lines modifiedOffset 451, 14 lines modified
451 Identifiers·and·References·Identifiers: ·CCE-82213-0451 Identifiers·and·References·Identifiers: ·CCE-82213-0
452 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1452 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1
453 Remediation_OSBuild_Blueprint_snippet_⇲453 Remediation_OSBuild_Blueprint_snippet_⇲
  
454 [[packages]]454 [[packages]]
455 name·=·"sudo"455 name·=·"sudo"
456 version·=·"*"456 version·=·"*"
457 Remediation_Anaconda_snippet_⇲ 
458 Complexity:·low 
459 Disruption:·low 
460 Strategy:···enable 
  
461 package·--add=sudo 
462 Remediation_Puppet_snippet_⇲457 Remediation_Puppet_snippet_⇲
463 Complexity:·low458 Complexity:·low
464 Disruption:·low459 Disruption:·low
465 Strategy:···enable460 Strategy:···enable
466 include·install_sudo461 include·install_sudo
  
467 class·install_sudo·{462 class·install_sudo·{
Offset 482, 14 lines modifiedOffset 476, 20 lines modified
482 if·!·rpm·-q·--quiet·"sudo"·;·then476 if·!·rpm·-q·--quiet·"sudo"·;·then
483 ····yum·install·-y·"sudo"477 ····yum·install·-y·"sudo"
484 fi478 fi
  
485 else479 else
486 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'480 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
487 fi481 fi
 482 Remediation_Anaconda_snippet_⇲
 483 Complexity:·low
 484 Disruption:·low
 485 Strategy:···enable
  
 486 package·--add=sudo
488 Remediation_Ansible_snippet_⇲487 Remediation_Ansible_snippet_⇲
489 Complexity:·low488 Complexity:·low
490 Disruption:·low489 Disruption:·low
491 Strategy:···enable490 Strategy:···enable
492 -·name:·Ensure·sudo·is·installed491 -·name:·Ensure·sudo·is·installed
493 ··package:492 ··package:
494 ····name:·sudo493 ····name:·sudo
Offset 7410, 15 lines modifiedOffset 7410, 15 lines modified
7410 Severity: ·medium7410 Severity: ·medium
7411 Rule·ID:····xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo7411 Rule·ID:····xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo
7412 Identifiers·Identifiers: ·CCE-80401-37412 Identifiers·Identifiers: ·CCE-80401-3
7413 and·········References: ·BP28(R19),·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR7413 and·········References: ·BP28(R19),·1,·12,·13,·14,·15,·16,·2,·3,·5,·6,·7,·8,·9,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·BAI03.05,·DSS01.03,·DSS03.05,·DSS05.02,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.10,·SR_2.11,·SR
7414 References··2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·RHEL-07-030690,·SV-204548r861044_rule7414 References··2.12,·SR_2.8,·SR_2.9,·SR_6.1,·SR_6.2,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),·CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·RHEL-07-030690,·SV-204548r861044_rule
7415 Remediation_Shell_script_⇲7415 Remediation_Shell_script_⇲
7416 #·Remediation·is·applicable·only·in·certain·platforms7416 #·Remediation·is·applicable·only·in·certain·platforms
7417 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then7417 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
7418 ACTION_ARCH_FILTERS="-a·always,exit"7418 ACTION_ARCH_FILTERS="-a·always,exit"
7419 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"7419 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
7420 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"7420 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
7421 SYSCALL=""7421 SYSCALL=""
7422 KEY="privileged"7422 KEY="privileged"
7423 SYSCALL_GROUPING=""7423 SYSCALL_GROUPING=""
Offset 7871, 16 lines modifiedOffset 7871, 16 lines modified
7871 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x7871 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
7872 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged7872 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
7873 ······create:·true7873 ······create:·true
7874 ······mode:·o-rwx7874 ······mode:·o-rwx
7875 ······state:·present7875 ······state:·present
7876 ····when:·syscalls_found·|·length·==·07876 ····when:·syscalls_found·|·length·==·0
7877 ··when:7877 ··when:
7878 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
7879 ··-·'"audit"·in·ansible_facts.packages'7878 ··-·'"audit"·in·ansible_facts.packages'
 7879 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
7880 ··tags:7880 ··tags:
7881 ··-·CCE-80401-37881 ··-·CCE-80401-3
7882 ··-·DISA-STIG-RHEL-07-0306907882 ··-·DISA-STIG-RHEL-07-030690
7883 ··-·NIST-800-171-3.1.77883 ··-·NIST-800-171-3.1.7
7884 ··-·NIST-800-53-AC-6(9)7884 ··-·NIST-800-53-AC-6(9)
7885 ··-·NIST-800-53-AU-12(c)7885 ··-·NIST-800-53-AU-12(c)
7886 ··-·NIST-800-53-AU-2(d)7886 ··-·NIST-800-53-AU-2(d)
Offset 8526, 20 lines modifiedOffset 8526, 14 lines modified
8526 Identifiers·and·References·Identifiers: ·CCE-86724-28526 Identifiers·and·References·Identifiers: ·CCE-86724-2
8527 ···························References: ·BP28(R43),·CCI-000366,·FTP_ITC_EXT.1.1,·SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-000618527 ···························References: ·BP28(R43),·CCI-000366,·FTP_ITC_EXT.1.1,·SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-00061
8528 Remediation_OSBuild_Blueprint_snippet_⇲8528 Remediation_OSBuild_Blueprint_snippet_⇲
  
8529 [[packages]]8529 [[packages]]
8530 name·=·"rsyslog-gnutls"8530 name·=·"rsyslog-gnutls"
8531 version·=·"*"8531 version·=·"*"
8532 Remediation_Anaconda_snippet_⇲ 
8533 Complexity:·low 
Max diff block lines reached; 52241/57447 bytes (90.94%) of diff not shown.
230 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-anssi_nt28_minimal.html
    
Offset 41013, 118 lines modifiedOffset 41013, 118 lines modified
000a0340:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=000a0340:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
000a0350:·2223·6964·6d34·3137·3338·2220·7461·6269··"#idm41738"·tabi000a0350:·2223·6964·6d34·3137·3338·2220·7461·6269··"#idm41738"·tabi
000a0360:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b000a0360:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
000a0370:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa000a0370:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
000a0380:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit000a0380:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
000a0390:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·000a0390:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
000a03a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!000a03a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
000a03b0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An000a03b0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
000a03c0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.000a03c0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
000a03d0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c000a03d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000a03e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000a03e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000a03f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i000a03f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
000a0400:·643d·2269·646d·3431·3733·3822·3e3c·7461··d="idm41738"><ta000a0400:·2269·646d·3431·3733·3822·3e3c·7461·626c··"idm41738"><tabl
000a0410:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table000a0410:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
000a0420:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t000a0420:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
000a0430:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta000a0430:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
000a0440:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><000a0440:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
000a0450:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit000a0450:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
000a0460:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</000a0460:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
000a0470:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>000a0470:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
000a0480:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>000a0480:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
000a0490:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr000a0490:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
000a04a0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg000a04a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
000a04b0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl000a04b0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
000a04c0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab000a04c0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
000a04d0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p000a04d0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
000a04e0:·6163·6b61·6765·202d·2d61·6464·3d72·7379··ackage·--add=rsy000a04e0:·7564·6520·696e·7374·616c·6c5f·7273·7973··ude·install_rsys
 000a04f0:·6c6f·670a·0a63·6c61·7373·2069·6e73·7461··log..class·insta
 000a0500:·6c6c·5f72·7379·736c·6f67·207b·0a20·2070··ll_rsyslog·{.··p
 000a0510:·6163·6b61·6765·207b·2027·7273·7973·6c6f··ackage·{·'rsyslo
 000a0520:·6727·3a0a·2020·2020·656e·7375·7265·203d··g':.····ensure·=
 000a0530:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 000a0540:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 000a0550:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 000a0560:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 000a0570:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 000a0580:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 000a0590:·612d·7461·7267·6574·3d22·2369·646d·3431··a-target="#idm41
 000a05a0:·3733·3922·2074·6162·696e·6465·783d·2230··739"·tabindex="0
 000a05b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 000a05c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 000a05d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 000a05e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 000a05f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 000a0600:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 000a0610:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 000a0620:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 000a0630:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 000a0640:·7365·2220·6964·3d22·6964·6d34·3137·3339··se"·id="idm41739
 000a0650:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 000a0660:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 000a0670:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 000a0680:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 000a0690:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 000a06a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 000a06b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 000a06c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 000a06d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 000a06e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 000a06f0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 000a0700:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 000a0710:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 000a0720:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 000a0730:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 000a0740:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 000a0750:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
 000a0760:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
 000a0770:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
 000a0780:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
 000a0790:·6572·656e·7620·5d3b·2074·6865·6e0a·0a69··erenv·];·then..i
 000a07a0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 000a07b0:·6574·2022·7273·7973·6c6f·6722·203b·2074··et·"rsyslog"·;·t
 000a07c0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 000a07d0:·616c·6c20·2d79·2022·7273·7973·6c6f·6722··all·-y·"rsyslog"
 000a07e0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 000a07f0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 000a0800:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 000a0810:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 000a0820:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
000a04f0:·736c·6f67·0a3c·2f63·6f64·653e·3c2f·7072··slog.</code></pr000a0830:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
000a0500:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class000a0840:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
000a0510:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes000a0850:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
000a0520:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="000a0860:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
000a0530:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t000a0870:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
000a0540:·6172·6765·743d·2223·6964·6d34·3137·3339··arget="#idm41739000a0880:·6765·743d·2223·6964·6d34·3137·3430·2220··get="#idm41740"·
000a0550:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r000a0890:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
000a0560:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari000a08a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
000a0570:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals000a08b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
000a0580:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa000a08c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
000a0590:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr000a08d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
000a05a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat000a08e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
000a05b0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp000a08f0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
000a05c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d000a0900:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
000a05d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-000a0910:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
000a05e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps000a0920:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
000a05f0:·6522·2069·643d·2269·646d·3431·3733·3922··e"·id="idm41739"000a0930:·6522·2069·643d·2269·646d·3431·3734·3022··e"·id="idm41740"
000a0600:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t000a0940:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
000a0610:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip000a0950:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
000a0620:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere000a0960:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
000a0630:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense000a0970:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
000a0640:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl000a0980:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
000a0650:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l000a0990:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
000a0660:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>000a09a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
000a0670:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<000a09b0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
000a0680:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>000a09c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
000a0690:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str000a09d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
000a06a0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e000a09e0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
000a06b0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><000a09f0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
000a06c0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod000a0a00:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 000a0a10:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
 000a0a20:·3d72·7379·736c·6f67·0a3c·2f63·6f64·653e··=rsyslog.</code>
000a06d0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
000a06e0:·6c5f·7273·7973·6c6f·670a·0a63·6c61·7373··l_rsyslog..class 
000a06f0:·2069·6e73·7461·6c6c·5f72·7379·736c·6f67···install_rsyslog 
000a0700:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
000a0710:·7273·7973·6c6f·6727·3a0a·2020·2020·656e··rsyslog':.····en 
000a0720:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
000a0730:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
000a0740:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
000a0750:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
000a0760:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
000a0770:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
000a0780:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
000a0790:·2369·646d·3431·3734·3022·2074·6162·696e··#idm41740"·tabin 
000a07a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
000a07b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
000a07c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
Max diff block lines reached; 203776/218708 bytes (93.17%) of diff not shown.
16.4 KB
html2text {}
    
Offset 6716, 20 lines modifiedOffset 6716, 14 lines modified
6716 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-6716 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
6717 ············00227,·4.2.1.16717 ············00227,·4.2.1.1
6718 Remediation_OSBuild_Blueprint_snippet_⇲6718 Remediation_OSBuild_Blueprint_snippet_⇲
  
6719 [[packages]]6719 [[packages]]
6720 name·=·"rsyslog"6720 name·=·"rsyslog"
6721 version·=·"*"6721 version·=·"*"
6722 Remediation_Anaconda_snippet_⇲ 
6723 Complexity:·low 
6724 Disruption:·low 
6725 Strategy:···enable 
  
6726 package·--add=rsyslog 
6727 Remediation_Puppet_snippet_⇲6722 Remediation_Puppet_snippet_⇲
6728 Complexity:·low6723 Complexity:·low
6729 Disruption:·low6724 Disruption:·low
6730 Strategy:···enable6725 Strategy:···enable
6731 include·install_rsyslog6726 include·install_rsyslog
  
6732 class·install_rsyslog·{6727 class·install_rsyslog·{
Offset 6747, 14 lines modifiedOffset 6741, 20 lines modified
6747 if·!·rpm·-q·--quiet·"rsyslog"·;·then6741 if·!·rpm·-q·--quiet·"rsyslog"·;·then
6748 ····yum·install·-y·"rsyslog"6742 ····yum·install·-y·"rsyslog"
6749 fi6743 fi
  
6750 else6744 else
6751 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6745 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6752 fi6746 fi
 6747 Remediation_Anaconda_snippet_⇲
 6748 Complexity:·low
 6749 Disruption:·low
 6750 Strategy:···enable
  
 6751 package·--add=rsyslog
6753 Remediation_Ansible_snippet_⇲6752 Remediation_Ansible_snippet_⇲
6754 Complexity:·low6753 Complexity:·low
6755 Disruption:·low6754 Disruption:·low
6756 Strategy:···enable6755 Strategy:···enable
6757 -·name:·Ensure·rsyslog·is·installed6756 -·name:·Ensure·rsyslog·is·installed
6758 ··package:6757 ··package:
6759 ····name:·rsyslog6758 ····name:·rsyslog
Offset 6945, 20 lines modifiedOffset 6945, 14 lines modified
6945 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,6945 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,
6946 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,6946 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
6947 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,6947 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
6948 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR6948 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
6949 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR6949 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
6950 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,6950 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
6951 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,·2.2.56951 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,·2.2.5
6952 Remediation_Anaconda_snippet_⇲ 
6953 Complexity:·low 
6954 Disruption:·low 
6955 Strategy:···disable 
  
6956 package·--remove=dhcp 
6957 Remediation_Puppet_snippet_⇲6952 Remediation_Puppet_snippet_⇲
6958 Complexity:·low6953 Complexity:·low
6959 Disruption:·low6954 Disruption:·low
6960 Strategy:···disable6955 Strategy:···disable
6961 include·remove_dhcp6956 include·remove_dhcp
  
6962 class·remove_dhcp·{6957 class·remove_dhcp·{
Offset 6978, 14 lines modifiedOffset 6972, 20 lines modified
6978 #»      ···system!6972 #»      ···system!
  
6979 if·rpm·-q·--quiet·"dhcp"·;·then6973 if·rpm·-q·--quiet·"dhcp"·;·then
  
6980 ····yum·remove·-y·"dhcp"6974 ····yum·remove·-y·"dhcp"
  
6981 fi6975 fi
 6976 Remediation_Anaconda_snippet_⇲
 6977 Complexity:·low
 6978 Disruption:·low
 6979 Strategy:···disable
  
 6980 package·--remove=dhcp
6982 Remediation_Ansible_snippet_⇲6981 Remediation_Ansible_snippet_⇲
6983 Complexity:·low6982 Complexity:·low
6984 Disruption:·low6983 Disruption:·low
6985 Strategy:···disable6984 Strategy:···disable
6986 -·name:·Ensure·dhcp·is·removed6985 -·name:·Ensure·dhcp·is·removed
6987 ··package:6986 ··package:
6988 ····name:·dhcp6987 ····name:·dhcp
Offset 7034, 20 lines modifiedOffset 7034, 14 lines modified
7034 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7034 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
7035 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,7035 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
7036 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR7036 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
7037 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR7037 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
7038 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,7038 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
7039 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,·SRG-OS-000480-GPOS-00227,·SRG-OS-7039 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3,·SRG-OS-000480-GPOS-00227,·SRG-OS-
7040 ············000095-GPOS-000497040 ············000095-GPOS-00049
7041 Remediation_Anaconda_snippet_⇲ 
7042 Complexity:·low 
7043 Disruption:·low 
7044 Strategy:···disable 
  
7045 package·--remove=sendmail 
7046 Remediation_Puppet_snippet_⇲7041 Remediation_Puppet_snippet_⇲
7047 Complexity:·low7042 Complexity:·low
7048 Disruption:·low7043 Disruption:·low
7049 Strategy:···disable7044 Strategy:···disable
7050 include·remove_sendmail7045 include·remove_sendmail
  
7051 class·remove_sendmail·{7046 class·remove_sendmail·{
Offset 7073, 14 lines modifiedOffset 7067, 20 lines modified
7073 ····yum·remove·-y·"sendmail"7067 ····yum·remove·-y·"sendmail"
  
7074 fi7068 fi
  
7075 else7069 else
7076 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7070 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7077 fi7071 fi
 7072 Remediation_Anaconda_snippet_⇲
 7073 Complexity:·low
 7074 Disruption:·low
 7075 Strategy:···disable
  
 7076 package·--remove=sendmail
7078 Remediation_Ansible_snippet_⇲7077 Remediation_Ansible_snippet_⇲
7079 Complexity:·low7078 Complexity:·low
7080 Disruption:·low7079 Disruption:·low
7081 Strategy:···disable7080 Strategy:···disable
7082 -·name:·Ensure·sendmail·is·removed7081 -·name:·Ensure·sendmail·is·removed
7083 ··package:7082 ··package:
7084 ····name:·sendmail7083 ····name:·sendmail
Offset 7128, 20 lines modifiedOffset 7128, 14 lines modified
7128 and·········4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,7128 and·········4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,
Max diff block lines reached; 13028/16789 bytes (77.60%) of diff not shown.
1.61 MB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-cis.html
    
Offset 15391, 116 lines modifiedOffset 15391, 116 lines modified
0003c1e0:·6172·6765·743d·2223·6964·6d39·3536·3722··arget="#idm9567"0003c1e0:·6172·6765·743d·2223·6964·6d39·3536·3722··arget="#idm9567"
0003c1f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c1f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c200:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c200:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c210:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c210:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c220:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c220:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c230:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c230:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c240:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c240:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003c250:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip0003c250:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
0003c260:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003c260:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c270:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003c270:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c280:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003c280:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c290:·7365·2220·6964·3d22·6964·6d39·3536·3722··se"·id="idm9567"0003c290:·2220·6964·3d22·6964·6d39·3536·3722·3e3c··"·id="idm9567"><
0003c2a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003c2a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c2b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003c2b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c2c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003c2c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c2d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003c2d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c2e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003c2e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c2f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003c2f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c300:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c300:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c310:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003c310:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003c320:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c320:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c330:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003c330:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003c340:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003c340:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003c350:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003c350:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003c360:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003c360:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003c370:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add0003c370:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003c380:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003c390:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003c3a0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003c3b0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003c3c0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003c3d0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003c3e0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003c3f0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003c400:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003c410:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003c420:·6765·743d·2223·6964·6d39·3536·3822·2074··get="#idm9568"·t
 0003c430:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003c440:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003c450:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003c460:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003c470:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003c480:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003c490:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003c4a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003c4b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003c4c0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003c4d0:·3d22·6964·6d39·3536·3822·3e3c·7461·626c··="idm9568"><tabl
 0003c4e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003c4f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003c500:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003c510:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003c520:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003c530:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003c540:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003c550:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003c560:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003c570:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003c580:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003c590:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003c5a0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 0003c5b0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003c5c0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003c5d0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003c5e0:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do
 0003c5f0:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&
 0003c600:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run
 0003c610:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]
 0003c620:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 0003c630:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid
 0003c640:·6522·203b·2074·6865·6e0a·2020·2020·7975··e"·;·then.····yu
 0003c650:·6d20·696e·7374·616c·6c20·2d79·2022·6169··m·install·-y·"ai
 0003c660:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.···
 0003c670:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo
 0003c680:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is
 0003c690:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable,
 0003c6a0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don
0003c380:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p0003c6b0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p
0003c390:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003c6c0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0003c3a0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003c6d0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0003c3b0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003c6e0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0003c3c0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003c6f0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0003c3d0:·7461·7267·6574·3d22·2369·646d·3935·3638··target="#idm95680003c700:·7461·7267·6574·3d22·2369·646d·3935·3639··target="#idm9569
0003c3e0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003c710:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c3f0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003c720:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c400:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003c730:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c410:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003c740:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c420:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003c750:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c430:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003c760:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003c440:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003c770:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
0003c450:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003c780:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003c460:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003c790:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003c470:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003c7a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003c480:·6522·2069·643d·2269·646d·3935·3638·223e··e"·id="idm9568">0003c7b0:·7073·6522·2069·643d·2269·646d·3935·3639··pse"·id="idm9569
0003c490:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003c7c0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003c4a0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003c7d0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003c4b0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003c7e0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003c4c0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003c7f0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003c4d0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003c800:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003c4e0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003c810:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003c4f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c820:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c500:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003c830:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c510:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c840:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c520:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003c850:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003c530:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003c860:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003c540:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003c870:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003c550:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003c880:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003c890:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
0003c560:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003c570:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins 
0003c580:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa 
0003c590:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':. 
0003c5a0:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
0003c5b0:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.·· 
0003c5c0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre 
0003c5d0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c5e0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c5f0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c600:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c610:·7267·6574·3d22·2369·646d·3935·3639·2220··rget="#idm9569"· 
0003c620:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c630:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c640:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c650:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c660:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c670:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c680:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
Max diff block lines reached; 1317300/1331956 bytes (98.90%) of diff not shown.
347 KB
html2text {}
    
Offset 101, 20 lines modifiedOffset 101, 14 lines modified
101 Identifiers·and·References·Identifiers: ·CCE-27096-7101 Identifiers·and·References·Identifiers: ·CCE-27096-7
102 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule102 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
103 Remediation_OSBuild_Blueprint_snippet_⇲103 Remediation_OSBuild_Blueprint_snippet_⇲
  
104 [[packages]]104 [[packages]]
105 name·=·"aide"105 name·=·"aide"
106 version·=·"*"106 version·=·"*"
107 Remediation_Anaconda_snippet_⇲ 
108 Complexity:·low 
109 Disruption:·low 
110 Strategy:···enable 
  
111 package·--add=aide 
112 Remediation_Puppet_snippet_⇲107 Remediation_Puppet_snippet_⇲
113 Complexity:·low108 Complexity:·low
114 Disruption:·low109 Disruption:·low
115 Strategy:···enable110 Strategy:···enable
116 include·install_aide111 include·install_aide
  
117 class·install_aide·{112 class·install_aide·{
Offset 132, 14 lines modifiedOffset 126, 20 lines modified
132 if·!·rpm·-q·--quiet·"aide"·;·then126 if·!·rpm·-q·--quiet·"aide"·;·then
133 ····yum·install·-y·"aide"127 ····yum·install·-y·"aide"
134 fi128 fi
  
135 else129 else
136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'130 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
137 fi131 fi
 132 Remediation_Anaconda_snippet_⇲
 133 Complexity:·low
 134 Disruption:·low
 135 Strategy:···enable
  
 136 package·--add=aide
138 Remediation_Ansible_snippet_⇲137 Remediation_Ansible_snippet_⇲
139 Complexity:·low138 Complexity:·low
140 Disruption:·low139 Disruption:·low
141 Strategy:···enable140 Strategy:···enable
142 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
143 ··package:142 ··package:
144 ····name:·aide143 ····name:·aide
Offset 774, 20 lines modifiedOffset 774, 14 lines modified
774 Identifiers·and·References·Identifiers: ·CCE-82213-0774 Identifiers·and·References·Identifiers: ·CCE-82213-0
775 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1775 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1
776 Remediation_OSBuild_Blueprint_snippet_⇲776 Remediation_OSBuild_Blueprint_snippet_⇲
  
777 [[packages]]777 [[packages]]
778 name·=·"sudo"778 name·=·"sudo"
779 version·=·"*"779 version·=·"*"
780 Remediation_Anaconda_snippet_⇲ 
781 Complexity:·low 
782 Disruption:·low 
783 Strategy:···enable 
  
784 package·--add=sudo 
785 Remediation_Puppet_snippet_⇲780 Remediation_Puppet_snippet_⇲
786 Complexity:·low781 Complexity:·low
787 Disruption:·low782 Disruption:·low
788 Strategy:···enable783 Strategy:···enable
789 include·install_sudo784 include·install_sudo
  
790 class·install_sudo·{785 class·install_sudo·{
Offset 805, 14 lines modifiedOffset 799, 20 lines modified
805 if·!·rpm·-q·--quiet·"sudo"·;·then799 if·!·rpm·-q·--quiet·"sudo"·;·then
806 ····yum·install·-y·"sudo"800 ····yum·install·-y·"sudo"
807 fi801 fi
  
808 else802 else
809 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'803 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
810 fi804 fi
 805 Remediation_Anaconda_snippet_⇲
 806 Complexity:·low
 807 Disruption:·low
 808 Strategy:···enable
  
 809 package·--add=sudo
811 Remediation_Ansible_snippet_⇲810 Remediation_Ansible_snippet_⇲
812 Complexity:·low811 Complexity:·low
813 Disruption:·low812 Disruption:·low
814 Strategy:···enable813 Strategy:···enable
815 -·name:·Ensure·sudo·is·installed814 -·name:·Ensure·sudo·is·installed
816 ··package:815 ··package:
817 ····name:·sudo816 ····name:·sudo
Offset 4989, 15 lines modifiedOffset 4989, 15 lines modified
4989 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.4989 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
4990 Severity: ················medium4990 Severity: ················medium
4991 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod4991 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
4992 Identifiers·and·References·Identifiers: ·CCE-27339-14992 Identifiers·and·References·Identifiers: ·CCE-27339-1
4993 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule4993 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
4994 Remediation_Shell_script_⇲4994 Remediation_Shell_script_⇲
4995 #·Remediation·is·applicable·only·in·certain·platforms4995 #·Remediation·is·applicable·only·in·certain·platforms
4996 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then4996 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
4997 #·First·perform·the·remediation·of·the·syscall·rule4997 #·First·perform·the·remediation·of·the·syscall·rule
4998 #·Retrieve·hardware·architecture·of·the·underlying·system4998 #·Retrieve·hardware·architecture·of·the·underlying·system
4999 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4999 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
5000 for·ARCH·in·"${RULE_ARCHS[@]}"5000 for·ARCH·in·"${RULE_ARCHS[@]}"
5001 do5001 do
Offset 5345, 16 lines modifiedOffset 5345, 16 lines modified
5345 ··-·reboot_required5345 ··-·reboot_required
5346 ··-·restrict_strategy5346 ··-·restrict_strategy
  
5347 -·name:·Set·architecture·for·audit·chmod·tasks5347 -·name:·Set·architecture·for·audit·chmod·tasks
5348 ··set_fact:5348 ··set_fact:
5349 ····audit_arch:·b645349 ····audit_arch:·b64
5350 ··when:5350 ··when:
5351 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5352 ··-·'"audit"·in·ansible_facts.packages'5351 ··-·'"audit"·in·ansible_facts.packages'
 5352 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5353 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5353 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5354 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5354 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5355 ··tags:5355 ··tags:
5356 ··-·CCE-27339-15356 ··-·CCE-27339-1
5357 ··-·CJIS-5.4.1.15357 ··-·CJIS-5.4.1.1
5358 ··-·DISA-STIG-RHEL-07-0304105358 ··-·DISA-STIG-RHEL-07-030410
5359 ··-·NIST-800-171-3.1.75359 ··-·NIST-800-171-3.1.7
Offset 5492, 16 lines modifiedOffset 5492, 16 lines modified
5492 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005492 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
5493 ········-F·auid!=unset·-F·key=perm_mod5493 ········-F·auid!=unset·-F·key=perm_mod
5494 ······create:·true5494 ······create:·true
5495 ······mode:·o-rwx5495 ······mode:·o-rwx
5496 ······state:·present5496 ······state:·present
5497 ····when:·syscalls_found·|·length·==·05497 ····when:·syscalls_found·|·length·==·0
5498 ··when:5498 ··when:
5499 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5500 ··-·'"audit"·in·ansible_facts.packages'5499 ··-·'"audit"·in·ansible_facts.packages'
Max diff block lines reached; 348717/354914 bytes (98.25%) of diff not shown.
725 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-cis_server_l1.html
    
Offset 15385, 116 lines modifiedOffset 15385, 116 lines modified
0003c180:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003c180:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003c190:·6964·6d39·3536·3722·2074·6162·696e·6465··idm9567"·tabinde0003c190:·6964·6d39·3536·3722·2074·6162·696e·6465··idm9567"·tabinde
0003c1a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003c1a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003c1b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003c1b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003c1c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003c1c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003c1d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003c1d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003c1e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003c1e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003c1f0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003c1f0:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
0003c200:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003c200:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003c210:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003c210:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003c220:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003c220:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003c230:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003c230:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003c240:·6964·6d39·3536·3722·3e3c·7461·626c·6520··idm9567"><table·0003c240:·6d39·3536·3722·3e3c·7461·626c·6520·636c··m9567"><table·cl
0003c250:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003c250:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003c260:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003c260:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003c270:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003c270:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003c280:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003c280:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003c290:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003c290:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003c2a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c2a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c2b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003c2b0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003c2c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003c2c0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003c2d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c2d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003c2e0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003c2e0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003c2f0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003c2f0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003c300:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003c300:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003c310:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003c320:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</0003c310:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003c320:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003c330:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003c340:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003c350:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003c360:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003c370:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003c380:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003c390:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003c3a0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003c3b0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003c3c0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003c3d0:·6d39·3536·3822·2074·6162·696e·6465·783d··m9568"·tabindex=
 0003c3e0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003c3f0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003c400:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003c410:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003c420:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003c430:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003c440:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003c450:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003c460:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003c470:·6170·7365·2220·6964·3d22·6964·6d39·3536··apse"·id="idm956
 0003c480:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=
 0003c490:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003c4a0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003c4b0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003c4c0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003c4d0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003c4e0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003c4f0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003c500:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c510:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003c520:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003c530:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003c540:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003c550:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 0003c560:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 0003c570:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 0003c580:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
 0003c590:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
 0003c5a0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
 0003c5b0:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 0003c5c0:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
 0003c5d0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003c5e0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003c5f0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 0003c600:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003c610:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003c620:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003c630:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003c640:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003c650:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
0003c330:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003c660:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003c340:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003c670:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003c350:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003c680:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003c360:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003c690:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003c370:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003c6a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003c380:·2369·646d·3935·3638·2220·7461·6269·6e64··#idm9568"·tabind0003c6b0:·2369·646d·3935·3639·2220·7461·6269·6e64··#idm9569"·tabind
0003c390:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003c6c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003c3a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003c6d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003c3b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003c6e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c3c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003c6f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c3d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003c700:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c3e0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003c710:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003c3f0:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003c720:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003c400:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c730:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003c410:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c740:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003c420:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003c750:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003c430:·646d·3935·3638·223e·3c74·6162·6c65·2063··dm9568"><table·c0003c760:·2269·646d·3935·3639·223e·3c74·6162·6c65··"idm9569"><table
0003c440:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003c770:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003c450:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003c780:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003c460:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003c790:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003c470:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003c7a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003c480:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003c7b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003c490:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c7c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c4a0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003c7d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003c4b0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003c7e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003c4c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c7f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c4d0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003c800:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003c4e0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003c810:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003c4f0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003c820:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003c830:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003c840:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
0003c500:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003c510:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003c520:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003c530:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003c540:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003c550:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003c560:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003c570:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003c580:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003c590:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003c5a0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003c5b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003c5c0:·646d·3935·3639·2220·7461·6269·6e64·6578··dm9569"·tabindex 
0003c5d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003c5e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003c5f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003c600:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
Max diff block lines reached; 648648/663304 bytes (97.79%) of diff not shown.
77.4 KB
html2text {}
    
Offset 100, 20 lines modifiedOffset 100, 14 lines modified
100 Identifiers·and·References·Identifiers: ·CCE-27096-7100 Identifiers·and·References·Identifiers: ·CCE-27096-7
101 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule101 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
102 Remediation_OSBuild_Blueprint_snippet_⇲102 Remediation_OSBuild_Blueprint_snippet_⇲
  
103 [[packages]]103 [[packages]]
104 name·=·"aide"104 name·=·"aide"
105 version·=·"*"105 version·=·"*"
106 Remediation_Anaconda_snippet_⇲ 
107 Complexity:·low 
108 Disruption:·low 
109 Strategy:···enable 
  
110 package·--add=aide 
111 Remediation_Puppet_snippet_⇲106 Remediation_Puppet_snippet_⇲
112 Complexity:·low107 Complexity:·low
113 Disruption:·low108 Disruption:·low
114 Strategy:···enable109 Strategy:···enable
115 include·install_aide110 include·install_aide
  
116 class·install_aide·{111 class·install_aide·{
Offset 131, 14 lines modifiedOffset 125, 20 lines modified
131 if·!·rpm·-q·--quiet·"aide"·;·then125 if·!·rpm·-q·--quiet·"aide"·;·then
132 ····yum·install·-y·"aide"126 ····yum·install·-y·"aide"
133 fi127 fi
  
134 else128 else
135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'129 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
136 fi130 fi
 131 Remediation_Anaconda_snippet_⇲
 132 Complexity:·low
 133 Disruption:·low
 134 Strategy:···enable
  
 135 package·--add=aide
137 Remediation_Ansible_snippet_⇲136 Remediation_Ansible_snippet_⇲
138 Complexity:·low137 Complexity:·low
139 Disruption:·low138 Disruption:·low
140 Strategy:···enable139 Strategy:···enable
141 -·name:·Ensure·aide·is·installed140 -·name:·Ensure·aide·is·installed
142 ··package:141 ··package:
143 ····name:·aide142 ····name:·aide
Offset 683, 20 lines modifiedOffset 683, 14 lines modified
683 Identifiers·and·References·Identifiers: ·CCE-82213-0683 Identifiers·and·References·Identifiers: ·CCE-82213-0
684 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1684 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1
685 Remediation_OSBuild_Blueprint_snippet_⇲685 Remediation_OSBuild_Blueprint_snippet_⇲
  
686 [[packages]]686 [[packages]]
687 name·=·"sudo"687 name·=·"sudo"
688 version·=·"*"688 version·=·"*"
689 Remediation_Anaconda_snippet_⇲ 
690 Complexity:·low 
691 Disruption:·low 
692 Strategy:···enable 
  
693 package·--add=sudo 
694 Remediation_Puppet_snippet_⇲689 Remediation_Puppet_snippet_⇲
695 Complexity:·low690 Complexity:·low
696 Disruption:·low691 Disruption:·low
697 Strategy:···enable692 Strategy:···enable
698 include·install_sudo693 include·install_sudo
  
699 class·install_sudo·{694 class·install_sudo·{
Offset 714, 14 lines modifiedOffset 708, 20 lines modified
714 if·!·rpm·-q·--quiet·"sudo"·;·then708 if·!·rpm·-q·--quiet·"sudo"·;·then
715 ····yum·install·-y·"sudo"709 ····yum·install·-y·"sudo"
716 fi710 fi
  
717 else711 else
718 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'712 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
719 fi713 fi
 714 Remediation_Anaconda_snippet_⇲
 715 Complexity:·low
 716 Disruption:·low
 717 Strategy:···enable
  
 718 package·--add=sudo
720 Remediation_Ansible_snippet_⇲719 Remediation_Ansible_snippet_⇲
721 Complexity:·low720 Complexity:·low
722 Disruption:·low721 Disruption:·low
723 Strategy:···enable722 Strategy:···enable
724 -·name:·Ensure·sudo·is·installed723 -·name:·Ensure·sudo·is·installed
725 ··package:724 ··package:
726 ····name:·sudo725 ····name:·sudo
Offset 4842, 15 lines modifiedOffset 4842, 15 lines modified
4842 Identifiers·and·References·Identifiers: ·CCE-82023-34842 Identifiers·and·References·Identifiers: ·CCE-82023-3
4843 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.24843 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
4844 Remediation_Shell_script_⇲4844 Remediation_Shell_script_⇲
4845 Complexity:·low4845 Complexity:·low
4846 Disruption:·low4846 Disruption:·low
4847 Strategy:···configure4847 Strategy:···configure
4848 #·Remediation·is·applicable·only·in·certain·platforms4848 #·Remediation·is·applicable·only·in·certain·platforms
4849 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then4849 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
4850 chgrp·0·/boot/grub2/grub.cfg4850 chgrp·0·/boot/grub2/grub.cfg
  
4851 else4851 else
4852 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4852 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4853 fi4853 fi
4854 Remediation_Ansible_snippet_⇲4854 Remediation_Ansible_snippet_⇲
Offset 4875, 16 lines modifiedOffset 4875, 16 lines modified
4875 ··-·no_reboot_needed4875 ··-·no_reboot_needed
  
4876 -·name:·Test·for·existence·/boot/grub2/grub.cfg4876 -·name:·Test·for·existence·/boot/grub2/grub.cfg
4877 ··stat:4877 ··stat:
4878 ····path:·/boot/grub2/grub.cfg4878 ····path:·/boot/grub2/grub.cfg
4879 ··register:·file_exists4879 ··register:·file_exists
4880 ··when:4880 ··when:
4881 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
4882 ··-·'"grub2-common"·in·ansible_facts.packages'4881 ··-·'"grub2-common"·in·ansible_facts.packages'
 4882 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
4883 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4883 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4884 ··tags:4884 ··tags:
4885 ··-·CCE-82023-34885 ··-·CCE-82023-3
4886 ··-·CJIS-5.5.2.24886 ··-·CJIS-5.5.2.2
4887 ··-·NIST-800-171-3.4.54887 ··-·NIST-800-171-3.4.5
4888 ··-·NIST-800-53-AC-6(1)4888 ··-·NIST-800-53-AC-6(1)
4889 ··-·NIST-800-53-CM-6(a)4889 ··-·NIST-800-53-CM-6(a)
Offset 4897, 16 lines modifiedOffset 4897, 16 lines modified
4897 ··-·no_reboot_needed4897 ··-·no_reboot_needed
  
4898 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg4898 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
4899 ··file:4899 ··file:
4900 ····path:·/boot/grub2/grub.cfg4900 ····path:·/boot/grub2/grub.cfg
4901 ····group:·'0'4901 ····group:·'0'
4902 ··when:4902 ··when:
4903 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
4904 ··-·'"grub2-common"·in·ansible_facts.packages'4903 ··-·'"grub2-common"·in·ansible_facts.packages'
Max diff block lines reached; 74442/79271 bytes (93.91%) of diff not shown.
665 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-cis_workstation_l1.html
    
Offset 15376, 117 lines modifiedOffset 15376, 117 lines modified
0003c0f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003c0f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c100:·743d·2223·6964·6d39·3536·3722·2074·6162··t="#idm9567"·tab0003c100:·743d·2223·6964·6d39·3536·3722·2074·6162··t="#idm9567"·tab
0003c110:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003c110:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c120:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003c120:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c130:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003c130:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c140:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003c140:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c150:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003c150:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c160:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003c160:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003c170:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003c170:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0003c180:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003c180:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003c190:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003c190:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003c1a0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003c1a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003c1b0:·6964·3d22·6964·6d39·3536·3722·3e3c·7461··id="idm9567"><ta0003c1b0:·3d22·6964·6d39·3536·3722·3e3c·7461·626c··="idm9567"><tabl
0003c1c0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003c1c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003c1d0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003c1d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003c1e0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003c1e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003c1f0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003c1f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003c200:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003c200:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003c210:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003c210:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c220:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c220:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003c230:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003c230:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003c240:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c240:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c250:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003c250:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003c260:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003c260:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003c270:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003c270:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003c280:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0003c280:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0003c290:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid0003c290:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003c2a0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003c2b0:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003c2c0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003c2d0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003c2e0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003c2f0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003c300:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003c310:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003c320:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003c330:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003c340:·2223·6964·6d39·3536·3822·2074·6162·696e··"#idm9568"·tabin
 0003c350:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003c360:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003c370:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003c380:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003c390:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003c3a0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003c3b0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003c3c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003c3d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003c3e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003c3f0:·6d39·3536·3822·3e3c·7461·626c·6520·636c··m9568"><table·cl
 0003c400:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003c410:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003c420:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003c430:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003c440:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003c450:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003c460:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003c470:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003c480:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003c490:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003c4a0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003c4b0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c4c0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003c4d0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003c4e0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003c4f0:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003c500:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
 0003c510:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 0003c520:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
 0003c530:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th
 0003c540:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003c550:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003c560:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003c570:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003c580:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003c590:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003c5a0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003c5b0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003c5c0:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
0003c2a0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0003c5d0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
0003c2b0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003c5e0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003c2c0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003c5f0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003c2d0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003c600:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003c2e0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003c610:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003c2f0:·6574·3d22·2369·646d·3935·3638·2220·7461··et="#idm9568"·ta0003c620:·6574·3d22·2369·646d·3935·3639·2220·7461··et="#idm9569"·ta
0003c300:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c630:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c310:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c640:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c320:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c650:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c330:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c660:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c340:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c670:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c350:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c680:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c360:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003c690:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003c370:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c6a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c380:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c6b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c390:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c6c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c3a0:·643d·2269·646d·3935·3638·223e·3c74·6162··d="idm9568"><tab0003c6d0:·2069·643d·2269·646d·3935·3639·223e·3c74···id="idm9569"><t
0003c3b0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c6e0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c3c0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c6f0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c3d0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c700:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c3e0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c710:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c3f0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c720:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c400:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c730:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003c410:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c740:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c420:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c750:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003c430:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c760:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c440:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c770:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003c450:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003c780:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003c460:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003c790:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003c470:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003c7a0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003c7b0:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
0003c480:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003c490:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003c4a0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003c4b0:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003c4c0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003c4d0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003c4e0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003c4f0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003c500:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003c510:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003c520:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003c530:·3d22·2369·646d·3935·3639·2220·7461·6269··="#idm9569"·tabi 
0003c540:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003c550:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003c560:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003c570:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003c580:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003c590:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
Max diff block lines reached; 594988/609782 bytes (97.57%) of diff not shown.
69.4 KB
html2text {}
    
Offset 99, 20 lines modifiedOffset 99, 14 lines modified
99 Identifiers·and·References·Identifiers: ·CCE-27096-799 Identifiers·and·References·Identifiers: ·CCE-27096-7
100 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule100 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
101 Remediation_OSBuild_Blueprint_snippet_⇲101 Remediation_OSBuild_Blueprint_snippet_⇲
  
102 [[packages]]102 [[packages]]
103 name·=·"aide"103 name·=·"aide"
104 version·=·"*"104 version·=·"*"
105 Remediation_Anaconda_snippet_⇲ 
106 Complexity:·low 
107 Disruption:·low 
108 Strategy:···enable 
  
109 package·--add=aide 
110 Remediation_Puppet_snippet_⇲105 Remediation_Puppet_snippet_⇲
111 Complexity:·low106 Complexity:·low
112 Disruption:·low107 Disruption:·low
113 Strategy:···enable108 Strategy:···enable
114 include·install_aide109 include·install_aide
  
115 class·install_aide·{110 class·install_aide·{
Offset 130, 14 lines modifiedOffset 124, 20 lines modified
130 if·!·rpm·-q·--quiet·"aide"·;·then124 if·!·rpm·-q·--quiet·"aide"·;·then
131 ····yum·install·-y·"aide"125 ····yum·install·-y·"aide"
132 fi126 fi
  
133 else127 else
134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
135 fi129 fi
 130 Remediation_Anaconda_snippet_⇲
 131 Complexity:·low
 132 Disruption:·low
 133 Strategy:···enable
  
 134 package·--add=aide
136 Remediation_Ansible_snippet_⇲135 Remediation_Ansible_snippet_⇲
137 Complexity:·low136 Complexity:·low
138 Disruption:·low137 Disruption:·low
139 Strategy:···enable138 Strategy:···enable
140 -·name:·Ensure·aide·is·installed139 -·name:·Ensure·aide·is·installed
141 ··package:140 ··package:
142 ····name:·aide141 ····name:·aide
Offset 682, 20 lines modifiedOffset 682, 14 lines modified
682 Identifiers·and·References·Identifiers: ·CCE-82213-0682 Identifiers·and·References·Identifiers: ·CCE-82213-0
683 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1683 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1
684 Remediation_OSBuild_Blueprint_snippet_⇲684 Remediation_OSBuild_Blueprint_snippet_⇲
  
685 [[packages]]685 [[packages]]
686 name·=·"sudo"686 name·=·"sudo"
687 version·=·"*"687 version·=·"*"
688 Remediation_Anaconda_snippet_⇲ 
689 Complexity:·low 
690 Disruption:·low 
691 Strategy:···enable 
  
692 package·--add=sudo 
693 Remediation_Puppet_snippet_⇲688 Remediation_Puppet_snippet_⇲
694 Complexity:·low689 Complexity:·low
695 Disruption:·low690 Disruption:·low
696 Strategy:···enable691 Strategy:···enable
697 include·install_sudo692 include·install_sudo
  
698 class·install_sudo·{693 class·install_sudo·{
Offset 713, 14 lines modifiedOffset 707, 20 lines modified
713 if·!·rpm·-q·--quiet·"sudo"·;·then707 if·!·rpm·-q·--quiet·"sudo"·;·then
714 ····yum·install·-y·"sudo"708 ····yum·install·-y·"sudo"
715 fi709 fi
  
716 else710 else
717 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'711 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
718 fi712 fi
 713 Remediation_Anaconda_snippet_⇲
 714 Complexity:·low
 715 Disruption:·low
 716 Strategy:···enable
  
 717 package·--add=sudo
719 Remediation_Ansible_snippet_⇲718 Remediation_Ansible_snippet_⇲
720 Complexity:·low719 Complexity:·low
721 Disruption:·low720 Disruption:·low
722 Strategy:···enable721 Strategy:···enable
723 -·name:·Ensure·sudo·is·installed722 -·name:·Ensure·sudo·is·installed
724 ··package:723 ··package:
725 ····name:·sudo724 ····name:·sudo
Offset 4841, 15 lines modifiedOffset 4841, 15 lines modified
4841 Identifiers·and·References·Identifiers: ·CCE-82023-34841 Identifiers·and·References·Identifiers: ·CCE-82023-3
4842 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.24842 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
4843 Remediation_Shell_script_⇲4843 Remediation_Shell_script_⇲
4844 Complexity:·low4844 Complexity:·low
4845 Disruption:·low4845 Disruption:·low
4846 Strategy:···configure4846 Strategy:···configure
4847 #·Remediation·is·applicable·only·in·certain·platforms4847 #·Remediation·is·applicable·only·in·certain·platforms
4848 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then4848 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
4849 chgrp·0·/boot/grub2/grub.cfg4849 chgrp·0·/boot/grub2/grub.cfg
  
4850 else4850 else
4851 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4851 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4852 fi4852 fi
4853 Remediation_Ansible_snippet_⇲4853 Remediation_Ansible_snippet_⇲
Offset 4874, 16 lines modifiedOffset 4874, 16 lines modified
4874 ··-·no_reboot_needed4874 ··-·no_reboot_needed
  
4875 -·name:·Test·for·existence·/boot/grub2/grub.cfg4875 -·name:·Test·for·existence·/boot/grub2/grub.cfg
4876 ··stat:4876 ··stat:
4877 ····path:·/boot/grub2/grub.cfg4877 ····path:·/boot/grub2/grub.cfg
4878 ··register:·file_exists4878 ··register:·file_exists
4879 ··when:4879 ··when:
4880 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
4881 ··-·'"grub2-common"·in·ansible_facts.packages'4880 ··-·'"grub2-common"·in·ansible_facts.packages'
 4881 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
4882 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4882 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4883 ··tags:4883 ··tags:
4884 ··-·CCE-82023-34884 ··-·CCE-82023-3
4885 ··-·CJIS-5.5.2.24885 ··-·CJIS-5.5.2.2
4886 ··-·NIST-800-171-3.4.54886 ··-·NIST-800-171-3.4.5
4887 ··-·NIST-800-53-AC-6(1)4887 ··-·NIST-800-53-AC-6(1)
4888 ··-·NIST-800-53-CM-6(a)4888 ··-·NIST-800-53-CM-6(a)
Offset 4896, 16 lines modifiedOffset 4896, 16 lines modified
4896 ··-·no_reboot_needed4896 ··-·no_reboot_needed
  
4897 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg4897 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
4898 ··file:4898 ··file:
4899 ····path:·/boot/grub2/grub.cfg4899 ····path:·/boot/grub2/grub.cfg
4900 ····group:·'0'4900 ····group:·'0'
4901 ··when:4901 ··when:
4902 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
4903 ··-·'"grub2-common"·in·ansible_facts.packages'4902 ··-·'"grub2-common"·in·ansible_facts.packages'
Max diff block lines reached; 66257/71084 bytes (93.21%) of diff not shown.
1.58 MB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-cis_workstation_l2.html
    
Offset 15387, 117 lines modifiedOffset 15387, 117 lines modified
0003c1a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003c1a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003c1b0:·3d22·2369·646d·3935·3637·2220·7461·6269··="#idm9567"·tabi0003c1b0:·3d22·2369·646d·3935·3637·2220·7461·6269··="#idm9567"·tabi
0003c1c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003c1c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003c1d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003c1d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003c1e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003c1e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003c1f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003c1f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003c200:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003c200:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003c210:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003c210:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003c220:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003c220:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003c230:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c230:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003c240:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c240:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003c250:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c250:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003c260:·643d·2269·646d·3935·3637·223e·3c74·6162··d="idm9567"><tab0003c260:·2269·646d·3935·3637·223e·3c74·6162·6c65··"idm9567"><table
0003c270:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c270:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003c280:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c280:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003c290:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c290:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003c2a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c2a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003c2b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c2b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003c2c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c2c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c2d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c2d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003c2e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c2e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003c2f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c2f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c300:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c300:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003c310:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003c310:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003c320:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003c320:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003c330:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0003c330:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
0003c340:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide0003c340:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003c350:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003c360:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003c370:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003c380:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003c390:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003c3a0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003c3b0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003c3c0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003c3d0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003c3e0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003c3f0:·2369·646d·3935·3638·2220·7461·6269·6e64··#idm9568"·tabind
 0003c400:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003c410:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003c420:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003c430:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003c440:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003c450:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003c460:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003c470:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003c480:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003c490:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003c4a0:·3935·3638·223e·3c74·6162·6c65·2063·6c61··9568"><table·cla
 0003c4b0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003c4c0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003c4d0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003c4e0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003c4f0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003c500:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c510:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003c520:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003c530:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c540:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003c550:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003c560:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c570:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003c580:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003c590:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003c5a0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003c5b0:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
 0003c5c0:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 0003c5d0:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
 0003c5e0:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the
 0003c5f0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003c600:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003c610:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 0003c620:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003c630:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003c640:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003c650:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003c660:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003c670:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
0003c350:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003c680:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003c360:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003c690:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003c370:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003c6a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003c380:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003c6b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003c390:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003c6c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c3a0:·743d·2223·6964·6d39·3536·3822·2074·6162··t="#idm9568"·tab0003c6d0:·743d·2223·6964·6d39·3536·3922·2074·6162··t="#idm9569"·tab
0003c3b0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003c6e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c3c0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003c6f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c3d0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003c700:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c3e0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003c710:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c3f0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003c720:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c400:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003c730:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003c410:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003c740:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003c420:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c750:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003c430:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003c760:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003c440:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003c770:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003c450:·3d22·6964·6d39·3536·3822·3e3c·7461·626c··="idm9568"><tabl0003c780:·6964·3d22·6964·6d39·3536·3922·3e3c·7461··id="idm9569"><ta
0003c460:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003c790:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003c470:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003c7a0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003c480:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003c7b0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003c490:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003c7c0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003c4a0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003c7d0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003c4b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c7e0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003c4c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003c7f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c4d0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003c800:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003c4e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c810:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c4f0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003c820:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003c500:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c830:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003c510:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003c840:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003c520:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003c850:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003c860:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
0003c530:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003c540:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003c550:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003c560:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003c570:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003c580:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003c590:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c5a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c5b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c5c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c5d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c5e0:·2223·6964·6d39·3536·3922·2074·6162·696e··"#idm9569"·tabin 
0003c5f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c600:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c610:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c620:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c630:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c640:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
Max diff block lines reached; 1291505/1306299 bytes (98.87%) of diff not shown.
343 KB
html2text {}
    
Offset 101, 20 lines modifiedOffset 101, 14 lines modified
101 Identifiers·and·References·Identifiers: ·CCE-27096-7101 Identifiers·and·References·Identifiers: ·CCE-27096-7
102 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule102 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
103 Remediation_OSBuild_Blueprint_snippet_⇲103 Remediation_OSBuild_Blueprint_snippet_⇲
  
104 [[packages]]104 [[packages]]
105 name·=·"aide"105 name·=·"aide"
106 version·=·"*"106 version·=·"*"
107 Remediation_Anaconda_snippet_⇲ 
108 Complexity:·low 
109 Disruption:·low 
110 Strategy:···enable 
  
111 package·--add=aide 
112 Remediation_Puppet_snippet_⇲107 Remediation_Puppet_snippet_⇲
113 Complexity:·low108 Complexity:·low
114 Disruption:·low109 Disruption:·low
115 Strategy:···enable110 Strategy:···enable
116 include·install_aide111 include·install_aide
  
117 class·install_aide·{112 class·install_aide·{
Offset 132, 14 lines modifiedOffset 126, 20 lines modified
132 if·!·rpm·-q·--quiet·"aide"·;·then126 if·!·rpm·-q·--quiet·"aide"·;·then
133 ····yum·install·-y·"aide"127 ····yum·install·-y·"aide"
134 fi128 fi
  
135 else129 else
136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'130 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
137 fi131 fi
 132 Remediation_Anaconda_snippet_⇲
 133 Complexity:·low
 134 Disruption:·low
 135 Strategy:···enable
  
 136 package·--add=aide
138 Remediation_Ansible_snippet_⇲137 Remediation_Ansible_snippet_⇲
139 Complexity:·low138 Complexity:·low
140 Disruption:·low139 Disruption:·low
141 Strategy:···enable140 Strategy:···enable
142 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
143 ··package:142 ··package:
144 ····name:·aide143 ····name:·aide
Offset 774, 20 lines modifiedOffset 774, 14 lines modified
774 Identifiers·and·References·Identifiers: ·CCE-82213-0774 Identifiers·and·References·Identifiers: ·CCE-82213-0
775 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1775 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.2.1
776 Remediation_OSBuild_Blueprint_snippet_⇲776 Remediation_OSBuild_Blueprint_snippet_⇲
  
777 [[packages]]777 [[packages]]
778 name·=·"sudo"778 name·=·"sudo"
779 version·=·"*"779 version·=·"*"
780 Remediation_Anaconda_snippet_⇲ 
781 Complexity:·low 
782 Disruption:·low 
783 Strategy:···enable 
  
784 package·--add=sudo 
785 Remediation_Puppet_snippet_⇲780 Remediation_Puppet_snippet_⇲
786 Complexity:·low781 Complexity:·low
787 Disruption:·low782 Disruption:·low
788 Strategy:···enable783 Strategy:···enable
789 include·install_sudo784 include·install_sudo
  
790 class·install_sudo·{785 class·install_sudo·{
Offset 805, 14 lines modifiedOffset 799, 20 lines modified
805 if·!·rpm·-q·--quiet·"sudo"·;·then799 if·!·rpm·-q·--quiet·"sudo"·;·then
806 ····yum·install·-y·"sudo"800 ····yum·install·-y·"sudo"
807 fi801 fi
  
808 else802 else
809 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'803 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
810 fi804 fi
 805 Remediation_Anaconda_snippet_⇲
 806 Complexity:·low
 807 Disruption:·low
 808 Strategy:···enable
  
 809 package·--add=sudo
811 Remediation_Ansible_snippet_⇲810 Remediation_Ansible_snippet_⇲
812 Complexity:·low811 Complexity:·low
813 Disruption:·low812 Disruption:·low
814 Strategy:···enable813 Strategy:···enable
815 -·name:·Ensure·sudo·is·installed814 -·name:·Ensure·sudo·is·installed
816 ··package:815 ··package:
817 ····name:·sudo816 ····name:·sudo
Offset 4989, 15 lines modifiedOffset 4989, 15 lines modified
4989 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.4989 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
4990 Severity: ················medium4990 Severity: ················medium
4991 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod4991 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
4992 Identifiers·and·References·Identifiers: ·CCE-27339-14992 Identifiers·and·References·Identifiers: ·CCE-27339-1
4993 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule4993 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
4994 Remediation_Shell_script_⇲4994 Remediation_Shell_script_⇲
4995 #·Remediation·is·applicable·only·in·certain·platforms4995 #·Remediation·is·applicable·only·in·certain·platforms
4996 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then4996 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
4997 #·First·perform·the·remediation·of·the·syscall·rule4997 #·First·perform·the·remediation·of·the·syscall·rule
4998 #·Retrieve·hardware·architecture·of·the·underlying·system4998 #·Retrieve·hardware·architecture·of·the·underlying·system
4999 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4999 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
5000 for·ARCH·in·"${RULE_ARCHS[@]}"5000 for·ARCH·in·"${RULE_ARCHS[@]}"
5001 do5001 do
Offset 5345, 16 lines modifiedOffset 5345, 16 lines modified
5345 ··-·reboot_required5345 ··-·reboot_required
5346 ··-·restrict_strategy5346 ··-·restrict_strategy
  
5347 -·name:·Set·architecture·for·audit·chmod·tasks5347 -·name:·Set·architecture·for·audit·chmod·tasks
5348 ··set_fact:5348 ··set_fact:
5349 ····audit_arch:·b645349 ····audit_arch:·b64
5350 ··when:5350 ··when:
5351 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5352 ··-·'"audit"·in·ansible_facts.packages'5351 ··-·'"audit"·in·ansible_facts.packages'
 5352 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5353 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5353 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5354 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5354 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5355 ··tags:5355 ··tags:
5356 ··-·CCE-27339-15356 ··-·CCE-27339-1
5357 ··-·CJIS-5.4.1.15357 ··-·CJIS-5.4.1.1
5358 ··-·DISA-STIG-RHEL-07-0304105358 ··-·DISA-STIG-RHEL-07-030410
5359 ··-·NIST-800-171-3.1.75359 ··-·NIST-800-171-3.1.7
Offset 5492, 16 lines modifiedOffset 5492, 16 lines modified
5492 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005492 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
5493 ········-F·auid!=unset·-F·key=perm_mod5493 ········-F·auid!=unset·-F·key=perm_mod
5494 ······create:·true5494 ······create:·true
5495 ······mode:·o-rwx5495 ······mode:·o-rwx
5496 ······state:·present5496 ······state:·present
5497 ····when:·syscalls_found·|·length·==·05497 ····when:·syscalls_found·|·length·==·0
5498 ··when:5498 ··when:
5499 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5500 ··-·'"audit"·in·ansible_facts.packages'5499 ··-·'"audit"·in·ansible_facts.packages'
Max diff block lines reached; 345389/351586 bytes (98.24%) of diff not shown.
612 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-cjis.html
    
Offset 17301, 116 lines modifiedOffset 17301, 116 lines modified
00043940:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm900043940:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
00043950:·3536·3722·2074·6162·696e·6465·783d·2230··567"·tabindex="000043950:·3536·3722·2074·6162·696e·6465·783d·2230··567"·tabindex="0
00043960:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00043960:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00043970:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00043970:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00043980:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00043980:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00043990:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00043990:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
000439a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed000439a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
000439b0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·000439b0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
000439c0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><000439c0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
000439d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p000439d0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
000439e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co000439e0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
000439f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9000439f0:·6170·7365·2220·6964·3d22·6964·6d39·3536··apse"·id="idm956
00043a00:·3536·3722·3e3c·7461·626c·6520·636c·6173··567"><table·clas00043a00:·3722·3e3c·7461·626c·6520·636c·6173·733d··7"><table·class=
00043a10:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s00043a10:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
00043a20:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor00043a20:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
00043a30:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond00043a30:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
00043a40:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C00043a40:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
00043a50:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><00043a50:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
00043a60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00043a60:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00043a70:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti00043a70:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
00043a80:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<00043a80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00043a90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00043a90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00043aa0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><00043aa0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00043ab0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></00043ab0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
00043ac0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>00043ac0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
00043ad0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
00043ae0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code00043ad0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 00043ae0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 00043af0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 00043b00:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 00043b10:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 00043b20:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 00043b30:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 00043b40:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00043b50:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00043b60:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 00043b70:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00043b80:·2d74·6172·6765·743d·2223·6964·6d39·3536··-target="#idm956
 00043b90:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
 00043ba0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 00043bb0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 00043bc0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 00043bd0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 00043be0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00043bf0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 00043c00:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00043c10:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00043c20:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00043c30:·2220·6964·3d22·6964·6d39·3536·3822·3e3c··"·id="idm9568"><
 00043c40:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 00043c50:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00043c60:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00043c70:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 00043c80:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 00043c90:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 00043ca0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00043cb0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00043cc0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00043cd0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 00043ce0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 00043cf0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 00043d00:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00043d10:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 00043d20:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 00043d30:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 00043d40:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 00043d50:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 00043d60:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 00043d70:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 00043d80:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 00043d90:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 00043da0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 00043db0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 00043dc0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 00043dd0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 00043de0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 00043df0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 00043e00:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 00043e10:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
00043af0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·00043e20:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
00043b00:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s00043e30:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
00043b10:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog00043e40:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
00043b20:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d00043e50:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
00043b30:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00043e60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00043b40:·3935·3638·2220·7461·6269·6e64·6578·3d22··9568"·tabindex="00043e70:·3935·3639·2220·7461·6269·6e64·6578·3d22··9569"·tabindex="
00043b50:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00043e80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00043b60:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00043e90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00043b70:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00043ea0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00043b80:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00043eb0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00043b90:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00043ec0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00043ba0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s00043ed0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
00043bb0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b00043ee0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
00043bc0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00043ef0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
00043bd0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00043f00:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
00043be0:·6c61·7073·6522·2069·643d·2269·646d·3935··lapse"·id="idm9500043f10:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
00043bf0:·3638·223e·3c74·6162·6c65·2063·6c61·7373··68"><table·class00043f20:·3935·3639·223e·3c74·6162·6c65·2063·6c61··9569"><table·cla
00043c00:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00043f30:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
00043c10:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00043f40:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
00043c20:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00043f50:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
00043c30:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00043f60:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
00043c40:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00043f70:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
00043c50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00043f80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
00043c60:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio00043f90:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
00043c70:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00043fa0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
00043c80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00043fb0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00043c90:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t00043fc0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
00043ca0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t00043fd0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
00043cb0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><00043fe0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 00043ff0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 00044000:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
00043cc0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
00043cd0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
00043ce0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
00043cf0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
00043d00:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
00043d10:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
00043d20:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
00043d30:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00043d40:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00043d50:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00043d60:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
00043d70:·612d·7461·7267·6574·3d22·2369·646d·3935··a-target="#idm95 
00043d80:·3639·2220·7461·6269·6e64·6578·3d22·3022··69"·tabindex="0" 
00043d90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00043da0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00043db0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00043dc0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 426874/441530 bytes (96.68%) of diff not shown.
180 KB
html2text {}
    
Offset 403, 20 lines modifiedOffset 403, 14 lines modified
403 Identifiers·and·References·Identifiers: ·CCE-27096-7403 Identifiers·and·References·Identifiers: ·CCE-27096-7
404 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule404 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
405 Remediation_OSBuild_Blueprint_snippet_⇲405 Remediation_OSBuild_Blueprint_snippet_⇲
  
406 [[packages]]406 [[packages]]
407 name·=·"aide"407 name·=·"aide"
408 version·=·"*"408 version·=·"*"
409 Remediation_Anaconda_snippet_⇲ 
410 Complexity:·low 
411 Disruption:·low 
412 Strategy:···enable 
  
413 package·--add=aide 
414 Remediation_Puppet_snippet_⇲409 Remediation_Puppet_snippet_⇲
415 Complexity:·low410 Complexity:·low
416 Disruption:·low411 Disruption:·low
417 Strategy:···enable412 Strategy:···enable
418 include·install_aide413 include·install_aide
  
419 class·install_aide·{414 class·install_aide·{
Offset 434, 14 lines modifiedOffset 428, 20 lines modified
434 if·!·rpm·-q·--quiet·"aide"·;·then428 if·!·rpm·-q·--quiet·"aide"·;·then
435 ····yum·install·-y·"aide"429 ····yum·install·-y·"aide"
436 fi430 fi
  
437 else431 else
438 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'432 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
439 fi433 fi
 434 Remediation_Anaconda_snippet_⇲
 435 Complexity:·low
 436 Disruption:·low
 437 Strategy:···enable
  
 438 package·--add=aide
440 Remediation_Ansible_snippet_⇲439 Remediation_Ansible_snippet_⇲
441 Complexity:·low440 Complexity:·low
442 Disruption:·low441 Disruption:·low
443 Strategy:···enable442 Strategy:···enable
444 -·name:·Ensure·aide·is·installed443 -·name:·Ensure·aide·is·installed
445 ··package:444 ··package:
446 ····name:·aide445 ····name:·aide
Offset 3946, 15 lines modifiedOffset 3946, 15 lines modified
3946 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.3946 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
3947 Severity: ················medium3947 Severity: ················medium
3948 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod3948 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
3949 Identifiers·and·References·Identifiers: ·CCE-27339-13949 Identifiers·and·References·Identifiers: ·CCE-27339-1
3950 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule3950 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
3951 Remediation_Shell_script_⇲3951 Remediation_Shell_script_⇲
3952 #·Remediation·is·applicable·only·in·certain·platforms3952 #·Remediation·is·applicable·only·in·certain·platforms
3953 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then3953 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
3954 #·First·perform·the·remediation·of·the·syscall·rule3954 #·First·perform·the·remediation·of·the·syscall·rule
3955 #·Retrieve·hardware·architecture·of·the·underlying·system3955 #·Retrieve·hardware·architecture·of·the·underlying·system
3956 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3956 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3957 for·ARCH·in·"${RULE_ARCHS[@]}"3957 for·ARCH·in·"${RULE_ARCHS[@]}"
3958 do3958 do
Offset 4302, 16 lines modifiedOffset 4302, 16 lines modified
4302 ··-·reboot_required4302 ··-·reboot_required
4303 ··-·restrict_strategy4303 ··-·restrict_strategy
  
4304 -·name:·Set·architecture·for·audit·chmod·tasks4304 -·name:·Set·architecture·for·audit·chmod·tasks
4305 ··set_fact:4305 ··set_fact:
4306 ····audit_arch:·b644306 ····audit_arch:·b64
4307 ··when:4307 ··when:
4308 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4309 ··-·'"audit"·in·ansible_facts.packages'4308 ··-·'"audit"·in·ansible_facts.packages'
 4309 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4310 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4310 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4311 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4311 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4312 ··tags:4312 ··tags:
4313 ··-·CCE-27339-14313 ··-·CCE-27339-1
4314 ··-·CJIS-5.4.1.14314 ··-·CJIS-5.4.1.1
4315 ··-·DISA-STIG-RHEL-07-0304104315 ··-·DISA-STIG-RHEL-07-030410
4316 ··-·NIST-800-171-3.1.74316 ··-·NIST-800-171-3.1.7
Offset 4449, 16 lines modifiedOffset 4449, 16 lines modified
4449 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004449 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4450 ········-F·auid!=unset·-F·key=perm_mod4450 ········-F·auid!=unset·-F·key=perm_mod
4451 ······create:·true4451 ······create:·true
4452 ······mode:·o-rwx4452 ······mode:·o-rwx
4453 ······state:·present4453 ······state:·present
4454 ····when:·syscalls_found·|·length·==·04454 ····when:·syscalls_found·|·length·==·0
4455 ··when:4455 ··when:
4456 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4457 ··-·'"audit"·in·ansible_facts.packages'4456 ··-·'"audit"·in·ansible_facts.packages'
 4457 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4458 ··tags:4458 ··tags:
4459 ··-·CCE-27339-14459 ··-·CCE-27339-1
4460 ··-·CJIS-5.4.1.14460 ··-·CJIS-5.4.1.1
4461 ··-·DISA-STIG-RHEL-07-0304104461 ··-·DISA-STIG-RHEL-07-030410
4462 ··-·NIST-800-171-3.1.74462 ··-·NIST-800-171-3.1.7
4463 ··-·NIST-800-53-AU-12(c)4463 ··-·NIST-800-53-AU-12(c)
4464 ··-·NIST-800-53-AU-2(d)4464 ··-·NIST-800-53-AU-2(d)
Offset 4594, 16 lines modifiedOffset 4594, 16 lines modified
4594 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10004594 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
4595 ········-F·auid!=unset·-F·key=perm_mod4595 ········-F·auid!=unset·-F·key=perm_mod
4596 ······create:·true4596 ······create:·true
4597 ······mode:·o-rwx4597 ······mode:·o-rwx
4598 ······state:·present4598 ······state:·present
4599 ····when:·syscalls_found·|·length·==·04599 ····when:·syscalls_found·|·length·==·0
4600 ··when:4600 ··when:
4601 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4602 ··-·'"audit"·in·ansible_facts.packages'4601 ··-·'"audit"·in·ansible_facts.packages'
 4602 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4603 ··-·audit_arch·==·"b64"4603 ··-·audit_arch·==·"b64"
4604 ··tags:4604 ··tags:
4605 ··-·CCE-27339-14605 ··-·CCE-27339-1
4606 ··-·CJIS-5.4.1.14606 ··-·CJIS-5.4.1.1
4607 ··-·DISA-STIG-RHEL-07-0304104607 ··-·DISA-STIG-RHEL-07-030410
4608 ··-·NIST-800-171-3.1.74608 ··-·NIST-800-171-3.1.7
4609 ··-·NIST-800-53-AU-12(c)4609 ··-·NIST-800-53-AU-12(c)
Offset 4629, 15 lines modifiedOffset 4629, 15 lines modified
4629 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.4629 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
4630 Severity: ················medium4630 Severity: ················medium
4631 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown4631 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
4632 Identifiers·and·References·Identifiers: ·CCE-27364-94632 Identifiers·and·References·Identifiers: ·CCE-27364-9
4633 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030370,·4.1.9,·SV-204517r809570_rule4633 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030370,·4.1.9,·SV-204517r809570_rule
4634 Remediation_Shell_script_⇲4634 Remediation_Shell_script_⇲
4635 #·Remediation·is·applicable·only·in·certain·platforms4635 #·Remediation·is·applicable·only·in·certain·platforms
4636 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then4636 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
4637 #·First·perform·the·remediation·of·the·syscall·rule4637 #·First·perform·the·remediation·of·the·syscall·rule
4638 #·Retrieve·hardware·architecture·of·the·underlying·system4638 #·Retrieve·hardware·architecture·of·the·underlying·system
4639 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4639 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4640 for·ARCH·in·"${RULE_ARCHS[@]}"4640 for·ARCH·in·"${RULE_ARCHS[@]}"
4641 do4641 do
Max diff block lines reached; 176100/184661 bytes (95.36%) of diff not shown.
363 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-cui.html
    
Offset 15291, 57 lines modifiedOffset 15291, 57 lines modified
0003bba0:·7461·7267·6574·3d22·2369·646d·3130·3130··target="#idm10100003bba0:·7461·7267·6574·3d22·2369·646d·3130·3130··target="#idm1010
0003bbb0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003bbb0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003bbc0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003bbc0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bbd0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003bbd0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bbe0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003bbe0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003bbf0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003bbf0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bc00:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003bc00:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bc10:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003bc10:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
0003bc20:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003bc20:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003bc30:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003bc30:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003bc40:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003bc40:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003bc50:·6170·7365·2220·6964·3d22·6964·6d31·3031··apse"·id="idm1010003bc50:·2220·6964·3d22·6964·6d31·3031·3032·223e··"·id="idm10102">
0003bc60:·3032·223e·3c70·7265·3e3c·636f·6465·3e0a··02"><pre><code>.0003bc60:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003bc70:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003bc80:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003bc90:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003bca0:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0003bcb0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0003bcc0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0003bcd0:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0003bce0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003bcf0:·2d71·202d·2d71·7569·6574·2022·6472·6163··-q·--quiet·"drac
 0003bd00:·7574·2d66·6970·7322·203b·2074·6865·6e0a··ut-fips"·;·then.
 0003bd10:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install·
 0003bd20:·2d79·2022·6472·6163·7574·2d66·6970·7322··-y·"dracut-fips"
 0003bd30:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 0003bd40:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
0003bc70:·7061·636b·6167·6520·2d2d·6164·643d·6472··package·--add=dr 
0003bc80:·6163·7574·2d66·6970·730a·3c2f·636f·6465··acut-fips.</code 
0003bc90:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bca0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bcb0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bcc0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003bcd0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bce0:·3130·3130·3322·2074·6162·696e·6465·783d··10103"·tabindex= 
0003bcf0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bd00:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bd10:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bd20:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bd30:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bd40:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003bd50:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003bd60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bd70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bd80:·6170·7365·2220·6964·3d22·6964·6d31·3031··apse"·id="idm101 
0003bd90:·3033·223e·3c70·7265·3e3c·636f·6465·3e23··03"><pre><code># 
0003bda0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·0003bd50:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
0003bdb0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·0003bd60:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
0003bdc0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003bdd0:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003bde0:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003bdf0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003be00:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003be10:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!· 
0003be20:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
0003be30:·6472·6163·7574·2d66·6970·7322·203b·2074··dracut-fips"·;·t 
0003be40:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst 
0003be50:·616c·6c20·2d79·2022·6472·6163·7574·2d66··all·-y·"dracut-f 
0003be60:·6970·7322·0a66·690a·0a65·6c73·650a·2020··ips".fi..else.·· 
0003be70:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003be80:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003be90:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003bea0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do0003bd70:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0003bd80:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 0003bd90:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003bda0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003bdb0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003bdc0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003bdd0:·6765·743d·2223·6964·6d31·3031·3033·2220··get="#idm10103"·
 0003bde0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003bdf0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003be00:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003be10:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003be20:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003be30:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003be40:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
 0003be50:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003be60:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003be70:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003be80:·6522·2069·643d·2269·646d·3130·3130·3322··e"·id="idm10103"
 0003be90:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003bea0:·6b61·6765·202d·2d61·6464·3d64·7261·6375··kage·--add=dracu
0003beb0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></0003beb0:·742d·6669·7073·0a3c·2f63·6f64·653e·3c2f··t-fips.</code></
0003bec0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003bec0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003bed0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003bed0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003bee0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003bee0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003bef0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003bef0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003bf00:·2d74·6172·6765·743d·2223·6964·6d31·3031··-target="#idm1010003bf00:·2d74·6172·6765·743d·2223·6964·6d31·3031··-target="#idm101
0003bf10:·3034·2220·7461·6269·6e64·6578·3d22·3022··04"·tabindex="0"0003bf10:·3034·2220·7461·6269·6e64·6578·3d22·3022··04"·tabindex="0"
0003bf20:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bf20:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
Offset 16015, 207 lines modifiedOffset 16015, 207 lines modified
0003e8e0:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm100003e8e0:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm10
0003e8f0:·3231·3922·2074·6162·696e·6465·783d·2230··219"·tabindex="00003e8f0:·3231·3922·2074·6162·696e·6465·783d·2230··219"·tabindex="0
0003e900:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003e900:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003e910:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003e910:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003e920:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003e920:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003e930:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003e930:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003e940:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003e940:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003e950:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003e950:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
0003e960:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003e960:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
0003e970:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003e970:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003e980:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003e980:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003e990:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10003e990:·7365·2220·6964·3d22·6964·6d31·3032·3139··se"·id="idm10219
0003e9a0:·3032·3139·223e·3c70·7265·3e3c·636f·6465··0219"><pre><code0003e9a0:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R
0003e9b0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
0003e9c0:·6472·6163·7574·2d66·6970·7320·2d2d·6164··dracut-fips·--ad 
0003e9d0:·643d·6472·6163·7574·2d66·6970·732d·6165··d=dracut-fips-ae 
0003e9e0:·736e·690a·3c2f·636f·6465·3e3c·2f70·7265··sni.</code></pre 
0003e9f0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003ea00:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003ea10:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003ea20:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003ea30:·7267·6574·3d22·2369·646d·3130·3232·3022··rget="#idm10220" 
0003ea40:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003ea50:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003ea60:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003ea70:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003ea80:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003ea90:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003eaa0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003eab0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003eac0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003ead0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003eae0:·6964·3d22·6964·6d31·3032·3230·223e·3c70··id="idm10220"><p 
0003eaf0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003eb00:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic0003e9b0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
0003eb10:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer0003e9c0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
Max diff block lines reached; 295102/329242 bytes (89.63%) of diff not shown.
41.8 KB
html2text {}
    
Offset 91, 28 lines modifiedOffset 91, 28 lines modified
91 $·sudo·yum·install·dracut-fips91 $·sudo·yum·install·dracut-fips
92 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.92 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
93 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.93 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
94 Severity: ················medium94 Severity: ················medium
95 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed95 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed
96 Identifiers·and·References·Identifiers: ·CCE-80358-596 Identifiers·and·References·Identifiers: ·CCE-80358-5
97 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-00159097 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590
98 Remediation_Anaconda_snippet_⇲ 
  
99 package·--add=dracut-fips 
100 Remediation_Shell_script_⇲98 Remediation_Shell_script_⇲
101 #·Remediation·is·applicable·only·in·certain·platforms99 #·Remediation·is·applicable·only·in·certain·platforms
102 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then100 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
103 if·!·rpm·-q·--quiet·"dracut-fips"·;·then101 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
104 ····yum·install·-y·"dracut-fips"102 ····yum·install·-y·"dracut-fips"
105 fi103 fi
  
106 else104 else
107 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'105 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
108 fi106 fi
 107 Remediation_Anaconda_snippet_⇲
  
 108 package·--add=dracut-fips
109 Remediation_Ansible_snippet_⇲109 Remediation_Ansible_snippet_⇲
110 Complexity:·low110 Complexity:·low
111 Disruption:·low111 Disruption:·low
112 Strategy:···enable112 Strategy:···enable
113 -·name:·Ensure·dracut-fips·is·installed113 -·name:·Ensure·dracut-fips·is·installed
114 ··package:114 ··package:
115 ····name:·dracut-fips115 ····name:·dracut-fips
Offset 156, 17 lines modifiedOffset 156, 14 lines modified
156 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.156 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
157 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.157 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
158 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.158 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
159 Severity: ················high159 Severity: ················high
160 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode160 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
161 Identifiers·and·References·Identifiers: ·CCE-80359-3161 Identifiers·and·References·Identifiers: ·CCE-80359-3
162 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule162 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule
163 Remediation_Anaconda_snippet_⇲ 
  
164 package·--add=dracut-fips·--add=dracut-fips-aesni 
165 Remediation_Shell_script_⇲163 Remediation_Shell_script_⇲
166 #·Remediation·is·applicable·only·in·certain·platforms164 #·Remediation·is·applicable·only·in·certain·platforms
167 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then165 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
168 #·prelink·not·installed166 #·prelink·not·installed
169 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then167 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
170 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink168 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 225, 14 lines modifiedOffset 222, 17 lines modified
225 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader222 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
226 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"223 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
227 fi224 fi
  
228 else225 else
229 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'226 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
230 fi227 fi
 228 Remediation_Anaconda_snippet_⇲
  
 229 package·--add=dracut-fips·--add=dracut-fips-aesni
231 Remediation_Ansible_snippet_⇲230 Remediation_Ansible_snippet_⇲
232 Complexity:·high231 Complexity:·high
233 Disruption:·medium232 Disruption:·medium
234 Reboot:·····true233 Reboot:·····true
235 Strategy:···restrict234 Strategy:···restrict
236 -·name:·Gather·the·package·facts235 -·name:·Gather·the·package·facts
237 ··package_facts:236 ··package_facts:
Offset 5002, 20 lines modifiedOffset 5002, 14 lines modified
5002 Identifiers·and·References·Identifiers: ·CCE-27351-65002 Identifiers·and·References·Identifiers: ·CCE-27351-6
5003 ···························References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-0001105003 ···························References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110
5004 Remediation_OSBuild_Blueprint_snippet_⇲5004 Remediation_OSBuild_Blueprint_snippet_⇲
  
5005 [[packages]]5005 [[packages]]
5006 name·=·"screen"5006 name·=·"screen"
5007 version·=·"*"5007 version·=·"*"
5008 Remediation_Anaconda_snippet_⇲ 
5009 Complexity:·low 
5010 Disruption:·low 
5011 Strategy:···enable 
  
5012 package·--add=screen 
5013 Remediation_Puppet_snippet_⇲5008 Remediation_Puppet_snippet_⇲
5014 Complexity:·low5009 Complexity:·low
5015 Disruption:·low5010 Disruption:·low
5016 Strategy:···enable5011 Strategy:···enable
5017 include·install_screen5012 include·install_screen
  
5018 class·install_screen·{5013 class·install_screen·{
Offset 5033, 14 lines modifiedOffset 5027, 20 lines modified
5033 if·!·rpm·-q·--quiet·"screen"·;·then5027 if·!·rpm·-q·--quiet·"screen"·;·then
5034 ····yum·install·-y·"screen"5028 ····yum·install·-y·"screen"
5035 fi5029 fi
  
5036 else5030 else
5037 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5031 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5038 fi5032 fi
 5033 Remediation_Anaconda_snippet_⇲
 5034 Complexity:·low
 5035 Disruption:·low
 5036 Strategy:···enable
  
 5037 package·--add=screen
5039 Remediation_Ansible_snippet_⇲5038 Remediation_Ansible_snippet_⇲
5040 Complexity:·low5039 Complexity:·low
5041 Disruption:·low5040 Disruption:·low
5042 Strategy:···enable5041 Strategy:···enable
5043 -·name:·Ensure·screen·is·installed5042 -·name:·Ensure·screen·is·installed
5044 ··package:5043 ··package:
5045 ····name:·screen5044 ····name:·screen
Offset 5062, 26 lines modifiedOffset 5062, 14 lines modified
5062 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:5062 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
5063 $·sudo·systemctl·mask·--now·debug-shell.service5063 $·sudo·systemctl·mask·--now·debug-shell.service
5064 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.5064 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
5065 Severity: ················medium5065 Severity: ················medium
5066 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled5066 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
5067 Identifiers·and·References·Identifiers: ·CCE-80206-65067 Identifiers·and·References·Identifiers: ·CCE-80206-6
5068 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002275068 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
5069 Remediation_Kubernetes_snippet_⇲ 
5070 --- 
5071 apiVersion:·machineconfiguration.openshift.io/v1 
5072 kind:·MachineConfig 
5073 spec: 
5074 ··config: 
5075 ····ignition: 
5076 ······version:·3.1.0 
5077 ····systemd: 
5078 ······units: 
Max diff block lines reached; 34375/42796 bytes (80.32%) of diff not shown.
694 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-e8.html
    
Offset 19805, 104 lines modifiedOffset 19805, 104 lines modified
0004d5c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0004d5c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0004d5d0:·2223·6964·6d31·3338·3933·2220·7461·6269··"#idm13893"·tabi0004d5d0:·2223·6964·6d31·3338·3933·2220·7461·6269··"#idm13893"·tabi
0004d5e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0004d5e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0004d5f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0004d5f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0004d600:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0004d600:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0004d610:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0004d610:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0004d620:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0004d620:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0004d630:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0004d630:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0004d640:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0004d640:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0004d650:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0004d650:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0004d660:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0004d660:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0004d670:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0004d670:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0004d680:·643d·2269·646d·3133·3839·3322·3e3c·7461··d="idm13893"><ta0004d680:·2269·646d·3133·3839·3322·3e3c·7461·626c··"idm13893"><tabl
0004d690:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0004d690:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0004d6a0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0004d6a0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0004d6b0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0004d6b0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0004d6c0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0004d6c0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0004d6d0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0004d6d0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0004d6e0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0004d6e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0004d6f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0004d6f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0004d700:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0004d700:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0004d710:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0004d710:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0004d720:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0004d720:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0004d730:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0004d730:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0004d740:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0004d740:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0004d750:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0004d750:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0004d760:·6163·6b61·6765·202d·2d61·6464·3d72·6561··ackage·--add=rea 
0004d770:·720a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··r.</code></pre>< 
0004d780:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004d790:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004d7a0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004d7b0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004d7c0:·6574·3d22·2369·646d·3133·3839·3422·2074··et="#idm13894"·t 
0004d7d0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0004d7e0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0004d7f0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0004d800:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0004d810:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0004d820:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0004d830:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet· 
0004d840:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0004d850:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0004d860:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0004d870:·6964·3d22·6964·6d31·3338·3934·223e·3c74··id="idm13894"><t 
0004d880:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0004d890:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0004d8a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0004d8b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0004d8c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0004d8d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0004d8e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0004d8f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0004d760:·7564·6520·696e·7374·616c·6c5f·7265·6172··ude·install_rear
 0004d770:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0004d780:·7265·6172·207b·0a20·2070·6163·6b61·6765··rear·{.··package
 0004d790:·207b·2027·7265·6172·273a·0a20·2020·2065···{·'rear':.····e
 0004d7a0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0004d7b0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0004d7c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0004d7d0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0004d7e0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0004d7f0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0004d800:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0004d810:·2223·6964·6d31·3338·3934·2220·7461·6269··"#idm13894"·tabi
 0004d820:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 0004d830:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 0004d840:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 0004d850:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 0004d860:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0004d870:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0004d880:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0004d890:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0004d8a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0004d8b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0004d8c0:·646d·3133·3839·3422·3e3c·7461·626c·6520··dm13894"><table·
 0004d8d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0004d8e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0004d8f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0004d900:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0004d910:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0004d900:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0004d920:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0004d910:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0004d920:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0004d930:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0004d940:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i 
0004d950:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f72··nclude·install_r 
0004d960:·6561·720a·0a63·6c61·7373·2069·6e73·7461··ear..class·insta 
0004d970:·6c6c·5f72·6561·7220·7b0a·2020·7061·636b··ll_rear·{.··pack 
0004d980:·6167·6520·7b20·2772·6561·7227·3a0a·2020··age·{·'rear':.·· 
0004d990:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0004d9a0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0004d9b0:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0004d9c0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004d9d0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004d9e0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004d9f0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004da00:·6574·3d22·2369·646d·3133·3839·3522·2074··et="#idm13895"·t 
0004da10:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0004da20:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0004da30:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0004da40:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0004da50:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0004da60:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0004da70:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..0004d930:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0004d940:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0004d950:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0004d960:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0004d970:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0004d980:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0004d990:·7072·653e·3c63·6f64·653e·0a69·6620·2120··pre><code>.if·!·
 0004d9a0:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"
 0004d9b0:·7265·6172·2220·3b20·7468·656e·0a20·2020··rear"·;·then.···
 0004d9c0:·2079·756d·2069·6e73·7461·6c6c·202d·7920···yum·install·-y·
 0004d9d0:·2272·6561·7222·0a66·690a·3c2f·636f·6465··"rear".fi.</code
 0004d9e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0004d9f0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0004da00:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0004da10:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0004da20:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0004da30:·3133·3839·3522·2074·6162·696e·6465·783d··13895"·tabindex=
 0004da40:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0004da50:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0004da60:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0004da70:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0004da80:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0004da90:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
 0004daa0:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0004da80:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0004dab0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
Max diff block lines reached; 550968/563968 bytes (97.69%) of diff not shown.
143 KB
html2text {}
    
Offset 790, 20 lines modifiedOffset 790, 14 lines modified
790 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed790 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
791 Identifiers·and·References·Identifiers: ·CCE-82882-2791 Identifiers·and·References·Identifiers: ·CCE-82882-2
792 Remediation_OSBuild_Blueprint_snippet_⇲792 Remediation_OSBuild_Blueprint_snippet_⇲
  
793 [[packages]]793 [[packages]]
794 name·=·"rear"794 name·=·"rear"
795 version·=·"*"795 version·=·"*"
796 Remediation_Anaconda_snippet_⇲ 
797 Complexity:·low 
798 Disruption:·low 
799 Strategy:···enable 
  
800 package·--add=rear 
801 Remediation_Puppet_snippet_⇲796 Remediation_Puppet_snippet_⇲
802 Complexity:·low797 Complexity:·low
803 Disruption:·low798 Disruption:·low
804 Strategy:···enable799 Strategy:···enable
805 include·install_rear800 include·install_rear
  
806 class·install_rear·{801 class·install_rear·{
Offset 815, 14 lines modifiedOffset 809, 20 lines modified
815 Complexity:·low809 Complexity:·low
816 Disruption:·low810 Disruption:·low
817 Strategy:···enable811 Strategy:···enable
  
818 if·!·rpm·-q·--quiet·"rear"·;·then812 if·!·rpm·-q·--quiet·"rear"·;·then
819 ····yum·install·-y·"rear"813 ····yum·install·-y·"rear"
820 fi814 fi
 815 Remediation_Anaconda_snippet_⇲
 816 Complexity:·low
 817 Disruption:·low
 818 Strategy:···enable
  
 819 package·--add=rear
821 Remediation_Ansible_snippet_⇲820 Remediation_Ansible_snippet_⇲
822 Complexity:·low821 Complexity:·low
823 Disruption:·low822 Disruption:·low
824 Strategy:···enable823 Strategy:···enable
825 -·name:·Ensure·rear·is·installed824 -·name:·Ensure·rear·is·installed
826 ··package:825 ··package:
827 ····name:·rear826 ····name:·rear
Offset 1649, 15 lines modifiedOffset 1649, 15 lines modified
1649 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1649 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1650 Severity: ················medium1650 Severity: ················medium
1651 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1651 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1652 Identifiers·and·References·Identifiers: ·CCE-27339-11652 Identifiers·and·References·Identifiers: ·CCE-27339-1
1653 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule1653 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
1654 Remediation_Shell_script_⇲1654 Remediation_Shell_script_⇲
1655 #·Remediation·is·applicable·only·in·certain·platforms1655 #·Remediation·is·applicable·only·in·certain·platforms
1656 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1656 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1657 #·First·perform·the·remediation·of·the·syscall·rule1657 #·First·perform·the·remediation·of·the·syscall·rule
1658 #·Retrieve·hardware·architecture·of·the·underlying·system1658 #·Retrieve·hardware·architecture·of·the·underlying·system
1659 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1659 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1660 for·ARCH·in·"${RULE_ARCHS[@]}"1660 for·ARCH·in·"${RULE_ARCHS[@]}"
1661 do1661 do
Offset 2005, 16 lines modifiedOffset 2005, 16 lines modified
2005 ··-·reboot_required2005 ··-·reboot_required
2006 ··-·restrict_strategy2006 ··-·restrict_strategy
  
2007 -·name:·Set·architecture·for·audit·chmod·tasks2007 -·name:·Set·architecture·for·audit·chmod·tasks
2008 ··set_fact:2008 ··set_fact:
2009 ····audit_arch:·b642009 ····audit_arch:·b64
2010 ··when:2010 ··when:
2011 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2012 ··-·'"audit"·in·ansible_facts.packages'2011 ··-·'"audit"·in·ansible_facts.packages'
 2012 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2013 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2013 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2014 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2014 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2015 ··tags:2015 ··tags:
2016 ··-·CCE-27339-12016 ··-·CCE-27339-1
2017 ··-·CJIS-5.4.1.12017 ··-·CJIS-5.4.1.1
2018 ··-·DISA-STIG-RHEL-07-0304102018 ··-·DISA-STIG-RHEL-07-030410
2019 ··-·NIST-800-171-3.1.72019 ··-·NIST-800-171-3.1.7
Offset 2152, 16 lines modifiedOffset 2152, 16 lines modified
2152 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002152 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2153 ········-F·auid!=unset·-F·key=perm_mod2153 ········-F·auid!=unset·-F·key=perm_mod
2154 ······create:·true2154 ······create:·true
2155 ······mode:·o-rwx2155 ······mode:·o-rwx
2156 ······state:·present2156 ······state:·present
2157 ····when:·syscalls_found·|·length·==·02157 ····when:·syscalls_found·|·length·==·0
2158 ··when:2158 ··when:
2159 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2160 ··-·'"audit"·in·ansible_facts.packages'2159 ··-·'"audit"·in·ansible_facts.packages'
 2160 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2161 ··tags:2161 ··tags:
2162 ··-·CCE-27339-12162 ··-·CCE-27339-1
2163 ··-·CJIS-5.4.1.12163 ··-·CJIS-5.4.1.1
2164 ··-·DISA-STIG-RHEL-07-0304102164 ··-·DISA-STIG-RHEL-07-030410
2165 ··-·NIST-800-171-3.1.72165 ··-·NIST-800-171-3.1.7
2166 ··-·NIST-800-53-AU-12(c)2166 ··-·NIST-800-53-AU-12(c)
2167 ··-·NIST-800-53-AU-2(d)2167 ··-·NIST-800-53-AU-2(d)
Offset 2297, 16 lines modifiedOffset 2297, 16 lines modified
2297 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002297 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2298 ········-F·auid!=unset·-F·key=perm_mod2298 ········-F·auid!=unset·-F·key=perm_mod
2299 ······create:·true2299 ······create:·true
2300 ······mode:·o-rwx2300 ······mode:·o-rwx
2301 ······state:·present2301 ······state:·present
2302 ····when:·syscalls_found·|·length·==·02302 ····when:·syscalls_found·|·length·==·0
2303 ··when:2303 ··when:
2304 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2305 ··-·'"audit"·in·ansible_facts.packages'2304 ··-·'"audit"·in·ansible_facts.packages'
 2305 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2306 ··-·audit_arch·==·"b64"2306 ··-·audit_arch·==·"b64"
2307 ··tags:2307 ··tags:
2308 ··-·CCE-27339-12308 ··-·CCE-27339-1
2309 ··-·CJIS-5.4.1.12309 ··-·CJIS-5.4.1.1
2310 ··-·DISA-STIG-RHEL-07-0304102310 ··-·DISA-STIG-RHEL-07-030410
2311 ··-·NIST-800-171-3.1.72311 ··-·NIST-800-171-3.1.7
2312 ··-·NIST-800-53-AU-12(c)2312 ··-·NIST-800-53-AU-12(c)
Offset 2332, 15 lines modifiedOffset 2332, 15 lines modified
2332 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2332 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2333 Severity: ················medium2333 Severity: ················medium
2334 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2334 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2335 Identifiers·and·References·Identifiers: ·CCE-27364-92335 Identifiers·and·References·Identifiers: ·CCE-27364-9
2336 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030370,·4.1.9,·SV-204517r809570_rule2336 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030370,·4.1.9,·SV-204517r809570_rule
2337 Remediation_Shell_script_⇲2337 Remediation_Shell_script_⇲
2338 #·Remediation·is·applicable·only·in·certain·platforms2338 #·Remediation·is·applicable·only·in·certain·platforms
2339 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then2339 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
2340 #·First·perform·the·remediation·of·the·syscall·rule2340 #·First·perform·the·remediation·of·the·syscall·rule
2341 #·Retrieve·hardware·architecture·of·the·underlying·system2341 #·Retrieve·hardware·architecture·of·the·underlying·system
2342 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2342 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2343 for·ARCH·in·"${RULE_ARCHS[@]}"2343 for·ARCH·in·"${RULE_ARCHS[@]}"
2344 do2344 do
Max diff block lines reached; 138683/146555 bytes (94.63%) of diff not shown.
1.34 MB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-hipaa.html
    
Offset 22424, 94 lines modifiedOffset 22424, 94 lines modified
00057970:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00057970:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00057980:·6964·6d31·3735·3430·2220·7461·6269·6e64··idm17540"·tabind00057980:·6964·6d31·3735·3430·2220·7461·6269·6e64··idm17540"·tabind
00057990:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00057990:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
000579a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand000579a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
000579b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title000579b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
000579c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re000579c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
000579d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">000579d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
000579e0:·5265·6d65·6469·6174·696f·6e20·4b75·6265··Remediation·Kube000579e0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu
 000579f0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn
 00057a00:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00057a10:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00057a20:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00057a30:·6170·7365·2220·6964·3d22·6964·6d31·3735··apse"·id="idm175
 00057a40:·3430·223e·3c70·7265·3e3c·636f·6465·3e0a··40"><pre><code>.
 00057a50:·5b63·7573·746f·6d69·7a61·7469·6f6e·732e··[customizations.
 00057a60:·7365·7276·6963·6573·5d0a·6469·7361·626c··services].disabl
 00057a70:·6564·203d·205b·2264·6562·7567·2d73·6865··ed·=·["debug-she
 00057a80:·6c6c·225d·0a3c·2f63·6f64·653e·3c2f·7072··ll"].</code></pr
000579f0:·726e·6574·6573·2073·6e69·7070·6574·20e2··rnetes·snippet·. 
00057a00:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00057a10:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00057a20:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00057a30:·643d·2269·646d·3137·3534·3022·3e3c·7072··d="idm17540"><pr 
00057a40:·653e·3c63·6f64·653e·2d2d·2d0a·6170·6956··e><code>---.apiV 
00057a50:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec 
00057a60:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope 
00057a70:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin 
00057a80:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig 
00057a90:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config: 
00057aa0:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.· 
00057ab0:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3. 
00057ac0:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd: 
00057ad0:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.·· 
00057ae0:·2020·2020·2d20·656e·6162·6c65·643a·2066······-·enabled:·f 
00057af0:·616c·7365·0a20·2020·2020·2020·206e·616d··alse.········nam 
00057b00:·653a·2064·6562·7567·2d73·6865·6c6c·2e73··e:·debug-shell.s 
00057b10:·6572·7669·6365·0a3c·2f63·6f64·653e·3c2f··ervice.</code></ 
00057b20:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla00057a90:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
00057b30:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ00057aa0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
00057b40:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle00057ab0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
00057b50:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data00057ac0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
00057b60:·2d74·6172·6765·743d·2223·6964·6d31·3735··-target="#idm17500057ad0:·6172·6765·743d·2223·6964·6d31·3735·3431··arget="#idm17541
00057b70:·3431·2220·7461·6269·6e64·6578·3d22·3022··41"·tabindex="0"00057ae0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00057b80:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00057af0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00057b90:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00057b00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00057ba0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00057b10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00057bb0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00057b20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00057bc0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00057b30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00057bd0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
00057be0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
00057bf0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00057c00:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00057c10:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00057c20:·6964·3d22·6964·6d31·3735·3431·223e·3c70··id="idm17541"><p 
00057c30:·7265·3e3c·636f·6465·3e0a·5b63·7573·746f··re><code>.[custo 
00057c40:·6d69·7a61·7469·6f6e·732e·7365·7276·6963··mizations.servic 
00057c50:·6573·5d0a·6469·7361·626c·6564·203d·205b··es].disabled·=·[ 
00057c60:·2264·6562·7567·2d73·6865·6c6c·225d·0a3c··"debug-shell"].<00057b40:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
 00057b50:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00057b60:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00057b70:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00057b80:·6522·2069·643d·2269·646d·3137·3534·3122··e"·id="idm17541"
 00057b90:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00057ba0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00057bb0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 00057bc0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 00057bd0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 00057be0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 00057bf0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00057c00:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 00057c10:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00057c20:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 00057c30:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 00057c40:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 00057c50:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 00057c60:·653e·696e·636c·7564·6520·6469·7361·626c··e>include·disabl
 00057c70:·655f·6465·6275·672d·7368·656c·6c0a·0a63··e_debug-shell..c
 00057c80:·6c61·7373·2064·6973·6162·6c65·5f64·6562··lass·disable_deb
 00057c90:·7567·2d73·6865·6c6c·207b·0a20·2073·6572··ug-shell·{.··ser
 00057ca0:·7669·6365·207b·2764·6562·7567·2d73·6865··vice·{'debug-she
 00057cb0:·6c6c·273a·0a20·2020·2065·6e61·626c·6520··ll':.····enable·
 00057cc0:·3d26·6774·3b20·6661·6c73·652c·0a20·2020··=&gt;·false,.···
 00057cd0:·2065·6e73·7572·6520·3d26·6774·3b20·2773···ensure·=&gt;·'s
 00057ce0:·746f·7070·6564·272c·0a20·207d·0a7d·0a3c··topped',.··}.}.<
00057c70:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di00057cf0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
00057c80:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·00057d00:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
00057c90:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat00057d10:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
00057ca0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap00057d20:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
00057cb0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00057d30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00057cc0:·2223·6964·6d31·3735·3432·2220·7461·6269··"#idm17542"·tabi00057d40:·2223·6964·6d31·3735·3432·2220·7461·6269··"#idm17542"·tabi
00057cd0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00057d50:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00057ce0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00057d60:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00057cf0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00057d70:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00057d00:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00057d80:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00057d10:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00057d90:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00057d20:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu00057da0:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
00057d30:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...00057db0:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
00057d40:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00057dc0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00057d50:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00057dd0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00057d60:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00057de0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00057d70:·2269·646d·3137·3534·3222·3e3c·7461·626c··"idm17542"><tabl00057df0:·2069·643d·2269·646d·3137·3534·3222·3e3c···id="idm17542"><
 00057e00:·7072·653e·3c63·6f64·653e·2d2d·2d0a·6170··pre><code>---.ap
 00057e10:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin
 00057e20:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o
 00057e30:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k
 00057e40:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf
 00057e50:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi
 00057e60:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:
 00057e70:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·
 00057e80:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system
 00057e90:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:.
 00057ea0:·2020·2020·2020·2d20·656e·6162·6c65·643a········-·enabled:
 00057eb0:·2066·616c·7365·0a20·2020·2020·2020·206e···false.········n
00057d80:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00057d90:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00057da0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00057db0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00057dc0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00057dd0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00057de0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00057df0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00057e00:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00057e10:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
00057e20:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
00057e30:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
00057e40:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl 
00057e50:·7564·6520·6469·7361·626c·655f·6465·6275··ude·disable_debu 
Max diff block lines reached; 1022487/1034105 bytes (98.88%) of diff not shown.
366 KB
html2text {}
    
Offset 1209, 26 lines modifiedOffset 1209, 14 lines modified
1209 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:1209 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
1210 $·sudo·systemctl·mask·--now·debug-shell.service1210 $·sudo·systemctl·mask·--now·debug-shell.service
1211 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.1211 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
1212 Severity: ················medium1212 Severity: ················medium
1213 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1213 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1214 Identifiers·and·References·Identifiers: ·CCE-80206-61214 Identifiers·and·References·Identifiers: ·CCE-80206-6
1215 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271215 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1216 Remediation_Kubernetes_snippet_⇲ 
1217 --- 
1218 apiVersion:·machineconfiguration.openshift.io/v1 
1219 kind:·MachineConfig 
1220 spec: 
1221 ··config: 
1222 ····ignition: 
1223 ······version:·3.1.0 
1224 ····systemd: 
1225 ······units: 
1226 ······-·enabled:·false 
1227 ········name:·debug-shell.service 
1228 Remediation_OSBuild_Blueprint_snippet_⇲1216 Remediation_OSBuild_Blueprint_snippet_⇲
  
1229 [customizations.services]1217 [customizations.services]
1230 disabled·=·["debug-shell"]1218 disabled·=·["debug-shell"]
1231 Remediation_Puppet_snippet_⇲1219 Remediation_Puppet_snippet_⇲
1232 Complexity:·low1220 Complexity:·low
1233 Disruption:·low1221 Disruption:·low
Offset 1237, 14 lines modifiedOffset 1225, 26 lines modified
  
1237 class·disable_debug-shell·{1225 class·disable_debug-shell·{
1238 ··service·{'debug-shell':1226 ··service·{'debug-shell':
1239 ····enable·=>·false,1227 ····enable·=>·false,
1240 ····ensure·=>·'stopped',1228 ····ensure·=>·'stopped',
1241 ··}1229 ··}
1242 }1230 }
 1231 Remediation_Kubernetes_snippet_⇲
 1232 ---
 1233 apiVersion:·machineconfiguration.openshift.io/v1
 1234 kind:·MachineConfig
 1235 spec:
 1236 ··config:
 1237 ····ignition:
 1238 ······version:·3.1.0
 1239 ····systemd:
 1240 ······units:
 1241 ······-·enabled:·false
 1242 ········name:·debug-shell.service
1243 Remediation_Shell_script_⇲1243 Remediation_Shell_script_⇲
1244 Complexity:·low1244 Complexity:·low
1245 Disruption:·low1245 Disruption:·low
1246 Strategy:···disable1246 Strategy:···disable
1247 #·Remediation·is·applicable·only·in·certain·platforms1247 #·Remediation·is·applicable·only·in·certain·platforms
1248 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1248 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
Offset 2079, 15 lines modifiedOffset 2079, 15 lines modified
2079 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2079 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2080 Severity: ················medium2080 Severity: ················medium
2081 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod2081 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
2082 Identifiers·and·References·Identifiers: ·CCE-27339-12082 Identifiers·and·References·Identifiers: ·CCE-27339-1
2083 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule2083 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
2084 Remediation_Shell_script_⇲2084 Remediation_Shell_script_⇲
2085 #·Remediation·is·applicable·only·in·certain·platforms2085 #·Remediation·is·applicable·only·in·certain·platforms
2086 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then2086 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
2087 #·First·perform·the·remediation·of·the·syscall·rule2087 #·First·perform·the·remediation·of·the·syscall·rule
2088 #·Retrieve·hardware·architecture·of·the·underlying·system2088 #·Retrieve·hardware·architecture·of·the·underlying·system
2089 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2089 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2090 for·ARCH·in·"${RULE_ARCHS[@]}"2090 for·ARCH·in·"${RULE_ARCHS[@]}"
2091 do2091 do
Offset 2435, 16 lines modifiedOffset 2435, 16 lines modified
2435 ··-·reboot_required2435 ··-·reboot_required
2436 ··-·restrict_strategy2436 ··-·restrict_strategy
  
2437 -·name:·Set·architecture·for·audit·chmod·tasks2437 -·name:·Set·architecture·for·audit·chmod·tasks
2438 ··set_fact:2438 ··set_fact:
2439 ····audit_arch:·b642439 ····audit_arch:·b64
2440 ··when:2440 ··when:
2441 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2442 ··-·'"audit"·in·ansible_facts.packages'2441 ··-·'"audit"·in·ansible_facts.packages'
 2442 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2443 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2443 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2444 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2444 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2445 ··tags:2445 ··tags:
2446 ··-·CCE-27339-12446 ··-·CCE-27339-1
2447 ··-·CJIS-5.4.1.12447 ··-·CJIS-5.4.1.1
2448 ··-·DISA-STIG-RHEL-07-0304102448 ··-·DISA-STIG-RHEL-07-030410
2449 ··-·NIST-800-171-3.1.72449 ··-·NIST-800-171-3.1.7
Offset 2582, 16 lines modifiedOffset 2582, 16 lines modified
2582 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002582 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2583 ········-F·auid!=unset·-F·key=perm_mod2583 ········-F·auid!=unset·-F·key=perm_mod
2584 ······create:·true2584 ······create:·true
2585 ······mode:·o-rwx2585 ······mode:·o-rwx
2586 ······state:·present2586 ······state:·present
2587 ····when:·syscalls_found·|·length·==·02587 ····when:·syscalls_found·|·length·==·0
2588 ··when:2588 ··when:
2589 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2590 ··-·'"audit"·in·ansible_facts.packages'2589 ··-·'"audit"·in·ansible_facts.packages'
 2590 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2591 ··tags:2591 ··tags:
2592 ··-·CCE-27339-12592 ··-·CCE-27339-1
2593 ··-·CJIS-5.4.1.12593 ··-·CJIS-5.4.1.1
2594 ··-·DISA-STIG-RHEL-07-0304102594 ··-·DISA-STIG-RHEL-07-030410
2595 ··-·NIST-800-171-3.1.72595 ··-·NIST-800-171-3.1.7
2596 ··-·NIST-800-53-AU-12(c)2596 ··-·NIST-800-53-AU-12(c)
2597 ··-·NIST-800-53-AU-2(d)2597 ··-·NIST-800-53-AU-2(d)
Offset 2727, 16 lines modifiedOffset 2727, 16 lines modified
2727 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002727 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2728 ········-F·auid!=unset·-F·key=perm_mod2728 ········-F·auid!=unset·-F·key=perm_mod
2729 ······create:·true2729 ······create:·true
2730 ······mode:·o-rwx2730 ······mode:·o-rwx
2731 ······state:·present2731 ······state:·present
2732 ····when:·syscalls_found·|·length·==·02732 ····when:·syscalls_found·|·length·==·0
2733 ··when:2733 ··when:
2734 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2735 ··-·'"audit"·in·ansible_facts.packages'2734 ··-·'"audit"·in·ansible_facts.packages'
 2735 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2736 ··-·audit_arch·==·"b64"2736 ··-·audit_arch·==·"b64"
2737 ··tags:2737 ··tags:
2738 ··-·CCE-27339-12738 ··-·CCE-27339-1
2739 ··-·CJIS-5.4.1.12739 ··-·CJIS-5.4.1.1
2740 ··-·DISA-STIG-RHEL-07-0304102740 ··-·DISA-STIG-RHEL-07-030410
2741 ··-·NIST-800-171-3.1.72741 ··-·NIST-800-171-3.1.7
2742 ··-·NIST-800-53-AU-12(c)2742 ··-·NIST-800-53-AU-12(c)
Offset 2762, 15 lines modifiedOffset 2762, 15 lines modified
2762 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2762 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2763 Severity: ················medium2763 Severity: ················medium
2764 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2764 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
Max diff block lines reached; 367513/374384 bytes (98.16%) of diff not shown.
1.76 MB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-ncp.html
    
Offset 17432, 116 lines modifiedOffset 17432, 116 lines modified
00044170:·7267·6574·3d22·2369·646d·3935·3637·2220··rget="#idm9567"·00044170:·7267·6574·3d22·2369·646d·3935·3637·2220··rget="#idm9567"·
00044180:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00044180:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00044190:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00044190:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
000441a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"000441a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
000441b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate000441b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
000441c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href000441c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
000441d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio000441d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
000441e0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp000441e0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
000441f0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d000441f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00044200:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00044200:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00044210:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00044210:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00044220:·6522·2069·643d·2269·646d·3935·3637·223e··e"·id="idm9567">00044220:·2069·643d·2269·646d·3935·3637·223e·3c74···id="idm9567"><t
00044230:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta00044230:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
00044240:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00044240:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
00044250:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00044250:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
00044260:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed00044260:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
00044270:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00044270:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00044280:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo00044280:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
00044290:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00044290:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
000442a0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</000442a0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
000442b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><000442b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
000442c0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra000442c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
000442d0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en000442d0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
000442e0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></000442e0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
000442f0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code000442f0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
00044300:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=00044300:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 00044310:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 00044320:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 00044330:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 00044340:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 00044350:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 00044360:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 00044370:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 00044380:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 00044390:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 000443a0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 000443b0:·6574·3d22·2369·646d·3935·3638·2220·7461··et="#idm9568"·ta
 000443c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 000443d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 000443e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 000443f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00044400:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00044410:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00044420:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 00044430:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00044440:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00044450:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00044460:·2269·646d·3935·3638·223e·3c74·6162·6c65··"idm9568"><table
 00044470:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00044480:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00044490:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 000444a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 000444b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 000444c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 000444d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 000444e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 000444f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00044500:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00044510:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 00044520:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00044530:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 00044540:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 00044550:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 00044560:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 00044570:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 00044580:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 00044590:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 000445a0:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 000445b0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 000445c0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 000445d0:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
 000445e0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 000445f0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 00044600:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 00044610:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 00044620:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 00044630:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
00044310:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr00044640:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
00044320:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class00044650:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
00044330:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes00044660:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
00044340:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="00044670:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
00044350:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t00044680:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
00044360:·6172·6765·743d·2223·6964·6d39·3536·3822··arget="#idm9568"00044690:·6172·6765·743d·2223·6964·6d39·3536·3922··arget="#idm9569"
00044370:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro000446a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00044380:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria000446b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00044390:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false000446c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
000443a0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat000446d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
000443b0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre000446e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
000443c0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati000446f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
000443d0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe00044700:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
000443e0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00044710:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
000443f0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00044720:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00044400:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00044730:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00044410:·2220·6964·3d22·6964·6d39·3536·3822·3e3c··"·id="idm9568"><00044740:·7365·2220·6964·3d22·6964·6d39·3536·3922··se"·id="idm9569"
00044420:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00044750:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00044430:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00044760:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00044440:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00044770:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
00044450:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00044780:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
00044460:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00044790:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00044470:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low000447a0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
00044480:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t000447b0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00044490:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t000447c0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
000444a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></000447d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
000444b0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat000447e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
000444c0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena000447f0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
000444d0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t00044800:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
000444e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00044810:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 00044820:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
000444f0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
00044500:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
00044510:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
00044520:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
00044530:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
00044540:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
00044550:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
00044560:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00044570:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00044580:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00044590:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
000445a0:·6765·743d·2223·6964·6d39·3536·3922·2074··get="#idm9569"·t 
000445b0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
000445c0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
000445d0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
000445e0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
000445f0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
00044600:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
00044610:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 1391065/1405721 bytes (98.96%) of diff not shown.
428 KB
html2text {}
    
Offset 431, 20 lines modifiedOffset 431, 14 lines modified
431 Identifiers·and·References·Identifiers: ·CCE-27096-7431 Identifiers·and·References·Identifiers: ·CCE-27096-7
432 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule432 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
433 Remediation_OSBuild_Blueprint_snippet_⇲433 Remediation_OSBuild_Blueprint_snippet_⇲
  
434 [[packages]]434 [[packages]]
435 name·=·"aide"435 name·=·"aide"
436 version·=·"*"436 version·=·"*"
437 Remediation_Anaconda_snippet_⇲ 
438 Complexity:·low 
439 Disruption:·low 
440 Strategy:···enable 
  
441 package·--add=aide 
442 Remediation_Puppet_snippet_⇲437 Remediation_Puppet_snippet_⇲
443 Complexity:·low438 Complexity:·low
444 Disruption:·low439 Disruption:·low
445 Strategy:···enable440 Strategy:···enable
446 include·install_aide441 include·install_aide
  
447 class·install_aide·{442 class·install_aide·{
Offset 462, 14 lines modifiedOffset 456, 20 lines modified
462 if·!·rpm·-q·--quiet·"aide"·;·then456 if·!·rpm·-q·--quiet·"aide"·;·then
463 ····yum·install·-y·"aide"457 ····yum·install·-y·"aide"
464 fi458 fi
  
465 else459 else
466 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'460 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
467 fi461 fi
 462 Remediation_Anaconda_snippet_⇲
 463 Complexity:·low
 464 Disruption:·low
 465 Strategy:···enable
  
 466 package·--add=aide
468 Remediation_Ansible_snippet_⇲467 Remediation_Ansible_snippet_⇲
469 Complexity:·low468 Complexity:·low
470 Disruption:·low469 Disruption:·low
471 Strategy:···enable470 Strategy:···enable
472 -·name:·Ensure·aide·is·installed471 -·name:·Ensure·aide·is·installed
473 ··package:472 ··package:
474 ····name:·aide473 ····name:·aide
Offset 964, 28 lines modifiedOffset 964, 28 lines modified
964 $·sudo·yum·install·dracut-fips964 $·sudo·yum·install·dracut-fips
965 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.965 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
966 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.966 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
967 Severity: ················medium967 Severity: ················medium
968 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed968 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed
969 Identifiers·and·References·Identifiers: ·CCE-80358-5969 Identifiers·and·References·Identifiers: ·CCE-80358-5
970 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590970 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590
971 Remediation_Anaconda_snippet_⇲ 
  
972 package·--add=dracut-fips 
973 Remediation_Shell_script_⇲971 Remediation_Shell_script_⇲
974 #·Remediation·is·applicable·only·in·certain·platforms972 #·Remediation·is·applicable·only·in·certain·platforms
975 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then973 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
976 if·!·rpm·-q·--quiet·"dracut-fips"·;·then974 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
977 ····yum·install·-y·"dracut-fips"975 ····yum·install·-y·"dracut-fips"
978 fi976 fi
  
979 else977 else
980 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'978 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
981 fi979 fi
 980 Remediation_Anaconda_snippet_⇲
  
 981 package·--add=dracut-fips
982 Remediation_Ansible_snippet_⇲982 Remediation_Ansible_snippet_⇲
983 Complexity:·low983 Complexity:·low
984 Disruption:·low984 Disruption:·low
985 Strategy:···enable985 Strategy:···enable
986 -·name:·Ensure·dracut-fips·is·installed986 -·name:·Ensure·dracut-fips·is·installed
987 ··package:987 ··package:
988 ····name:·dracut-fips988 ····name:·dracut-fips
Offset 1029, 17 lines modifiedOffset 1029, 14 lines modified
1029 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1029 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1030 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1030 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1031 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1031 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1032 Severity: ················high1032 Severity: ················high
1033 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode1033 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
1034 Identifiers·and·References·Identifiers: ·CCE-80359-31034 Identifiers·and·References·Identifiers: ·CCE-80359-3
1035 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule1035 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule
1036 Remediation_Anaconda_snippet_⇲ 
  
1037 package·--add=dracut-fips·--add=dracut-fips-aesni 
1038 Remediation_Shell_script_⇲1036 Remediation_Shell_script_⇲
1039 #·Remediation·is·applicable·only·in·certain·platforms1037 #·Remediation·is·applicable·only·in·certain·platforms
1040 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then1038 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
1041 #·prelink·not·installed1039 #·prelink·not·installed
1042 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then1040 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
1043 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink1041 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 1098, 14 lines modifiedOffset 1095, 17 lines modified
1098 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader1095 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
1099 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"1096 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
1100 fi1097 fi
  
1101 else1098 else
1102 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1099 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1103 fi1100 fi
 1101 Remediation_Anaconda_snippet_⇲
  
 1102 package·--add=dracut-fips·--add=dracut-fips-aesni
1104 Remediation_Ansible_snippet_⇲1103 Remediation_Ansible_snippet_⇲
1105 Complexity:·high1104 Complexity:·high
1106 Disruption:·medium1105 Disruption:·medium
1107 Reboot:·····true1106 Reboot:·····true
1108 Strategy:···restrict1107 Strategy:···restrict
1109 -·name:·Gather·the·package·facts1108 -·name:·Gather·the·package·facts
1110 ··package_facts:1109 ··package_facts:
Offset 12669, 20 lines modifiedOffset 12669, 14 lines modified
12669 Identifiers·and·References·Identifiers: ·CCE-27351-612669 Identifiers·and·References·Identifiers: ·CCE-27351-6
12670 ···························References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-00011012670 ···························References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110
12671 Remediation_OSBuild_Blueprint_snippet_⇲12671 Remediation_OSBuild_Blueprint_snippet_⇲
  
12672 [[packages]]12672 [[packages]]
12673 name·=·"screen"12673 name·=·"screen"
12674 version·=·"*"12674 version·=·"*"
12675 Remediation_Anaconda_snippet_⇲ 
12676 Complexity:·low 
12677 Disruption:·low 
12678 Strategy:···enable 
  
12679 package·--add=screen 
12680 Remediation_Puppet_snippet_⇲12675 Remediation_Puppet_snippet_⇲
12681 Complexity:·low12676 Complexity:·low
12682 Disruption:·low12677 Disruption:·low
12683 Strategy:···enable12678 Strategy:···enable
Max diff block lines reached; 430045/438371 bytes (98.10%) of diff not shown.
363 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-ospp.html
    
Offset 15266, 57 lines modifiedOffset 15266, 57 lines modified
0003ba10:·7461·7267·6574·3d22·2369·646d·3130·3130··target="#idm10100003ba10:·7461·7267·6574·3d22·2369·646d·3130·3130··target="#idm1010
0003ba20:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003ba20:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003ba30:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003ba30:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003ba40:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003ba40:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003ba50:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003ba50:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003ba60:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003ba60:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003ba70:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003ba70:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003ba80:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003ba80:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
0003ba90:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003ba90:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003baa0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003baa0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003bab0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003bab0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003bac0:·6170·7365·2220·6964·3d22·6964·6d31·3031··apse"·id="idm1010003bac0:·2220·6964·3d22·6964·6d31·3031·3032·223e··"·id="idm10102">
0003bad0:·3032·223e·3c70·7265·3e3c·636f·6465·3e0a··02"><pre><code>.0003bad0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003bae0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003baf0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003bb00:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003bb10:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0003bb20:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0003bb30:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0003bb40:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0003bb50:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003bb60:·2d71·202d·2d71·7569·6574·2022·6472·6163··-q·--quiet·"drac
 0003bb70:·7574·2d66·6970·7322·203b·2074·6865·6e0a··ut-fips"·;·then.
 0003bb80:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install·
 0003bb90:·2d79·2022·6472·6163·7574·2d66·6970·7322··-y·"dracut-fips"
 0003bba0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 0003bbb0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
0003bae0:·7061·636b·6167·6520·2d2d·6164·643d·6472··package·--add=dr 
0003baf0:·6163·7574·2d66·6970·730a·3c2f·636f·6465··acut-fips.</code 
0003bb00:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bb10:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bb20:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bb30:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003bb40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bb50:·3130·3130·3322·2074·6162·696e·6465·783d··10103"·tabindex= 
0003bb60:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bb70:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bb80:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bb90:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bba0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bbb0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003bbc0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003bbd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bbe0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bbf0:·6170·7365·2220·6964·3d22·6964·6d31·3031··apse"·id="idm101 
0003bc00:·3033·223e·3c70·7265·3e3c·636f·6465·3e23··03"><pre><code># 
0003bc10:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·0003bbc0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
0003bc20:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·0003bbd0:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
0003bc30:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003bc40:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/ 
0003bc50:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
0003bc60:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
0003bc70:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren 
0003bc80:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!· 
0003bc90:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
0003bca0:·6472·6163·7574·2d66·6970·7322·203b·2074··dracut-fips"·;·t 
0003bcb0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst 
0003bcc0:·616c·6c20·2d79·2022·6472·6163·7574·2d66··all·-y·"dracut-f 
0003bcd0:·6970·7322·0a66·690a·0a65·6c73·650a·2020··ips".fi..else.·· 
0003bce0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003bcf0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003bd00:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003bd10:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do0003bbe0:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0003bbf0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 0003bc00:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003bc10:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003bc20:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003bc30:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003bc40:·6765·743d·2223·6964·6d31·3031·3033·2220··get="#idm10103"·
 0003bc50:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003bc60:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003bc70:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003bc80:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003bc90:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003bca0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003bcb0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
 0003bcc0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003bcd0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bce0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003bcf0:·6522·2069·643d·2269·646d·3130·3130·3322··e"·id="idm10103"
 0003bd00:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003bd10:·6b61·6765·202d·2d61·6464·3d64·7261·6375··kage·--add=dracu
0003bd20:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></0003bd20:·742d·6669·7073·0a3c·2f63·6f64·653e·3c2f··t-fips.</code></
0003bd30:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003bd30:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003bd40:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003bd40:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003bd50:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003bd50:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003bd60:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003bd60:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003bd70:·2d74·6172·6765·743d·2223·6964·6d31·3031··-target="#idm1010003bd70:·2d74·6172·6765·743d·2223·6964·6d31·3031··-target="#idm101
0003bd80:·3034·2220·7461·6269·6e64·6578·3d22·3022··04"·tabindex="0"0003bd80:·3034·2220·7461·6269·6e64·6578·3d22·3022··04"·tabindex="0"
0003bd90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bd90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
Offset 15990, 207 lines modifiedOffset 15990, 207 lines modified
0003e750:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm100003e750:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm10
0003e760:·3231·3922·2074·6162·696e·6465·783d·2230··219"·tabindex="00003e760:·3231·3922·2074·6162·696e·6465·783d·2230··219"·tabindex="0
0003e770:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003e770:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003e780:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003e780:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003e790:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003e790:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003e7a0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003e7a0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003e7b0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003e7b0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003e7c0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003e7c0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
0003e7d0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003e7d0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
0003e7e0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003e7e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003e7f0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003e7f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003e800:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10003e800:·7365·2220·6964·3d22·6964·6d31·3032·3139··se"·id="idm10219
0003e810:·3032·3139·223e·3c70·7265·3e3c·636f·6465··0219"><pre><code0003e810:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R
0003e820:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add= 
0003e830:·6472·6163·7574·2d66·6970·7320·2d2d·6164··dracut-fips·--ad 
0003e840:·643d·6472·6163·7574·2d66·6970·732d·6165··d=dracut-fips-ae 
0003e850:·736e·690a·3c2f·636f·6465·3e3c·2f70·7265··sni.</code></pre 
0003e860:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003e870:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003e880:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003e890:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003e8a0:·7267·6574·3d22·2369·646d·3130·3232·3022··rget="#idm10220" 
0003e8b0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003e8c0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003e8d0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003e8e0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003e8f0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003e900:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003e910:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003e920:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003e930:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003e940:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003e950:·6964·3d22·6964·6d31·3032·3230·223e·3c70··id="idm10220"><p 
0003e960:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003e970:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic0003e820:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
0003e980:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer0003e830:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
Max diff block lines reached; 295102/329242 bytes (89.63%) of diff not shown.
41.8 KB
html2text {}
    
Offset 85, 28 lines modifiedOffset 85, 28 lines modified
85 $·sudo·yum·install·dracut-fips85 $·sudo·yum·install·dracut-fips
86 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.86 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
87 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.87 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
88 Severity: ················medium88 Severity: ················medium
89 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed89 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed
90 Identifiers·and·References·Identifiers: ·CCE-80358-590 Identifiers·and·References·Identifiers: ·CCE-80358-5
91 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-00159091 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590
92 Remediation_Anaconda_snippet_⇲ 
  
93 package·--add=dracut-fips 
94 Remediation_Shell_script_⇲92 Remediation_Shell_script_⇲
95 #·Remediation·is·applicable·only·in·certain·platforms93 #·Remediation·is·applicable·only·in·certain·platforms
96 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then94 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
97 if·!·rpm·-q·--quiet·"dracut-fips"·;·then95 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
98 ····yum·install·-y·"dracut-fips"96 ····yum·install·-y·"dracut-fips"
99 fi97 fi
  
100 else98 else
101 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'99 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
102 fi100 fi
 101 Remediation_Anaconda_snippet_⇲
  
 102 package·--add=dracut-fips
103 Remediation_Ansible_snippet_⇲103 Remediation_Ansible_snippet_⇲
104 Complexity:·low104 Complexity:·low
105 Disruption:·low105 Disruption:·low
106 Strategy:···enable106 Strategy:···enable
107 -·name:·Ensure·dracut-fips·is·installed107 -·name:·Ensure·dracut-fips·is·installed
108 ··package:108 ··package:
109 ····name:·dracut-fips109 ····name:·dracut-fips
Offset 150, 17 lines modifiedOffset 150, 14 lines modified
150 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.150 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
151 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.151 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
152 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.152 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
153 Severity: ················high153 Severity: ················high
154 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode154 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
155 Identifiers·and·References·Identifiers: ·CCE-80359-3155 Identifiers·and·References·Identifiers: ·CCE-80359-3
156 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule156 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule
157 Remediation_Anaconda_snippet_⇲ 
  
158 package·--add=dracut-fips·--add=dracut-fips-aesni 
159 Remediation_Shell_script_⇲157 Remediation_Shell_script_⇲
160 #·Remediation·is·applicable·only·in·certain·platforms158 #·Remediation·is·applicable·only·in·certain·platforms
161 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then159 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
162 #·prelink·not·installed160 #·prelink·not·installed
163 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then161 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
164 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink162 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 219, 14 lines modifiedOffset 216, 17 lines modified
219 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader216 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
220 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"217 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
221 fi218 fi
  
222 else219 else
223 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'220 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
224 fi221 fi
 222 Remediation_Anaconda_snippet_⇲
  
 223 package·--add=dracut-fips·--add=dracut-fips-aesni
225 Remediation_Ansible_snippet_⇲224 Remediation_Ansible_snippet_⇲
226 Complexity:·high225 Complexity:·high
227 Disruption:·medium226 Disruption:·medium
228 Reboot:·····true227 Reboot:·····true
229 Strategy:···restrict228 Strategy:···restrict
230 -·name:·Gather·the·package·facts229 -·name:·Gather·the·package·facts
231 ··package_facts:230 ··package_facts:
Offset 4996, 20 lines modifiedOffset 4996, 14 lines modified
4996 Identifiers·and·References·Identifiers: ·CCE-27351-64996 Identifiers·and·References·Identifiers: ·CCE-27351-6
4997 ···························References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-0001104997 ···························References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000057,·CCI-000058,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_MOF_EXT.1,·SRG-OS-000029-GPOS-00010,·SRG-OS-000030-VMM-000110
4998 Remediation_OSBuild_Blueprint_snippet_⇲4998 Remediation_OSBuild_Blueprint_snippet_⇲
  
4999 [[packages]]4999 [[packages]]
5000 name·=·"screen"5000 name·=·"screen"
5001 version·=·"*"5001 version·=·"*"
5002 Remediation_Anaconda_snippet_⇲ 
5003 Complexity:·low 
5004 Disruption:·low 
5005 Strategy:···enable 
  
5006 package·--add=screen 
5007 Remediation_Puppet_snippet_⇲5002 Remediation_Puppet_snippet_⇲
5008 Complexity:·low5003 Complexity:·low
5009 Disruption:·low5004 Disruption:·low
5010 Strategy:···enable5005 Strategy:···enable
5011 include·install_screen5006 include·install_screen
  
5012 class·install_screen·{5007 class·install_screen·{
Offset 5027, 14 lines modifiedOffset 5021, 20 lines modified
5027 if·!·rpm·-q·--quiet·"screen"·;·then5021 if·!·rpm·-q·--quiet·"screen"·;·then
5028 ····yum·install·-y·"screen"5022 ····yum·install·-y·"screen"
5029 fi5023 fi
  
5030 else5024 else
5031 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5025 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5032 fi5026 fi
 5027 Remediation_Anaconda_snippet_⇲
 5028 Complexity:·low
 5029 Disruption:·low
 5030 Strategy:···enable
  
 5031 package·--add=screen
5033 Remediation_Ansible_snippet_⇲5032 Remediation_Ansible_snippet_⇲
5034 Complexity:·low5033 Complexity:·low
5035 Disruption:·low5034 Disruption:·low
5036 Strategy:···enable5035 Strategy:···enable
5037 -·name:·Ensure·screen·is·installed5036 -·name:·Ensure·screen·is·installed
5038 ··package:5037 ··package:
5039 ····name:·screen5038 ····name:·screen
Offset 5056, 26 lines modifiedOffset 5056, 14 lines modified
5056 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:5056 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
5057 $·sudo·systemctl·mask·--now·debug-shell.service5057 $·sudo·systemctl·mask·--now·debug-shell.service
5058 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.5058 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
5059 Severity: ················medium5059 Severity: ················medium
5060 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled5060 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
5061 Identifiers·and·References·Identifiers: ·CCE-80206-65061 Identifiers·and·References·Identifiers: ·CCE-80206-6
5062 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002275062 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
5063 Remediation_Kubernetes_snippet_⇲ 
5064 --- 
5065 apiVersion:·machineconfiguration.openshift.io/v1 
5066 kind:·MachineConfig 
5067 spec: 
5068 ··config: 
5069 ····ignition: 
5070 ······version:·3.1.0 
5071 ····systemd: 
5072 ······units: 
Max diff block lines reached; 34375/42796 bytes (80.32%) of diff not shown.
679 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-pci-dss.html
    
Offset 17303, 116 lines modifiedOffset 17303, 116 lines modified
00043960:·7267·6574·3d22·2369·646d·3935·3637·2220··rget="#idm9567"·00043960:·7267·6574·3d22·2369·646d·3935·3637·2220··rget="#idm9567"·
00043970:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00043970:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00043980:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00043980:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
00043990:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00043990:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
000439a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate000439a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
000439b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href000439b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
000439c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio000439c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
000439d0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp000439d0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
000439e0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d000439e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
000439f0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-000439f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00043a00:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00043a00:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00043a10:·6522·2069·643d·2269·646d·3935·3637·223e··e"·id="idm9567">00043a10:·2069·643d·2269·646d·3935·3637·223e·3c74···id="idm9567"><t
00043a20:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta00043a20:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
00043a30:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00043a30:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
00043a40:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00043a40:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
00043a50:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed00043a50:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
00043a60:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00043a60:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00043a70:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo00043a70:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
00043a80:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00043a80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00043a90:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</00043a90:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
00043aa0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00043aa0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00043ab0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra00043ab0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
00043ac0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en00043ac0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
00043ad0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></00043ad0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
00043ae0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code00043ae0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
00043af0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=00043af0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 00043b00:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 00043b10:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 00043b20:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 00043b30:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 00043b40:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 00043b50:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 00043b60:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 00043b70:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 00043b80:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 00043b90:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 00043ba0:·6574·3d22·2369·646d·3935·3638·2220·7461··et="#idm9568"·ta
 00043bb0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 00043bc0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 00043bd0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 00043be0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00043bf0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00043c00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00043c10:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 00043c20:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00043c30:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00043c40:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00043c50:·2269·646d·3935·3638·223e·3c74·6162·6c65··"idm9568"><table
 00043c60:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00043c70:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00043c80:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00043c90:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00043ca0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00043cb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00043cc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00043cd0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00043ce0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00043cf0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00043d00:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 00043d10:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00043d20:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 00043d30:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 00043d40:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 00043d50:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 00043d60:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 00043d70:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 00043d80:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 00043d90:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 00043da0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 00043db0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 00043dc0:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
 00043dd0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 00043de0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 00043df0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 00043e00:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 00043e10:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 00043e20:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
00043b00:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr00043e30:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
00043b10:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class00043e40:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
00043b20:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes00043e50:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
00043b30:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="00043e60:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
00043b40:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t00043e70:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
00043b50:·6172·6765·743d·2223·6964·6d39·3536·3822··arget="#idm9568"00043e80:·6172·6765·743d·2223·6964·6d39·3536·3922··arget="#idm9569"
00043b60:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00043e90:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00043b70:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00043ea0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00043b80:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00043eb0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00043b90:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00043ec0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00043ba0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00043ed0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00043bb0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00043ee0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
00043bc0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe00043ef0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
00043bd0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00043f00:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
00043be0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00043f10:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00043bf0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00043f20:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00043c00:·2220·6964·3d22·6964·6d39·3536·3822·3e3c··"·id="idm9568"><00043f30:·7365·2220·6964·3d22·6964·6d39·3536·3922··se"·id="idm9569"
00043c10:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00043f40:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00043c20:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00043f50:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00043c30:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00043f60:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
00043c40:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00043f70:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
00043c50:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00043f80:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00043c60:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low00043f90:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
00043c70:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00043fa0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00043c80:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t00043fb0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
00043c90:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00043fc0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00043ca0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat00043fd0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
00043cb0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena00043fe0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00043cc0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t00043ff0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00043cd0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00044000:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 00044010:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
00043ce0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
00043cf0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
00043d00:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
00043d10:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
00043d20:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
00043d30:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
00043d40:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
00043d50:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00043d60:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00043d70:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00043d80:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00043d90:·6765·743d·2223·6964·6d39·3536·3922·2074··get="#idm9569"·t 
00043da0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00043db0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00043dc0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00043dd0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
00043de0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
00043df0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
00043e00:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 490951/505607 bytes (97.10%) of diff not shown.
185 KB
html2text {}
    
Offset 402, 20 lines modifiedOffset 402, 14 lines modified
402 Identifiers·and·References·Identifiers: ·CCE-27096-7402 Identifiers·and·References·Identifiers: ·CCE-27096-7
403 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule403 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
404 Remediation_OSBuild_Blueprint_snippet_⇲404 Remediation_OSBuild_Blueprint_snippet_⇲
  
405 [[packages]]405 [[packages]]
406 name·=·"aide"406 name·=·"aide"
407 version·=·"*"407 version·=·"*"
408 Remediation_Anaconda_snippet_⇲ 
409 Complexity:·low 
410 Disruption:·low 
411 Strategy:···enable 
  
412 package·--add=aide 
413 Remediation_Puppet_snippet_⇲408 Remediation_Puppet_snippet_⇲
414 Complexity:·low409 Complexity:·low
415 Disruption:·low410 Disruption:·low
416 Strategy:···enable411 Strategy:···enable
417 include·install_aide412 include·install_aide
  
418 class·install_aide·{413 class·install_aide·{
Offset 433, 14 lines modifiedOffset 427, 20 lines modified
433 if·!·rpm·-q·--quiet·"aide"·;·then427 if·!·rpm·-q·--quiet·"aide"·;·then
434 ····yum·install·-y·"aide"428 ····yum·install·-y·"aide"
435 fi429 fi
  
436 else430 else
437 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'431 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
438 fi432 fi
 433 Remediation_Anaconda_snippet_⇲
 434 Complexity:·low
 435 Disruption:·low
 436 Strategy:···enable
  
 437 package·--add=aide
439 Remediation_Ansible_snippet_⇲438 Remediation_Ansible_snippet_⇲
440 Complexity:·low439 Complexity:·low
441 Disruption:·low440 Disruption:·low
442 Strategy:···enable441 Strategy:···enable
443 -·name:·Ensure·aide·is·installed442 -·name:·Ensure·aide·is·installed
444 ··package:443 ··package:
445 ····name:·aide444 ····name:·aide
Offset 5778, 17 lines modifiedOffset 5778, 14 lines modified
5778 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:5778 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:
5779 ····*·https://access.redhat.com/solutions/822735779 ····*·https://access.redhat.com/solutions/82273
5780 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.5780 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.
5781 Severity: ················medium5781 Severity: ················medium
5782 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth5782 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth
5783 Identifiers·and·References·Identifiers: ·CCE-80207-45783 Identifiers·and·References·Identifiers: ·CCE-80207-4
5784 ···························References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-010500,·SV-204441r818813_rule5784 ···························References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-010500,·SV-204441r818813_rule
5785 Remediation_Anaconda_snippet_⇲ 
  
5786 package·--add=pam_pkcs11·--add=esc 
5787 Remediation_Shell_script_⇲5785 Remediation_Shell_script_⇲
5788 #·Remediation·is·applicable·only·in·certain·platforms5786 #·Remediation·is·applicable·only·in·certain·platforms
5789 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·!·grep·-q·s390x·/proc/sys/kernel/osrelease;·};·then5787 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·!·grep·-q·s390x·/proc/sys/kernel/osrelease;·};·then
  
5790 #·Install·required·packages5788 #·Install·required·packages
5791 if·!·rpm·-q·--quiet·"esc"·;·then5789 if·!·rpm·-q·--quiet·"esc"·;·then
5792 ····yum·install·-y·"esc"5790 ····yum·install·-y·"esc"
Offset 5893, 14 lines modifiedOffset 5890, 17 lines modified
5893 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,5890 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,
5894 #·which·does·not·contain·it·yet5891 #·which·does·not·contain·it·yet
5895 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"5892 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"
  
5896 else5893 else
5897 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5894 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5898 fi5895 fi
 5896 Remediation_Anaconda_snippet_⇲
  
 5897 package·--add=pam_pkcs11·--add=esc
5899 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules5898 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules
5900 [ref]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.5899 [ref]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.
5901 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules5900 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules
5902 [ref]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:5901 [ref]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:
5903 $·sudo·chage·-I·NUM_DAYS·USER5902 $·sudo·chage·-I·NUM_DAYS·USER
5904 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.5903 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.
5905 Warning: ·This·will·only·apply·to·newly·created·accounts5904 Warning: ·This·will·only·apply·to·newly·created·accounts
Offset 6378, 15 lines modifiedOffset 6378, 15 lines modified
6378 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.6378 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
6379 Severity: ················medium6379 Severity: ················medium
6380 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod6380 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
6381 Identifiers·and·References·Identifiers: ·CCE-27339-16381 Identifiers·and·References·Identifiers: ·CCE-27339-1
6382 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule6382 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
6383 Remediation_Shell_script_⇲6383 Remediation_Shell_script_⇲
6384 #·Remediation·is·applicable·only·in·certain·platforms6384 #·Remediation·is·applicable·only·in·certain·platforms
6385 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then6385 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
6386 #·First·perform·the·remediation·of·the·syscall·rule6386 #·First·perform·the·remediation·of·the·syscall·rule
6387 #·Retrieve·hardware·architecture·of·the·underlying·system6387 #·Retrieve·hardware·architecture·of·the·underlying·system
6388 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6388 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6389 for·ARCH·in·"${RULE_ARCHS[@]}"6389 for·ARCH·in·"${RULE_ARCHS[@]}"
6390 do6390 do
Offset 6734, 16 lines modifiedOffset 6734, 16 lines modified
6734 ··-·reboot_required6734 ··-·reboot_required
6735 ··-·restrict_strategy6735 ··-·restrict_strategy
  
6736 -·name:·Set·architecture·for·audit·chmod·tasks6736 -·name:·Set·architecture·for·audit·chmod·tasks
6737 ··set_fact:6737 ··set_fact:
6738 ····audit_arch:·b646738 ····audit_arch:·b64
6739 ··when:6739 ··when:
6740 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6741 ··-·'"audit"·in·ansible_facts.packages'6740 ··-·'"audit"·in·ansible_facts.packages'
 6741 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6742 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6742 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6743 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6743 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6744 ··tags:6744 ··tags:
6745 ··-·CCE-27339-16745 ··-·CCE-27339-1
6746 ··-·CJIS-5.4.1.16746 ··-·CJIS-5.4.1.1
6747 ··-·DISA-STIG-RHEL-07-0304106747 ··-·DISA-STIG-RHEL-07-030410
6748 ··-·NIST-800-171-3.1.76748 ··-·NIST-800-171-3.1.7
Offset 6881, 16 lines modifiedOffset 6881, 16 lines modified
6881 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006881 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6882 ········-F·auid!=unset·-F·key=perm_mod6882 ········-F·auid!=unset·-F·key=perm_mod
6883 ······create:·true6883 ······create:·true
6884 ······mode:·o-rwx6884 ······mode:·o-rwx
6885 ······state:·present6885 ······state:·present
6886 ····when:·syscalls_found·|·length·==·06886 ····when:·syscalls_found·|·length·==·0
6887 ··when:6887 ··when:
6888 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6889 ··-·'"audit"·in·ansible_facts.packages'6888 ··-·'"audit"·in·ansible_facts.packages'
 6889 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6890 ··tags:6890 ··tags:
6891 ··-·CCE-27339-16891 ··-·CCE-27339-1
6892 ··-·CJIS-5.4.1.16892 ··-·CJIS-5.4.1.1
6893 ··-·DISA-STIG-RHEL-07-0304106893 ··-·DISA-STIG-RHEL-07-030410
6894 ··-·NIST-800-171-3.1.76894 ··-·NIST-800-171-3.1.7
Max diff block lines reached; 180647/189919 bytes (95.12%) of diff not shown.
1.69 MB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-rhelh-stig.html
    
Offset 18353, 116 lines modifiedOffset 18353, 116 lines modified
00047b00:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00047b00:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00047b10:·2369·646d·3935·3637·2220·7461·6269·6e64··#idm9567"·tabind00047b10:·2369·646d·3935·3637·2220·7461·6269·6e64··#idm9567"·tabind
00047b20:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00047b20:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00047b30:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00047b30:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
00047b40:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00047b40:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00047b50:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00047b50:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00047b60:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00047b60:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00047b70:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac00047b70:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
00047b80:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...00047b80:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
00047b90:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00047b90:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
00047ba0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00047ba0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
00047bb0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00047bb0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
00047bc0:·2269·646d·3935·3637·223e·3c74·6162·6c65··"idm9567"><table00047bc0:·646d·3935·3637·223e·3c74·6162·6c65·2063··dm9567"><table·c
00047bd0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00047bd0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
00047be0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00047be0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
00047bf0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table00047bf0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
00047c00:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>00047c00:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
00047c10:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<00047c10:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
00047c20:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00047c20:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
00047c30:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis00047c30:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
00047c40:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td00047c40:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
00047c50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00047c50:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00047c60:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<00047c60:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00047c70:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</00047c70:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
00047c80:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>00047c80:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
00047c90:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
00047ca0:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<00047c90:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 00047ca0:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 00047cb0:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 00047cc0:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 00047cd0:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 00047ce0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 00047cf0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 00047d00:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 00047d10:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 00047d20:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 00047d30:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 00047d40:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 00047d50:·646d·3935·3638·2220·7461·6269·6e64·6578··dm9568"·tabindex
 00047d60:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 00047d70:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 00047d80:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 00047d90:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 00047da0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00047db0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 00047dc0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 00047dd0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00047de0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00047df0:·6c61·7073·6522·2069·643d·2269·646d·3935··lapse"·id="idm95
 00047e00:·3638·223e·3c74·6162·6c65·2063·6c61·7373··68"><table·class
 00047e10:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00047e20:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00047e30:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00047e40:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00047e50:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 00047e60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00047e70:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 00047e80:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 00047e90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00047ea0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 00047eb0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 00047ec0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00047ed0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 00047ee0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 00047ef0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 00047f00:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
 00047f10:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
 00047f20:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
 00047f30:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
 00047f40:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.
 00047f50:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 00047f60:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 00047f70:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta
 00047f80:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 00047f90:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 00047fa0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 00047fb0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 00047fc0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 00047fd0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
00047cb0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di00047fe0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
00047cc0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·00047ff0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
00047cd0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat00048000:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
00047ce0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap00048010:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
00047cf0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00048020:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00047d00:·2223·6964·6d39·3536·3822·2074·6162·696e··"#idm9568"·tabin00048030:·2223·6964·6d39·3536·3922·2074·6162·696e··"#idm9569"·tabin
00047d10:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00048040:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00047d20:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00048050:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00047d30:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00048060:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00047d40:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00048070:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00047d50:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00048080:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00047d60:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup00048090:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
00047d70:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<000480a0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
00047d80:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas000480b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
00047d90:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps000480c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
00047da0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="000480d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
00047db0:·6964·6d39·3536·3822·3e3c·7461·626c·6520··idm9568"><table·000480e0:·3d22·6964·6d39·3536·3922·3e3c·7461·626c··="idm9569"><tabl
00047dc0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab000480f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
00047dd0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00048100:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
00047de0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00048110:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
00047df0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00048120:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
00047e00:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</00048130:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00047e10:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00048140:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00047e20:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00048150:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
00047e30:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00048160:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
00047e40:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00048170:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00047e50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</00048180:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
00047e60:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t00048190:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
00047e70:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><000481a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 000481b0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 000481c0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
00047e80:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ 
00047e90:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
00047ea0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
00047eb0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
00047ec0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
00047ed0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
00047ee0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
00047ef0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00047f00:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00047f10:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00047f20:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00047f30:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00047f40:·6964·6d39·3536·3922·2074·6162·696e·6465··idm9569"·tabinde 
00047f50:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00047f60:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00047f70:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00047f80:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
Max diff block lines reached; 1313801/1328457 bytes (98.90%) of diff not shown.
433 KB
html2text {}
    
Offset 535, 20 lines modifiedOffset 535, 14 lines modified
535 Identifiers·and·References·Identifiers: ·CCE-27096-7535 Identifiers·and·References·Identifiers: ·CCE-27096-7
536 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule536 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
537 Remediation_OSBuild_Blueprint_snippet_⇲537 Remediation_OSBuild_Blueprint_snippet_⇲
  
538 [[packages]]538 [[packages]]
539 name·=·"aide"539 name·=·"aide"
540 version·=·"*"540 version·=·"*"
541 Remediation_Anaconda_snippet_⇲ 
542 Complexity:·low 
543 Disruption:·low 
544 Strategy:···enable 
  
545 package·--add=aide 
546 Remediation_Puppet_snippet_⇲541 Remediation_Puppet_snippet_⇲
547 Complexity:·low542 Complexity:·low
548 Disruption:·low543 Disruption:·low
549 Strategy:···enable544 Strategy:···enable
550 include·install_aide545 include·install_aide
  
551 class·install_aide·{546 class·install_aide·{
Offset 566, 14 lines modifiedOffset 560, 20 lines modified
566 if·!·rpm·-q·--quiet·"aide"·;·then560 if·!·rpm·-q·--quiet·"aide"·;·then
567 ····yum·install·-y·"aide"561 ····yum·install·-y·"aide"
568 fi562 fi
  
569 else563 else
570 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'564 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
571 fi565 fi
 566 Remediation_Anaconda_snippet_⇲
 567 Complexity:·low
 568 Disruption:·low
 569 Strategy:···enable
  
 570 package·--add=aide
572 Remediation_Ansible_snippet_⇲571 Remediation_Ansible_snippet_⇲
573 Complexity:·low572 Complexity:·low
574 Disruption:·low573 Disruption:·low
575 Strategy:···enable574 Strategy:···enable
576 -·name:·Ensure·aide·is·installed575 -·name:·Ensure·aide·is·installed
577 ··package:576 ··package:
578 ····name:·aide577 ····name:·aide
Offset 1068, 28 lines modifiedOffset 1068, 28 lines modified
1068 $·sudo·yum·install·dracut-fips1068 $·sudo·yum·install·dracut-fips
1069 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1069 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1070 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1070 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1071 Severity: ················medium1071 Severity: ················medium
1072 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed1072 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_dracut-fips_installed
1073 Identifiers·and·References·Identifiers: ·CCE-80358-51073 Identifiers·and·References·Identifiers: ·CCE-80358-5
1074 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-0015901074 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.11,·3.13.8,·CCI-000068,·CCI-000803,·CCI-002450,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590
1075 Remediation_Anaconda_snippet_⇲ 
  
1076 package·--add=dracut-fips 
1077 Remediation_Shell_script_⇲1075 Remediation_Shell_script_⇲
1078 #·Remediation·is·applicable·only·in·certain·platforms1076 #·Remediation·is·applicable·only·in·certain·platforms
1079 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1077 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1080 if·!·rpm·-q·--quiet·"dracut-fips"·;·then1078 if·!·rpm·-q·--quiet·"dracut-fips"·;·then
1081 ····yum·install·-y·"dracut-fips"1079 ····yum·install·-y·"dracut-fips"
1082 fi1080 fi
  
1083 else1081 else
1084 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1082 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1085 fi1083 fi
 1084 Remediation_Anaconda_snippet_⇲
  
 1085 package·--add=dracut-fips
1086 Remediation_Ansible_snippet_⇲1086 Remediation_Ansible_snippet_⇲
1087 Complexity:·low1087 Complexity:·low
1088 Disruption:·low1088 Disruption:·low
1089 Strategy:···enable1089 Strategy:···enable
1090 -·name:·Ensure·dracut-fips·is·installed1090 -·name:·Ensure·dracut-fips·is·installed
1091 ··package:1091 ··package:
1092 ····name:·dracut-fips1092 ····name:·dracut-fips
Offset 1133, 17 lines modifiedOffset 1133, 14 lines modified
1133 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1133 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1134 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1134 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1135 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1135 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1136 Severity: ················high1136 Severity: ················high
1137 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode1137 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
1138 Identifiers·and·References·Identifiers: ·CCE-80359-31138 Identifiers·and·References·Identifiers: ·CCE-80359-3
1139 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule1139 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule
1140 Remediation_Anaconda_snippet_⇲ 
  
1141 package·--add=dracut-fips·--add=dracut-fips-aesni 
1142 Remediation_Shell_script_⇲1140 Remediation_Shell_script_⇲
1143 #·Remediation·is·applicable·only·in·certain·platforms1141 #·Remediation·is·applicable·only·in·certain·platforms
1144 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then1142 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
1145 #·prelink·not·installed1143 #·prelink·not·installed
1146 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then1144 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
1147 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink1145 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 1202, 14 lines modifiedOffset 1199, 17 lines modified
1202 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader1199 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
1203 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"1200 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
1204 fi1201 fi
  
1205 else1202 else
1206 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1203 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1207 fi1204 fi
 1205 Remediation_Anaconda_snippet_⇲
  
 1206 package·--add=dracut-fips·--add=dracut-fips-aesni
1208 Remediation_Ansible_snippet_⇲1207 Remediation_Ansible_snippet_⇲
1209 Complexity:·high1208 Complexity:·high
1210 Disruption:·medium1209 Disruption:·medium
1211 Reboot:·····true1210 Reboot:·····true
1212 Strategy:···restrict1211 Strategy:···restrict
1213 -·name:·Gather·the·package·facts1212 -·name:·Gather·the·package·facts
1214 ··package_facts:1213 ··package_facts:
Offset 1833, 20 lines modifiedOffset 1833, 14 lines modified
1833 By·removing·the·gdm·package,·the·system·no·longer·has·GNOME·installed·installed.·If·X·Windows·is·not·installed·then·the·system·cannot·boot·into·graphical·user·mode.·This·prevents·the·system·from·being·accidentally·or·maliciously·booted·into·a·graphical.target·mode.·To·do·so,·run·the·following·command:1833 By·removing·the·gdm·package,·the·system·no·longer·has·GNOME·installed·installed.·If·X·Windows·is·not·installed·then·the·system·cannot·boot·into·graphical·user·mode.·This·prevents·the·system·from·being·accidentally·or·maliciously·booted·into·a·graphical.target·mode.·To·do·so,·run·the·following·command:
1834 $·sudo·yum·remove·gdm1834 $·sudo·yum·remove·gdm
1835 Rationale:·················Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack·surface·of·the·system.·A·graphical·environment·is·unnecessary·for·certain·types·of·systems·including·a·virtualization·hypervisor.1835 Rationale:·················Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack·surface·of·the·system.·A·graphical·environment·is·unnecessary·for·certain·types·of·systems·including·a·virtualization·hypervisor.
1836 Severity: ················medium1836 Severity: ················medium
1837 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gdm_removed1837 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gdm_removed
1838 Identifiers·and·References·Identifiers: ·CCE-82348-41838 Identifiers·and·References·Identifiers: ·CCE-82348-4
1839 ···························References: ·CM-7(a),·CM-7(b),·CM-6(a),·SRG-OS-000480-GPOS-002271839 ···························References: ·CM-7(a),·CM-7(b),·CM-6(a),·SRG-OS-000480-GPOS-00227
1840 Remediation_Anaconda_snippet_⇲ 
1841 Complexity:·low 
1842 Disruption:·low 
1843 Strategy:···disable 
  
1844 package·--remove=gdm 
1845 Remediation_Puppet_snippet_⇲1840 Remediation_Puppet_snippet_⇲
1846 Complexity:·low1841 Complexity:·low
1847 Disruption:·low1842 Disruption:·low
1848 Strategy:···disable1843 Strategy:···disable
Max diff block lines reached; 434907/443497 bytes (98.06%) of diff not shown.
884 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-rhelh-vpp.html
    
Offset 18514, 207 lines modifiedOffset 18514, 207 lines modified
00048510:·743d·2223·6964·6d31·3032·3139·2220·7461··t="#idm10219"·ta00048510:·743d·2223·6964·6d31·3032·3139·2220·7461··t="#idm10219"·ta
00048520:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00048520:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00048530:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00048530:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00048540:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00048540:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00048550:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00048550:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00048560:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00048560:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00048570:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00048570:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00048580:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet00048580:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
00048590:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div00048590:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
000485a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000485a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000485b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"000485b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
000485c0:·2069·643d·2269·646d·3130·3231·3922·3e3c···id="idm10219"><000485c0:·2269·646d·3130·3231·3922·3e3c·7072·653e··"idm10219"><pre>
000485d0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
000485e0:·6765·202d·2d61·6464·3d64·7261·6375·742d··ge·--add=dracut- 
000485f0:·6669·7073·202d·2d61·6464·3d64·7261·6375··fips·--add=dracu 
00048600:·742d·6669·7073·2d61·6573·6e69·0a3c·2f63··t-fips-aesni.</c 
00048610:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00048620:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00048630:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00048640:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00048650:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00048660:·6964·6d31·3032·3230·2220·7461·6269·6e64··idm10220"·tabind 
00048670:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00048680:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00048690:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
000486a0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
000486b0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
000486c0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
000486d0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
000486e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
000486f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
00048700:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00048710:·3130·3232·3022·3e3c·7072·653e·3c63·6f64··10220"><pre><cod 
00048720:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·000485d0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
00048730:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on000485e0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
00048740:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl000485f0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
00048750:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-00048600:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
00048760:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·00048610:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
00048770:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-00048620:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
00048780:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe00048630:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
00048790:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp00048640:·6169·6e65·7265·6e76·205d·2026·616d·703b··ainerenv·]·&amp;
000487a0:·3b20·7b20·7270·6d20·2d2d·7175·6965·7420··;·{·rpm·--quiet·00048650:·2661·6d70·3b20·7b20·7270·6d20·2d2d·7175··&amp;·{·rpm·--qu
000487b0:·2d71·2067·7275·6232·2d63·6f6d·6d6f·6e3b··-q·grub2-common;00048660:·6965·7420·2d71·2067·7275·6232·2d63·6f6d··iet·-q·grub2-com
000487c0:·207d·3b20·7468·656e·0a0a·2320·7072·656c···};·then..#·prel00048670:·6d6f·6e3b·207d·3b20·7468·656e·0a0a·2320··mon;·};·then..#·
000487d0:·696e·6b20·6e6f·7420·696e·7374·616c·6c65··ink·not·installe00048680:·7072·656c·696e·6b20·6e6f·7420·696e·7374··prelink·not·inst
000487e0:·640a·6966·2074·6573·7420·2d65·202f·6574··d.if·test·-e·/et00048690:·616c·6c65·640a·6966·2074·6573·7420·2d65··alled.if·test·-e
 000486a0:·202f·6574·632f·7379·7363·6f6e·6669·672f···/etc/sysconfig/
 000486b0:·7072·656c·696e·6b20·2d6f·202d·6520·2f75··prelink·-o·-e·/u
 000486c0:·7372·2f73·6269·6e2f·7072·656c·696e·6b3b··sr/sbin/prelink;
 000486d0:·2074·6865·6e0a·2020·2020·6966·2067·7265···then.····if·gre
 000486e0:·7020·2d71·205e·5052·454c·494e·4b49·4e47··p·-q·^PRELINKING
000487f0:·632f·7379·7363·6f6e·6669·672f·7072·656c··c/sysconfig/prel000486f0:·202f·6574·632f·7379·7363·6f6e·6669·672f···/etc/sysconfig/
00048800:·696e·6b20·2d6f·202d·6520·2f75·7372·2f73··ink·-o·-e·/usr/s 
00048810:·6269·6e2f·7072·656c·696e·6b3b·2074·6865··bin/prelink;·the 
00048820:·6e0a·2020·2020·6966·2067·7265·7020·2d71··n.····if·grep·-q 
00048830:·205e·5052·454c·494e·4b49·4e47·202f·6574···^PRELINKING·/et 
00048840:·632f·7379·7363·6f6e·6669·672f·7072·656c··c/sysconfig/prel 
00048850:·696e·6b0a·2020·2020·7468·656e·0a20·2020··ink.····then.···00048700:·7072·656c·696e·6b0a·2020·2020·7468·656e··prelink.····then
00048860:·2020·2020·2073·6564·202d·6920·2773·2f5e·······sed·-i·'s/^00048710:·0a20·2020·2020·2020·2073·6564·202d·6920··.········sed·-i·
00048870:·5052·454c·494e·4b49·4e47·5b3a·626c·616e··PRELINKING[:blan00048720:·2773·2f5e·5052·454c·494e·4b49·4e47·5b3a··'s/^PRELINKING[:
00048880:·6b3a·5d2a·3d5b·3a62·6c61·6e6b·3a5d·2a5b··k:]*=[:blank:]*[00048730:·626c·616e·6b3a·5d2a·3d5b·3a62·6c61·6e6b··blank:]*=[:blank
00048890:·3a61·6c70·6861·3a5d·2a2f·5052·454c·494e··:alpha:]*/PRELIN00048740:·3a5d·2a5b·3a61·6c70·6861·3a5d·2a2f·5052··:]*[:alpha:]*/PR
000488a0:·4b49·4e47·3d6e·6f2f·2720·2f65·7463·2f73··KING=no/'·/etc/s00048750:·454c·494e·4b49·4e47·3d6e·6f2f·2720·2f65··ELINKING=no/'·/e
000488b0:·7973·636f·6e66·6967·2f70·7265·6c69·6e6b··ysconfig/prelink00048760:·7463·2f73·7973·636f·6e66·6967·2f70·7265··tc/sysconfig/pre
000488c0:·0a20·2020·2065·6c73·650a·2020·2020·2020··.····else.······00048770:·6c69·6e6b·0a20·2020·2065·6c73·650a·2020··link.····else.··
000488d0:·2020·7072·696e·7466·2027·5c6e·2720·2667····printf·'\n'·&g 
000488e0:·743b·2667·743b·202f·6574·632f·7379·7363··t;&gt;·/etc/sysc 
000488f0:·6f6e·6669·672f·7072·656c·696e·6b0a·2020··onfig/prelink.·· 
00048900:·2020·2020·2020·7072·696e·7466·2027·2573········printf·'%s00048780:·2020·2020·2020·7072·696e·7466·2027·5c6e········printf·'\n
00048910:·5c6e·2720·2723·2053·6574·2050·5245·4c49··\n'·'#·Set·PRELI 
00048920:·4e4b·494e·473d·6e6f·2070·6572·2073·6563··NKING=no·per·sec 
00048930:·7572·6974·7920·7265·7175·6972·656d·656e··urity·requiremen 
00048940:·7473·2720·2750·5245·4c49·4e4b·494e·473d··ts'·'PRELINKING= 
00048950:·6e6f·2720·2667·743b·2667·743b·202f·6574··no'·&gt;&gt;·/et00048790:·2720·2667·743b·2667·743b·202f·6574·632f··'·&gt;&gt;·/etc/
00048960:·632f·7379·7363·6f6e·6669·672f·7072·656c··c/sysconfig/prel000487a0:·7379·7363·6f6e·6669·672f·7072·656c·696e··sysconfig/prelin
 000487b0:·6b0a·2020·2020·2020·2020·7072·696e·7466··k.········printf
 000487c0:·2027·2573·5c6e·2720·2723·2053·6574·2050···'%s\n'·'#·Set·P
 000487d0:·5245·4c49·4e4b·494e·473d·6e6f·2070·6572··RELINKING=no·per
 000487e0:·2073·6563·7572·6974·7920·7265·7175·6972···security·requir
 000487f0:·656d·656e·7473·2720·2750·5245·4c49·4e4b··ements'·'PRELINK
 00048800:·494e·473d·6e6f·2720·2667·743b·2667·743b··ING=no'·&gt;&gt;
 00048810:·202f·6574·632f·7379·7363·6f6e·6669·672f···/etc/sysconfig/
00048970:·696e·6b0a·2020·2020·6669·0a0a·2020·2020··ink.····fi..····00048820:·7072·656c·696e·6b0a·2020·2020·6669·0a0a··prelink.····fi..
00048980:·2320·556e·646f·2070·7265·7669·6f75·7320··#·Undo·previous·00048830:·2020·2020·2320·556e·646f·2070·7265·7669······#·Undo·previ
00048990:·7072·656c·696e·6b20·6368·616e·6765·7320··prelink·changes·00048840:·6f75·7320·7072·656c·696e·6b20·6368·616e··ous·prelink·chan
000489a0:·746f·2062·696e·6172·6965·7320·6966·2070··to·binaries·if·p00048850:·6765·7320·746f·2062·696e·6172·6965·7320··ges·to·binaries·
000489b0:·7265·6c69·6e6b·2069·7320·6176·6169·6c61··relink·is·availa00048860:·6966·2070·7265·6c69·6e6b·2069·7320·6176··if·prelink·is·av
000489c0:·626c·652e·0a20·2020·2069·6620·7465·7374··ble..····if·test00048870:·6169·6c61·626c·652e·0a20·2020·2069·6620··ailable..····if·
000489d0:·202d·7820·2f75·7372·2f73·6269·6e2f·7072···-x·/usr/sbin/pr00048880:·7465·7374·202d·7820·2f75·7372·2f73·6269··test·-x·/usr/sbi
000489e0:·656c·696e·6b3b·2074·6865·6e0a·2020·2020··elink;·then.····00048890:·6e2f·7072·656c·696e·6b3b·2074·6865·6e0a··n/prelink;·then.
000489f0:·2020·2020·2f75·7372·2f73·6269·6e2f·7072······/usr/sbin/pr000488a0:·2020·2020·2020·2020·2f75·7372·2f73·6269··········/usr/sbi
00048a00:·656c·696e·6b20·2d75·610a·2020·2020·6669··elink·-ua.····fi000488b0:·6e2f·7072·656c·696e·6b20·2d75·610a·2020··n/prelink·-ua.··
00048a10:·0a66·690a·0a69·6620·6772·6570·202d·7120··.fi..if·grep·-q·000488c0:·2020·6669·0a66·690a·0a69·6620·6772·6570····fi.fi..if·grep
00048a20:·2d6d·3120·2d6f·2061·6573·202f·7072·6f63··-m1·-o·aes·/proc000488d0:·202d·7120·2d6d·3120·2d6f·2061·6573·202f···-q·-m1·-o·aes·/
00048a30:·2f63·7075·696e·666f·3b20·7468·656e·0a09··/cpuinfo;·then..000488e0:·7072·6f63·2f63·7075·696e·666f·3b20·7468··proc/cpuinfo;·th
 000488f0:·656e·0a09·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 00048900:·2d2d·7175·6965·7420·2264·7261·6375·742d··--quiet·"dracut-
 00048910:·6669·7073·2d61·6573·6e69·2220·3b20·7468··fips-aesni"·;·th
 00048920:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta
 00048930:·6c6c·202d·7920·2264·7261·6375·742d·6669··ll·-y·"dracut-fi
 00048940:·7073·2d61·6573·6e69·220a·6669·0a66·690a··ps-aesni".fi.fi.
00048a40:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu00048950:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
00048a50:·6965·7420·2264·7261·6375·742d·6669·7073··iet·"dracut-fips00048960:·6965·7420·2264·7261·6375·742d·6669·7073··iet·"dracut-fips
00048a60:·2d61·6573·6e69·2220·3b20·7468·656e·0a20··-aesni"·;·then.· 
00048a70:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·- 
00048a80:·7920·2264·7261·6375·742d·6669·7073·2d61··y·"dracut-fips-a 
00048a90:·6573·6e69·220a·6669·0a66·690a·6966·2021··esni".fi.fi.if·! 
00048aa0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
00048ab0:·2264·7261·6375·742d·6669·7073·2220·3b20··"dracut-fips"·;· 
00048ac0:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins00048970:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
00048ad0:·7461·6c6c·202d·7920·2264·7261·6375·742d··tall·-y·"dracut-00048980:·2069·6e73·7461·6c6c·202d·7920·2264·7261···install·-y·"dra
00048ae0:·6669·7073·220a·6669·0a0a·6472·6163·7574··fips".fi..dracut00048990:·6375·742d·6669·7073·220a·6669·0a0a·6472··cut-fips".fi..dr
00048af0:·202d·660a·0a23·2043·6f72·7265·6374·2074···-f..#·Correct·t000489a0:·6163·7574·202d·660a·0a23·2043·6f72·7265··acut·-f..#·Corre
00048b00:·6865·2066·6f72·6d20·6f66·2064·6566·6175··he·form·of·defau000489b0:·6374·2074·6865·2066·6f72·6d20·6f66·2064··ct·the·form·of·d
00048b10:·6c74·206b·6572·6e65·6c20·636f·6d6d·616e··lt·kernel·comman000489c0:·6566·6175·6c74·206b·6572·6e65·6c20·636f··efault·kernel·co
00048b20:·6420·6c69·6e65·2069·6e20·2067·7275·620a··d·line·in··grub.000489d0:·6d6d·616e·6420·6c69·6e65·2069·6e20·2067··mmand·line·in··g
00048b30:·6966·2067·7265·7020·2d71·2027·5e47·5255··if·grep·-q·'^GRU000489e0:·7275·620a·6966·2067·7265·7020·2d71·2027··rub.if·grep·-q·'
00048b40:·425f·434d·444c·494e·455f·4c49·4e55·583d··B_CMDLINE_LINUX= 
00048b50:·2e2a·6669·7073·3d2e·2a22·2720·202f·6574··.*fips=.*"'··/et 
00048b60:·632f·6465·6661·756c·742f·6772·7562·3b20··c/default/grub;· 
00048b70:·7468·656e·0a09·2320·6d6f·6469·6679·2074··then..#·modify·t 
00048b80:·6865·2047·5255·4220·636f·6d6d·616e·642d··he·GRUB·command- 
00048b90:·6c69·6e65·2069·6620·6120·6669·7073·3d20··line·if·a·fips=· 
00048ba0:·6172·6720·616c·7265·6164·7920·6578·6973··arg·already·exis 
00048bb0:·7473·0a09·7365·6420·2d69·2027·732f·5c28··ts..sed·-i·'s/\( 
00048bc0:·5e47·5255·425f·434d·444c·494e·455f·4c49··^GRUB_CMDLINE_LI000489f0:·5e47·5255·425f·434d·444c·494e·455f·4c49··^GRUB_CMDLINE_LI
 00048a00:·4e55·583d·2e2a·6669·7073·3d2e·2a22·2720··NUX=.*fips=.*"'·
Max diff block lines reached; 599846/627060 bytes (95.66%) of diff not shown.
271 KB
html2text {}
    
Offset 559, 17 lines modifiedOffset 559, 14 lines modified
559 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.559 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
560 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.560 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
561 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.561 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
562 Severity: ················high562 Severity: ················high
563 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode563 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
564 Identifiers·and·References·Identifiers: ·CCE-80359-3564 Identifiers·and·References·Identifiers: ·CCE-80359-3
565 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule565 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule
566 Remediation_Anaconda_snippet_⇲ 
  
567 package·--add=dracut-fips·--add=dracut-fips-aesni 
568 Remediation_Shell_script_⇲566 Remediation_Shell_script_⇲
569 #·Remediation·is·applicable·only·in·certain·platforms567 #·Remediation·is·applicable·only·in·certain·platforms
570 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then568 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
571 #·prelink·not·installed569 #·prelink·not·installed
572 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then570 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
573 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink571 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 628, 14 lines modifiedOffset 625, 17 lines modified
628 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader625 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
629 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"626 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
630 fi627 fi
  
631 else628 else
632 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'629 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
633 fi630 fi
 631 Remediation_Anaconda_snippet_⇲
  
 632 package·--add=dracut-fips·--add=dracut-fips-aesni
634 Remediation_Ansible_snippet_⇲633 Remediation_Ansible_snippet_⇲
635 Complexity:·high634 Complexity:·high
636 Disruption:·medium635 Disruption:·medium
637 Reboot:·····true636 Reboot:·····true
638 Strategy:···restrict637 Strategy:···restrict
639 -·name:·Gather·the·package·facts638 -·name:·Gather·the·package·facts
640 ··package_facts:639 ··package_facts:
Offset 6822, 20 lines modifiedOffset 6822, 14 lines modified
6822 Identifiers·and·References·Identifiers: ·CCE-80568-96822 Identifiers·and·References·Identifiers: ·CCE-80568-9
6823 ···························References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-0015206823 ···························References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520
6824 Remediation_OSBuild_Blueprint_snippet_⇲6824 Remediation_OSBuild_Blueprint_snippet_⇲
  
6825 [[packages]]6825 [[packages]]
6826 name·=·"opensc"6826 name·=·"opensc"
6827 version·=·"*"6827 version·=·"*"
6828 Remediation_Anaconda_snippet_⇲ 
6829 Complexity:·low 
6830 Disruption:·low 
6831 Strategy:···enable 
  
6832 package·--add=opensc 
6833 Remediation_Puppet_snippet_⇲6828 Remediation_Puppet_snippet_⇲
6834 Complexity:·low6829 Complexity:·low
6835 Disruption:·low6830 Disruption:·low
6836 Strategy:···enable6831 Strategy:···enable
6837 include·install_opensc6832 include·install_opensc
  
6838 class·install_opensc·{6833 class·install_opensc·{
Offset 6853, 14 lines modifiedOffset 6847, 20 lines modified
6853 if·!·rpm·-q·--quiet·"opensc"·;·then6847 if·!·rpm·-q·--quiet·"opensc"·;·then
6854 ····yum·install·-y·"opensc"6848 ····yum·install·-y·"opensc"
6855 fi6849 fi
  
6856 else6850 else
6857 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6851 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6858 fi6852 fi
 6853 Remediation_Anaconda_snippet_⇲
 6854 Complexity:·low
 6855 Disruption:·low
 6856 Strategy:···enable
  
 6857 package·--add=opensc
6859 Remediation_Ansible_snippet_⇲6858 Remediation_Ansible_snippet_⇲
6860 Complexity:·low6859 Complexity:·low
6861 Disruption:·low6860 Disruption:·low
6862 Strategy:···enable6861 Strategy:···enable
6863 -·name:·Ensure·opensc·is·installed6862 -·name:·Ensure·opensc·is·installed
6864 ··package:6863 ··package:
6865 ····name:·opensc6864 ····name:·opensc
Offset 6884, 20 lines modifiedOffset 6884, 14 lines modified
6884 Identifiers·and·References·Identifiers: ·CCE-82347-66884 Identifiers·and·References·Identifiers: ·CCE-82347-6
6885 ···························References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015306885 ···························References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
6886 Remediation_OSBuild_Blueprint_snippet_⇲6886 Remediation_OSBuild_Blueprint_snippet_⇲
  
6887 [[packages]]6887 [[packages]]
6888 name·=·"pcsc-lite"6888 name·=·"pcsc-lite"
6889 version·=·"*"6889 version·=·"*"
6890 Remediation_Anaconda_snippet_⇲ 
6891 Complexity:·low 
6892 Disruption:·low 
6893 Strategy:···enable 
  
6894 package·--add=pcsc-lite 
6895 Remediation_Puppet_snippet_⇲6890 Remediation_Puppet_snippet_⇲
6896 Complexity:·low6891 Complexity:·low
6897 Disruption:·low6892 Disruption:·low
6898 Strategy:···enable6893 Strategy:···enable
6899 include·install_pcsc-lite6894 include·install_pcsc-lite
  
6900 class·install_pcsc-lite·{6895 class·install_pcsc-lite·{
Offset 6915, 14 lines modifiedOffset 6909, 20 lines modified
6915 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then6909 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
6916 ····yum·install·-y·"pcsc-lite"6910 ····yum·install·-y·"pcsc-lite"
6917 fi6911 fi
  
6918 else6912 else
6919 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6913 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6920 fi6914 fi
 6915 Remediation_Anaconda_snippet_⇲
 6916 Complexity:·low
 6917 Disruption:·low
 6918 Strategy:···enable
  
 6919 package·--add=pcsc-lite
6921 Remediation_Ansible_snippet_⇲6920 Remediation_Ansible_snippet_⇲
6922 Complexity:·low6921 Complexity:·low
6923 Disruption:·low6922 Disruption:·low
6924 Strategy:···enable6923 Strategy:···enable
6925 -·name:·Ensure·pcsc-lite·is·installed6924 -·name:·Ensure·pcsc-lite·is·installed
6926 ··package:6925 ··package:
6927 ····name:·pcsc-lite6926 ····name:·pcsc-lite
Offset 8224, 15 lines modifiedOffset 8224, 15 lines modified
8224 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.8224 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
8225 Severity: ················medium8225 Severity: ················medium
8226 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod8226 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
8227 Identifiers·and·References·Identifiers: ·CCE-27339-18227 Identifiers·and·References·Identifiers: ·CCE-27339-1
8228 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule8228 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
8229 Remediation_Shell_script_⇲8229 Remediation_Shell_script_⇲
8230 #·Remediation·is·applicable·only·in·certain·platforms8230 #·Remediation·is·applicable·only·in·certain·platforms
Max diff block lines reached; 270389/277886 bytes (97.30%) of diff not shown.
113 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-rht-ccp.html
    
Offset 15309, 116 lines modifiedOffset 15309, 116 lines modified
0003bcc0:·6765·743d·2223·6964·6d39·3536·3722·2074··get="#idm9567"·t0003bcc0:·6765·743d·2223·6964·6d39·3536·3722·2074··get="#idm9567"·t
0003bcd0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003bcd0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003bce0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003bce0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003bcf0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003bcf0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003bd00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003bd00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003bd10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003bd10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003bd20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003bd20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003bd30:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe0003bd30:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
0003bd40:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bd40:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003bd50:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bd50:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003bd60:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bd60:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003bd70:·2220·6964·3d22·6964·6d39·3536·3722·3e3c··"·id="idm9567"><0003bd70:·6964·3d22·6964·6d39·3536·3722·3e3c·7461··id="idm9567"><ta
0003bd80:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003bd80:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003bd90:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003bd90:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003bda0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003bda0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003bdb0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003bdb0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003bdc0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003bdc0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003bdd0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003bdd0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003bde0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bde0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bdf0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003bdf0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003be00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003be00:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003be10:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003be10:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003be20:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003be20:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003be30:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003be30:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003be40:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003be40:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
0003be50:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a0003be50:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai
 0003be60:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal
 0003be70:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa
 0003be80:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.···
 0003be90:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i
 0003bea0:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.}
 0003beb0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003bec0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003bed0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003bee0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003bef0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003bf00:·743d·2223·6964·6d39·3536·3822·2074·6162··t="#idm9568"·tab
 0003bf10:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003bf20:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003bf30:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003bf40:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003bf50:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003bf60:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 0003bf70:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0003bf80:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003bf90:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003bfa0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003bfb0:·6964·6d39·3536·3822·3e3c·7461·626c·6520··idm9568"><table·
 0003bfc0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003bfd0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003bfe0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003bff0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003c000:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003c010:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003c020:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003c030:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003c040:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003c050:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003c060:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003c070:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003c080:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 0003c090:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003c0a0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003c0b0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003c0c0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
 0003c0d0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
 0003c0e0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
 0003c0f0:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·
 0003c100:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 0003c110:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 0003c120:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
 0003c130:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003c140:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 0003c150:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003c160:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003c170:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003c180:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
0003be60:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre0003c190:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
0003be70:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003c1a0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
0003be80:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003c1b0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
0003be90:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003c1c0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
0003bea0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003c1d0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
0003beb0:·7267·6574·3d22·2369·646d·3935·3638·2220··rget="#idm9568"·0003c1e0:·7267·6574·3d22·2369·646d·3935·3639·2220··rget="#idm9569"·
0003bec0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003c1f0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bed0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003c200:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bee0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003c210:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bef0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003c220:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bf00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003c230:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bf10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003c240:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003bf20:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet0003c250:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
0003bf30:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003c260:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003bf40:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003c270:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003bf50:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003c280:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003bf60:·2069·643d·2269·646d·3935·3638·223e·3c74···id="idm9568"><t0003c290:·6522·2069·643d·2269·646d·3935·3639·223e··e"·id="idm9569">
0003bf70:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003c2a0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003bf80:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003c2b0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003bf90:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003c2c0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003bfa0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003c2d0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003bfb0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003c2e0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003bfc0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003c2f0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003bfd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c300:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bfe0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003c310:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003bff0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c320:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003c000:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003c330:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003c010:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003c340:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003c020:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003c350:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003c030:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i0003c360:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003c370:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=
0003c040:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a 
0003c050:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta 
0003c060:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack 
0003c070:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.·· 
0003c080:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003c090:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003c0a0:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003c0b0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c0c0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c0d0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c0e0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c0f0:·6574·3d22·2369·646d·3935·3639·2220·7461··et="#idm9569"·ta 
0003c100:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c110:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c120:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c130:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c140:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c150:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c160:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
Max diff block lines reached; 80136/94792 bytes (84.54%) of diff not shown.
20.5 KB
html2text {}
    
Offset 84, 20 lines modifiedOffset 84, 14 lines modified
84 Identifiers·and·References·Identifiers: ·CCE-27096-784 Identifiers·and·References·Identifiers: ·CCE-27096-7
85 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule85 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
86 Remediation_OSBuild_Blueprint_snippet_⇲86 Remediation_OSBuild_Blueprint_snippet_⇲
  
87 [[packages]]87 [[packages]]
88 name·=·"aide"88 name·=·"aide"
89 version·=·"*"89 version·=·"*"
90 Remediation_Anaconda_snippet_⇲ 
91 Complexity:·low 
92 Disruption:·low 
93 Strategy:···enable 
  
94 package·--add=aide 
95 Remediation_Puppet_snippet_⇲90 Remediation_Puppet_snippet_⇲
96 Complexity:·low91 Complexity:·low
97 Disruption:·low92 Disruption:·low
98 Strategy:···enable93 Strategy:···enable
99 include·install_aide94 include·install_aide
  
100 class·install_aide·{95 class·install_aide·{
Offset 115, 14 lines modifiedOffset 109, 20 lines modified
115 if·!·rpm·-q·--quiet·"aide"·;·then109 if·!·rpm·-q·--quiet·"aide"·;·then
116 ····yum·install·-y·"aide"110 ····yum·install·-y·"aide"
117 fi111 fi
  
118 else112 else
119 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'113 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
120 fi114 fi
 115 Remediation_Anaconda_snippet_⇲
 116 Complexity:·low
 117 Disruption:·low
 118 Strategy:···enable
  
 119 package·--add=aide
121 Remediation_Ansible_snippet_⇲120 Remediation_Ansible_snippet_⇲
122 Complexity:·low121 Complexity:·low
123 Disruption:·low122 Disruption:·low
124 Strategy:···enable123 Strategy:···enable
125 -·name:·Ensure·aide·is·installed124 -·name:·Ensure·aide·is·installed
126 ··package:125 ··package:
127 ····name:·aide126 ····name:·aide
Offset 3945, 15 lines modifiedOffset 3945, 15 lines modified
3945 Rationale:·················If·users·can·write·to·audit·logs,·audit·trails·can·be·modified·or·destroyed.3945 Rationale:·················If·users·can·write·to·audit·logs,·audit·trails·can·be·modified·or·destroyed.
3946 Severity: ················medium3946 Severity: ················medium
3947 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit3947 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit
3948 Identifiers·and·References·Identifiers: ·CCE-27205-43948 Identifiers·and·References·Identifiers: ·CCE-27205-4
3949 ···························References: ·1,·11,·12,·13,·14,·15,·16,·18,·19,·3,·4,·5,·6,·7,·8,·5.4.1.1,·APO01.06,·APO11.04,·APO12.06,·BAI03.05,·BAI08.02,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS05.04,·DSS05.07,·DSS06.02,·MEA02.01,·3.3.1,·CCI-000162,·CCI-000163,·CCI-000164,·CCI-001314,·4.2.3.10,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.7.3,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.1,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_5.2,·SR_6.1,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CIP-003-8_R5.1.1,·CIP-003-8_R5.3,·CIP-004-6_R2.3,·CIP-007-3_R2.1,·CIP-007-3_R2.2,·CIP-007-3_R2.3,·CIP-007-3_R5.1,·CIP-007-3_R5.1.1,·CIP-007-3_R5.1.2,·CM-6(a),·AC-6(1),·AU-9(4),·DE.AE-3,·DE.AE-5,·PR.AC-4,·PR.DS-5,·PR.PT-1,·RS.AN-1,·RS.AN-4,·Req-10.5,·SRG-OS-000057-GPOS-00027,·SRG-OS-000058-GPOS-00028,·SRG-OS-000059-GPOS-00029,·SRG-OS-000206-GPOS-00084,·RHEL-07-910055,·SV-228564r606407_rule3949 ···························References: ·1,·11,·12,·13,·14,·15,·16,·18,·19,·3,·4,·5,·6,·7,·8,·5.4.1.1,·APO01.06,·APO11.04,·APO12.06,·BAI03.05,·BAI08.02,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS05.04,·DSS05.07,·DSS06.02,·MEA02.01,·3.3.1,·CCI-000162,·CCI-000163,·CCI-000164,·CCI-001314,·4.2.3.10,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.7.3,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.1,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_5.2,·SR_6.1,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CIP-003-8_R5.1.1,·CIP-003-8_R5.3,·CIP-004-6_R2.3,·CIP-007-3_R2.1,·CIP-007-3_R2.2,·CIP-007-3_R2.3,·CIP-007-3_R5.1,·CIP-007-3_R5.1.1,·CIP-007-3_R5.1.2,·CM-6(a),·AC-6(1),·AU-9(4),·DE.AE-3,·DE.AE-5,·PR.AC-4,·PR.DS-5,·PR.PT-1,·RS.AN-1,·RS.AN-4,·Req-10.5,·SRG-OS-000057-GPOS-00027,·SRG-OS-000058-GPOS-00028,·SRG-OS-000059-GPOS-00029,·SRG-OS-000206-GPOS-00084,·RHEL-07-910055,·SV-228564r606407_rule
3950 Remediation_Shell_script_⇲3950 Remediation_Shell_script_⇲
3951 #·Remediation·is·applicable·only·in·certain·platforms3951 #·Remediation·is·applicable·only·in·certain·platforms
3952 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then3952 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
3953 if·LC_ALL=C·grep·-iw·^log_file·/etc/audit/auditd.conf;·then3953 if·LC_ALL=C·grep·-iw·^log_file·/etc/audit/auditd.conf;·then
3954 ····FILE=$(awk·-F·"="·'/^log_file/·{print·$2}'·/etc/audit/auditd.conf·|·tr·-d·'·')3954 ····FILE=$(awk·-F·"="·'/^log_file/·{print·$2}'·/etc/audit/auditd.conf·|·tr·-d·'·')
3955 else3955 else
3956 ····FILE="/var/log/audit/audit.log"3956 ····FILE="/var/log/audit/audit.log"
3957 fi3957 fi
  
Offset 3976, 15 lines modifiedOffset 3976, 15 lines modified
3976 Identifiers·and·References·Identifiers: ·CCE-82023-33976 Identifiers·and·References·Identifiers: ·CCE-82023-3
3977 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.23977 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
3978 Remediation_Shell_script_⇲3978 Remediation_Shell_script_⇲
3979 Complexity:·low3979 Complexity:·low
3980 Disruption:·low3980 Disruption:·low
3981 Strategy:···configure3981 Strategy:···configure
3982 #·Remediation·is·applicable·only·in·certain·platforms3982 #·Remediation·is·applicable·only·in·certain·platforms
3983 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then3983 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
3984 chgrp·0·/boot/grub2/grub.cfg3984 chgrp·0·/boot/grub2/grub.cfg
  
3985 else3985 else
3986 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3986 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3987 fi3987 fi
3988 Remediation_Ansible_snippet_⇲3988 Remediation_Ansible_snippet_⇲
Offset 4009, 16 lines modifiedOffset 4009, 16 lines modified
4009 ··-·no_reboot_needed4009 ··-·no_reboot_needed
  
4010 -·name:·Test·for·existence·/boot/grub2/grub.cfg4010 -·name:·Test·for·existence·/boot/grub2/grub.cfg
4011 ··stat:4011 ··stat:
4012 ····path:·/boot/grub2/grub.cfg4012 ····path:·/boot/grub2/grub.cfg
4013 ··register:·file_exists4013 ··register:·file_exists
4014 ··when:4014 ··when:
4015 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
4016 ··-·'"grub2-common"·in·ansible_facts.packages'4015 ··-·'"grub2-common"·in·ansible_facts.packages'
 4016 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
4017 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4017 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4018 ··tags:4018 ··tags:
4019 ··-·CCE-82023-34019 ··-·CCE-82023-3
4020 ··-·CJIS-5.5.2.24020 ··-·CJIS-5.5.2.2
4021 ··-·NIST-800-171-3.4.54021 ··-·NIST-800-171-3.4.5
4022 ··-·NIST-800-53-AC-6(1)4022 ··-·NIST-800-53-AC-6(1)
4023 ··-·NIST-800-53-CM-6(a)4023 ··-·NIST-800-53-CM-6(a)
Offset 4031, 16 lines modifiedOffset 4031, 16 lines modified
4031 ··-·no_reboot_needed4031 ··-·no_reboot_needed
  
4032 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg4032 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
4033 ··file:4033 ··file:
4034 ····path:·/boot/grub2/grub.cfg4034 ····path:·/boot/grub2/grub.cfg
4035 ····group:·'0'4035 ····group:·'0'
4036 ··when:4036 ··when:
4037 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
4038 ··-·'"grub2-common"·in·ansible_facts.packages'4037 ··-·'"grub2-common"·in·ansible_facts.packages'
 4038 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
4039 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4039 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4040 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists4040 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
4041 ··tags:4041 ··tags:
4042 ··-·CCE-82023-34042 ··-·CCE-82023-3
4043 ··-·CJIS-5.5.2.24043 ··-·CJIS-5.5.2.2
4044 ··-·NIST-800-171-3.4.54044 ··-·NIST-800-171-3.4.5
4045 ··-·NIST-800-53-AC-6(1)4045 ··-·NIST-800-53-AC-6(1)
Offset 4061, 15 lines modifiedOffset 4061, 15 lines modified
4061 Identifiers·and·References·Identifiers: ·CCE-82026-64061 Identifiers·and·References·Identifiers: ·CCE-82026-6
4062 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.24062 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.2
4063 Remediation_Shell_script_⇲4063 Remediation_Shell_script_⇲
4064 Complexity:·low4064 Complexity:·low
4065 Disruption:·low4065 Disruption:·low
4066 Strategy:···configure4066 Strategy:···configure
4067 #·Remediation·is·applicable·only·in·certain·platforms4067 #·Remediation·is·applicable·only·in·certain·platforms
4068 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then4068 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
4069 chown·0·/boot/grub2/grub.cfg4069 chown·0·/boot/grub2/grub.cfg
  
4070 else4070 else
4071 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4071 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4072 fi4072 fi
4073 Remediation_Ansible_snippet_⇲4073 Remediation_Ansible_snippet_⇲
Offset 4094, 16 lines modifiedOffset 4094, 16 lines modified
4094 ··-·no_reboot_needed4094 ··-·no_reboot_needed
Max diff block lines reached; 13756/20986 bytes (65.55%) of diff not shown.
568 KB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-standard.html
    
Offset 24192, 21 lines modifiedOffset 24192, 21 lines modified
0005e7f0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0005e7f0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0005e800:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0005e800:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0005e810:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0005e810:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0005e820:·646d·3235·3534·3722·3e3c·7072·653e·3c63··dm25547"><pre><c0005e820:·646d·3235·3534·3722·3e3c·7072·653e·3c63··dm25547"><pre><c
0005e830:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio0005e830:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
0005e840:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·0005e840:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
0005e850:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·0005e850:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
0005e860:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!0005e860:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 0005e870:·202d·2d71·7569·6574·202d·7120·6175·6469···--quiet·-q·audi
 0005e880:·7420·2661·6d70·3b26·616d·703b·205b·2021··t·&amp;&amp;·[·!
0005e870:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·0005e890:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
0005e880:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!0005e8a0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
0005e890:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai0005e8b0:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 0005e8c0:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
0005e8a0:·6e65·7265·6e76·205d·2026·616d·703b·2661··nerenv·]·&amp;&a 
0005e8b0:·6d70·3b20·7270·6d20·2d2d·7175·6965·7420··mp;·rpm·--quiet· 
0005e8c0:·2d71·2061·7564·6974·3b20·7468·656e·0a0a··-q·audit;·then.. 
0005e8d0:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·0005e8d0:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·
0005e8e0:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·0005e8e0:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·
0005e8f0:·6f66·2074·6865·2073·7973·6361·6c6c·2072··of·the·syscall·r0005e8f0:·6f66·2074·6865·2073·7973·6361·6c6c·2072··of·the·syscall·r
0005e900:·756c·650a·2320·5265·7472·6965·7665·2068··ule.#·Retrieve·h0005e900:·756c·650a·2320·5265·7472·6965·7665·2068··ule.#·Retrieve·h
0005e910:·6172·6477·6172·6520·6172·6368·6974·6563··ardware·architec0005e910:·6172·6477·6172·6520·6172·6368·6974·6563··ardware·architec
0005e920:·7475·7265·206f·6620·7468·6520·756e·6465··ture·of·the·unde0005e920:·7475·7265·206f·6620·7468·6520·756e·6465··ture·of·the·unde
0005e930:·726c·7969·6e67·2073·7973·7465·6d0a·5b20··rlying·system.[·0005e930:·726c·7969·6e67·2073·7973·7465·6d0a·5b20··rlying·system.[·
Offset 25087, 23 lines modifiedOffset 25087, 23 lines modified
00061fe0:·7569·7265·640a·2020·2d20·7265·7374·7269··uired.··-·restri00061fe0:·7569·7265·640a·2020·2d20·7265·7374·7269··uired.··-·restri
00061ff0:·6374·5f73·7472·6174·6567·790a·0a2d·206e··ct_strategy..-·n00061ff0:·6374·5f73·7472·6174·6567·790a·0a2d·206e··ct_strategy..-·n
00062000:·616d·653a·2053·6574·2061·7263·6869·7465··ame:·Set·archite00062000:·616d·653a·2053·6574·2061·7263·6869·7465··ame:·Set·archite
00062010:·6374·7572·6520·666f·7220·6175·6469·7420··cture·for·audit·00062010:·6374·7572·6520·666f·7220·6175·6469·7420··cture·for·audit·
00062020:·6368·6d6f·6420·7461·736b·730a·2020·7365··chmod·tasks.··se00062020:·6368·6d6f·6420·7461·736b·730a·2020·7365··chmod·tasks.··se
00062030:·745f·6661·6374·3a0a·2020·2020·6175·6469··t_fact:.····audi00062030:·745f·6661·6374·3a0a·2020·2020·6175·6469··t_fact:.····audi
00062040:·745f·6172·6368·3a20·6236·340a·2020·7768··t_arch:·b64.··wh00062040:·745f·6172·6368·3a20·6236·340a·2020·7768··t_arch:·b64.··wh
00062050:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_ 
00062060:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
00062070:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
00062080:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
00062090:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
000620a0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].·· 
000620b0:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an 
000620c0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack00062050:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit"
 00062060:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 00062070:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-·
 00062080:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 00062090:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 000620a0:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 000620b0:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 000620c0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
000620d0:·6167·6573·270a·2020·2d20·616e·7369·626c··ages'.··-·ansibl000620d0:·6e65·7222·5d0a·2020·2d20·616e·7369·626c··ner"].··-·ansibl
000620e0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=000620e0:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=
000620f0:·3d20·2261·6172·6368·3634·2220·6f72·2061··=·"aarch64"·or·a000620f0:·3d20·2261·6172·6368·3634·2220·6f72·2061··=·"aarch64"·or·a
00062100:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect00062100:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
00062110:·7572·6520·3d3d·2022·7070·6336·3422·206f··ure·==·"ppc64"·o00062110:·7572·6520·3d3d·2022·7070·6336·3422·206f··ure·==·"ppc64"·o
00062120:·7220·616e·7369·626c·655f·6172·6368·6974··r·ansible_archit00062120:·7220·616e·7369·626c·655f·6172·6368·6974··r·ansible_archit
00062130:·6563·7475·7265·0a20·2020·203d·3d20·2270··ecture.····==·"p00062130:·6563·7475·7265·0a20·2020·203d·3d20·2270··ecture.····==·"p
00062140:·7063·3634·6c65·2220·6f72·2061·6e73·6962··pc64le"·or·ansib00062140:·7063·3634·6c65·2220·6f72·2061·6e73·6962··pc64le"·or·ansib
Offset 25411, 23 lines modifiedOffset 25411, 23 lines modified
00063420:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··00063420:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··
00063430:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true00063430:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true
00063440:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r00063440:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r
00063450:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·00063450:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·
00063460:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when00063460:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when
00063470:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found00063470:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found
00063480:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·00063480:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·
00063490:·2077·6865·6e3a·0a20·202d·2061·6e73·6962···when:.··-·ansib00063490:·2077·6865·6e3a·0a20·202d·2027·2261·7564···when:.··-·'"aud
000634a0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
000634b0:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
000634c0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
000634d0:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
000634e0:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"] 
000634f0:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in 
00063500:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p 
00063510:·6163·6b61·6765·7327·0a20·2074·6167·733a··ackages'.··tags:000634a0:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f
 000634b0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·
 000634c0:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu
 000634d0:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 000634e0:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 000634f0:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 00063500:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 00063510:·7461·696e·6572·225d·0a20·2074·6167·733a··tainer"].··tags:
00063520:·0a20·202d·2043·4345·2d32·3733·3339·2d31··.··-·CCE-27339-100063520:·0a20·202d·2043·4345·2d32·3733·3339·2d31··.··-·CCE-27339-1
00063530:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.00063530:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.
00063540:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-00063540:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-
00063550:·5248·454c·2d30·372d·3033·3034·3130·0a20··RHEL-07-030410.·00063550:·5248·454c·2d30·372d·3033·3034·3130·0a20··RHEL-07-030410.·
00063560:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-00063560:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
00063570:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-800063570:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8
00063580:·3030·2d35·332d·4155·2d31·3228·6329·0a20··00-53-AU-12(c).·00063580:·3030·2d35·332d·4155·2d31·3228·6329·0a20··00-53-AU-12(c).·
Offset 25724, 23 lines modifiedOffset 25724, 23 lines modified
000647b0:·6572·6d5f·6d6f·640a·2020·2020·2020·6372··erm_mod.······cr000647b0:·6572·6d5f·6d6f·640a·2020·2020·2020·6372··erm_mod.······cr
000647c0:·6561·7465·3a20·7472·7565·0a20·2020·2020··eate:·true.·····000647c0:·6561·7465·3a20·7472·7565·0a20·2020·2020··eate:·true.·····
000647d0:·206d·6f64·653a·206f·2d72·7778·0a20·2020···mode:·o-rwx.···000647d0:·206d·6f64·653a·206f·2d72·7778·0a20·2020···mode:·o-rwx.···
000647e0:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen000647e0:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen
000647f0:·740a·2020·2020·7768·656e·3a20·7379·7363··t.····when:·sysc000647f0:·740a·2020·2020·7768·656e·3a20·7379·7363··t.····when:·sysc
00064800:·616c·6c73·5f66·6f75·6e64·207c·206c·656e··alls_found·|·len00064800:·616c·6c73·5f66·6f75·6e64·207c·206c·656e··alls_found·|·len
00064810:·6774·6820·3d3d·2030·0a20·2077·6865·6e3a··gth·==·0.··when:00064810:·6774·6820·3d3d·2030·0a20·2077·6865·6e3a··gth·==·0.··when:
00064820:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
00064830:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
00064840:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
00064850:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
00064860:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
00064870:·6f6e·7461·696e·6572·225d·0a20·202d·2027··ontainer"].··-·' 
00064880:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib 
00064890:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package00064820:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 00064830:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 00064840:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans
 00064850:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 00064860:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 00064870:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 00064880:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 00064890:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
000648a0:·7327·0a20·202d·2061·7564·6974·5f61·7263··s'.··-·audit_arc000648a0:·225d·0a20·202d·2061·7564·6974·5f61·7263··"].··-·audit_arc
000648b0:·6820·3d3d·2022·6236·3422·0a20·2074·6167··h·==·"b64".··tag000648b0:·6820·3d3d·2022·6236·3422·0a20·2074·6167··h·==·"b64".··tag
000648c0:·733a·0a20·202d·2043·4345·2d32·3733·3339··s:.··-·CCE-27339000648c0:·733a·0a20·202d·2043·4345·2d32·3733·3339··s:.··-·CCE-27339
000648d0:·2d31·0a20·202d·2043·4a49·532d·352e·342e··-1.··-·CJIS-5.4.000648d0:·2d31·0a20·202d·2043·4a49·532d·352e·342e··-1.··-·CJIS-5.4.
000648e0:·312e·310a·2020·2d20·4449·5341·2d53·5449··1.1.··-·DISA-STI000648e0:·312e·310a·2020·2d20·4449·5341·2d53·5449··1.1.··-·DISA-STI
000648f0:·472d·5248·454c·2d30·372d·3033·3034·3130··G-RHEL-07-030410000648f0:·472d·5248·454c·2d30·372d·3033·3034·3130··G-RHEL-07-030410
00064900:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-1700064900:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17
00064910:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST00064910:·312d·332e·312e·370a·2020·2d20·4e49·5354··1-3.1.7.··-·NIST
Offset 26728, 21 lines modifiedOffset 26728, 21 lines modified
00068670:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00068670:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
00068680:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c00068680:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
00068690:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm00068690:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
000686a0:·3235·3730·3722·3e3c·7072·653e·3c63·6f64··25707"><pre><cod000686a0:·3235·3730·3722·3e3c·7072·653e·3c63·6f64··25707"><pre><cod
000686b0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·000686b0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
000686c0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on000686c0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
000686d0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl000686d0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
000686e0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-000686e0:·6174·666f·726d·730a·6966·2072·706d·202d··atforms.if·rpm·-
000686f0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·000686f0:·2d71·7569·6574·202d·7120·6175·6469·7420··-quiet·-q·audit·
Max diff block lines reached; 417900/427414 bytes (97.77%) of diff not shown.
151 KB
html2text {}
    
Offset 1090, 15 lines modifiedOffset 1090, 15 lines modified
1090 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1090 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1091 Severity: ················medium1091 Severity: ················medium
1092 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1092 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1093 Identifiers·and·References·Identifiers: ·CCE-27339-11093 Identifiers·and·References·Identifiers: ·CCE-27339-1
1094 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule1094 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030410,·4.1.9,·SV-204521r809772_rule
1095 Remediation_Shell_script_⇲1095 Remediation_Shell_script_⇲
1096 #·Remediation·is·applicable·only·in·certain·platforms1096 #·Remediation·is·applicable·only·in·certain·platforms
1097 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1097 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1098 #·First·perform·the·remediation·of·the·syscall·rule1098 #·First·perform·the·remediation·of·the·syscall·rule
1099 #·Retrieve·hardware·architecture·of·the·underlying·system1099 #·Retrieve·hardware·architecture·of·the·underlying·system
1100 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1100 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1101 for·ARCH·in·"${RULE_ARCHS[@]}"1101 for·ARCH·in·"${RULE_ARCHS[@]}"
1102 do1102 do
Offset 1446, 16 lines modifiedOffset 1446, 16 lines modified
1446 ··-·reboot_required1446 ··-·reboot_required
1447 ··-·restrict_strategy1447 ··-·restrict_strategy
  
1448 -·name:·Set·architecture·for·audit·chmod·tasks1448 -·name:·Set·architecture·for·audit·chmod·tasks
1449 ··set_fact:1449 ··set_fact:
1450 ····audit_arch:·b641450 ····audit_arch:·b64
1451 ··when:1451 ··when:
1452 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1453 ··-·'"audit"·in·ansible_facts.packages'1452 ··-·'"audit"·in·ansible_facts.packages'
 1453 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1454 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1454 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1455 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1455 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1456 ··tags:1456 ··tags:
1457 ··-·CCE-27339-11457 ··-·CCE-27339-1
1458 ··-·CJIS-5.4.1.11458 ··-·CJIS-5.4.1.1
1459 ··-·DISA-STIG-RHEL-07-0304101459 ··-·DISA-STIG-RHEL-07-030410
1460 ··-·NIST-800-171-3.1.71460 ··-·NIST-800-171-3.1.7
Offset 1593, 16 lines modifiedOffset 1593, 16 lines modified
1593 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001593 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1594 ········-F·auid!=unset·-F·key=perm_mod1594 ········-F·auid!=unset·-F·key=perm_mod
1595 ······create:·true1595 ······create:·true
1596 ······mode:·o-rwx1596 ······mode:·o-rwx
1597 ······state:·present1597 ······state:·present
1598 ····when:·syscalls_found·|·length·==·01598 ····when:·syscalls_found·|·length·==·0
1599 ··when:1599 ··when:
1600 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1601 ··-·'"audit"·in·ansible_facts.packages'1600 ··-·'"audit"·in·ansible_facts.packages'
 1601 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1602 ··tags:1602 ··tags:
1603 ··-·CCE-27339-11603 ··-·CCE-27339-1
1604 ··-·CJIS-5.4.1.11604 ··-·CJIS-5.4.1.1
1605 ··-·DISA-STIG-RHEL-07-0304101605 ··-·DISA-STIG-RHEL-07-030410
1606 ··-·NIST-800-171-3.1.71606 ··-·NIST-800-171-3.1.7
1607 ··-·NIST-800-53-AU-12(c)1607 ··-·NIST-800-53-AU-12(c)
1608 ··-·NIST-800-53-AU-2(d)1608 ··-·NIST-800-53-AU-2(d)
Offset 1738, 16 lines modifiedOffset 1738, 16 lines modified
1738 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001738 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1739 ········-F·auid!=unset·-F·key=perm_mod1739 ········-F·auid!=unset·-F·key=perm_mod
1740 ······create:·true1740 ······create:·true
1741 ······mode:·o-rwx1741 ······mode:·o-rwx
1742 ······state:·present1742 ······state:·present
1743 ····when:·syscalls_found·|·length·==·01743 ····when:·syscalls_found·|·length·==·0
1744 ··when:1744 ··when:
1745 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1746 ··-·'"audit"·in·ansible_facts.packages'1745 ··-·'"audit"·in·ansible_facts.packages'
 1746 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1747 ··-·audit_arch·==·"b64"1747 ··-·audit_arch·==·"b64"
1748 ··tags:1748 ··tags:
1749 ··-·CCE-27339-11749 ··-·CCE-27339-1
1750 ··-·CJIS-5.4.1.11750 ··-·CJIS-5.4.1.1
1751 ··-·DISA-STIG-RHEL-07-0304101751 ··-·DISA-STIG-RHEL-07-030410
1752 ··-·NIST-800-171-3.1.71752 ··-·NIST-800-171-3.1.7
1753 ··-·NIST-800-53-AU-12(c)1753 ··-·NIST-800-53-AU-12(c)
Offset 1773, 15 lines modifiedOffset 1773, 15 lines modified
1773 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1773 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1774 Severity: ················medium1774 Severity: ················medium
1775 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown1775 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
1776 Identifiers·and·References·Identifiers: ·CCE-27364-91776 Identifiers·and·References·Identifiers: ·CCE-27364-9
1777 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030370,·4.1.9,·SV-204517r809570_rule1777 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-07-030370,·4.1.9,·SV-204517r809570_rule
1778 Remediation_Shell_script_⇲1778 Remediation_Shell_script_⇲
1779 #·Remediation·is·applicable·only·in·certain·platforms1779 #·Remediation·is·applicable·only·in·certain·platforms
1780 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1780 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1781 #·First·perform·the·remediation·of·the·syscall·rule1781 #·First·perform·the·remediation·of·the·syscall·rule
1782 #·Retrieve·hardware·architecture·of·the·underlying·system1782 #·Retrieve·hardware·architecture·of·the·underlying·system
1783 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1783 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1784 for·ARCH·in·"${RULE_ARCHS[@]}"1784 for·ARCH·in·"${RULE_ARCHS[@]}"
1785 do1785 do
Offset 2129, 16 lines modifiedOffset 2129, 16 lines modified
2129 ··-·reboot_required2129 ··-·reboot_required
2130 ··-·restrict_strategy2130 ··-·restrict_strategy
  
2131 -·name:·Set·architecture·for·audit·chown·tasks2131 -·name:·Set·architecture·for·audit·chown·tasks
2132 ··set_fact:2132 ··set_fact:
2133 ····audit_arch:·b642133 ····audit_arch:·b64
2134 ··when:2134 ··when:
2135 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2136 ··-·'"audit"·in·ansible_facts.packages'2135 ··-·'"audit"·in·ansible_facts.packages'
 2136 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2137 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2137 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2138 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2138 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2139 ··tags:2139 ··tags:
2140 ··-·CCE-27364-92140 ··-·CCE-27364-9
2141 ··-·CJIS-5.4.1.12141 ··-·CJIS-5.4.1.1
2142 ··-·DISA-STIG-RHEL-07-0303702142 ··-·DISA-STIG-RHEL-07-030370
2143 ··-·NIST-800-171-3.1.72143 ··-·NIST-800-171-3.1.7
Offset 2278, 16 lines modifiedOffset 2278, 16 lines modified
2278 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002278 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2279 ········-F·auid!=unset·-F·key=perm_mod2279 ········-F·auid!=unset·-F·key=perm_mod
2280 ······create:·true2280 ······create:·true
2281 ······mode:·o-rwx2281 ······mode:·o-rwx
2282 ······state:·present2282 ······state:·present
2283 ····when:·syscalls_found·|·length·==·02283 ····when:·syscalls_found·|·length·==·0
2284 ··when:2284 ··when:
2285 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2286 ··-·'"audit"·in·ansible_facts.packages'2285 ··-·'"audit"·in·ansible_facts.packages'
 2286 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2287 ··tags:2287 ··tags:
2288 ··-·CCE-27364-92288 ··-·CCE-27364-9
2289 ··-·CJIS-5.4.1.12289 ··-·CJIS-5.4.1.1
2290 ··-·DISA-STIG-RHEL-07-0303702290 ··-·DISA-STIG-RHEL-07-030370
2291 ··-·NIST-800-171-3.1.72291 ··-·NIST-800-171-3.1.7
2292 ··-·NIST-800-53-AU-12(c)2292 ··-·NIST-800-53-AU-12(c)
2293 ··-·NIST-800-53-AU-2(d)2293 ··-·NIST-800-53-AU-2(d)
Offset 2425, 16 lines modifiedOffset 2425, 16 lines modified
2425 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002425 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2426 ········-F·auid!=unset·-F·key=perm_mod2426 ········-F·auid!=unset·-F·key=perm_mod
2427 ······create:·true2427 ······create:·true
2428 ······mode:·o-rwx2428 ······mode:·o-rwx
2429 ······state:·present2429 ······state:·present
Max diff block lines reached; 145708/154219 bytes (94.48%) of diff not shown.
1.13 MB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-stig.html
    
Offset 18377, 116 lines modifiedOffset 18377, 116 lines modified
00047c80:·6765·743d·2223·6964·6d39·3536·3722·2074··get="#idm9567"·t00047c80:·6765·743d·2223·6964·6d39·3536·3722·2074··get="#idm9567"·t
00047c90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00047c90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00047ca0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00047ca0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00047cb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00047cb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00047cc0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00047cc0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00047cd0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00047cd0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00047ce0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00047ce0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00047cf0:·2041·6e61·636f·6e64·6120·736e·6970·7065···Anaconda·snippe00047cf0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet·
00047d00:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00047d00:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00047d10:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00047d10:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00047d20:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00047d20:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00047d30:·2220·6964·3d22·6964·6d39·3536·3722·3e3c··"·id="idm9567"><00047d30:·6964·3d22·6964·6d39·3536·3722·3e3c·7461··id="idm9567"><ta
00047d40:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00047d40:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
00047d50:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00047d50:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
00047d60:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00047d60:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
00047d70:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00047d70:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
00047d80:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00047d80:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
00047d90:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low00047d90:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
00047da0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00047da0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00047db0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t00047db0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
00047dc0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00047dc0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
00047dd0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat00047dd0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
00047de0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena00047de0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
00047df0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t00047df0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
00047e00:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00047e00:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
00047e10:·0a70·6163·6b61·6765·202d·2d61·6464·3d61··.package·--add=a00047e10:·636c·7564·6520·696e·7374·616c·6c5f·6169··clude·install_ai
 00047e20:·6465·0a0a·636c·6173·7320·696e·7374·616c··de..class·instal
 00047e30:·6c5f·6169·6465·207b·0a20·2070·6163·6b61··l_aide·{.··packa
 00047e40:·6765·207b·2027·6169·6465·273a·0a20·2020··ge·{·'aide':.···
 00047e50:·2065·6e73·7572·6520·3d26·6774·3b20·2769···ensure·=&gt;·'i
 00047e60:·6e73·7461·6c6c·6564·272c·0a20·207d·0a7d··nstalled',.··}.}
 00047e70:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 00047e80:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 00047e90:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 00047ea0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 00047eb0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 00047ec0:·743d·2223·6964·6d39·3536·3822·2074·6162··t="#idm9568"·tab
 00047ed0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00047ee0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00047ef0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00047f00:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 00047f10:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 00047f20:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 00047f30:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 00047f40:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00047f50:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00047f60:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00047f70:·6964·6d39·3536·3822·3e3c·7461·626c·6520··idm9568"><table·
 00047f80:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00047f90:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00047fa0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00047fb0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00047fc0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 00047fd0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00047fe0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 00047ff0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 00048000:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00048010:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00048020:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00048030:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00048040:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 00048050:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00048060:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00048070:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00048080:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
 00048090:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
 000480a0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
 000480b0:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·
 000480c0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 000480d0:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 000480e0:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
 000480f0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 00048100:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 00048110:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 00048120:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 00048130:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 00048140:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
00047e20:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre00048150:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
00047e30:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=00048160:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
00047e40:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success00048170:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
00047e50:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c00048180:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
00047e60:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta00048190:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
00047e70:·7267·6574·3d22·2369·646d·3935·3638·2220··rget="#idm9568"·000481a0:·7267·6574·3d22·2369·646d·3935·3639·2220··rget="#idm9569"·
00047e80:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol000481b0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00047e90:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-000481c0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
00047ea0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"000481d0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
00047eb0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate000481e0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
00047ec0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href000481f0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
00047ed0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00048200:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
00047ee0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet00048210:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
00047ef0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div00048220:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
00047f00:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00048230:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
00047f10:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00048240:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
00047f20:·2069·643d·2269·646d·3935·3638·223e·3c74···id="idm9568"><t00048250:·6522·2069·643d·2269·646d·3935·3639·223e··e"·id="idm9569">
00047f30:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00048260:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
00047f40:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00048270:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
00047f50:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00048280:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
00047f60:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00048290:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
00047f70:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi000482a0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
00047f80:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<000482b0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
00047f90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th000482c0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
00047fa0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th000482d0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
00047fb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t000482e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00047fc0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate000482f0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
00047fd0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab00048300:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
00047fe0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta00048310:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
00047ff0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i00048320:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 00048330:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=
00048000:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a 
00048010:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta 
00048020:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack 
00048030:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.·· 
00048040:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
00048050:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
00048060:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
00048070:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00048080:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00048090:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
000480a0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
000480b0:·6574·3d22·2369·646d·3935·3639·2220·7461··et="#idm9569"·ta 
000480c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
000480d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
000480e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
000480f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00048100:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00048110:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00048120:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
Max diff block lines reached; 850753/865409 bytes (98.31%) of diff not shown.
311 KB
html2text {}
    
Offset 540, 20 lines modifiedOffset 540, 14 lines modified
540 Identifiers·and·References·Identifiers: ·CCE-27096-7540 Identifiers·and·References·Identifiers: ·CCE-27096-7
541 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule541 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
542 Remediation_OSBuild_Blueprint_snippet_⇲542 Remediation_OSBuild_Blueprint_snippet_⇲
  
543 [[packages]]543 [[packages]]
544 name·=·"aide"544 name·=·"aide"
545 version·=·"*"545 version·=·"*"
546 Remediation_Anaconda_snippet_⇲ 
547 Complexity:·low 
548 Disruption:·low 
549 Strategy:···enable 
  
550 package·--add=aide 
551 Remediation_Puppet_snippet_⇲546 Remediation_Puppet_snippet_⇲
552 Complexity:·low547 Complexity:·low
553 Disruption:·low548 Disruption:·low
554 Strategy:···enable549 Strategy:···enable
555 include·install_aide550 include·install_aide
  
556 class·install_aide·{551 class·install_aide·{
Offset 571, 14 lines modifiedOffset 565, 20 lines modified
571 if·!·rpm·-q·--quiet·"aide"·;·then565 if·!·rpm·-q·--quiet·"aide"·;·then
572 ····yum·install·-y·"aide"566 ····yum·install·-y·"aide"
573 fi567 fi
  
574 else568 else
575 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'569 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
576 fi570 fi
 571 Remediation_Anaconda_snippet_⇲
 572 Complexity:·low
 573 Disruption:·low
 574 Strategy:···enable
  
 575 package·--add=aide
577 Remediation_Ansible_snippet_⇲576 Remediation_Ansible_snippet_⇲
578 Complexity:·low577 Complexity:·low
579 Disruption:·low578 Disruption:·low
580 Strategy:···enable579 Strategy:···enable
581 -·name:·Ensure·aide·is·installed580 -·name:·Ensure·aide·is·installed
582 ··package:581 ··package:
583 ····name:·aide582 ····name:·aide
Offset 984, 17 lines modifiedOffset 984, 14 lines modified
984 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.984 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
985 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.985 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
986 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.986 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
987 Severity: ················high987 Severity: ················high
988 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode988 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
989 Identifiers·and·References·Identifiers: ·CCE-80359-3989 Identifiers·and·References·Identifiers: ·CCE-80359-3
990 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule990 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule
991 Remediation_Anaconda_snippet_⇲ 
  
992 package·--add=dracut-fips·--add=dracut-fips-aesni 
993 Remediation_Shell_script_⇲991 Remediation_Shell_script_⇲
994 #·Remediation·is·applicable·only·in·certain·platforms992 #·Remediation·is·applicable·only·in·certain·platforms
995 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then993 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
996 #·prelink·not·installed994 #·prelink·not·installed
997 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then995 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
998 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink996 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 1053, 14 lines modifiedOffset 1050, 17 lines modified
1053 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader1050 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
1054 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"1051 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
1055 fi1052 fi
  
1056 else1053 else
1057 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1054 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1058 fi1055 fi
 1056 Remediation_Anaconda_snippet_⇲
  
 1057 package·--add=dracut-fips·--add=dracut-fips-aesni
1059 Remediation_Ansible_snippet_⇲1058 Remediation_Ansible_snippet_⇲
1060 Complexity:·high1059 Complexity:·high
1061 Disruption:·medium1060 Disruption:·medium
1062 Reboot:·····true1061 Reboot:·····true
1063 Strategy:···restrict1062 Strategy:···restrict
1064 -·name:·Gather·the·package·facts1063 -·name:·Gather·the·package·facts
1065 ··package_facts:1064 ··package_facts:
Offset 11901, 20 lines modifiedOffset 11901, 14 lines modified
11901 Identifiers·and·References·Identifiers: ·CCE-80519-211901 Identifiers·and·References·Identifiers: ·CCE-80519-2
11902 ···························References: ·CCI-000765,·CCI-001948,·CCI-001953,·CCI-001954,·CM-6(a),·Req-8.3,·SRG-OS-000105-GPOS-00052,·SRG-OS-000375-GPOS-00160,·SRG-OS-000375-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-041001,·SV-204631r853997_rule11902 ···························References: ·CCI-000765,·CCI-001948,·CCI-001953,·CCI-001954,·CM-6(a),·Req-8.3,·SRG-OS-000105-GPOS-00052,·SRG-OS-000375-GPOS-00160,·SRG-OS-000375-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-041001,·SV-204631r853997_rule
11903 Remediation_OSBuild_Blueprint_snippet_⇲11903 Remediation_OSBuild_Blueprint_snippet_⇲
  
11904 [[packages]]11904 [[packages]]
11905 name·=·"pam_pkcs11"11905 name·=·"pam_pkcs11"
11906 version·=·"*"11906 version·=·"*"
11907 Remediation_Anaconda_snippet_⇲ 
11908 Complexity:·low 
11909 Disruption:·low 
11910 Strategy:···enable 
  
11911 package·--add=pam_pkcs11 
11912 Remediation_Puppet_snippet_⇲11907 Remediation_Puppet_snippet_⇲
11913 Complexity:·low11908 Complexity:·low
11914 Disruption:·low11909 Disruption:·low
11915 Strategy:···enable11910 Strategy:···enable
11916 include·install_pam_pkcs1111911 include·install_pam_pkcs11
  
11917 class·install_pam_pkcs11·{11912 class·install_pam_pkcs11·{
Offset 11932, 14 lines modifiedOffset 11926, 20 lines modified
11932 if·!·rpm·-q·--quiet·"pam_pkcs11"·;·then11926 if·!·rpm·-q·--quiet·"pam_pkcs11"·;·then
11933 ····yum·install·-y·"pam_pkcs11"11927 ····yum·install·-y·"pam_pkcs11"
11934 fi11928 fi
  
11935 else11929 else
11936 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'11930 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
11937 fi11931 fi
 11932 Remediation_Anaconda_snippet_⇲
 11933 Complexity:·low
 11934 Disruption:·low
 11935 Strategy:···enable
  
 11936 package·--add=pam_pkcs11
11938 Remediation_Ansible_snippet_⇲11937 Remediation_Ansible_snippet_⇲
11939 Complexity:·low11938 Complexity:·low
11940 Disruption:·low11939 Disruption:·low
11941 Strategy:···enable11940 Strategy:···enable
11942 -·name:·Ensure·pam_pkcs11·is·installed11941 -·name:·Ensure·pam_pkcs11·is·installed
11943 ··package:11942 ··package:
11944 ····name:·pam_pkcs1111943 ····name:·pam_pkcs11
Offset 11964, 17 lines modifiedOffset 11964, 14 lines modified
11964 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:11964 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:
11965 ····*·https://access.redhat.com/solutions/8227311965 ····*·https://access.redhat.com/solutions/82273
11966 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.11966 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.
11967 Severity: ················medium11967 Severity: ················medium
11968 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth11968 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth
11969 Identifiers·and·References·Identifiers: ·CCE-80207-411969 Identifiers·and·References·Identifiers: ·CCE-80207-4
11970 ···························References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-010500,·SV-204441r818813_rule11970 ···························References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-010500,·SV-204441r818813_rule
Max diff block lines reached; 311187/318735 bytes (97.63%) of diff not shown.
1.12 MB
./usr/share/doc/ssg-nondebian/ssg-rhel7-guide-stig_gui.html
    
Offset 18396, 116 lines modifiedOffset 18396, 116 lines modified
00047db0:·7267·6574·3d22·2369·646d·3935·3637·2220··rget="#idm9567"·00047db0:·7267·6574·3d22·2369·646d·3935·3637·2220··rget="#idm9567"·
00047dc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00047dc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00047dd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00047dd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
00047de0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00047de0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
00047df0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00047df0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
00047e00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00047e00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
00047e10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00047e10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
00047e20:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp00047e20:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
00047e30:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d00047e30:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00047e40:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00047e40:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00047e50:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00047e50:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00047e60:·6522·2069·643d·2269·646d·3935·3637·223e··e"·id="idm9567">00047e60:·2069·643d·2269·646d·3935·3637·223e·3c74···id="idm9567"><t
00047e70:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta00047e70:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
00047e80:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00047e80:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
00047e90:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00047e90:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
00047ea0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed00047ea0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
00047eb0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00047eb0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00047ec0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo00047ec0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
00047ed0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00047ed0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00047ee0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</00047ee0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
00047ef0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00047ef0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00047f00:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra00047f00:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
00047f10:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en00047f10:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
00047f20:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></00047f20:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
00047f30:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code00047f30:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
00047f40:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=00047f40:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 00047f50:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 00047f60:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 00047f70:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 00047f80:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 00047f90:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 00047fa0:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 00047fb0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 00047fc0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 00047fd0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 00047fe0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 00047ff0:·6574·3d22·2369·646d·3935·3638·2220·7461··et="#idm9568"·ta
 00048000:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 00048010:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 00048020:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 00048030:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 00048040:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 00048050:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00048060:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 00048070:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00048080:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00048090:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000480a0:·2269·646d·3935·3638·223e·3c74·6162·6c65··"idm9568"><table
 000480b0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 000480c0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 000480d0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 000480e0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 000480f0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00048100:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00048110:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00048120:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00048130:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00048140:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00048150:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 00048160:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00048170:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 00048180:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 00048190:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 000481a0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 000481b0:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 000481c0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 000481d0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 000481e0:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 000481f0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 00048200:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 00048210:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
 00048220:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 00048230:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 00048240:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 00048250:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 00048260:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 00048270:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
00047f50:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr00048280:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
00047f60:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class00048290:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
00047f70:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes000482a0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
00047f80:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="000482b0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
00047f90:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t000482c0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
00047fa0:·6172·6765·743d·2223·6964·6d39·3536·3822··arget="#idm9568"000482d0:·6172·6765·743d·2223·6964·6d39·3536·3922··arget="#idm9569"
00047fb0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro000482e0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00047fc0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria000482f0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00047fd0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00048300:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00047fe0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00048310:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00047ff0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00048320:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00048000:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00048330:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
00048010:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe00048340:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
00048020:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00048350:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
00048030:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00048360:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00048040:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00048370:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00048050:·2220·6964·3d22·6964·6d39·3536·3822·3e3c··"·id="idm9568"><00048380:·7365·2220·6964·3d22·6964·6d39·3536·3922··se"·id="idm9569"
00048060:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00048390:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00048070:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped000483a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00048080:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·000483b0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
00048090:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"000483c0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
000480a0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex000483d0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
000480b0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low000483e0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
000480c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t000483f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
000480d0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t00048400:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
000480e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00048410:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
000480f0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat00048420:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
00048100:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena00048430:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00048110:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t00048440:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00048120:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00048450:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 00048460:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
00048130:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
00048140:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
00048150:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
00048160:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
00048170:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
00048180:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
00048190:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
000481a0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
000481b0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
000481c0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
000481d0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
000481e0:·6765·743d·2223·6964·6d39·3536·3922·2074··get="#idm9569"·t 
000481f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00048200:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00048210:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00048220:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
00048230:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
00048240:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
00048250:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 841341/855997 bytes (98.29%) of diff not shown.
309 KB
html2text {}
    
Offset 545, 20 lines modifiedOffset 545, 14 lines modified
545 Identifiers·and·References·Identifiers: ·CCE-27096-7545 Identifiers·and·References·Identifiers: ·CCE-27096-7
546 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule546 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-07-020029,·1.3.1,·SV-251705r861078_rule
547 Remediation_OSBuild_Blueprint_snippet_⇲547 Remediation_OSBuild_Blueprint_snippet_⇲
  
548 [[packages]]548 [[packages]]
549 name·=·"aide"549 name·=·"aide"
550 version·=·"*"550 version·=·"*"
551 Remediation_Anaconda_snippet_⇲ 
552 Complexity:·low 
553 Disruption:·low 
554 Strategy:···enable 
  
555 package·--add=aide 
556 Remediation_Puppet_snippet_⇲551 Remediation_Puppet_snippet_⇲
557 Complexity:·low552 Complexity:·low
558 Disruption:·low553 Disruption:·low
559 Strategy:···enable554 Strategy:···enable
560 include·install_aide555 include·install_aide
  
561 class·install_aide·{556 class·install_aide·{
Offset 576, 14 lines modifiedOffset 570, 20 lines modified
576 if·!·rpm·-q·--quiet·"aide"·;·then570 if·!·rpm·-q·--quiet·"aide"·;·then
577 ····yum·install·-y·"aide"571 ····yum·install·-y·"aide"
578 fi572 fi
  
579 else573 else
580 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'574 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
581 fi575 fi
 576 Remediation_Anaconda_snippet_⇲
 577 Complexity:·low
 578 Disruption:·low
 579 Strategy:···enable
  
 580 package·--add=aide
582 Remediation_Ansible_snippet_⇲581 Remediation_Ansible_snippet_⇲
583 Complexity:·low582 Complexity:·low
584 Disruption:·low583 Disruption:·low
585 Strategy:···enable584 Strategy:···enable
586 -·name:·Ensure·aide·is·installed585 -·name:·Ensure·aide·is·installed
587 ··package:586 ··package:
588 ····name:·aide587 ····name:·aide
Offset 989, 17 lines modifiedOffset 989, 14 lines modified
989 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.989 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
990 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.990 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
991 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.991 Rationale:·················Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
992 Severity: ················high992 Severity: ················high
993 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode993 Rule·ID:···················xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode
994 Identifiers·and·References·Identifiers: ·CCE-80359-3994 Identifiers·and·References·Identifiers: ·CCE-80359-3
995 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule995 ···························References: ·12,·15,·8,·5.10.1.2,·APO13.01,·DSS01.04,·DSS05.02,·DSS05.03,·3.13.8,·3.13.11,·CCI-000068,·CCI-000803,·CCI-001199,·CCI-002450,·CCI-002476,·4.3.3.6.6,·SR_1.13,·SR_2.6,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_7.1,·SR_7.6,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2,·CIP-003-8_R4.2,·CIP-007-3_R5.1,·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12,·PR.AC-3,·PR.PT-4,·SRG-OS-000033-GPOS-00014,·SRG-OS-000185-GPOS-00079,·SRG-OS-000396-GPOS-00176,·SRG-OS-000405-GPOS-00184,·SRG-OS-000478-GPOS-00223,·SRG-OS-000120-VMM-000600,·SRG-OS-000478-VMM-001980,·SRG-OS-000396-VMM-001590,·RHEL-07-021350,·SV-204497r863227_rule
996 Remediation_Anaconda_snippet_⇲ 
  
997 package·--add=dracut-fips·--add=dracut-fips-aesni 
998 Remediation_Shell_script_⇲996 Remediation_Shell_script_⇲
999 #·Remediation·is·applicable·only·in·certain·platforms997 #·Remediation·is·applicable·only·in·certain·platforms
1000 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then998 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·rpm·--quiet·-q·grub2-common;·};·then
  
1001 #·prelink·not·installed999 #·prelink·not·installed
1002 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then1000 if·test·-e·/etc/sysconfig/prelink·-o·-e·/usr/sbin/prelink;·then
1003 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink1001 ····if·grep·-q·^PRELINKING·/etc/sysconfig/prelink
Offset 1058, 14 lines modifiedOffset 1055, 17 lines modified
1058 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader1055 »       #·Correct·the·form·of·kernel·command·line·for·each·installed·kernel·in·the·bootloader
1059 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"1056 »       /sbin/grubby·--update-kernel=ALL·--args="fips=1·boot=UUID=${BOOT_UUID}"
1060 fi1057 fi
  
1061 else1058 else
1062 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1059 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1063 fi1060 fi
 1061 Remediation_Anaconda_snippet_⇲
  
 1062 package·--add=dracut-fips·--add=dracut-fips-aesni
1064 Remediation_Ansible_snippet_⇲1063 Remediation_Ansible_snippet_⇲
1065 Complexity:·high1064 Complexity:·high
1066 Disruption:·medium1065 Disruption:·medium
1067 Reboot:·····true1066 Reboot:·····true
1068 Strategy:···restrict1067 Strategy:···restrict
1069 -·name:·Gather·the·package·facts1068 -·name:·Gather·the·package·facts
1070 ··package_facts:1069 ··package_facts:
Offset 11906, 20 lines modifiedOffset 11906, 14 lines modified
11906 Identifiers·and·References·Identifiers: ·CCE-80519-211906 Identifiers·and·References·Identifiers: ·CCE-80519-2
11907 ···························References: ·CCI-000765,·CCI-001948,·CCI-001953,·CCI-001954,·CM-6(a),·Req-8.3,·SRG-OS-000105-GPOS-00052,·SRG-OS-000375-GPOS-00160,·SRG-OS-000375-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-041001,·SV-204631r853997_rule11907 ···························References: ·CCI-000765,·CCI-001948,·CCI-001953,·CCI-001954,·CM-6(a),·Req-8.3,·SRG-OS-000105-GPOS-00052,·SRG-OS-000375-GPOS-00160,·SRG-OS-000375-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-041001,·SV-204631r853997_rule
11908 Remediation_OSBuild_Blueprint_snippet_⇲11908 Remediation_OSBuild_Blueprint_snippet_⇲
  
11909 [[packages]]11909 [[packages]]
11910 name·=·"pam_pkcs11"11910 name·=·"pam_pkcs11"
11911 version·=·"*"11911 version·=·"*"
11912 Remediation_Anaconda_snippet_⇲ 
11913 Complexity:·low 
11914 Disruption:·low 
11915 Strategy:···enable 
  
11916 package·--add=pam_pkcs11 
11917 Remediation_Puppet_snippet_⇲11912 Remediation_Puppet_snippet_⇲
11918 Complexity:·low11913 Complexity:·low
11919 Disruption:·low11914 Disruption:·low
11920 Strategy:···enable11915 Strategy:···enable
11921 include·install_pam_pkcs1111916 include·install_pam_pkcs11
  
11922 class·install_pam_pkcs11·{11917 class·install_pam_pkcs11·{
Offset 11937, 14 lines modifiedOffset 11931, 20 lines modified
11937 if·!·rpm·-q·--quiet·"pam_pkcs11"·;·then11931 if·!·rpm·-q·--quiet·"pam_pkcs11"·;·then
11938 ····yum·install·-y·"pam_pkcs11"11932 ····yum·install·-y·"pam_pkcs11"
11939 fi11933 fi
  
11940 else11934 else
11941 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'11935 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
11942 fi11936 fi
 11937 Remediation_Anaconda_snippet_⇲
 11938 Complexity:·low
 11939 Disruption:·low
 11940 Strategy:···enable
  
 11941 package·--add=pam_pkcs11
11943 Remediation_Ansible_snippet_⇲11942 Remediation_Ansible_snippet_⇲
11944 Complexity:·low11943 Complexity:·low
11945 Disruption:·low11944 Disruption:·low
11946 Strategy:···enable11945 Strategy:···enable
11947 -·name:·Ensure·pam_pkcs11·is·installed11946 -·name:·Ensure·pam_pkcs11·is·installed
11948 ··package:11947 ··package:
11949 ····name:·pam_pkcs1111948 ····name:·pam_pkcs11
Offset 11969, 17 lines modifiedOffset 11969, 14 lines modified
11969 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:11969 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:
11970 ····*·https://access.redhat.com/solutions/8227311970 ····*·https://access.redhat.com/solutions/82273
11971 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.11971 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.
11972 Severity: ················medium11972 Severity: ················medium
11973 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth11973 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth
11974 Identifiers·and·References·Identifiers: ·CCE-80207-411974 Identifiers·and·References·Identifiers: ·CCE-80207-4
11975 ···························References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-010500,·SV-204441r818813_rule11975 ···························References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·RHEL-07-010500,·SV-204441r818813_rule
Max diff block lines reached; 309272/316820 bytes (97.62%) of diff not shown.
656 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_enhanced.html
    
Offset 15419, 116 lines modifiedOffset 15419, 116 lines modified
0003c3a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003c3a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003c3b0:·6d38·3532·3222·2074·6162·696e·6465·783d··m8522"·tabindex=0003c3b0:·6d38·3532·3222·2074·6162·696e·6465·783d··m8522"·tabindex=
0003c3c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003c3c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003c3d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003c3d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003c3e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003c3e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003c3f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003c3f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003c400:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003c400:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003c410:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003c410:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003c420:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003c420:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003c430:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003c430:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003c440:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003c440:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003c450:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003c450:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003c460:·6d38·3532·3222·3e3c·7461·626c·6520·636c··m8522"><table·cl0003c460:·3532·3222·3e3c·7461·626c·6520·636c·6173··522"><table·clas
0003c470:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003c470:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003c480:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003c480:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003c490:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003c490:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003c4a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003c4a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003c4b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003c4b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003c4c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c4c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c4d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003c4d0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c4e0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c4e0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003c4f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c4f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c500:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003c500:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c510:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003c510:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003c520:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003c520:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003c530:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
0003c540:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co0003c530:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003c540:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003c550:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003c560:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003c570:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003c580:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003c590:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003c5a0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003c5b0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003c5c0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003c5d0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003c5e0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
 0003c5f0:·3532·3322·2074·6162·696e·6465·783d·2230··523"·tabindex="0
 0003c600:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003c610:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003c620:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003c630:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003c640:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003c650:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 0003c660:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003c670:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003c680:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003c690:·7365·2220·6964·3d22·6964·6d38·3532·3322··se"·id="idm8523"
 0003c6a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003c6b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003c6c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003c6d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003c6e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003c6f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003c700:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003c710:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003c720:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003c730:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003c740:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003c750:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003c760:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c770:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 0003c780:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 0003c790:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 0003c7a0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-
 0003c7b0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·
 0003c7c0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-
 0003c7d0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe
 0003c7e0:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if
 0003c7f0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003c800:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 0003c810:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install·
 0003c820:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 0003c830:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003c840:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003c850:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003c860:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003c870:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
0003c550:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003c880:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003c560:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003c890:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003c570:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003c8a0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003c580:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003c8b0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003c590:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003c8c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003c5a0:·646d·3835·3233·2220·7461·6269·6e64·6578··dm8523"·tabindex0003c8d0:·646d·3835·3234·2220·7461·6269·6e64·6578··dm8524"·tabindex
0003c5b0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003c8e0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003c5c0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003c8f0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003c5d0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003c900:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003c5e0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003c910:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003c5f0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003c920:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003c600:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003c930:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003c610:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003c940:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003c620:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003c950:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003c630:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003c960:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003c640:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003c970:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003c650:·3835·3233·223e·3c74·6162·6c65·2063·6c61··8523"><table·cla0003c980:·646d·3835·3234·223e·3c74·6162·6c65·2063··dm8524"><table·c
0003c660:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003c990:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003c670:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003c9a0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003c680:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003c9b0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003c690:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003c9c0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003c6a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003c9d0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003c6b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c9e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c6c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003c9f0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003c6d0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003ca00:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003c6e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ca10:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c6f0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003ca20:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003c700:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003ca30:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003c710:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003ca40:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003ca50:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003ca60:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
0003c720:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003c730:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003c740:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003c750:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003c760:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003c770:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003c780:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003c790:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003c7a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003c7b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003c7c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003c7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003c7e0:·3835·3234·2220·7461·6269·6e64·6578·3d22··8524"·tabindex=" 
0003c7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003c800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003c810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003c820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
Max diff block lines reached; 598061/612717 bytes (97.61%) of diff not shown.
57.5 KB
html2text {}
    
Offset 100, 20 lines modifiedOffset 100, 14 lines modified
100 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,100 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
101 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule101 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
102 Remediation_OSBuild_Blueprint_snippet_⇲102 Remediation_OSBuild_Blueprint_snippet_⇲
  
103 [[packages]]103 [[packages]]
104 name·=·"aide"104 name·=·"aide"
105 version·=·"*"105 version·=·"*"
106 Remediation_Anaconda_snippet_⇲ 
107 Complexity:·low 
108 Disruption:·low 
109 Strategy:···enable 
  
110 package·--add=aide 
111 Remediation_Puppet_snippet_⇲106 Remediation_Puppet_snippet_⇲
112 Complexity:·low107 Complexity:·low
113 Disruption:·low108 Disruption:·low
114 Strategy:···enable109 Strategy:···enable
115 include·install_aide110 include·install_aide
  
116 class·install_aide·{111 class·install_aide·{
Offset 131, 14 lines modifiedOffset 125, 20 lines modified
131 if·!·rpm·-q·--quiet·"aide"·;·then125 if·!·rpm·-q·--quiet·"aide"·;·then
132 ····yum·install·-y·"aide"126 ····yum·install·-y·"aide"
133 fi127 fi
  
134 else128 else
135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'129 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
136 fi130 fi
 131 Remediation_Anaconda_snippet_⇲
 132 Complexity:·low
 133 Disruption:·low
 134 Strategy:···enable
  
 135 package·--add=aide
137 Remediation_Ansible_snippet_⇲136 Remediation_Ansible_snippet_⇲
138 Complexity:·low137 Complexity:·low
139 Disruption:·low138 Disruption:·low
140 Strategy:···enable139 Strategy:···enable
141 -·name:·Ensure·aide·is·installed140 -·name:·Ensure·aide·is·installed
142 ··package:141 ··package:
143 ····name:·aide142 ····name:·aide
Offset 460, 20 lines modifiedOffset 460, 14 lines modified
460 Identifiers·and·References·Identifiers: ·CCE-82214-8460 Identifiers·and·References·Identifiers: ·CCE-82214-8
461 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1461 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
462 Remediation_OSBuild_Blueprint_snippet_⇲462 Remediation_OSBuild_Blueprint_snippet_⇲
  
463 [[packages]]463 [[packages]]
464 name·=·"sudo"464 name·=·"sudo"
465 version·=·"*"465 version·=·"*"
466 Remediation_Anaconda_snippet_⇲ 
467 Complexity:·low 
468 Disruption:·low 
469 Strategy:···enable 
  
470 package·--add=sudo 
471 Remediation_Puppet_snippet_⇲466 Remediation_Puppet_snippet_⇲
472 Complexity:·low467 Complexity:·low
473 Disruption:·low468 Disruption:·low
474 Strategy:···enable469 Strategy:···enable
475 include·install_sudo470 include·install_sudo
  
476 class·install_sudo·{471 class·install_sudo·{
Offset 491, 14 lines modifiedOffset 485, 20 lines modified
491 if·!·rpm·-q·--quiet·"sudo"·;·then485 if·!·rpm·-q·--quiet·"sudo"·;·then
492 ····yum·install·-y·"sudo"486 ····yum·install·-y·"sudo"
493 fi487 fi
  
494 else488 else
495 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'489 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
496 fi490 fi
 491 Remediation_Anaconda_snippet_⇲
 492 Complexity:·low
 493 Disruption:·low
 494 Strategy:···enable
  
 495 package·--add=sudo
497 Remediation_Ansible_snippet_⇲496 Remediation_Ansible_snippet_⇲
498 Complexity:·low497 Complexity:·low
499 Disruption:·low498 Disruption:·low
500 Strategy:···enable499 Strategy:···enable
501 -·name:·Ensure·sudo·is·installed500 -·name:·Ensure·sudo·is·installed
502 ··package:501 ··package:
503 ····name:·sudo502 ····name:·sudo
Offset 1120, 20 lines modifiedOffset 1120, 14 lines modified
1120 Identifiers·and·References·Identifiers: ·CCE-82985-31120 Identifiers·and·References·Identifiers: ·CCE-82985-3
1121 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-000801121 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1122 Remediation_OSBuild_Blueprint_snippet_⇲1122 Remediation_OSBuild_Blueprint_snippet_⇲
  
1123 [[packages]]1123 [[packages]]
1124 name·=·"dnf-automatic"1124 name·=·"dnf-automatic"
1125 version·=·"*"1125 version·=·"*"
1126 Remediation_Anaconda_snippet_⇲ 
1127 Complexity:·low 
1128 Disruption:·low 
1129 Strategy:···enable 
  
1130 package·--add=dnf-automatic 
1131 Remediation_Puppet_snippet_⇲1126 Remediation_Puppet_snippet_⇲
1132 Complexity:·low1127 Complexity:·low
1133 Disruption:·low1128 Disruption:·low
1134 Strategy:···enable1129 Strategy:···enable
1135 include·install_dnf-automatic1130 include·install_dnf-automatic
  
1136 class·install_dnf-automatic·{1131 class·install_dnf-automatic·{
Offset 1145, 14 lines modifiedOffset 1139, 20 lines modified
1145 Complexity:·low1139 Complexity:·low
1146 Disruption:·low1140 Disruption:·low
1147 Strategy:···enable1141 Strategy:···enable
  
1148 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1142 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1149 ····yum·install·-y·"dnf-automatic"1143 ····yum·install·-y·"dnf-automatic"
1150 fi1144 fi
 1145 Remediation_Anaconda_snippet_⇲
 1146 Complexity:·low
 1147 Disruption:·low
 1148 Strategy:···enable
  
 1149 package·--add=dnf-automatic
1151 Remediation_Ansible_snippet_⇲1150 Remediation_Ansible_snippet_⇲
1152 Complexity:·low1151 Complexity:·low
1153 Disruption:·low1152 Disruption:·low
1154 Strategy:···enable1153 Strategy:···enable
1155 -·name:·Ensure·dnf-automatic·is·installed1154 -·name:·Ensure·dnf-automatic·is·installed
1156 ··package:1155 ··package:
1157 ····name:·dnf-automatic1156 ····name:·dnf-automatic
Offset 8156, 15 lines modifiedOffset 8156, 15 lines modified
8156 Severity: ·medium8156 Severity: ·medium
Max diff block lines reached; 55295/58861 bytes (93.94%) of diff not shown.
713 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_high.html
    
Offset 15418, 116 lines modifiedOffset 15418, 116 lines modified
0003c390:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003c390:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003c3a0:·6d38·3532·3222·2074·6162·696e·6465·783d··m8522"·tabindex=0003c3a0:·6d38·3532·3222·2074·6162·696e·6465·783d··m8522"·tabindex=
0003c3b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003c3b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003c3c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003c3c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003c3d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003c3d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003c3e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003c3e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003c3f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003c3f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003c400:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003c400:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003c410:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003c410:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003c420:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003c420:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003c430:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003c430:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003c440:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003c440:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003c450:·6d38·3532·3222·3e3c·7461·626c·6520·636c··m8522"><table·cl0003c450:·3532·3222·3e3c·7461·626c·6520·636c·6173··522"><table·clas
0003c460:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003c460:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003c470:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003c470:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003c480:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003c480:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003c490:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003c490:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003c4a0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003c4a0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003c4b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c4b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c4c0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003c4c0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c4d0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c4d0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003c4e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c4e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c4f0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003c4f0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c500:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003c500:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003c510:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003c510:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003c520:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
0003c530:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co0003c520:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003c530:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003c540:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003c550:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003c560:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003c570:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003c580:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003c590:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003c5a0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003c5b0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003c5c0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003c5d0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
 0003c5e0:·3532·3322·2074·6162·696e·6465·783d·2230··523"·tabindex="0
 0003c5f0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003c600:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003c610:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003c620:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003c630:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003c640:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 0003c650:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003c660:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003c670:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003c680:·7365·2220·6964·3d22·6964·6d38·3532·3322··se"·id="idm8523"
 0003c690:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003c6a0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003c6b0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003c6c0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003c6d0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003c6e0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003c6f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003c700:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003c710:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003c720:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003c730:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003c740:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003c750:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c760:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 0003c770:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 0003c780:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 0003c790:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-
 0003c7a0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·
 0003c7b0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-
 0003c7c0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe
 0003c7d0:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if
 0003c7e0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003c7f0:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 0003c800:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install·
 0003c810:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 0003c820:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003c830:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003c840:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003c850:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003c860:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
0003c540:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003c870:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003c550:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003c880:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003c560:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003c890:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003c570:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003c8a0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003c580:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003c8b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003c590:·646d·3835·3233·2220·7461·6269·6e64·6578··dm8523"·tabindex0003c8c0:·646d·3835·3234·2220·7461·6269·6e64·6578··dm8524"·tabindex
0003c5a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003c8d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003c5b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003c8e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003c5c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003c8f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003c5d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003c900:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003c5e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003c910:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003c5f0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003c920:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003c600:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003c930:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003c610:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003c940:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003c620:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003c950:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003c630:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003c960:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003c640:·3835·3233·223e·3c74·6162·6c65·2063·6c61··8523"><table·cla0003c970:·646d·3835·3234·223e·3c74·6162·6c65·2063··dm8524"><table·c
0003c650:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003c980:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003c660:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003c990:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003c670:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003c9a0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003c680:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003c9b0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003c690:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003c9c0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003c6a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c9d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c6b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003c9e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003c6c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003c9f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003c6d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ca00:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c6e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003ca10:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003c6f0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003ca20:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003c700:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003ca30:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003ca40:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003ca50:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
0003c710:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003c720:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003c730:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003c740:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003c750:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003c760:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003c770:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003c780:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003c790:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003c7a0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003c7b0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003c7c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003c7d0:·3835·3234·2220·7461·6269·6e64·6578·3d22··8524"·tabindex=" 
0003c7e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003c7f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003c800:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003c810:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
Max diff block lines reached; 652178/666834 bytes (97.80%) of diff not shown.
61.7 KB
html2text {}
    
Offset 100, 20 lines modifiedOffset 100, 14 lines modified
100 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,100 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
101 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule101 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
102 Remediation_OSBuild_Blueprint_snippet_⇲102 Remediation_OSBuild_Blueprint_snippet_⇲
  
103 [[packages]]103 [[packages]]
104 name·=·"aide"104 name·=·"aide"
105 version·=·"*"105 version·=·"*"
106 Remediation_Anaconda_snippet_⇲ 
107 Complexity:·low 
108 Disruption:·low 
109 Strategy:···enable 
  
110 package·--add=aide 
111 Remediation_Puppet_snippet_⇲106 Remediation_Puppet_snippet_⇲
112 Complexity:·low107 Complexity:·low
113 Disruption:·low108 Disruption:·low
114 Strategy:···enable109 Strategy:···enable
115 include·install_aide110 include·install_aide
  
116 class·install_aide·{111 class·install_aide·{
Offset 131, 14 lines modifiedOffset 125, 20 lines modified
131 if·!·rpm·-q·--quiet·"aide"·;·then125 if·!·rpm·-q·--quiet·"aide"·;·then
132 ····yum·install·-y·"aide"126 ····yum·install·-y·"aide"
133 fi127 fi
  
134 else128 else
135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'129 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
136 fi130 fi
 131 Remediation_Anaconda_snippet_⇲
 132 Complexity:·low
 133 Disruption:·low
 134 Strategy:···enable
  
 135 package·--add=aide
137 Remediation_Ansible_snippet_⇲136 Remediation_Ansible_snippet_⇲
138 Complexity:·low137 Complexity:·low
139 Disruption:·low138 Disruption:·low
140 Strategy:···enable139 Strategy:···enable
141 -·name:·Ensure·aide·is·installed140 -·name:·Ensure·aide·is·installed
142 ··package:141 ··package:
143 ····name:·aide142 ····name:·aide
Offset 773, 20 lines modifiedOffset 773, 14 lines modified
773 Identifiers·and·References·Identifiers: ·CCE-82214-8773 Identifiers·and·References·Identifiers: ·CCE-82214-8
774 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1774 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
775 Remediation_OSBuild_Blueprint_snippet_⇲775 Remediation_OSBuild_Blueprint_snippet_⇲
  
776 [[packages]]776 [[packages]]
777 name·=·"sudo"777 name·=·"sudo"
778 version·=·"*"778 version·=·"*"
779 Remediation_Anaconda_snippet_⇲ 
780 Complexity:·low 
781 Disruption:·low 
782 Strategy:···enable 
  
783 package·--add=sudo 
784 Remediation_Puppet_snippet_⇲779 Remediation_Puppet_snippet_⇲
785 Complexity:·low780 Complexity:·low
786 Disruption:·low781 Disruption:·low
787 Strategy:···enable782 Strategy:···enable
788 include·install_sudo783 include·install_sudo
  
789 class·install_sudo·{784 class·install_sudo·{
Offset 804, 14 lines modifiedOffset 798, 20 lines modified
804 if·!·rpm·-q·--quiet·"sudo"·;·then798 if·!·rpm·-q·--quiet·"sudo"·;·then
805 ····yum·install·-y·"sudo"799 ····yum·install·-y·"sudo"
806 fi800 fi
  
807 else801 else
808 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'802 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
809 fi803 fi
 804 Remediation_Anaconda_snippet_⇲
 805 Complexity:·low
 806 Disruption:·low
 807 Strategy:···enable
  
 808 package·--add=sudo
810 Remediation_Ansible_snippet_⇲809 Remediation_Ansible_snippet_⇲
811 Complexity:·low810 Complexity:·low
812 Disruption:·low811 Disruption:·low
813 Strategy:···enable812 Strategy:···enable
814 -·name:·Ensure·sudo·is·installed813 -·name:·Ensure·sudo·is·installed
815 ··package:814 ··package:
816 ····name:·sudo815 ····name:·sudo
Offset 1433, 20 lines modifiedOffset 1433, 14 lines modified
1433 Identifiers·and·References·Identifiers: ·CCE-82985-31433 Identifiers·and·References·Identifiers: ·CCE-82985-3
1434 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-000801434 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1435 Remediation_OSBuild_Blueprint_snippet_⇲1435 Remediation_OSBuild_Blueprint_snippet_⇲
  
1436 [[packages]]1436 [[packages]]
1437 name·=·"dnf-automatic"1437 name·=·"dnf-automatic"
1438 version·=·"*"1438 version·=·"*"
1439 Remediation_Anaconda_snippet_⇲ 
1440 Complexity:·low 
1441 Disruption:·low 
1442 Strategy:···enable 
  
1443 package·--add=dnf-automatic 
1444 Remediation_Puppet_snippet_⇲1439 Remediation_Puppet_snippet_⇲
1445 Complexity:·low1440 Complexity:·low
1446 Disruption:·low1441 Disruption:·low
1447 Strategy:···enable1442 Strategy:···enable
1448 include·install_dnf-automatic1443 include·install_dnf-automatic
  
1449 class·install_dnf-automatic·{1444 class·install_dnf-automatic·{
Offset 1458, 14 lines modifiedOffset 1452, 20 lines modified
1458 Complexity:·low1452 Complexity:·low
1459 Disruption:·low1453 Disruption:·low
1460 Strategy:···enable1454 Strategy:···enable
  
1461 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1455 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1462 ····yum·install·-y·"dnf-automatic"1456 ····yum·install·-y·"dnf-automatic"
1463 fi1457 fi
 1458 Remediation_Anaconda_snippet_⇲
 1459 Complexity:·low
 1460 Disruption:·low
 1461 Strategy:···enable
  
 1462 package·--add=dnf-automatic
1464 Remediation_Ansible_snippet_⇲1463 Remediation_Ansible_snippet_⇲
1465 Complexity:·low1464 Complexity:·low
1466 Disruption:·low1465 Disruption:·low
1467 Strategy:···enable1466 Strategy:···enable
1468 -·name:·Ensure·dnf-automatic·is·installed1467 -·name:·Ensure·dnf-automatic·is·installed
1469 ··package:1468 ··package:
1470 ····name:·dnf-automatic1469 ····name:·dnf-automatic
Offset 8469, 15 lines modifiedOffset 8469, 15 lines modified
8469 Severity: ·medium8469 Severity: ·medium
Max diff block lines reached; 59565/63131 bytes (94.35%) of diff not shown.
656 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_intermediary.html
    
Offset 15413, 117 lines modifiedOffset 15413, 117 lines modified
0003c340:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003c340:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c350:·743d·2223·6964·6d38·3532·3222·2074·6162··t="#idm8522"·tab0003c350:·743d·2223·6964·6d38·3532·3222·2074·6162··t="#idm8522"·tab
0003c360:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003c360:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c370:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003c370:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c380:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003c380:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c390:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003c390:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c3a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003c3a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c3b0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003c3b0:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
0003c3c0:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·0003c3c0:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
0003c3d0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003c3d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003c3e0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003c3e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003c3f0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003c3f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003c400:·6964·3d22·6964·6d38·3532·3222·3e3c·7461··id="idm8522"><ta0003c400:·3d22·6964·6d38·3532·3222·3e3c·7461·626c··="idm8522"><tabl
0003c410:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003c410:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003c420:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003c420:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003c430:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003c430:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003c440:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003c440:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003c450:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003c450:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003c460:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003c460:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c470:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c470:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003c480:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003c480:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003c490:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c490:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c4a0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003c4a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003c4b0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003c4b0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003c4c0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003c4c0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003c4d0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p0003c4d0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
0003c4e0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid0003c4e0:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide
 0003c4f0:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 0003c500:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package
 0003c510:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e
 0003c520:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003c530:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003c540:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003c550:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003c560:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003c570:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003c580:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003c590:·2223·6964·6d38·3532·3322·2074·6162·696e··"#idm8523"·tabin
 0003c5a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003c5b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003c5c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003c5d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003c5e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003c5f0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003c600:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003c610:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003c620:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003c630:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003c640:·6d38·3532·3322·3e3c·7461·626c·6520·636c··m8523"><table·cl
 0003c650:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003c660:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003c670:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003c680:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003c690:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003c6a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003c6b0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003c6c0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003c6d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003c6e0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003c6f0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003c700:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c710:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003c720:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003c730:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003c740:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003c750:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
 0003c760:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 0003c770:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
 0003c780:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th
 0003c790:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003c7a0:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003c7b0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003c7c0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003c7d0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003c7e0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003c7f0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003c800:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003c810:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
0003c4f0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><0003c820:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
0003c500:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003c830:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003c510:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003c840:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003c520:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003c850:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003c530:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003c860:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003c540:·6574·3d22·2369·646d·3835·3233·2220·7461··et="#idm8523"·ta0003c870:·6574·3d22·2369·646d·3835·3234·2220·7461··et="#idm8524"·ta
0003c550:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c880:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c560:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c890:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c570:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c8a0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c580:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c8b0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c590:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c8c0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c5a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c8d0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c5b0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.0003c8e0:·416e·6163·6f6e·6461·2073·6e69·7070·6574··Anaconda·snippet
0003c5c0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c8f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c5d0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c900:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c5e0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c910:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c5f0:·643d·2269·646d·3835·3233·223e·3c74·6162··d="idm8523"><tab0003c920:·2069·643d·2269·646d·3835·3234·223e·3c74···id="idm8524"><t
0003c600:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c930:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c610:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c940:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c620:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c950:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c630:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c960:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c640:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c970:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c650:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c980:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003c660:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c990:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c670:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c9a0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003c680:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c9b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c690:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c9c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003c6a0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003c9d0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003c6b0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003c9e0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003c6c0:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc0003c9f0:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003ca00:·7061·636b·6167·6520·2d2d·6164·643d·6169··package·--add=ai
0003c6d0:·6c75·6465·2069·6e73·7461·6c6c·5f61·6964··lude·install_aid 
0003c6e0:·650a·0a63·6c61·7373·2069·6e73·7461·6c6c··e..class·install 
0003c6f0:·5f61·6964·6520·7b0a·2020·7061·636b·6167··_aide·{.··packag 
0003c700:·6520·7b20·2761·6964·6527·3a0a·2020·2020··e·{·'aide':.···· 
0003c710:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in 
0003c720:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}. 
0003c730:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003c740:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003c750:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003c760:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003c770:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003c780:·3d22·2369·646d·3835·3234·2220·7461·6269··="#idm8524"·tabi 
0003c790:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003c7a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003c7b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003c7c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003c7d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003c7e0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
Max diff block lines reached; 598260/613054 bytes (97.59%) of diff not shown.
57.5 KB
html2text {}
    
Offset 99, 20 lines modifiedOffset 99, 14 lines modified
99 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,99 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
100 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule100 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
101 Remediation_OSBuild_Blueprint_snippet_⇲101 Remediation_OSBuild_Blueprint_snippet_⇲
  
102 [[packages]]102 [[packages]]
103 name·=·"aide"103 name·=·"aide"
104 version·=·"*"104 version·=·"*"
105 Remediation_Anaconda_snippet_⇲ 
106 Complexity:·low 
107 Disruption:·low 
108 Strategy:···enable 
  
109 package·--add=aide 
110 Remediation_Puppet_snippet_⇲105 Remediation_Puppet_snippet_⇲
111 Complexity:·low106 Complexity:·low
112 Disruption:·low107 Disruption:·low
113 Strategy:···enable108 Strategy:···enable
114 include·install_aide109 include·install_aide
  
115 class·install_aide·{110 class·install_aide·{
Offset 130, 14 lines modifiedOffset 124, 20 lines modified
130 if·!·rpm·-q·--quiet·"aide"·;·then124 if·!·rpm·-q·--quiet·"aide"·;·then
131 ····yum·install·-y·"aide"125 ····yum·install·-y·"aide"
132 fi126 fi
  
133 else127 else
134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
135 fi129 fi
 130 Remediation_Anaconda_snippet_⇲
 131 Complexity:·low
 132 Disruption:·low
 133 Strategy:···enable
  
 134 package·--add=aide
136 Remediation_Ansible_snippet_⇲135 Remediation_Ansible_snippet_⇲
137 Complexity:·low136 Complexity:·low
138 Disruption:·low137 Disruption:·low
139 Strategy:···enable138 Strategy:···enable
140 -·name:·Ensure·aide·is·installed139 -·name:·Ensure·aide·is·installed
141 ··package:140 ··package:
142 ····name:·aide141 ····name:·aide
Offset 459, 20 lines modifiedOffset 459, 14 lines modified
459 Identifiers·and·References·Identifiers: ·CCE-82214-8459 Identifiers·and·References·Identifiers: ·CCE-82214-8
460 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1460 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
461 Remediation_OSBuild_Blueprint_snippet_⇲461 Remediation_OSBuild_Blueprint_snippet_⇲
  
462 [[packages]]462 [[packages]]
463 name·=·"sudo"463 name·=·"sudo"
464 version·=·"*"464 version·=·"*"
465 Remediation_Anaconda_snippet_⇲ 
466 Complexity:·low 
467 Disruption:·low 
468 Strategy:···enable 
  
469 package·--add=sudo 
470 Remediation_Puppet_snippet_⇲465 Remediation_Puppet_snippet_⇲
471 Complexity:·low466 Complexity:·low
472 Disruption:·low467 Disruption:·low
473 Strategy:···enable468 Strategy:···enable
474 include·install_sudo469 include·install_sudo
  
475 class·install_sudo·{470 class·install_sudo·{
Offset 490, 14 lines modifiedOffset 484, 20 lines modified
490 if·!·rpm·-q·--quiet·"sudo"·;·then484 if·!·rpm·-q·--quiet·"sudo"·;·then
491 ····yum·install·-y·"sudo"485 ····yum·install·-y·"sudo"
492 fi486 fi
  
493 else487 else
494 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'488 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
495 fi489 fi
 490 Remediation_Anaconda_snippet_⇲
 491 Complexity:·low
 492 Disruption:·low
 493 Strategy:···enable
  
 494 package·--add=sudo
496 Remediation_Ansible_snippet_⇲495 Remediation_Ansible_snippet_⇲
497 Complexity:·low496 Complexity:·low
498 Disruption:·low497 Disruption:·low
499 Strategy:···enable498 Strategy:···enable
500 -·name:·Ensure·sudo·is·installed499 -·name:·Ensure·sudo·is·installed
501 ··package:500 ··package:
502 ····name:·sudo501 ····name:·sudo
Offset 1119, 20 lines modifiedOffset 1119, 14 lines modified
1119 Identifiers·and·References·Identifiers: ·CCE-82985-31119 Identifiers·and·References·Identifiers: ·CCE-82985-3
1120 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-000801120 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1121 Remediation_OSBuild_Blueprint_snippet_⇲1121 Remediation_OSBuild_Blueprint_snippet_⇲
  
1122 [[packages]]1122 [[packages]]
1123 name·=·"dnf-automatic"1123 name·=·"dnf-automatic"
1124 version·=·"*"1124 version·=·"*"
1125 Remediation_Anaconda_snippet_⇲ 
1126 Complexity:·low 
1127 Disruption:·low 
1128 Strategy:···enable 
  
1129 package·--add=dnf-automatic 
1130 Remediation_Puppet_snippet_⇲1125 Remediation_Puppet_snippet_⇲
1131 Complexity:·low1126 Complexity:·low
1132 Disruption:·low1127 Disruption:·low
1133 Strategy:···enable1128 Strategy:···enable
1134 include·install_dnf-automatic1129 include·install_dnf-automatic
  
1135 class·install_dnf-automatic·{1130 class·install_dnf-automatic·{
Offset 1144, 14 lines modifiedOffset 1138, 20 lines modified
1144 Complexity:·low1138 Complexity:·low
1145 Disruption:·low1139 Disruption:·low
1146 Strategy:···enable1140 Strategy:···enable
  
1147 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1141 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1148 ····yum·install·-y·"dnf-automatic"1142 ····yum·install·-y·"dnf-automatic"
1149 fi1143 fi
 1144 Remediation_Anaconda_snippet_⇲
 1145 Complexity:·low
 1146 Disruption:·low
 1147 Strategy:···enable
  
 1148 package·--add=dnf-automatic
1150 Remediation_Ansible_snippet_⇲1149 Remediation_Ansible_snippet_⇲
1151 Complexity:·low1150 Complexity:·low
1152 Disruption:·low1151 Disruption:·low
1153 Strategy:···enable1152 Strategy:···enable
1154 -·name:·Ensure·dnf-automatic·is·installed1153 -·name:·Ensure·dnf-automatic·is·installed
1155 ··package:1154 ··package:
1156 ····name:·dnf-automatic1155 ····name:·dnf-automatic
Offset 7727, 15 lines modifiedOffset 7727, 15 lines modified
7727 Severity: ·medium7727 Severity: ·medium
Max diff block lines reached; 55295/58859 bytes (93.94%) of diff not shown.
245 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_minimal.html
    
Offset 16164, 107 lines modifiedOffset 16164, 107 lines modified
0003f230:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm130003f230:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm13
0003f240:·3734·3422·2074·6162·696e·6465·783d·2230··744"·tabindex="00003f240:·3734·3422·2074·6162·696e·6465·783d·2230··744"·tabindex="0
0003f250:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003f250:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003f260:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003f260:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003f270:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003f270:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003f280:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003f280:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003f290:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003f290:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003f2a0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003f2a0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003f2b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003f2b0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003f2c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003f2c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003f2d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003f2d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003f2e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10003f2e0:·6170·7365·2220·6964·3d22·6964·6d31·3337··apse"·id="idm137
0003f2f0:·3337·3434·223e·3c74·6162·6c65·2063·6c61··3744"><table·cla0003f2f0:·3434·223e·3c74·6162·6c65·2063·6c61·7373··44"><table·class
0003f300:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003f300:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003f310:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003f310:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003f320:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003f320:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003f330:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003f330:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003f340:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003f340:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003f350:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003f360:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003f370:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003f380:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003f390:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003f3a0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003f3b0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003f3c0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003f3d0:·7461·6c6c·5f64·6e66·2d61·7574·6f6d·6174··tall_dnf-automat
 0003f3e0:·6963·0a0a·636c·6173·7320·696e·7374·616c··ic..class·instal
 0003f3f0:·6c5f·646e·662d·6175·746f·6d61·7469·6320··l_dnf-automatic·
 0003f400:·7b0a·2020·7061·636b·6167·6520·7b20·2764··{.··package·{·'d
 0003f410:·6e66·2d61·7574·6f6d·6174·6963·273a·0a20··nf-automatic':.·
 0003f420:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003f430:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003f440:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003f450:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003f460:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003f470:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003f480:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003f490:·6765·743d·2223·6964·6d31·3337·3435·2220··get="#idm13745"·
 0003f4a0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003f4b0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003f4c0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003f4d0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003f4e0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003f4f0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003f500:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0003f510:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003f520:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003f530:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003f540:·643d·2269·646d·3133·3734·3522·3e3c·7461··d="idm13745"><ta
 0003f550:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003f560:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003f570:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003f580:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003f590:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003f5a0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003f5b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003f5c0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003f350:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003f5d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003f360:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003f370:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003f380:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003f390:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003f3a0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003f3b0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003f3c0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003f3d0:·2d2d·6164·643d·646e·662d·6175·746f·6d61··--add=dnf-automa0003f5e0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003f5f0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003f600:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003f610:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a69··le><pre><code>.i
 0003f620:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 0003f630:·6574·2022·646e·662d·6175·746f·6d61·7469··et·"dnf-automati
 0003f640:·6322·203b·2074·6865·6e0a·2020·2020·7975··c"·;·then.····yu
 0003f650:·6d20·696e·7374·616c·6c20·2d79·2022·646e··m·install·-y·"dn
 0003f660:·662d·6175·746f·6d61·7469·6322·0a66·690a··f-automatic".fi.
0003f3e0:·7469·630a·3c2f·636f·6465·3e3c·2f70·7265··tic.</code></pre0003f670:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003f3f0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003f680:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003f400:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003f690:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003f410:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003f6a0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003f420:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003f6b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003f430:·7267·6574·3d22·2369·646d·3133·3734·3522··rget="#idm13745"0003f6c0:·3d22·2369·646d·3133·3734·3622·2074·6162··="#idm13746"·tab
0003f440:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003f6d0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003f450:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003f6e0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003f460:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003f6f0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003f470:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003f700:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003f480:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003f710:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003f490:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003f720:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003f4a0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003f730:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003f4b0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003f740:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003f4c0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003f750:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003f4d0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003f760:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003f4e0:·2220·6964·3d22·6964·6d31·3337·3435·223e··"·id="idm13745">0003f770:·6964·3d22·6964·6d31·3337·3436·223e·3c74··id="idm13746"><t
0003f4f0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003f780:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003f500:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003f790:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003f510:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003f7a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003f520:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003f7b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003f530:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003f7c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003f540:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003f7d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003f550:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003f7e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003f560:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003f7f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003f570:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003f800:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003f580:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003f810:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003f590:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003f820:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003f5a0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003f830:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003f5b0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003f840:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003f850:·7061·636b·6167·6520·2d2d·6164·643d·646e··package·--add=dn
0003f5c0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003f5d0:·5f64·6e66·2d61·7574·6f6d·6174·6963·0a0a··_dnf-automatic.. 
0003f5e0:·636c·6173·7320·696e·7374·616c·6c5f·646e··class·install_dn 
0003f5f0:·662d·6175·746f·6d61·7469·6320·7b0a·2020··f-automatic·{.··0003f860:·662d·6175·746f·6d61·7469·630a·3c2f·636f··f-automatic.</co
0003f600:·7061·636b·6167·6520·7b20·2764·6e66·2d61··package·{·'dnf-a 
0003f610:·7574·6f6d·6174·6963·273a·0a20·2020·2065··utomatic':.····e 
0003f620:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003f630:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003f640:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003f650:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003f660:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003f670:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003f680:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003f690:·2223·6964·6d31·3337·3436·2220·7461·6269··"#idm13746"·tabi 
0003f6a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003f6b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003f6c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003f6d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003f6e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003f6f0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003f700:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
Max diff block lines reached; 219398/232812 bytes (94.24%) of diff not shown.
17.4 KB
html2text {}
    
Offset 265, 20 lines modifiedOffset 265, 14 lines modified
265 Identifiers·and·References·Identifiers: ·CCE-82985-3265 Identifiers·and·References·Identifiers: ·CCE-82985-3
266 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080266 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
267 Remediation_OSBuild_Blueprint_snippet_⇲267 Remediation_OSBuild_Blueprint_snippet_⇲
  
268 [[packages]]268 [[packages]]
269 name·=·"dnf-automatic"269 name·=·"dnf-automatic"
270 version·=·"*"270 version·=·"*"
271 Remediation_Anaconda_snippet_⇲ 
272 Complexity:·low 
273 Disruption:·low 
274 Strategy:···enable 
  
275 package·--add=dnf-automatic 
276 Remediation_Puppet_snippet_⇲271 Remediation_Puppet_snippet_⇲
277 Complexity:·low272 Complexity:·low
278 Disruption:·low273 Disruption:·low
279 Strategy:···enable274 Strategy:···enable
280 include·install_dnf-automatic275 include·install_dnf-automatic
  
281 class·install_dnf-automatic·{276 class·install_dnf-automatic·{
Offset 290, 14 lines modifiedOffset 284, 20 lines modified
290 Complexity:·low284 Complexity:·low
291 Disruption:·low285 Disruption:·low
292 Strategy:···enable286 Strategy:···enable
  
293 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then287 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
294 ····yum·install·-y·"dnf-automatic"288 ····yum·install·-y·"dnf-automatic"
295 fi289 fi
 290 Remediation_Anaconda_snippet_⇲
 291 Complexity:·low
 292 Disruption:·low
 293 Strategy:···enable
  
 294 package·--add=dnf-automatic
296 Remediation_Ansible_snippet_⇲295 Remediation_Ansible_snippet_⇲
297 Complexity:·low296 Complexity:·low
298 Disruption:·low297 Disruption:·low
299 Strategy:···enable298 Strategy:···enable
300 -·name:·Ensure·dnf-automatic·is·installed299 -·name:·Ensure·dnf-automatic·is·installed
301 ··package:300 ··package:
302 ····name:·dnf-automatic301 ····name:·dnf-automatic
Offset 7061, 20 lines modifiedOffset 7061, 14 lines modified
7061 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-7061 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
7062 ············00227,·RHEL-08-030670,·4.2.1.1,·SV-230477r627750_rule7062 ············00227,·RHEL-08-030670,·4.2.1.1,·SV-230477r627750_rule
7063 Remediation_OSBuild_Blueprint_snippet_⇲7063 Remediation_OSBuild_Blueprint_snippet_⇲
  
7064 [[packages]]7064 [[packages]]
7065 name·=·"rsyslog"7065 name·=·"rsyslog"
7066 version·=·"*"7066 version·=·"*"
7067 Remediation_Anaconda_snippet_⇲ 
7068 Complexity:·low 
7069 Disruption:·low 
7070 Strategy:···enable 
  
7071 package·--add=rsyslog 
7072 Remediation_Puppet_snippet_⇲7067 Remediation_Puppet_snippet_⇲
7073 Complexity:·low7068 Complexity:·low
7074 Disruption:·low7069 Disruption:·low
7075 Strategy:···enable7070 Strategy:···enable
7076 include·install_rsyslog7071 include·install_rsyslog
  
7077 class·install_rsyslog·{7072 class·install_rsyslog·{
Offset 7092, 14 lines modifiedOffset 7086, 20 lines modified
7092 if·!·rpm·-q·--quiet·"rsyslog"·;·then7086 if·!·rpm·-q·--quiet·"rsyslog"·;·then
7093 ····yum·install·-y·"rsyslog"7087 ····yum·install·-y·"rsyslog"
7094 fi7088 fi
  
7095 else7089 else
7096 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7090 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7097 fi7091 fi
 7092 Remediation_Anaconda_snippet_⇲
 7093 Complexity:·low
 7094 Disruption:·low
 7095 Strategy:···enable
  
 7096 package·--add=rsyslog
7098 Remediation_Ansible_snippet_⇲7097 Remediation_Ansible_snippet_⇲
7099 Complexity:·low7098 Complexity:·low
7100 Disruption:·low7099 Disruption:·low
7101 Strategy:···enable7100 Strategy:···enable
7102 -·name:·Ensure·rsyslog·is·installed7101 -·name:·Ensure·rsyslog·is·installed
7103 ··package:7102 ··package:
7104 ····name:·rsyslog7103 ····name:·rsyslog
Offset 7292, 20 lines modifiedOffset 7292, 14 lines modified
7292 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,7292 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,
7293 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7293 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
7294 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,7294 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
7295 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR7295 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
7296 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR7296 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
7297 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,7297 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
7298 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-37298 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3
7299 Remediation_Anaconda_snippet_⇲ 
7300 Complexity:·low 
7301 Disruption:·low 
7302 Strategy:···disable 
  
7303 package·--remove=dhcp-server 
7304 Remediation_Puppet_snippet_⇲7299 Remediation_Puppet_snippet_⇲
7305 Complexity:·low7300 Complexity:·low
7306 Disruption:·low7301 Disruption:·low
7307 Strategy:···disable7302 Strategy:···disable
7308 include·remove_dhcp-server7303 include·remove_dhcp-server
  
7309 class·remove_dhcp-server·{7304 class·remove_dhcp-server·{
Offset 7325, 14 lines modifiedOffset 7319, 20 lines modified
7325 #»      ···system!7319 #»      ···system!
  
7326 if·rpm·-q·--quiet·"dhcp-server"·;·then7320 if·rpm·-q·--quiet·"dhcp-server"·;·then
  
7327 ····yum·remove·-y·"dhcp-server"7321 ····yum·remove·-y·"dhcp-server"
  
7328 fi7322 fi
 7323 Remediation_Anaconda_snippet_⇲
 7324 Complexity:·low
 7325 Disruption:·low
 7326 Strategy:···disable
  
 7327 package·--remove=dhcp-server
7329 Remediation_Ansible_snippet_⇲7328 Remediation_Ansible_snippet_⇲
7330 Complexity:·low7329 Complexity:·low
7331 Disruption:·low7330 Disruption:·low
7332 Strategy:···disable7331 Strategy:···disable
7333 -·name:·Ensure·dhcp-server·is·removed7332 -·name:·Ensure·dhcp-server·is·removed
7334 ··package:7333 ··package:
7335 ····name:·dhcp-server7334 ····name:·dhcp-server
Offset 7381, 20 lines modifiedOffset 7381, 14 lines modified
7381 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7381 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
Max diff block lines reached; 14344/17840 bytes (80.40%) of diff not shown.
1.74 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis.html
    
Offset 15459, 116 lines modifiedOffset 15459, 116 lines modified
0003c620:·7461·7267·6574·3d22·2369·646d·3835·3232··target="#idm85220003c620:·7461·7267·6574·3d22·2369·646d·3835·3232··target="#idm8522
0003c630:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003c630:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c640:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003c640:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c650:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003c650:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c660:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003c660:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c670:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003c670:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c680:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003c680:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003c690:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni0003c690:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
0003c6a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003c6a0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
0003c6b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003c6b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003c6c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003c6c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003c6d0:·7073·6522·2069·643d·2269·646d·3835·3232··pse"·id="idm85220003c6d0:·6522·2069·643d·2269·646d·3835·3232·223e··e"·id="idm8522">
0003c6e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003c6e0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003c6f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003c6f0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003c700:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003c700:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003c710:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003c710:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003c720:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003c720:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003c730:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003c730:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003c740:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c740:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003c750:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003c750:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003c760:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c760:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003c770:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003c770:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003c780:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003c780:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003c790:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003c790:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003c7a0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003c7a0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003c7b0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad0003c7b0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 0003c7c0:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins
 0003c7d0:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa
 0003c7e0:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':.
 0003c7f0:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 0003c800:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 0003c810:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 0003c820:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003c830:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003c840:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003c850:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003c860:·7267·6574·3d22·2369·646d·3835·3233·2220··rget="#idm8523"·
 0003c870:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003c880:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003c890:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003c8a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003c8b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003c8c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003c8d0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0003c8e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003c8f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003c900:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003c910:·643d·2269·646d·3835·3233·223e·3c74·6162··d="idm8523"><tab
 0003c920:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003c930:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003c940:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003c950:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003c960:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003c970:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c980:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003c990:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003c9a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003c9b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003c9c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003c9d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003c9e0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 0003c9f0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003ca00:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003ca10:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003ca20:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d
 0003ca30:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;
 0003ca40:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru
 0003ca50:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·
 0003ca60:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp
 0003ca70:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 0003ca80:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y
 0003ca90:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a
 0003caa0:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 0003cab0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003cac0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003cad0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003cae0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
0003c7c0:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></0003caf0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
0003c7d0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003cb00:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003c7e0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003cb10:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003c7f0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003cb20:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003c800:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003cb30:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003c810:·2d74·6172·6765·743d·2223·6964·6d38·3532··-target="#idm8520003cb40:·2d74·6172·6765·743d·2223·6964·6d38·3532··-target="#idm852
0003c820:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·0003cb50:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·
0003c830:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003cb60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003c840:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003cb70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003c850:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003cb80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003c860:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003cb90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003c870:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003cba0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003c880:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip0003cbb0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
0003c890:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003cbc0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003c8a0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003cbd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003c8b0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003cbe0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003c8c0:·7365·2220·6964·3d22·6964·6d38·3532·3322··se"·id="idm8523"0003cbf0:·6170·7365·2220·6964·3d22·6964·6d38·3532··apse"·id="idm852
0003c8d0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003cc00:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
0003c8e0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003cc10:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c8f0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003cc20:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c900:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003cc30:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c910:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003cc40:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c920:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003cc50:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c930:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003cc60:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c940:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003cc70:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c950:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003cc80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c960:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003cc90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c970:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003cca0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c980:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003ccb0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003c990:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003ccc0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003ccd0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 0003cce0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><
0003c9a0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
0003c9b0:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in 
0003c9c0:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p 
0003c9d0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide': 
0003c9e0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
0003c9f0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
0003ca00:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
0003ca10:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003ca20:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003ca30:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003ca40:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003ca50:·6172·6765·743d·2223·6964·6d38·3532·3422··arget="#idm8524" 
0003ca60:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003ca70:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003ca80:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003ca90:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003caa0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003cab0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
Max diff block lines reached; 1471460/1486116 bytes (99.01%) of diff not shown.
333 KB
html2text {}
    
Offset 105, 20 lines modifiedOffset 105, 14 lines modified
105 Identifiers·and·References·Identifiers: ·CCE-80844-4105 Identifiers·and·References·Identifiers: ·CCE-80844-4
106 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule106 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
107 Remediation_OSBuild_Blueprint_snippet_⇲107 Remediation_OSBuild_Blueprint_snippet_⇲
  
108 [[packages]]108 [[packages]]
109 name·=·"aide"109 name·=·"aide"
110 version·=·"*"110 version·=·"*"
111 Remediation_Anaconda_snippet_⇲ 
112 Complexity:·low 
113 Disruption:·low 
114 Strategy:···enable 
  
115 package·--add=aide 
116 Remediation_Puppet_snippet_⇲111 Remediation_Puppet_snippet_⇲
117 Complexity:·low112 Complexity:·low
118 Disruption:·low113 Disruption:·low
119 Strategy:···enable114 Strategy:···enable
120 include·install_aide115 include·install_aide
  
121 class·install_aide·{116 class·install_aide·{
Offset 136, 14 lines modifiedOffset 130, 20 lines modified
136 if·!·rpm·-q·--quiet·"aide"·;·then130 if·!·rpm·-q·--quiet·"aide"·;·then
137 ····yum·install·-y·"aide"131 ····yum·install·-y·"aide"
138 fi132 fi
  
139 else133 else
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
141 fi135 fi
 136 Remediation_Anaconda_snippet_⇲
 137 Complexity:·low
 138 Disruption:·low
 139 Strategy:···enable
  
 140 package·--add=aide
142 Remediation_Ansible_snippet_⇲141 Remediation_Ansible_snippet_⇲
143 Complexity:·low142 Complexity:·low
144 Disruption:·low143 Disruption:·low
145 Strategy:···enable144 Strategy:···enable
146 -·name:·Ensure·aide·is·installed145 -·name:·Ensure·aide·is·installed
147 ··package:146 ··package:
148 ····name:·aide147 ····name:·aide
Offset 1246, 20 lines modifiedOffset 1246, 14 lines modified
1246 Identifiers·and·References·Identifiers: ·CCE-82214-81246 Identifiers·and·References·Identifiers: ·CCE-82214-8
1247 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11247 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1248 Remediation_OSBuild_Blueprint_snippet_⇲1248 Remediation_OSBuild_Blueprint_snippet_⇲
  
1249 [[packages]]1249 [[packages]]
1250 name·=·"sudo"1250 name·=·"sudo"
1251 version·=·"*"1251 version·=·"*"
1252 Remediation_Anaconda_snippet_⇲ 
1253 Complexity:·low 
1254 Disruption:·low 
1255 Strategy:···enable 
  
1256 package·--add=sudo 
1257 Remediation_Puppet_snippet_⇲1252 Remediation_Puppet_snippet_⇲
1258 Complexity:·low1253 Complexity:·low
1259 Disruption:·low1254 Disruption:·low
1260 Strategy:···enable1255 Strategy:···enable
1261 include·install_sudo1256 include·install_sudo
  
1262 class·install_sudo·{1257 class·install_sudo·{
Offset 1277, 14 lines modifiedOffset 1271, 20 lines modified
1277 if·!·rpm·-q·--quiet·"sudo"·;·then1271 if·!·rpm·-q·--quiet·"sudo"·;·then
1278 ····yum·install·-y·"sudo"1272 ····yum·install·-y·"sudo"
1279 fi1273 fi
  
1280 else1274 else
1281 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1275 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1282 fi1276 fi
 1277 Remediation_Anaconda_snippet_⇲
 1278 Complexity:·low
 1279 Disruption:·low
 1280 Strategy:···enable
  
 1281 package·--add=sudo
1283 Remediation_Ansible_snippet_⇲1282 Remediation_Ansible_snippet_⇲
1284 Complexity:·low1283 Complexity:·low
1285 Disruption:·low1284 Disruption:·low
1286 Strategy:···enable1285 Strategy:···enable
1287 -·name:·Ensure·sudo·is·installed1286 -·name:·Ensure·sudo·is·installed
1288 ··package:1287 ··package:
1289 ····name:·sudo1288 ····name:·sudo
Offset 8460, 15 lines modifiedOffset 8460, 15 lines modified
8460 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.8460 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
8461 Severity: ················medium8461 Severity: ················medium
8462 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod8462 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
8463 Identifiers·and·References·Identifiers: ·CCE-80685-18463 Identifiers·and·References·Identifiers: ·CCE-80685-1
8464 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule8464 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule
8465 Remediation_Shell_script_⇲8465 Remediation_Shell_script_⇲
8466 #·Remediation·is·applicable·only·in·certain·platforms8466 #·Remediation·is·applicable·only·in·certain·platforms
8467 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8467 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8468 #·First·perform·the·remediation·of·the·syscall·rule8468 #·First·perform·the·remediation·of·the·syscall·rule
8469 #·Retrieve·hardware·architecture·of·the·underlying·system8469 #·Retrieve·hardware·architecture·of·the·underlying·system
8470 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8470 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8471 for·ARCH·in·"${RULE_ARCHS[@]}"8471 for·ARCH·in·"${RULE_ARCHS[@]}"
8472 do8472 do
Offset 8816, 16 lines modifiedOffset 8816, 16 lines modified
8816 ··-·reboot_required8816 ··-·reboot_required
8817 ··-·restrict_strategy8817 ··-·restrict_strategy
  
8818 -·name:·Set·architecture·for·audit·chmod·tasks8818 -·name:·Set·architecture·for·audit·chmod·tasks
8819 ··set_fact:8819 ··set_fact:
8820 ····audit_arch:·b648820 ····audit_arch:·b64
8821 ··when:8821 ··when:
8822 ··-·'"audit"·in·ansible_facts.packages' 
8823 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8822 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8823 ··-·'"audit"·in·ansible_facts.packages'
8824 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8824 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8825 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8825 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8826 ··tags:8826 ··tags:
8827 ··-·CCE-80685-18827 ··-·CCE-80685-1
8828 ··-·CJIS-5.4.1.18828 ··-·CJIS-5.4.1.1
8829 ··-·DISA-STIG-RHEL-08-0304908829 ··-·DISA-STIG-RHEL-08-030490
8830 ··-·NIST-800-171-3.1.78830 ··-·NIST-800-171-3.1.7
Offset 8963, 16 lines modifiedOffset 8963, 16 lines modified
8963 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008963 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8964 ········-F·auid!=unset·-F·key=perm_mod8964 ········-F·auid!=unset·-F·key=perm_mod
8965 ······create:·true8965 ······create:·true
8966 ······mode:·o-rwx8966 ······mode:·o-rwx
8967 ······state:·present8967 ······state:·present
8968 ····when:·syscalls_found·|·length·==·08968 ····when:·syscalls_found·|·length·==·0
8969 ··when:8969 ··when:
8970 ··-·'"audit"·in·ansible_facts.packages' 
8971 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8970 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
Max diff block lines reached; 334465/340568 bytes (98.21%) of diff not shown.
886 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_server_l1.html
    
Offset 15449, 116 lines modifiedOffset 15449, 116 lines modified
0003c580:·7267·6574·3d22·2369·646d·3835·3232·2220··rget="#idm8522"·0003c580:·7267·6574·3d22·2369·646d·3835·3232·2220··rget="#idm8522"·
0003c590:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003c590:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003c5a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003c5a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003c5b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003c5b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003c5c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003c5c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003c5d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003c5d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003c5e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003c5e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003c5f0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp0003c5f0:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003c600:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003c600:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003c610:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003c610:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003c620:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003c620:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003c630:·6522·2069·643d·2269·646d·3835·3232·223e··e"·id="idm8522">0003c630:·2069·643d·2269·646d·3835·3232·223e·3c74···id="idm8522"><t
0003c640:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003c640:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003c650:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003c650:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003c660:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003c660:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003c670:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003c670:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003c680:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003c680:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003c690:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003c690:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003c6a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c6a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c6b0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003c6b0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003c6c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c6c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003c6d0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003c6d0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003c6e0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003c6e0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003c6f0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003c6f0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003c700:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003c700:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
0003c710:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=0003c710:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003c720:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003c730:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003c740:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003c750:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003c760:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003c770:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003c780:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003c790:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003c7a0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003c7b0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003c7c0:·6574·3d22·2369·646d·3835·3233·2220·7461··et="#idm8523"·ta
 0003c7d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003c7e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003c7f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003c800:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003c810:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003c820:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003c830:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003c840:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003c850:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003c860:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003c870:·2269·646d·3835·3233·223e·3c74·6162·6c65··"idm8523"><table
 0003c880:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003c890:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003c8a0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003c8b0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003c8c0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003c8d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003c8e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003c8f0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003c900:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003c910:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003c920:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003c930:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003c940:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003c950:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003c960:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003c970:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003c980:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0003c990:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0003c9a0:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0003c9b0:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0003c9c0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003c9d0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 0003c9e0:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
 0003c9f0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003ca00:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 0003ca10:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003ca20:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003ca30:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003ca40:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
0003c720:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003ca50:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003c730:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003ca60:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003c740:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003ca70:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003c750:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003ca80:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003c760:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003ca90:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003c770:·6172·6765·743d·2223·6964·6d38·3532·3322··arget="#idm8523"0003caa0:·6172·6765·743d·2223·6964·6d38·3532·3422··arget="#idm8524"
0003c780:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003cab0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c790:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003cac0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c7a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003cad0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c7b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003cae0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c7c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003caf0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c7d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003cb00:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003c7e0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003cb10:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003c7f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003cb20:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003c800:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003cb30:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003c810:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003cb40:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003c820:·2220·6964·3d22·6964·6d38·3532·3322·3e3c··"·id="idm8523"><0003cb50:·7365·2220·6964·3d22·6964·6d38·3532·3422··se"·id="idm8524"
0003c830:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003cb60:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003c840:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003cb70:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003c850:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003cb80:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003c860:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003cb90:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003c870:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003cba0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003c880:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003cbb0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003c890:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003cbc0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c8a0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003cbd0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003c8b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003cbe0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c8c0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003cbf0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003c8d0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003cc00:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003c8e0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003cc10:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003c8f0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003cc20:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003cc30:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
0003c900:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003c910:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003c920:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003c930:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003c940:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003c950:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003c960:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003c970:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c980:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c990:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003c9a0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c9b0:·6765·743d·2223·6964·6d38·3532·3422·2074··get="#idm8524"·t 
0003c9c0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c9d0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c9e0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c9f0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003ca00:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003ca10:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003ca20:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 801538/816194 bytes (98.20%) of diff not shown.
89.2 KB
html2text {}
    
Offset 103, 20 lines modifiedOffset 103, 14 lines modified
103 Identifiers·and·References·Identifiers: ·CCE-80844-4103 Identifiers·and·References·Identifiers: ·CCE-80844-4
104 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule104 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
105 Remediation_OSBuild_Blueprint_snippet_⇲105 Remediation_OSBuild_Blueprint_snippet_⇲
  
106 [[packages]]106 [[packages]]
107 name·=·"aide"107 name·=·"aide"
108 version·=·"*"108 version·=·"*"
109 Remediation_Anaconda_snippet_⇲ 
110 Complexity:·low 
111 Disruption:·low 
112 Strategy:···enable 
  
113 package·--add=aide 
114 Remediation_Puppet_snippet_⇲109 Remediation_Puppet_snippet_⇲
115 Complexity:·low110 Complexity:·low
116 Disruption:·low111 Disruption:·low
117 Strategy:···enable112 Strategy:···enable
118 include·install_aide113 include·install_aide
  
119 class·install_aide·{114 class·install_aide·{
Offset 134, 14 lines modifiedOffset 128, 20 lines modified
134 if·!·rpm·-q·--quiet·"aide"·;·then128 if·!·rpm·-q·--quiet·"aide"·;·then
135 ····yum·install·-y·"aide"129 ····yum·install·-y·"aide"
136 fi130 fi
  
137 else131 else
138 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'132 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
139 fi133 fi
 134 Remediation_Anaconda_snippet_⇲
 135 Complexity:·low
 136 Disruption:·low
 137 Strategy:···enable
  
 138 package·--add=aide
140 Remediation_Ansible_snippet_⇲139 Remediation_Ansible_snippet_⇲
141 Complexity:·low140 Complexity:·low
142 Disruption:·low141 Disruption:·low
143 Strategy:···enable142 Strategy:···enable
144 -·name:·Ensure·aide·is·installed143 -·name:·Ensure·aide·is·installed
145 ··package:144 ··package:
146 ····name:·aide145 ····name:·aide
Offset 1154, 20 lines modifiedOffset 1154, 14 lines modified
1154 Identifiers·and·References·Identifiers: ·CCE-82214-81154 Identifiers·and·References·Identifiers: ·CCE-82214-8
1155 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11155 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1156 Remediation_OSBuild_Blueprint_snippet_⇲1156 Remediation_OSBuild_Blueprint_snippet_⇲
  
1157 [[packages]]1157 [[packages]]
1158 name·=·"sudo"1158 name·=·"sudo"
1159 version·=·"*"1159 version·=·"*"
1160 Remediation_Anaconda_snippet_⇲ 
1161 Complexity:·low 
1162 Disruption:·low 
1163 Strategy:···enable 
  
1164 package·--add=sudo 
1165 Remediation_Puppet_snippet_⇲1160 Remediation_Puppet_snippet_⇲
1166 Complexity:·low1161 Complexity:·low
1167 Disruption:·low1162 Disruption:·low
1168 Strategy:···enable1163 Strategy:···enable
1169 include·install_sudo1164 include·install_sudo
  
1170 class·install_sudo·{1165 class·install_sudo·{
Offset 1185, 14 lines modifiedOffset 1179, 20 lines modified
1185 if·!·rpm·-q·--quiet·"sudo"·;·then1179 if·!·rpm·-q·--quiet·"sudo"·;·then
1186 ····yum·install·-y·"sudo"1180 ····yum·install·-y·"sudo"
1187 fi1181 fi
  
1188 else1182 else
1189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1183 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1190 fi1184 fi
 1185 Remediation_Anaconda_snippet_⇲
 1186 Complexity:·low
 1187 Disruption:·low
 1188 Strategy:···enable
  
 1189 package·--add=sudo
1191 Remediation_Ansible_snippet_⇲1190 Remediation_Ansible_snippet_⇲
1192 Complexity:·low1191 Complexity:·low
1193 Disruption:·low1192 Disruption:·low
1194 Strategy:···enable1193 Strategy:···enable
1195 -·name:·Ensure·sudo·is·installed1194 -·name:·Ensure·sudo·is·installed
1196 ··package:1195 ··package:
1197 ····name:·sudo1196 ····name:·sudo
Offset 8312, 15 lines modifiedOffset 8312, 15 lines modified
8312 Identifiers·and·References·Identifiers: ·CCE-80800-68312 Identifiers·and·References·Identifiers: ·CCE-80800-6
8313 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.28313 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
8314 Remediation_Shell_script_⇲8314 Remediation_Shell_script_⇲
8315 Complexity:·low8315 Complexity:·low
8316 Disruption:·low8316 Disruption:·low
8317 Strategy:···configure8317 Strategy:···configure
8318 #·Remediation·is·applicable·only·in·certain·platforms8318 #·Remediation·is·applicable·only·in·certain·platforms
8319 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then8319 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
8320 chgrp·0·/boot/grub2/grub.cfg8320 chgrp·0·/boot/grub2/grub.cfg
  
8321 else8321 else
8322 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8322 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8323 fi8323 fi
8324 Remediation_Ansible_snippet_⇲8324 Remediation_Ansible_snippet_⇲
Offset 8345, 16 lines modifiedOffset 8345, 16 lines modified
8345 ··-·no_reboot_needed8345 ··-·no_reboot_needed
  
8346 -·name:·Test·for·existence·/boot/grub2/grub.cfg8346 -·name:·Test·for·existence·/boot/grub2/grub.cfg
8347 ··stat:8347 ··stat:
8348 ····path:·/boot/grub2/grub.cfg8348 ····path:·/boot/grub2/grub.cfg
8349 ··register:·file_exists8349 ··register:·file_exists
8350 ··when:8350 ··when:
8351 ··-·'"grub2-common"·in·ansible_facts.packages' 
8352 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8351 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8352 ··-·'"grub2-common"·in·ansible_facts.packages'
8353 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8353 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8354 ··tags:8354 ··tags:
8355 ··-·CCE-80800-68355 ··-·CCE-80800-6
8356 ··-·CJIS-5.5.2.28356 ··-·CJIS-5.5.2.2
8357 ··-·NIST-800-171-3.4.58357 ··-·NIST-800-171-3.4.5
8358 ··-·NIST-800-53-AC-6(1)8358 ··-·NIST-800-53-AC-6(1)
8359 ··-·NIST-800-53-CM-6(a)8359 ··-·NIST-800-53-CM-6(a)
Offset 8367, 16 lines modifiedOffset 8367, 16 lines modified
8367 ··-·no_reboot_needed8367 ··-·no_reboot_needed
  
8368 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg8368 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
8369 ··file:8369 ··file:
8370 ····path:·/boot/grub2/grub.cfg8370 ····path:·/boot/grub2/grub.cfg
8371 ····group:·'0'8371 ····group:·'0'
8372 ··when:8372 ··when:
8373 ··-·'"grub2-common"·in·ansible_facts.packages' 
8374 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8373 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
Max diff block lines reached; 86522/91305 bytes (94.76%) of diff not shown.
855 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_workstation_l1.html
    
Offset 15445, 116 lines modifiedOffset 15445, 116 lines modified
0003c540:·6172·6765·743d·2223·6964·6d38·3532·3222··arget="#idm8522"0003c540:·6172·6765·743d·2223·6964·6d38·3532·3222··arget="#idm8522"
0003c550:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c550:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c560:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c560:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c570:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c570:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c580:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c580:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c590:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c590:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c5a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c5a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003c5b0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip0003c5b0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
0003c5c0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003c5c0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c5d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003c5d0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c5e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003c5e0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c5f0:·7365·2220·6964·3d22·6964·6d38·3532·3222··se"·id="idm8522"0003c5f0:·2220·6964·3d22·6964·6d38·3532·3222·3e3c··"·id="idm8522"><
0003c600:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003c600:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c610:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003c610:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c620:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003c620:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c630:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003c630:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c640:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003c640:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c650:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003c650:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c660:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c660:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c670:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003c670:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003c680:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c680:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c690:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003c690:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003c6a0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003c6a0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003c6b0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003c6b0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003c6c0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003c6c0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003c6d0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add0003c6d0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 0003c6e0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 0003c6f0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 0003c700:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 0003c710:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003c720:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003c730:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003c740:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003c750:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003c760:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003c770:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003c780:·6765·743d·2223·6964·6d38·3532·3322·2074··get="#idm8523"·t
 0003c790:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003c7a0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003c7b0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003c7c0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003c7d0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003c7e0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003c7f0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003c800:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003c810:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003c820:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003c830:·3d22·6964·6d38·3532·3322·3e3c·7461·626c··="idm8523"><tabl
 0003c840:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003c850:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003c860:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003c870:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003c880:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003c890:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003c8a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003c8b0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003c8c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003c8d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003c8e0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003c8f0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003c900:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 0003c910:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003c920:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003c930:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003c940:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do
 0003c950:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&
 0003c960:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run
 0003c970:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]
 0003c980:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 0003c990:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid
 0003c9a0:·6522·203b·2074·6865·6e0a·2020·2020·7975··e"·;·then.····yu
 0003c9b0:·6d20·696e·7374·616c·6c20·2d79·2022·6169··m·install·-y·"ai
 0003c9c0:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.···
 0003c9d0:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo
 0003c9e0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is
 0003c9f0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable,
 0003ca00:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don
0003c6e0:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p0003ca10:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p
0003c6f0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003ca20:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0003c700:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003ca30:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0003c710:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003ca40:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0003c720:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003ca50:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0003c730:·7461·7267·6574·3d22·2369·646d·3835·3233··target="#idm85230003ca60:·7461·7267·6574·3d22·2369·646d·3835·3234··target="#idm8524
0003c740:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ca70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c750:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ca80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c760:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003ca90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c770:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003caa0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c780:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003cab0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c790:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003cac0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003c7a0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp0003cad0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
0003c7b0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003cae0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003c7c0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003caf0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003c7d0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003cb00:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003c7e0:·6522·2069·643d·2269·646d·3835·3233·223e··e"·id="idm8523">0003cb10:·7073·6522·2069·643d·2269·646d·3835·3234··pse"·id="idm8524
0003c7f0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003cb20:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003c800:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003cb30:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003c810:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003cb40:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003c820:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003cb50:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003c830:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003cb60:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003c840:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003cb70:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003c850:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003cb80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c860:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003cb90:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c870:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003cba0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c880:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003cbb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003c890:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003cbc0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003c8a0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003cbd0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003c8b0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003cbe0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003cbf0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
0003c8c0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003c8d0:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins 
0003c8e0:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa 
0003c8f0:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':. 
0003c900:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
0003c910:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.·· 
0003c920:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre 
0003c930:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c940:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c950:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c960:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c970:·7267·6574·3d22·2369·646d·3835·3234·2220··rget="#idm8524"· 
0003c980:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c990:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c9a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c9b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c9c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c9d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c9e0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
Max diff block lines reached; 773466/788122 bytes (98.14%) of diff not shown.
84.8 KB
html2text {}
    
Offset 103, 20 lines modifiedOffset 103, 14 lines modified
103 Identifiers·and·References·Identifiers: ·CCE-80844-4103 Identifiers·and·References·Identifiers: ·CCE-80844-4
104 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule104 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
105 Remediation_OSBuild_Blueprint_snippet_⇲105 Remediation_OSBuild_Blueprint_snippet_⇲
  
106 [[packages]]106 [[packages]]
107 name·=·"aide"107 name·=·"aide"
108 version·=·"*"108 version·=·"*"
109 Remediation_Anaconda_snippet_⇲ 
110 Complexity:·low 
111 Disruption:·low 
112 Strategy:···enable 
  
113 package·--add=aide 
114 Remediation_Puppet_snippet_⇲109 Remediation_Puppet_snippet_⇲
115 Complexity:·low110 Complexity:·low
116 Disruption:·low111 Disruption:·low
117 Strategy:···enable112 Strategy:···enable
118 include·install_aide113 include·install_aide
  
119 class·install_aide·{114 class·install_aide·{
Offset 134, 14 lines modifiedOffset 128, 20 lines modified
134 if·!·rpm·-q·--quiet·"aide"·;·then128 if·!·rpm·-q·--quiet·"aide"·;·then
135 ····yum·install·-y·"aide"129 ····yum·install·-y·"aide"
136 fi130 fi
  
137 else131 else
138 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'132 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
139 fi133 fi
 134 Remediation_Anaconda_snippet_⇲
 135 Complexity:·low
 136 Disruption:·low
 137 Strategy:···enable
  
 138 package·--add=aide
140 Remediation_Ansible_snippet_⇲139 Remediation_Ansible_snippet_⇲
141 Complexity:·low140 Complexity:·low
142 Disruption:·low141 Disruption:·low
143 Strategy:···enable142 Strategy:···enable
144 -·name:·Ensure·aide·is·installed143 -·name:·Ensure·aide·is·installed
145 ··package:144 ··package:
146 ····name:·aide145 ····name:·aide
Offset 1154, 20 lines modifiedOffset 1154, 14 lines modified
1154 Identifiers·and·References·Identifiers: ·CCE-82214-81154 Identifiers·and·References·Identifiers: ·CCE-82214-8
1155 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11155 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1156 Remediation_OSBuild_Blueprint_snippet_⇲1156 Remediation_OSBuild_Blueprint_snippet_⇲
  
1157 [[packages]]1157 [[packages]]
1158 name·=·"sudo"1158 name·=·"sudo"
1159 version·=·"*"1159 version·=·"*"
1160 Remediation_Anaconda_snippet_⇲ 
1161 Complexity:·low 
1162 Disruption:·low 
1163 Strategy:···enable 
  
1164 package·--add=sudo 
1165 Remediation_Puppet_snippet_⇲1160 Remediation_Puppet_snippet_⇲
1166 Complexity:·low1161 Complexity:·low
1167 Disruption:·low1162 Disruption:·low
1168 Strategy:···enable1163 Strategy:···enable
1169 include·install_sudo1164 include·install_sudo
  
1170 class·install_sudo·{1165 class·install_sudo·{
Offset 1185, 14 lines modifiedOffset 1179, 20 lines modified
1185 if·!·rpm·-q·--quiet·"sudo"·;·then1179 if·!·rpm·-q·--quiet·"sudo"·;·then
1186 ····yum·install·-y·"sudo"1180 ····yum·install·-y·"sudo"
1187 fi1181 fi
  
1188 else1182 else
1189 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1183 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1190 fi1184 fi
 1185 Remediation_Anaconda_snippet_⇲
 1186 Complexity:·low
 1187 Disruption:·low
 1188 Strategy:···enable
  
 1189 package·--add=sudo
1191 Remediation_Ansible_snippet_⇲1190 Remediation_Ansible_snippet_⇲
1192 Complexity:·low1191 Complexity:·low
1193 Disruption:·low1192 Disruption:·low
1194 Strategy:···enable1193 Strategy:···enable
1195 -·name:·Ensure·sudo·is·installed1194 -·name:·Ensure·sudo·is·installed
1196 ··package:1195 ··package:
1197 ····name:·sudo1196 ····name:·sudo
Offset 8312, 15 lines modifiedOffset 8312, 15 lines modified
8312 Identifiers·and·References·Identifiers: ·CCE-80800-68312 Identifiers·and·References·Identifiers: ·CCE-80800-6
8313 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.28313 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
8314 Remediation_Shell_script_⇲8314 Remediation_Shell_script_⇲
8315 Complexity:·low8315 Complexity:·low
8316 Disruption:·low8316 Disruption:·low
8317 Strategy:···configure8317 Strategy:···configure
8318 #·Remediation·is·applicable·only·in·certain·platforms8318 #·Remediation·is·applicable·only·in·certain·platforms
8319 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then8319 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
8320 chgrp·0·/boot/grub2/grub.cfg8320 chgrp·0·/boot/grub2/grub.cfg
  
8321 else8321 else
8322 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8322 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8323 fi8323 fi
8324 Remediation_Ansible_snippet_⇲8324 Remediation_Ansible_snippet_⇲
Offset 8345, 16 lines modifiedOffset 8345, 16 lines modified
8345 ··-·no_reboot_needed8345 ··-·no_reboot_needed
  
8346 -·name:·Test·for·existence·/boot/grub2/grub.cfg8346 -·name:·Test·for·existence·/boot/grub2/grub.cfg
8347 ··stat:8347 ··stat:
8348 ····path:·/boot/grub2/grub.cfg8348 ····path:·/boot/grub2/grub.cfg
8349 ··register:·file_exists8349 ··register:·file_exists
8350 ··when:8350 ··when:
8351 ··-·'"grub2-common"·in·ansible_facts.packages' 
8352 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8351 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 8352 ··-·'"grub2-common"·in·ansible_facts.packages'
8353 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8353 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8354 ··tags:8354 ··tags:
8355 ··-·CCE-80800-68355 ··-·CCE-80800-6
8356 ··-·CJIS-5.5.2.28356 ··-·CJIS-5.5.2.2
8357 ··-·NIST-800-171-3.4.58357 ··-·NIST-800-171-3.4.5
8358 ··-·NIST-800-53-AC-6(1)8358 ··-·NIST-800-53-AC-6(1)
8359 ··-·NIST-800-53-CM-6(a)8359 ··-·NIST-800-53-CM-6(a)
Offset 8367, 16 lines modifiedOffset 8367, 16 lines modified
8367 ··-·no_reboot_needed8367 ··-·no_reboot_needed
  
8368 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg8368 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
8369 ··file:8369 ··file:
8370 ····path:·/boot/grub2/grub.cfg8370 ····path:·/boot/grub2/grub.cfg
8371 ····group:·'0'8371 ····group:·'0'
8372 ··when:8372 ··when:
8373 ··-·'"grub2-common"·in·ansible_facts.packages' 
8374 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'8373 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
Max diff block lines reached; 82057/86840 bytes (94.49%) of diff not shown.
1.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_workstation_l2.html
    
Offset 15455, 117 lines modifiedOffset 15455, 117 lines modified
0003c5e0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003c5e0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003c5f0:·3d22·2369·646d·3835·3232·2220·7461·6269··="#idm8522"·tabi0003c5f0:·3d22·2369·646d·3835·3232·2220·7461·6269··="#idm8522"·tabi
0003c600:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003c600:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003c610:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003c610:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003c620:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003c620:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003c630:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003c630:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003c640:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003c640:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003c650:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003c650:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003c660:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003c660:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003c670:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003c670:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003c680:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003c680:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003c690:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003c690:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003c6a0:·643d·2269·646d·3835·3232·223e·3c74·6162··d="idm8522"><tab0003c6a0:·2269·646d·3835·3232·223e·3c74·6162·6c65··"idm8522"><table
0003c6b0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003c6b0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003c6c0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003c6c0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003c6d0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003c6d0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003c6e0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003c6e0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003c6f0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003c6f0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003c700:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c700:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c710:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003c710:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003c720:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003c720:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003c730:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c730:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c740:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003c740:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003c750:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003c750:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003c760:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003c760:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003c770:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0003c770:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
0003c780:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide0003c780:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003c790:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003c7a0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003c7b0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003c7c0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003c7d0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003c7e0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003c7f0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003c800:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003c810:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003c820:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003c830:·2369·646d·3835·3233·2220·7461·6269·6e64··#idm8523"·tabind
 0003c840:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003c850:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003c860:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003c870:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003c880:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003c890:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003c8a0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003c8b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003c8c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003c8d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003c8e0:·3835·3233·223e·3c74·6162·6c65·2063·6c61··8523"><table·cla
 0003c8f0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003c900:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003c910:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003c920:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003c930:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003c940:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c950:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003c960:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003c970:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c980:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003c990:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003c9a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c9b0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003c9c0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003c9d0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003c9e0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003c9f0:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
 0003ca00:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 0003ca10:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
 0003ca20:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the
 0003ca30:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003ca40:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003ca50:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins
 0003ca60:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003ca70:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003ca80:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003ca90:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003caa0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003cab0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
0003c790:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003cac0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003c7a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003cad0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003c7b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003cae0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003c7c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003caf0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003c7d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003cb00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c7e0:·743d·2223·6964·6d38·3532·3322·2074·6162··t="#idm8523"·tab0003cb10:·743d·2223·6964·6d38·3532·3422·2074·6162··t="#idm8524"·tab
0003c7f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003cb20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c800:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003cb30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c810:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003cb40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c820:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003cb50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c830:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003cb60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c840:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003cb70:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003c850:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003cb80:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003c860:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003cb90:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003c870:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003cba0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003c880:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003cbb0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003c890:·3d22·6964·6d38·3532·3322·3e3c·7461·626c··="idm8523"><tabl0003cbc0:·6964·3d22·6964·6d38·3532·3422·3e3c·7461··id="idm8524"><ta
0003c8a0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003cbd0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003c8b0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003cbe0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003c8c0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003cbf0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003c8d0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003cc00:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003c8e0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003cc10:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003c8f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003cc20:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003c900:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003cc30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c910:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003cc40:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003c920:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003cc50:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c930:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003cc60:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003c940:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003cc70:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003c950:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003cc80:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003c960:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003cc90:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003cca0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
0003c970:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003c980:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003c990:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003c9a0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003c9b0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003c9c0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003c9d0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c9e0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c9f0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003ca00:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003ca10:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003ca20:·2223·6964·6d38·3532·3422·2074·6162·696e··"#idm8524"·tabin 
0003ca30:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003ca40:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003ca50:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003ca60:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003ca70:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003ca80:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
Max diff block lines reached; 1435382/1450176 bytes (98.98%) of diff not shown.
329 KB
html2text {}
    
Offset 105, 20 lines modifiedOffset 105, 14 lines modified
105 Identifiers·and·References·Identifiers: ·CCE-80844-4105 Identifiers·and·References·Identifiers: ·CCE-80844-4
106 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule106 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
107 Remediation_OSBuild_Blueprint_snippet_⇲107 Remediation_OSBuild_Blueprint_snippet_⇲
  
108 [[packages]]108 [[packages]]
109 name·=·"aide"109 name·=·"aide"
110 version·=·"*"110 version·=·"*"
111 Remediation_Anaconda_snippet_⇲ 
112 Complexity:·low 
113 Disruption:·low 
114 Strategy:···enable 
  
115 package·--add=aide 
116 Remediation_Puppet_snippet_⇲111 Remediation_Puppet_snippet_⇲
117 Complexity:·low112 Complexity:·low
118 Disruption:·low113 Disruption:·low
119 Strategy:···enable114 Strategy:···enable
120 include·install_aide115 include·install_aide
  
121 class·install_aide·{116 class·install_aide·{
Offset 136, 14 lines modifiedOffset 130, 20 lines modified
136 if·!·rpm·-q·--quiet·"aide"·;·then130 if·!·rpm·-q·--quiet·"aide"·;·then
137 ····yum·install·-y·"aide"131 ····yum·install·-y·"aide"
138 fi132 fi
  
139 else133 else
140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
141 fi135 fi
 136 Remediation_Anaconda_snippet_⇲
 137 Complexity:·low
 138 Disruption:·low
 139 Strategy:···enable
  
 140 package·--add=aide
142 Remediation_Ansible_snippet_⇲141 Remediation_Ansible_snippet_⇲
143 Complexity:·low142 Complexity:·low
144 Disruption:·low143 Disruption:·low
145 Strategy:···enable144 Strategy:···enable
146 -·name:·Ensure·aide·is·installed145 -·name:·Ensure·aide·is·installed
147 ··package:146 ··package:
148 ····name:·aide147 ····name:·aide
Offset 1246, 20 lines modifiedOffset 1246, 14 lines modified
1246 Identifiers·and·References·Identifiers: ·CCE-82214-81246 Identifiers·and·References·Identifiers: ·CCE-82214-8
1247 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11247 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1248 Remediation_OSBuild_Blueprint_snippet_⇲1248 Remediation_OSBuild_Blueprint_snippet_⇲
  
1249 [[packages]]1249 [[packages]]
1250 name·=·"sudo"1250 name·=·"sudo"
1251 version·=·"*"1251 version·=·"*"
1252 Remediation_Anaconda_snippet_⇲ 
1253 Complexity:·low 
1254 Disruption:·low 
1255 Strategy:···enable 
  
1256 package·--add=sudo 
1257 Remediation_Puppet_snippet_⇲1252 Remediation_Puppet_snippet_⇲
1258 Complexity:·low1253 Complexity:·low
1259 Disruption:·low1254 Disruption:·low
1260 Strategy:···enable1255 Strategy:···enable
1261 include·install_sudo1256 include·install_sudo
  
1262 class·install_sudo·{1257 class·install_sudo·{
Offset 1277, 14 lines modifiedOffset 1271, 20 lines modified
1277 if·!·rpm·-q·--quiet·"sudo"·;·then1271 if·!·rpm·-q·--quiet·"sudo"·;·then
1278 ····yum·install·-y·"sudo"1272 ····yum·install·-y·"sudo"
1279 fi1273 fi
  
1280 else1274 else
1281 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1275 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1282 fi1276 fi
 1277 Remediation_Anaconda_snippet_⇲
 1278 Complexity:·low
 1279 Disruption:·low
 1280 Strategy:···enable
  
 1281 package·--add=sudo
1283 Remediation_Ansible_snippet_⇲1282 Remediation_Ansible_snippet_⇲
1284 Complexity:·low1283 Complexity:·low
1285 Disruption:·low1284 Disruption:·low
1286 Strategy:···enable1285 Strategy:···enable
1287 -·name:·Ensure·sudo·is·installed1286 -·name:·Ensure·sudo·is·installed
1288 ··package:1287 ··package:
1289 ····name:·sudo1288 ····name:·sudo
Offset 8460, 15 lines modifiedOffset 8460, 15 lines modified
8460 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.8460 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
8461 Severity: ················medium8461 Severity: ················medium
8462 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod8462 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
8463 Identifiers·and·References·Identifiers: ·CCE-80685-18463 Identifiers·and·References·Identifiers: ·CCE-80685-1
8464 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule8464 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule
8465 Remediation_Shell_script_⇲8465 Remediation_Shell_script_⇲
8466 #·Remediation·is·applicable·only·in·certain·platforms8466 #·Remediation·is·applicable·only·in·certain·platforms
8467 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8467 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8468 #·First·perform·the·remediation·of·the·syscall·rule8468 #·First·perform·the·remediation·of·the·syscall·rule
8469 #·Retrieve·hardware·architecture·of·the·underlying·system8469 #·Retrieve·hardware·architecture·of·the·underlying·system
8470 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8470 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8471 for·ARCH·in·"${RULE_ARCHS[@]}"8471 for·ARCH·in·"${RULE_ARCHS[@]}"
8472 do8472 do
Offset 8816, 16 lines modifiedOffset 8816, 16 lines modified
8816 ··-·reboot_required8816 ··-·reboot_required
8817 ··-·restrict_strategy8817 ··-·restrict_strategy
  
8818 -·name:·Set·architecture·for·audit·chmod·tasks8818 -·name:·Set·architecture·for·audit·chmod·tasks
8819 ··set_fact:8819 ··set_fact:
8820 ····audit_arch:·b648820 ····audit_arch:·b64
8821 ··when:8821 ··when:
8822 ··-·'"audit"·in·ansible_facts.packages' 
8823 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8822 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8823 ··-·'"audit"·in·ansible_facts.packages'
8824 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8824 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8825 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8825 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8826 ··tags:8826 ··tags:
8827 ··-·CCE-80685-18827 ··-·CCE-80685-1
8828 ··-·CJIS-5.4.1.18828 ··-·CJIS-5.4.1.1
8829 ··-·DISA-STIG-RHEL-08-0304908829 ··-·DISA-STIG-RHEL-08-030490
8830 ··-·NIST-800-171-3.1.78830 ··-·NIST-800-171-3.1.7
Offset 8963, 16 lines modifiedOffset 8963, 16 lines modified
8963 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008963 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8964 ········-F·auid!=unset·-F·key=perm_mod8964 ········-F·auid!=unset·-F·key=perm_mod
8965 ······create:·true8965 ······create:·true
8966 ······mode:·o-rwx8966 ······mode:·o-rwx
8967 ······state:·present8967 ······state:·present
8968 ····when:·syscalls_found·|·length·==·08968 ····when:·syscalls_found·|·length·==·0
8969 ··when:8969 ··when:
8970 ··-·'"audit"·in·ansible_facts.packages' 
8971 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8970 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
Max diff block lines reached; 330979/337082 bytes (98.19%) of diff not shown.
602 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cjis.html
    
Offset 17341, 116 lines modifiedOffset 17341, 116 lines modified
00043bc0:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm8500043bc0:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm85
00043bd0:·3232·2220·7461·6269·6e64·6578·3d22·3022··22"·tabindex="0"00043bd0:·3232·2220·7461·6269·6e64·6578·3d22·3022··22"·tabindex="0"
00043be0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00043be0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00043bf0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00043bf0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00043c00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00043c00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00043c10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00043c10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00043c20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00043c20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00043c30:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s00043c30:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
00043c40:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b00043c40:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
00043c50:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00043c50:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00043c60:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00043c60:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00043c70:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm8500043c70:·7073·6522·2069·643d·2269·646d·3835·3232··pse"·id="idm8522
00043c80:·3232·223e·3c74·6162·6c65·2063·6c61·7373··22"><table·class00043c80:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
00043c90:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00043c90:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00043ca0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00043ca0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
00043cb0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00043cb0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
00043cc0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00043cc0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
00043cd0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00043cd0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
00043ce0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00043ce0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00043cf0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio00043cf0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
00043d00:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00043d00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00043d10:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00043d10:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
00043d20:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t00043d20:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
00043d30:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t00043d30:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
00043d40:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><00043d40:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
00043d50:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
00043d60:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>00043d50:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 00043d60:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 00043d70:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 00043d80:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 00043d90:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 00043da0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 00043db0:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 00043dc0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 00043dd0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 00043de0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 00043df0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 00043e00:·7461·7267·6574·3d22·2369·646d·3835·3233··target="#idm8523
 00043e10:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 00043e20:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 00043e30:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 00043e40:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 00043e50:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 00043e60:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00043e70:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 00043e80:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00043e90:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00043ea0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00043eb0:·2069·643d·2269·646d·3835·3233·223e·3c74···id="idm8523"><t
 00043ec0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00043ed0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00043ee0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00043ef0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00043f00:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00043f10:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00043f20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00043f30:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00043f40:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00043f50:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00043f60:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00043f70:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00043f80:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 00043f90:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 00043fa0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 00043fb0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 00043fc0:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
 00043fd0:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
 00043fe0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
 00043ff0:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 00044000:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!·
 00044010:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"
 00044020:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.···
 00044030:·2079·756d·2069·6e73·7461·6c6c·202d·7920···yum·install·-y·
 00044040:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else.
 00044050:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 00044060:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 00044070:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 00044080:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 00044090:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
00043d70:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c000440a0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
00043d80:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su000440b0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
00043d90:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg000440c0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
00043da0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da000440d0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
00043db0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8000440e0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
00043dc0:·3532·3322·2074·6162·696e·6465·783d·2230··523"·tabindex="0000440f0:·3532·3422·2074·6162·696e·6465·783d·2230··524"·tabindex="0
00043dd0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00044100:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00043de0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00044110:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00043df0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00044120:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00043e00:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00044130:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00043e10:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00044140:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00043e20:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn00044150:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
00043e30:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br00044160:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
00043e40:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00044170:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00043e50:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00044180:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
00043e60:·6170·7365·2220·6964·3d22·6964·6d38·3532··apse"·id="idm85200044190:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
00043e70:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=000441a0:·3532·3422·3e3c·7461·626c·6520·636c·6173··524"><table·clas
00043e80:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str000441b0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
00043e90:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde000441c0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
00043ea0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden000441d0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00043eb0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com000441e0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
00043ec0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td000441f0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
00043ed0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00044200:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00043ee0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption00044210:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
00043ef0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00044220:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
00043f00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00044230:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00043f10:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00044240:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00043f20:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00044250:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
00043f30:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00044260:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00044270:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 00044280:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code
00043f40:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
00043f50:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class· 
00043f60:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.· 
00043f70:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide 
00043f80:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
00043f90:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
00043fa0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
00043fb0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00043fc0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00043fd0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00043fe0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00043ff0:·2d74·6172·6765·743d·2223·6964·6d38·3532··-target="#idm852 
00044000:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"· 
00044010:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00044020:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00044030:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00044040:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
Max diff block lines reached; 425000/439656 bytes (96.67%) of diff not shown.
173 KB
html2text {}
    
Offset 401, 20 lines modifiedOffset 401, 14 lines modified
401 Identifiers·and·References·Identifiers: ·CCE-80844-4401 Identifiers·and·References·Identifiers: ·CCE-80844-4
402 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule402 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
403 Remediation_OSBuild_Blueprint_snippet_⇲403 Remediation_OSBuild_Blueprint_snippet_⇲
  
404 [[packages]]404 [[packages]]
405 name·=·"aide"405 name·=·"aide"
406 version·=·"*"406 version·=·"*"
407 Remediation_Anaconda_snippet_⇲ 
408 Complexity:·low 
409 Disruption:·low 
410 Strategy:···enable 
  
411 package·--add=aide 
412 Remediation_Puppet_snippet_⇲407 Remediation_Puppet_snippet_⇲
413 Complexity:·low408 Complexity:·low
414 Disruption:·low409 Disruption:·low
415 Strategy:···enable410 Strategy:···enable
416 include·install_aide411 include·install_aide
  
417 class·install_aide·{412 class·install_aide·{
Offset 432, 14 lines modifiedOffset 426, 20 lines modified
432 if·!·rpm·-q·--quiet·"aide"·;·then426 if·!·rpm·-q·--quiet·"aide"·;·then
433 ····yum·install·-y·"aide"427 ····yum·install·-y·"aide"
434 fi428 fi
  
435 else429 else
436 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'430 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
437 fi431 fi
 432 Remediation_Anaconda_snippet_⇲
 433 Complexity:·low
 434 Disruption:·low
 435 Strategy:···enable
  
 436 package·--add=aide
438 Remediation_Ansible_snippet_⇲437 Remediation_Ansible_snippet_⇲
439 Complexity:·low438 Complexity:·low
440 Disruption:·low439 Disruption:·low
441 Strategy:···enable440 Strategy:···enable
442 -·name:·Ensure·aide·is·installed441 -·name:·Ensure·aide·is·installed
443 ··package:442 ··package:
444 ····name:·aide443 ····name:·aide
Offset 4501, 15 lines modifiedOffset 4501, 15 lines modified
4501 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.4501 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
4502 Severity: ················medium4502 Severity: ················medium
4503 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod4503 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
4504 Identifiers·and·References·Identifiers: ·CCE-80685-14504 Identifiers·and·References·Identifiers: ·CCE-80685-1
4505 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule4505 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule
4506 Remediation_Shell_script_⇲4506 Remediation_Shell_script_⇲
4507 #·Remediation·is·applicable·only·in·certain·platforms4507 #·Remediation·is·applicable·only·in·certain·platforms
4508 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then4508 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
4509 #·First·perform·the·remediation·of·the·syscall·rule4509 #·First·perform·the·remediation·of·the·syscall·rule
4510 #·Retrieve·hardware·architecture·of·the·underlying·system4510 #·Retrieve·hardware·architecture·of·the·underlying·system
4511 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")4511 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
4512 for·ARCH·in·"${RULE_ARCHS[@]}"4512 for·ARCH·in·"${RULE_ARCHS[@]}"
4513 do4513 do
Offset 4857, 16 lines modifiedOffset 4857, 16 lines modified
4857 ··-·reboot_required4857 ··-·reboot_required
4858 ··-·restrict_strategy4858 ··-·restrict_strategy
  
4859 -·name:·Set·architecture·for·audit·chmod·tasks4859 -·name:·Set·architecture·for·audit·chmod·tasks
4860 ··set_fact:4860 ··set_fact:
4861 ····audit_arch:·b644861 ····audit_arch:·b64
4862 ··when:4862 ··when:
4863 ··-·'"audit"·in·ansible_facts.packages' 
4864 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4863 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4864 ··-·'"audit"·in·ansible_facts.packages'
4865 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4865 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4866 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4866 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4867 ··tags:4867 ··tags:
4868 ··-·CCE-80685-14868 ··-·CCE-80685-1
4869 ··-·CJIS-5.4.1.14869 ··-·CJIS-5.4.1.1
4870 ··-·DISA-STIG-RHEL-08-0304904870 ··-·DISA-STIG-RHEL-08-030490
4871 ··-·NIST-800-171-3.1.74871 ··-·NIST-800-171-3.1.7
Offset 5004, 16 lines modifiedOffset 5004, 16 lines modified
5004 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005004 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
5005 ········-F·auid!=unset·-F·key=perm_mod5005 ········-F·auid!=unset·-F·key=perm_mod
5006 ······create:·true5006 ······create:·true
5007 ······mode:·o-rwx5007 ······mode:·o-rwx
5008 ······state:·present5008 ······state:·present
5009 ····when:·syscalls_found·|·length·==·05009 ····when:·syscalls_found·|·length·==·0
5010 ··when:5010 ··when:
5011 ··-·'"audit"·in·ansible_facts.packages' 
5012 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5011 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5012 ··-·'"audit"·in·ansible_facts.packages'
5013 ··tags:5013 ··tags:
5014 ··-·CCE-80685-15014 ··-·CCE-80685-1
5015 ··-·CJIS-5.4.1.15015 ··-·CJIS-5.4.1.1
5016 ··-·DISA-STIG-RHEL-08-0304905016 ··-·DISA-STIG-RHEL-08-030490
5017 ··-·NIST-800-171-3.1.75017 ··-·NIST-800-171-3.1.7
5018 ··-·NIST-800-53-AU-12(c)5018 ··-·NIST-800-53-AU-12(c)
5019 ··-·NIST-800-53-AU-2(d)5019 ··-·NIST-800-53-AU-2(d)
Offset 5149, 16 lines modifiedOffset 5149, 16 lines modified
5149 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10005149 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
5150 ········-F·auid!=unset·-F·key=perm_mod5150 ········-F·auid!=unset·-F·key=perm_mod
5151 ······create:·true5151 ······create:·true
5152 ······mode:·o-rwx5152 ······mode:·o-rwx
5153 ······state:·present5153 ······state:·present
5154 ····when:·syscalls_found·|·length·==·05154 ····when:·syscalls_found·|·length·==·0
5155 ··when:5155 ··when:
5156 ··-·'"audit"·in·ansible_facts.packages' 
5157 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5156 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5157 ··-·'"audit"·in·ansible_facts.packages'
5158 ··-·audit_arch·==·"b64"5158 ··-·audit_arch·==·"b64"
5159 ··tags:5159 ··tags:
5160 ··-·CCE-80685-15160 ··-·CCE-80685-1
5161 ··-·CJIS-5.4.1.15161 ··-·CJIS-5.4.1.1
5162 ··-·DISA-STIG-RHEL-08-0304905162 ··-·DISA-STIG-RHEL-08-030490
5163 ··-·NIST-800-171-3.1.75163 ··-·NIST-800-171-3.1.7
5164 ··-·NIST-800-53-AU-12(c)5164 ··-·NIST-800-53-AU-12(c)
Offset 5184, 15 lines modifiedOffset 5184, 15 lines modified
5184 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.5184 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
5185 Severity: ················medium5185 Severity: ················medium
5186 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown5186 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
5187 Identifiers·and·References·Identifiers: ·CCE-80686-95187 Identifiers·and·References·Identifiers: ·CCE-80686-9
5188 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030480,·4.1.3.9,·SV-230455r810459_rule5188 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030480,·4.1.3.9,·SV-230455r810459_rule
5189 Remediation_Shell_script_⇲5189 Remediation_Shell_script_⇲
5190 #·Remediation·is·applicable·only·in·certain·platforms5190 #·Remediation·is·applicable·only·in·certain·platforms
5191 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then5191 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
5192 #·First·perform·the·remediation·of·the·syscall·rule5192 #·First·perform·the·remediation·of·the·syscall·rule
5193 #·Retrieve·hardware·architecture·of·the·underlying·system5193 #·Retrieve·hardware·architecture·of·the·underlying·system
5194 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")5194 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
5195 for·ARCH·in·"${RULE_ARCHS[@]}"5195 for·ARCH·in·"${RULE_ARCHS[@]}"
5196 do5196 do
Max diff block lines reached; 168398/176813 bytes (95.24%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cui.html
    
Offset 15470, 116 lines modifiedOffset 15470, 116 lines modified
0003c6d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003c6d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003c6e0:·6d38·3532·3222·2074·6162·696e·6465·783d··m8522"·tabindex=0003c6e0:·6d38·3532·3222·2074·6162·696e·6465·783d··m8522"·tabindex=
0003c6f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003c6f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003c700:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003c700:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003c710:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003c710:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003c720:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003c720:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003c730:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003c730:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003c740:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond0003c740:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·
0003c750:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0003c750:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003c760:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003c760:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003c770:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003c770:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003c780:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003c780:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003c790:·6d38·3532·3222·3e3c·7461·626c·6520·636c··m8522"><table·cl0003c790:·3532·3222·3e3c·7461·626c·6520·636c·6173··522"><table·clas
0003c7a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003c7a0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003c7b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003c7b0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003c7c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003c7c0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003c7d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003c7d0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003c7e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003c7e0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003c7f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003c7f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c800:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003c800:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c810:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c810:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003c820:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c820:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c830:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003c830:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c840:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003c840:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003c850:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003c850:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003c860:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package 
0003c870:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co0003c860:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in
 0003c870:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas
 0003c880:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{
 0003c890:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai
 0003c8a0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure·
 0003c8b0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed
 0003c8c0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code>
 0003c8d0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003c8e0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003c8f0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003c900:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003c910:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
 0003c920:·3532·3322·2074·6162·696e·6465·783d·2230··523"·tabindex="0
 0003c930:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003c940:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003c950:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003c960:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003c970:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003c980:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 0003c990:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003c9a0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003c9b0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003c9c0:·7365·2220·6964·3d22·6964·6d38·3532·3322··se"·id="idm8523"
 0003c9d0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003c9e0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003c9f0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003ca00:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003ca10:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003ca20:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003ca30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003ca40:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003ca50:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003ca60:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003ca70:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003ca80:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003ca90:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003caa0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 0003cab0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 0003cac0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 0003cad0:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-
 0003cae0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·
 0003caf0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-
 0003cb00:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe
 0003cb10:·7265·6e76·205d·3b20·7468·656e·0a0a·6966··renv·];·then..if
 0003cb20:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003cb30:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 0003cb40:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install·
 0003cb50:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 0003cb60:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003cb70:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003cb80:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003cb90:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003cba0:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
0003c880:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003cbb0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003c890:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003cbc0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003c8a0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003cbd0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003c8b0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003cbe0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003c8c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003cbf0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003c8d0:·646d·3835·3233·2220·7461·6269·6e64·6578··dm8523"·tabindex0003cc00:·646d·3835·3234·2220·7461·6269·6e64·6578··dm8524"·tabindex
0003c8e0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003cc10:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003c8f0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003cc20:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003c900:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003cc30:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003c910:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003cc40:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003c920:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003cc50:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003c930:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0003cc60:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
0003c940:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003cc70:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
0003c950:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003cc80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003c960:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003cc90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003c970:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003cca0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003c980:·3835·3233·223e·3c74·6162·6c65·2063·6c61··8523"><table·cla0003ccb0:·646d·3835·3234·223e·3c74·6162·6c65·2063··dm8524"><table·c
0003c990:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003ccc0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003c9a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003ccd0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003c9b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003cce0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003c9c0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003ccf0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003c9d0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003cd00:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003c9e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003cd10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c9f0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003cd20:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003ca00:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003cd30:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003ca10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003cd40:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003ca20:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003cd50:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003ca30:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003cd60:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003ca40:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003cd70:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003cd80:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003cd90:·6520·2d2d·6164·643d·6169·6465·0a3c·2f63··e·--add=aide.</c
0003ca50:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003ca60:·6e73·7461·6c6c·5f61·6964·650a·0a63·6c61··nstall_aide..cla 
0003ca70:·7373·2069·6e73·7461·6c6c·5f61·6964·6520··ss·install_aide· 
0003ca80:·7b0a·2020·7061·636b·6167·6520·7b20·2761··{.··package·{·'a 
0003ca90:·6964·6527·3a0a·2020·2020·656e·7375·7265··ide':.····ensure 
0003caa0:·203d·2667·743b·2027·696e·7374·616c·6c65···=&gt;·'installe 
0003cab0:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code 
0003cac0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003cad0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003cae0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003caf0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003cb00:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003cb10:·3835·3234·2220·7461·6269·6e64·6578·3d22··8524"·tabindex=" 
0003cb20:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003cb30:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003cb40:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003cb50:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
Max diff block lines reached; 973234/987890 bytes (98.52%) of diff not shown.
96.0 KB
html2text {}
    
Offset 109, 20 lines modifiedOffset 109, 14 lines modified
109 Identifiers·and·References·Identifiers: ·CCE-80844-4109 Identifiers·and·References·Identifiers: ·CCE-80844-4
110 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule110 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
111 Remediation_OSBuild_Blueprint_snippet_⇲111 Remediation_OSBuild_Blueprint_snippet_⇲
  
112 [[packages]]112 [[packages]]
113 name·=·"aide"113 name·=·"aide"
114 version·=·"*"114 version·=·"*"
115 Remediation_Anaconda_snippet_⇲ 
116 Complexity:·low 
117 Disruption:·low 
118 Strategy:···enable 
  
119 package·--add=aide 
120 Remediation_Puppet_snippet_⇲115 Remediation_Puppet_snippet_⇲
121 Complexity:·low116 Complexity:·low
122 Disruption:·low117 Disruption:·low
123 Strategy:···enable118 Strategy:···enable
124 include·install_aide119 include·install_aide
  
125 class·install_aide·{120 class·install_aide·{
Offset 140, 14 lines modifiedOffset 134, 20 lines modified
140 if·!·rpm·-q·--quiet·"aide"·;·then134 if·!·rpm·-q·--quiet·"aide"·;·then
141 ····yum·install·-y·"aide"135 ····yum·install·-y·"aide"
142 fi136 fi
  
143 else137 else
144 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'138 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
145 fi139 fi
 140 Remediation_Anaconda_snippet_⇲
 141 Complexity:·low
 142 Disruption:·low
 143 Strategy:···enable
  
 144 package·--add=aide
146 Remediation_Ansible_snippet_⇲145 Remediation_Ansible_snippet_⇲
147 Complexity:·low146 Complexity:·low
148 Disruption:·low147 Disruption:·low
149 Strategy:···enable148 Strategy:···enable
150 -·name:·Ensure·aide·is·installed149 -·name:·Ensure·aide·is·installed
151 ··package:150 ··package:
152 ····name:·aide151 ····name:·aide
Offset 423, 20 lines modifiedOffset 423, 14 lines modified
423 Identifiers·and·References·Identifiers: ·CCE-82723-8423 Identifiers·and·References·Identifiers: ·CCE-82723-8
424 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174424 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
425 Remediation_OSBuild_Blueprint_snippet_⇲425 Remediation_OSBuild_Blueprint_snippet_⇲
  
426 [[packages]]426 [[packages]]
427 name·=·"crypto-policies"427 name·=·"crypto-policies"
428 version·=·"*"428 version·=·"*"
429 Remediation_Anaconda_snippet_⇲ 
430 Complexity:·low 
431 Disruption:·low 
432 Strategy:···enable 
  
433 package·--add=crypto-policies 
434 Remediation_Puppet_snippet_⇲429 Remediation_Puppet_snippet_⇲
435 Complexity:·low430 Complexity:·low
436 Disruption:·low431 Disruption:·low
437 Strategy:···enable432 Strategy:···enable
438 include·install_crypto-policies433 include·install_crypto-policies
  
439 class·install_crypto-policies·{434 class·install_crypto-policies·{
Offset 448, 14 lines modifiedOffset 442, 20 lines modified
448 Complexity:·low442 Complexity:·low
449 Disruption:·low443 Disruption:·low
450 Strategy:···enable444 Strategy:···enable
  
451 if·!·rpm·-q·--quiet·"crypto-policies"·;·then445 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
452 ····yum·install·-y·"crypto-policies"446 ····yum·install·-y·"crypto-policies"
453 fi447 fi
 448 Remediation_Anaconda_snippet_⇲
 449 Complexity:·low
 450 Disruption:·low
 451 Strategy:···enable
  
 452 package·--add=crypto-policies
454 Remediation_Ansible_snippet_⇲453 Remediation_Ansible_snippet_⇲
455 Complexity:·low454 Complexity:·low
456 Disruption:·low455 Disruption:·low
457 Strategy:···enable456 Strategy:···enable
458 -·name:·Ensure·crypto-policies·is·installed457 -·name:·Ensure·crypto-policies·is·installed
459 ··package:458 ··package:
460 ····name:·crypto-policies459 ····name:·crypto-policies
Offset 1048, 20 lines modifiedOffset 1048, 14 lines modified
1048 Identifiers·and·References·Identifiers: ·CCE-82214-81048 Identifiers·and·References·Identifiers: ·CCE-82214-8
1049 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11049 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1050 Remediation_OSBuild_Blueprint_snippet_⇲1050 Remediation_OSBuild_Blueprint_snippet_⇲
  
1051 [[packages]]1051 [[packages]]
1052 name·=·"sudo"1052 name·=·"sudo"
1053 version·=·"*"1053 version·=·"*"
1054 Remediation_Anaconda_snippet_⇲ 
1055 Complexity:·low 
1056 Disruption:·low 
1057 Strategy:···enable 
  
1058 package·--add=sudo 
1059 Remediation_Puppet_snippet_⇲1054 Remediation_Puppet_snippet_⇲
1060 Complexity:·low1055 Complexity:·low
1061 Disruption:·low1056 Disruption:·low
1062 Strategy:···enable1057 Strategy:···enable
1063 include·install_sudo1058 include·install_sudo
  
1064 class·install_sudo·{1059 class·install_sudo·{
Offset 1079, 14 lines modifiedOffset 1073, 20 lines modified
1079 if·!·rpm·-q·--quiet·"sudo"·;·then1073 if·!·rpm·-q·--quiet·"sudo"·;·then
1080 ····yum·install·-y·"sudo"1074 ····yum·install·-y·"sudo"
1081 fi1075 fi
  
1082 else1076 else
1083 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1077 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1084 fi1078 fi
 1079 Remediation_Anaconda_snippet_⇲
 1080 Complexity:·low
 1081 Disruption:·low
 1082 Strategy:···enable
  
 1083 package·--add=sudo
1085 Remediation_Ansible_snippet_⇲1084 Remediation_Ansible_snippet_⇲
1086 Complexity:·low1085 Complexity:·low
1087 Disruption:·low1086 Disruption:·low
1088 Strategy:···enable1087 Strategy:···enable
1089 -·name:·Ensure·sudo·is·installed1088 -·name:·Ensure·sudo·is·installed
1090 ··package:1089 ··package:
1091 ····name:·sudo1090 ····name:·sudo
Offset 1113, 20 lines modifiedOffset 1113, 14 lines modified
1113 Identifiers·and·References·Identifiers: ·CCE-82315-31113 Identifiers·and·References·Identifiers: ·CCE-82315-3
Max diff block lines reached; 94445/98316 bytes (96.06%) of diff not shown.
704 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-e8.html
    
Offset 21058, 104 lines modifiedOffset 21058, 104 lines modified
00052410:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm1300052410:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm13
00052420:·3238·3522·2074·6162·696e·6465·783d·2230··285"·tabindex="000052420:·3238·3522·2074·6162·696e·6465·783d·2230··285"·tabindex="0
00052430:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00052430:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00052440:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00052440:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00052450:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00052450:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00052460:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00052460:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00052470:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00052470:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00052480:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·00052480:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
00052490:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><00052490:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
000524a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p000524a0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
000524b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co000524b0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
000524c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1000524c0:·6170·7365·2220·6964·3d22·6964·6d31·3332··apse"·id="idm132
000524d0:·3332·3835·223e·3c74·6162·6c65·2063·6c61··3285"><table·cla000524d0:·3835·223e·3c74·6162·6c65·2063·6c61·7373··85"><table·class
000524e0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-000524e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
000524f0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo000524f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00052500:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con00052500:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
00052510:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>00052510:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
00052520:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>00052520:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00052530:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr00052530:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00052540:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt00052540:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00052550:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low00052550:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00052560:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00052560:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00052570:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>00052570:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00052580:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><00052580:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
00052590:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre00052590:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
000525a0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
000525b0:·2d2d·6164·643d·7265·6172·0a3c·2f63·6f64··--add=rear.</cod 
000525c0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
000525d0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
000525e0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
000525f0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
00052600:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
00052610:·6d31·3332·3836·2220·7461·6269·6e64·6578··m13286"·tabindex 
00052620:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00052630:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00052640:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00052650:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00052660:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00052670:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet 
00052680:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>000525a0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 000525b0:·7461·6c6c·5f72·6561·720a·0a63·6c61·7373··tall_rear..class
 000525c0:·2069·6e73·7461·6c6c·5f72·6561·7220·7b0a···install_rear·{.
 000525d0:·2020·7061·636b·6167·6520·7b20·2772·6561····package·{·'rea
 000525e0:·7227·3a0a·2020·2020·656e·7375·7265·203d··r':.····ensure·=
 000525f0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 00052600:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 00052610:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 00052620:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 00052630:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 00052640:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 00052650:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm13
 00052660:·3238·3622·2074·6162·696e·6465·783d·2230··286"·tabindex="0
 00052670:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 00052680:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 00052690:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 000526a0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 000526b0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 000526c0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 000526d0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 000526e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 000526f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00052700:·7365·2220·6964·3d22·6964·6d31·3332·3836··se"·id="idm13286
00052690:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00052710:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00052720:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00052730:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00052740:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00052750:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
000526a0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
000526b0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
000526c0:·3133·3238·3622·3e3c·7461·626c·6520·636c··13286"><table·cl 
000526d0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
000526e0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
000526f0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00052700:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00052710:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00052720:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00052730:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00052740:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo00052760:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
00052750:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00052770:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00052760:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00052770:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00052780:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00052790:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
000527a0:·696e·7374·616c·6c5f·7265·6172·0a0a·636c··install_rear..cl 
000527b0:·6173·7320·696e·7374·616c·6c5f·7265·6172··ass·install_rear 
000527c0:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·' 
000527d0:·7265·6172·273a·0a20·2020·2065·6e73·7572··rear':.····ensur 
000527e0:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
000527f0:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
00052800:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
00052810:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
00052820:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
00052830:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
00052840:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
00052850:·6d31·3332·3837·2220·7461·6269·6e64·6578··m13287"·tabindex 
00052860:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00052870:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00052880:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00052890:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
000528a0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
000528b0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·00052780:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00052790:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 000527a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 000527b0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 000527c0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 000527d0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 000527e0:·6465·3e0a·6966·2021·2072·706d·202d·7120··de>.if·!·rpm·-q·
 000527f0:·2d2d·7175·6965·7420·2272·6561·7222·203b··--quiet·"rear"·;
 00052800:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 00052810:·7374·616c·6c20·2d79·2022·7265·6172·220a··stall·-y·"rear".
 00052820:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 00052830:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 00052840:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00052850:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00052860:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 00052870:·6765·743d·2223·6964·6d31·3332·3837·2220··get="#idm13287"·
 00052880:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 00052890:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 000528a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 000528b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 000528c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 000528d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 000528e0:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp
000528c0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b000528f0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
000528d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00052900:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
000528e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00052910:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
000528f0:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm1300052920:·6522·2069·643d·2269·646d·3133·3238·3722··e"·id="idm13287"
Max diff block lines reached; 565352/578352 bytes (97.75%) of diff not shown.
139 KB
html2text {}
    
Offset 940, 20 lines modifiedOffset 940, 14 lines modified
940 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed940 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
941 Identifiers·and·References·Identifiers: ·CCE-82883-0941 Identifiers·and·References·Identifiers: ·CCE-82883-0
942 Remediation_OSBuild_Blueprint_snippet_⇲942 Remediation_OSBuild_Blueprint_snippet_⇲
  
943 [[packages]]943 [[packages]]
944 name·=·"rear"944 name·=·"rear"
945 version·=·"*"945 version·=·"*"
946 Remediation_Anaconda_snippet_⇲ 
947 Complexity:·low 
948 Disruption:·low 
949 Strategy:···enable 
  
950 package·--add=rear 
951 Remediation_Puppet_snippet_⇲946 Remediation_Puppet_snippet_⇲
952 Complexity:·low947 Complexity:·low
953 Disruption:·low948 Disruption:·low
954 Strategy:···enable949 Strategy:···enable
955 include·install_rear950 include·install_rear
  
956 class·install_rear·{951 class·install_rear·{
Offset 965, 14 lines modifiedOffset 959, 20 lines modified
965 Complexity:·low959 Complexity:·low
966 Disruption:·low960 Disruption:·low
967 Strategy:···enable961 Strategy:···enable
  
968 if·!·rpm·-q·--quiet·"rear"·;·then962 if·!·rpm·-q·--quiet·"rear"·;·then
969 ····yum·install·-y·"rear"963 ····yum·install·-y·"rear"
970 fi964 fi
 965 Remediation_Anaconda_snippet_⇲
 966 Complexity:·low
 967 Disruption:·low
 968 Strategy:···enable
  
 969 package·--add=rear
971 Remediation_Ansible_snippet_⇲970 Remediation_Ansible_snippet_⇲
972 Complexity:·low971 Complexity:·low
973 Disruption:·low972 Disruption:·low
974 Strategy:···enable973 Strategy:···enable
975 -·name:·Ensure·rear·is·installed974 -·name:·Ensure·rear·is·installed
976 ··package:975 ··package:
977 ····name:·rear976 ····name:·rear
Offset 1908, 15 lines modifiedOffset 1908, 15 lines modified
1908 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1908 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1909 Severity: ················medium1909 Severity: ················medium
1910 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1910 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1911 Identifiers·and·References·Identifiers: ·CCE-80685-11911 Identifiers·and·References·Identifiers: ·CCE-80685-1
1912 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule1912 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule
1913 Remediation_Shell_script_⇲1913 Remediation_Shell_script_⇲
1914 #·Remediation·is·applicable·only·in·certain·platforms1914 #·Remediation·is·applicable·only·in·certain·platforms
1915 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1915 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1916 #·First·perform·the·remediation·of·the·syscall·rule1916 #·First·perform·the·remediation·of·the·syscall·rule
1917 #·Retrieve·hardware·architecture·of·the·underlying·system1917 #·Retrieve·hardware·architecture·of·the·underlying·system
1918 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1918 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1919 for·ARCH·in·"${RULE_ARCHS[@]}"1919 for·ARCH·in·"${RULE_ARCHS[@]}"
1920 do1920 do
Offset 2264, 16 lines modifiedOffset 2264, 16 lines modified
2264 ··-·reboot_required2264 ··-·reboot_required
2265 ··-·restrict_strategy2265 ··-·restrict_strategy
  
2266 -·name:·Set·architecture·for·audit·chmod·tasks2266 -·name:·Set·architecture·for·audit·chmod·tasks
2267 ··set_fact:2267 ··set_fact:
2268 ····audit_arch:·b642268 ····audit_arch:·b64
2269 ··when:2269 ··when:
2270 ··-·'"audit"·in·ansible_facts.packages' 
2271 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2270 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2271 ··-·'"audit"·in·ansible_facts.packages'
2272 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2272 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2273 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2273 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2274 ··tags:2274 ··tags:
2275 ··-·CCE-80685-12275 ··-·CCE-80685-1
2276 ··-·CJIS-5.4.1.12276 ··-·CJIS-5.4.1.1
2277 ··-·DISA-STIG-RHEL-08-0304902277 ··-·DISA-STIG-RHEL-08-030490
2278 ··-·NIST-800-171-3.1.72278 ··-·NIST-800-171-3.1.7
Offset 2411, 16 lines modifiedOffset 2411, 16 lines modified
2411 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002411 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2412 ········-F·auid!=unset·-F·key=perm_mod2412 ········-F·auid!=unset·-F·key=perm_mod
2413 ······create:·true2413 ······create:·true
2414 ······mode:·o-rwx2414 ······mode:·o-rwx
2415 ······state:·present2415 ······state:·present
2416 ····when:·syscalls_found·|·length·==·02416 ····when:·syscalls_found·|·length·==·0
2417 ··when:2417 ··when:
2418 ··-·'"audit"·in·ansible_facts.packages' 
2419 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2418 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2419 ··-·'"audit"·in·ansible_facts.packages'
2420 ··tags:2420 ··tags:
2421 ··-·CCE-80685-12421 ··-·CCE-80685-1
2422 ··-·CJIS-5.4.1.12422 ··-·CJIS-5.4.1.1
2423 ··-·DISA-STIG-RHEL-08-0304902423 ··-·DISA-STIG-RHEL-08-030490
2424 ··-·NIST-800-171-3.1.72424 ··-·NIST-800-171-3.1.7
2425 ··-·NIST-800-53-AU-12(c)2425 ··-·NIST-800-53-AU-12(c)
2426 ··-·NIST-800-53-AU-2(d)2426 ··-·NIST-800-53-AU-2(d)
Offset 2556, 16 lines modifiedOffset 2556, 16 lines modified
2556 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002556 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2557 ········-F·auid!=unset·-F·key=perm_mod2557 ········-F·auid!=unset·-F·key=perm_mod
2558 ······create:·true2558 ······create:·true
2559 ······mode:·o-rwx2559 ······mode:·o-rwx
2560 ······state:·present2560 ······state:·present
2561 ····when:·syscalls_found·|·length·==·02561 ····when:·syscalls_found·|·length·==·0
2562 ··when:2562 ··when:
2563 ··-·'"audit"·in·ansible_facts.packages' 
2564 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2563 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2564 ··-·'"audit"·in·ansible_facts.packages'
2565 ··-·audit_arch·==·"b64"2565 ··-·audit_arch·==·"b64"
2566 ··tags:2566 ··tags:
2567 ··-·CCE-80685-12567 ··-·CCE-80685-1
2568 ··-·CJIS-5.4.1.12568 ··-·CJIS-5.4.1.1
2569 ··-·DISA-STIG-RHEL-08-0304902569 ··-·DISA-STIG-RHEL-08-030490
2570 ··-·NIST-800-171-3.1.72570 ··-·NIST-800-171-3.1.7
2571 ··-·NIST-800-53-AU-12(c)2571 ··-·NIST-800-53-AU-12(c)
Offset 2591, 15 lines modifiedOffset 2591, 15 lines modified
2591 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2591 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2592 Severity: ················medium2592 Severity: ················medium
2593 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2593 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2594 Identifiers·and·References·Identifiers: ·CCE-80686-92594 Identifiers·and·References·Identifiers: ·CCE-80686-9
2595 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030480,·4.1.3.9,·SV-230455r810459_rule2595 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030480,·4.1.3.9,·SV-230455r810459_rule
2596 Remediation_Shell_script_⇲2596 Remediation_Shell_script_⇲
2597 #·Remediation·is·applicable·only·in·certain·platforms2597 #·Remediation·is·applicable·only·in·certain·platforms
2598 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2598 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2599 #·First·perform·the·remediation·of·the·syscall·rule2599 #·First·perform·the·remediation·of·the·syscall·rule
2600 #·Retrieve·hardware·architecture·of·the·underlying·system2600 #·Retrieve·hardware·architecture·of·the·underlying·system
2601 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2601 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2602 for·ARCH·in·"${RULE_ARCHS[@]}"2602 for·ARCH·in·"${RULE_ARCHS[@]}"
2603 do2603 do
Max diff block lines reached; 134697/142423 bytes (94.58%) of diff not shown.
1.25 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-hipaa.html
    
Offset 23706, 93 lines modifiedOffset 23706, 93 lines modified
0005c990:·7267·6574·3d22·2369·646d·3137·3330·3122··rget="#idm17301"0005c990:·7267·6574·3d22·2369·646d·3137·3330·3122··rget="#idm17301"
0005c9a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0005c9a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0005c9b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0005c9b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0005c9c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0005c9c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0005c9d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0005c9d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0005c9e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0005c9e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0005c9f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0005c9f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0005ca00:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep
 0005ca10:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...
 0005ca20:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0005ca30:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0005ca40:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0005ca50:·2269·646d·3137·3330·3122·3e3c·7072·653e··"idm17301"><pre>
 0005ca60:·3c63·6f64·653e·0a5b·6375·7374·6f6d·697a··<code>.[customiz
 0005ca70:·6174·696f·6e73·2e73·6572·7669·6365·735d··ations.services]
 0005ca80:·0a64·6973·6162·6c65·6420·3d20·5b22·6465··.disabled·=·["de
 0005ca90:·6275·672d·7368·656c·6c22·5d0a·3c2f·636f··bug-shell"].</co
0005ca00:·6f6e·204b·7562·6572·6e65·7465·7320·736e··on·Kubernetes·sn 
0005ca10:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0005ca20:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0005ca30:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0005ca40:·6170·7365·2220·6964·3d22·6964·6d31·3733··apse"·id="idm173 
0005ca50:·3031·223e·3c70·7265·3e3c·636f·6465·3e2d··01"><pre><code>- 
0005ca60:·2d2d·0a61·7069·5665·7273·696f·6e3a·206d··--.apiVersion:·m 
0005ca70:·6163·6869·6e65·636f·6e66·6967·7572·6174··achineconfigurat 
0005ca80:·696f·6e2e·6f70·656e·7368·6966·742e·696f··ion.openshift.io 
0005ca90:·2f76·310a·6b69·6e64·3a20·4d61·6368·696e··/v1.kind:·Machin 
0005caa0:·6543·6f6e·6669·670a·7370·6563·3a0a·2020··eConfig.spec:.·· 
0005cab0:·636f·6e66·6967·3a0a·2020·2020·6967·6e69··config:.····igni 
0005cac0:·7469·6f6e·3a0a·2020·2020·2020·7665·7273··tion:.······vers 
0005cad0:·696f·6e3a·2033·2e31·2e30·0a20·2020·2073··ion:·3.1.0.····s 
0005cae0:·7973·7465·6d64·3a0a·2020·2020·2020·756e··ystemd:.······un 
0005caf0:·6974·733a·0a20·2020·2020·202d·2065·6e61··its:.······-·ena 
0005cb00:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.···· 
0005cb10:·2020·2020·6e61·6d65·3a20·6465·6275·672d······name:·debug- 
0005cb20:·7368·656c·6c2e·7365·7276·6963·650a·3c2f··shell.service.</ 
0005cb30:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0005caa0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0005cb40:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0005cab0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0005cb50:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0005cac0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0005cb60:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0005cad0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0005cb70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0005cae0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0005cb80:·2369·646d·3137·3330·3222·2074·6162·696e··#idm17302"·tabin0005caf0:·646d·3137·3330·3222·2074·6162·696e·6465··dm17302"·tabinde
0005cb90:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0005cb00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0005cba0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0005cb10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0005cbb0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0005cb20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0005cbc0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0005cb30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0005cbd0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0005cb40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0005cbe0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0005cb50:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
0005cbf0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0005cc00:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0005cc10:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0005cc20:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0005cc30:·6c61·7073·6522·2069·643d·2269·646d·3137··lapse"·id="idm17 
0005cc40:·3330·3222·3e3c·7072·653e·3c63·6f64·653e··302"><pre><code> 
0005cc50:·0a5b·6375·7374·6f6d·697a·6174·696f·6e73··.[customizations 
0005cc60:·2e73·6572·7669·6365·735d·0a64·6973·6162··.services].disab 
0005cc70:·6c65·6420·3d20·5b22·6465·6275·672d·7368··led·=·["debug-sh0005cb60:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0005cb70:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0005cb80:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0005cb90:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0005cba0:·6d31·3733·3032·223e·3c74·6162·6c65·2063··m17302"><table·c
 0005cbb0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0005cbc0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0005cbd0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0005cbe0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0005cbf0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0005cc00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0005cc10:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0005cc20:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0005cc30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0005cc40:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0005cc50:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0005cc60:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0005cc70:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 0005cc80:·2064·6973·6162·6c65·5f64·6562·7567·2d73···disable_debug-s
 0005cc90:·6865·6c6c·0a0a·636c·6173·7320·6469·7361··hell..class·disa
 0005cca0:·626c·655f·6465·6275·672d·7368·656c·6c20··ble_debug-shell·
 0005ccb0:·7b0a·2020·7365·7276·6963·6520·7b27·6465··{.··service·{'de
 0005ccc0:·6275·672d·7368·656c·6c27·3a0a·2020·2020··bug-shell':.····
 0005ccd0:·656e·6162·6c65·203d·2667·743b·2066·616c··enable·=&gt;·fal
 0005cce0:·7365·2c0a·2020·2020·656e·7375·7265·203d··se,.····ensure·=
 0005ccf0:·2667·743b·2027·7374·6f70·7065·6427·2c0a··&gt;·'stopped',.
0005cc80:·656c·6c22·5d0a·3c2f·636f·6465·3e3c·2f70··ell"].</code></p0005cd00:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
0005cc90:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0005cd10:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0005cca0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0005cd20:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0005ccb0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0005cd30:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0005ccc0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0005cd40:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0005ccd0:·7461·7267·6574·3d22·2369·646d·3137·3330··target="#idm17300005cd50:·7461·7267·6574·3d22·2369·646d·3137·3330··target="#idm1730
0005cce0:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·0005cd60:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·
0005ccf0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0005cd70:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0005cd00:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0005cd80:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0005cd10:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0005cd90:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0005cd20:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0005cda0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0005cd30:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0005cdb0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0005cd40:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip0005cdc0:·7469·6f6e·204b·7562·6572·6e65·7465·7320··tion·Kubernetes·
0005cd50:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0005cdd0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0005cd60:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0005cde0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0005cd70:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0005cdf0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0005cd80:·7365·2220·6964·3d22·6964·6d31·3733·3033··se"·id="idm173030005ce00:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0005ce10:·3733·3033·223e·3c70·7265·3e3c·636f·6465··7303"><pre><code
 0005ce20:·3e2d·2d2d·0a61·7069·5665·7273·696f·6e3a··>---.apiVersion:
 0005ce30:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur
 0005ce40:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift.
 0005ce50:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach
 0005ce60:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:.
 0005ce70:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig
 0005ce80:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve
 0005ce90:·7273·696f·6e3a·2033·2e31·2e30·0a20·2020··rsion:·3.1.0.···
 0005cea0:·2073·7973·7465·6d64·3a0a·2020·2020·2020···systemd:.······
 0005ceb0:·756e·6974·733a·0a20·2020·2020·202d·2065··units:.······-·e
 0005cec0:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.··
 0005ced0:·2020·2020·2020·6e61·6d65·3a20·6465·6275········name:·debu
 0005cee0:·672d·7368·656c·6c2e·7365·7276·6963·650a··g-shell.service.
0005cd90:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0005cda0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0005cdb0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0005cdc0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0005cdd0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0005cde0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0005cdf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0005ce00:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0005ce10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0005ce20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0005ce30:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0005ce40:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0005ce50:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0005ce60:·6465·3e69·6e63·6c75·6465·2064·6973·6162··de>include·disab 
Max diff block lines reached; 948397/959877 bytes (98.80%) of diff not shown.
341 KB
html2text {}
    
Offset 1362, 26 lines modifiedOffset 1362, 14 lines modified
1362 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:1362 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
1363 $·sudo·systemctl·mask·--now·debug-shell.service1363 $·sudo·systemctl·mask·--now·debug-shell.service
1364 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.1364 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
1365 Severity: ················medium1365 Severity: ················medium
1366 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1366 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1367 Identifiers·and·References·Identifiers: ·CCE-80876-61367 Identifiers·and·References·Identifiers: ·CCE-80876-6
1368 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227,·RHEL-08-040180,·SV-230532r627750_rule1368 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227,·RHEL-08-040180,·SV-230532r627750_rule
1369 Remediation_Kubernetes_snippet_⇲ 
1370 --- 
1371 apiVersion:·machineconfiguration.openshift.io/v1 
1372 kind:·MachineConfig 
1373 spec: 
1374 ··config: 
1375 ····ignition: 
1376 ······version:·3.1.0 
1377 ····systemd: 
1378 ······units: 
1379 ······-·enabled:·false 
1380 ········name:·debug-shell.service 
1381 Remediation_OSBuild_Blueprint_snippet_⇲1369 Remediation_OSBuild_Blueprint_snippet_⇲
  
1382 [customizations.services]1370 [customizations.services]
1383 disabled·=·["debug-shell"]1371 disabled·=·["debug-shell"]
1384 Remediation_Puppet_snippet_⇲1372 Remediation_Puppet_snippet_⇲
1385 Complexity:·low1373 Complexity:·low
1386 Disruption:·low1374 Disruption:·low
Offset 1390, 14 lines modifiedOffset 1378, 26 lines modified
  
1390 class·disable_debug-shell·{1378 class·disable_debug-shell·{
1391 ··service·{'debug-shell':1379 ··service·{'debug-shell':
1392 ····enable·=>·false,1380 ····enable·=>·false,
1393 ····ensure·=>·'stopped',1381 ····ensure·=>·'stopped',
1394 ··}1382 ··}
1395 }1383 }
 1384 Remediation_Kubernetes_snippet_⇲
 1385 ---
 1386 apiVersion:·machineconfiguration.openshift.io/v1
 1387 kind:·MachineConfig
 1388 spec:
 1389 ··config:
 1390 ····ignition:
 1391 ······version:·3.1.0
 1392 ····systemd:
 1393 ······units:
 1394 ······-·enabled:·false
 1395 ········name:·debug-shell.service
1396 Remediation_Shell_script_⇲1396 Remediation_Shell_script_⇲
1397 Complexity:·low1397 Complexity:·low
1398 Disruption:·low1398 Disruption:·low
1399 Strategy:···disable1399 Strategy:···disable
1400 #·Remediation·is·applicable·only·in·certain·platforms1400 #·Remediation·is·applicable·only·in·certain·platforms
1401 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1401 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
Offset 2331, 15 lines modifiedOffset 2331, 15 lines modified
2331 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2331 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2332 Severity: ················medium2332 Severity: ················medium
2333 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod2333 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
2334 Identifiers·and·References·Identifiers: ·CCE-80685-12334 Identifiers·and·References·Identifiers: ·CCE-80685-1
2335 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule2335 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule
2336 Remediation_Shell_script_⇲2336 Remediation_Shell_script_⇲
2337 #·Remediation·is·applicable·only·in·certain·platforms2337 #·Remediation·is·applicable·only·in·certain·platforms
2338 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2338 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2339 #·First·perform·the·remediation·of·the·syscall·rule2339 #·First·perform·the·remediation·of·the·syscall·rule
2340 #·Retrieve·hardware·architecture·of·the·underlying·system2340 #·Retrieve·hardware·architecture·of·the·underlying·system
2341 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2341 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2342 for·ARCH·in·"${RULE_ARCHS[@]}"2342 for·ARCH·in·"${RULE_ARCHS[@]}"
2343 do2343 do
Offset 2687, 16 lines modifiedOffset 2687, 16 lines modified
2687 ··-·reboot_required2687 ··-·reboot_required
2688 ··-·restrict_strategy2688 ··-·restrict_strategy
  
2689 -·name:·Set·architecture·for·audit·chmod·tasks2689 -·name:·Set·architecture·for·audit·chmod·tasks
2690 ··set_fact:2690 ··set_fact:
2691 ····audit_arch:·b642691 ····audit_arch:·b64
2692 ··when:2692 ··when:
2693 ··-·'"audit"·in·ansible_facts.packages' 
2694 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2693 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2694 ··-·'"audit"·in·ansible_facts.packages'
2695 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2695 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2696 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2696 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2697 ··tags:2697 ··tags:
2698 ··-·CCE-80685-12698 ··-·CCE-80685-1
2699 ··-·CJIS-5.4.1.12699 ··-·CJIS-5.4.1.1
2700 ··-·DISA-STIG-RHEL-08-0304902700 ··-·DISA-STIG-RHEL-08-030490
2701 ··-·NIST-800-171-3.1.72701 ··-·NIST-800-171-3.1.7
Offset 2834, 16 lines modifiedOffset 2834, 16 lines modified
2834 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002834 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2835 ········-F·auid!=unset·-F·key=perm_mod2835 ········-F·auid!=unset·-F·key=perm_mod
2836 ······create:·true2836 ······create:·true
2837 ······mode:·o-rwx2837 ······mode:·o-rwx
2838 ······state:·present2838 ······state:·present
2839 ····when:·syscalls_found·|·length·==·02839 ····when:·syscalls_found·|·length·==·0
2840 ··when:2840 ··when:
2841 ··-·'"audit"·in·ansible_facts.packages' 
2842 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2841 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2842 ··-·'"audit"·in·ansible_facts.packages'
2843 ··tags:2843 ··tags:
2844 ··-·CCE-80685-12844 ··-·CCE-80685-1
2845 ··-·CJIS-5.4.1.12845 ··-·CJIS-5.4.1.1
2846 ··-·DISA-STIG-RHEL-08-0304902846 ··-·DISA-STIG-RHEL-08-030490
2847 ··-·NIST-800-171-3.1.72847 ··-·NIST-800-171-3.1.7
2848 ··-·NIST-800-53-AU-12(c)2848 ··-·NIST-800-53-AU-12(c)
2849 ··-·NIST-800-53-AU-2(d)2849 ··-·NIST-800-53-AU-2(d)
Offset 2979, 16 lines modifiedOffset 2979, 16 lines modified
2979 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002979 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2980 ········-F·auid!=unset·-F·key=perm_mod2980 ········-F·auid!=unset·-F·key=perm_mod
2981 ······create:·true2981 ······create:·true
2982 ······mode:·o-rwx2982 ······mode:·o-rwx
2983 ······state:·present2983 ······state:·present
2984 ····when:·syscalls_found·|·length·==·02984 ····when:·syscalls_found·|·length·==·0
2985 ··when:2985 ··when:
2986 ··-·'"audit"·in·ansible_facts.packages' 
2987 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2986 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2987 ··-·'"audit"·in·ansible_facts.packages'
2988 ··-·audit_arch·==·"b64"2988 ··-·audit_arch·==·"b64"
2989 ··tags:2989 ··tags:
2990 ··-·CCE-80685-12990 ··-·CCE-80685-1
2991 ··-·CJIS-5.4.1.12991 ··-·CJIS-5.4.1.1
2992 ··-·DISA-STIG-RHEL-08-0304902992 ··-·DISA-STIG-RHEL-08-030490
2993 ··-·NIST-800-171-3.1.72993 ··-·NIST-800-171-3.1.7
2994 ··-·NIST-800-53-AU-12(c)2994 ··-·NIST-800-53-AU-12(c)
Offset 3014, 15 lines modifiedOffset 3014, 15 lines modified
3014 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.3014 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
3015 Severity: ················medium3015 Severity: ················medium
3016 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown3016 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
Max diff block lines reached; 342591/349353 bytes (98.06%) of diff not shown.
889 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-ism_o.html
    
Offset 18384, 116 lines modifiedOffset 18384, 116 lines modified
00047cf0:·7461·7267·6574·3d22·2369·646d·3835·3232··target="#idm852200047cf0:·7461·7267·6574·3d22·2369·646d·3835·3232··target="#idm8522
00047d00:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00047d00:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00047d10:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00047d10:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00047d20:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00047d20:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00047d30:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00047d30:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00047d40:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00047d40:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00047d50:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00047d50:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00047d60:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni00047d60:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp
00047d70:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>00047d70:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
00047d80:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane00047d80:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
00047d90:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00047d90:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
00047da0:·7073·6522·2069·643d·2269·646d·3835·3232··pse"·id="idm852200047da0:·6522·2069·643d·2269·646d·3835·3232·223e··e"·id="idm8522">
00047db0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="00047db0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
00047dc0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri00047dc0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
00047dd0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border00047dd0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
00047de0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens00047de0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
00047df0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp00047df0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
00047e00:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>00047e00:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
00047e10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00047e10:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
00047e20:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:00047e20:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
00047e30:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00047e30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00047e40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00047e40:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
00047e50:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>00047e50:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
00047e60:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>00047e60:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
00047e70:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co00047e70:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
00047e80:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad 
00047e90:·643d·6169·6465·0a3c·2f63·6f64·653e·3c2f··d=aide.</code></00047e80:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install
 00047e90:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins
 00047ea0:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa
 00047eb0:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':.
 00047ec0:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt;
 00047ed0:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.··
 00047ee0:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre
 00047ef0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 00047f00:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 00047f10:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 00047f20:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 00047f30:·7267·6574·3d22·2369·646d·3835·3233·2220··rget="#idm8523"·
 00047f40:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 00047f50:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 00047f60:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 00047f70:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 00047f80:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 00047f90:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 00047fa0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 00047fb0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00047fc0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00047fd0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00047fe0:·643d·2269·646d·3835·3233·223e·3c74·6162··d="idm8523"><tab
 00047ff0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00048000:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00048010:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00048020:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00048030:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00048040:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00048050:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00048060:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00048070:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00048080:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 00048090:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 000480a0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 000480b0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 000480c0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 000480d0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 000480e0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 000480f0:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d
 00048100:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;
 00048110:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru
 00048120:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·
 00048130:·5d3b·2074·6865·6e0a·0a69·6620·2120·7270··];·then..if·!·rp
 00048140:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 00048150:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y
 00048160:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a
 00048170:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 00048180:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 00048190:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 000481a0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 000481b0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 000481c0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
00047ea0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla000481d0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
00047eb0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ000481e0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
00047ec0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle000481f0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
00047ed0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data00048200:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
00047ee0:·2d74·6172·6765·743d·2223·6964·6d38·3532··-target="#idm85200048210:·2d74·6172·6765·743d·2223·6964·6d38·3532··-target="#idm852
00047ef0:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·00048220:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·
00047f00:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00048230:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00047f10:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00048240:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00047f20:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00048250:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00047f30:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00048260:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00047f40:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00048270:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00047f50:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip00048280:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
00047f60:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><00048290:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
00047f70:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel000482a0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
00047f80:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap000482b0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
00047f90:·7365·2220·6964·3d22·6964·6d38·3532·3322··se"·id="idm8523"000482c0:·6170·7365·2220·6964·3d22·6964·6d38·3532··apse"·id="idm852
00047fa0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t000482d0:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
00047fb0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip000482e0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
00047fc0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere000482f0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
00047fd0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense00048300:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
00047fe0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl00048310:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
00047ff0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l00048320:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
00048000:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00048330:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
00048010:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<00048340:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
00048020:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00048350:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00048030:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str00048360:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00048040:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e00048370:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00048050:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><00048380:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
00048060:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod00048390:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 000483a0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a
 000483b0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><
00048070:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal 
00048080:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in 
00048090:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p 
000480a0:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide': 
000480b0:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt 
000480c0:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.· 
000480d0:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr 
000480e0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
000480f0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
00048100:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
00048110:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
00048120:·6172·6765·743d·2223·6964·6d38·3532·3422··arget="#idm8524" 
00048130:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
00048140:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
00048150:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
00048160:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
00048170:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
Max diff block lines reached; 722698/737354 bytes (98.01%) of diff not shown.
169 KB
html2text {}
    
Offset 533, 20 lines modifiedOffset 533, 14 lines modified
533 Identifiers·and·References·Identifiers: ·CCE-80844-4533 Identifiers·and·References·Identifiers: ·CCE-80844-4
534 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule534 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
535 Remediation_OSBuild_Blueprint_snippet_⇲535 Remediation_OSBuild_Blueprint_snippet_⇲
  
536 [[packages]]536 [[packages]]
537 name·=·"aide"537 name·=·"aide"
538 version·=·"*"538 version·=·"*"
539 Remediation_Anaconda_snippet_⇲ 
540 Complexity:·low 
541 Disruption:·low 
542 Strategy:···enable 
  
543 package·--add=aide 
544 Remediation_Puppet_snippet_⇲539 Remediation_Puppet_snippet_⇲
545 Complexity:·low540 Complexity:·low
546 Disruption:·low541 Disruption:·low
547 Strategy:···enable542 Strategy:···enable
548 include·install_aide543 include·install_aide
  
549 class·install_aide·{544 class·install_aide·{
Offset 564, 14 lines modifiedOffset 558, 20 lines modified
564 if·!·rpm·-q·--quiet·"aide"·;·then558 if·!·rpm·-q·--quiet·"aide"·;·then
565 ····yum·install·-y·"aide"559 ····yum·install·-y·"aide"
566 fi560 fi
  
567 else561 else
568 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'562 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
569 fi563 fi
 564 Remediation_Anaconda_snippet_⇲
 565 Complexity:·low
 566 Disruption:·low
 567 Strategy:···enable
  
 568 package·--add=aide
570 Remediation_Ansible_snippet_⇲569 Remediation_Ansible_snippet_⇲
571 Complexity:·low570 Complexity:·low
572 Disruption:·low571 Disruption:·low
573 Strategy:···enable572 Strategy:···enable
574 -·name:·Ensure·aide·is·installed573 -·name:·Ensure·aide·is·installed
575 ··package:574 ··package:
576 ····name:·aide575 ····name:·aide
Offset 1014, 20 lines modifiedOffset 1014, 14 lines modified
1014 Identifiers·and·References·Identifiers: ·CCE-82214-81014 Identifiers·and·References·Identifiers: ·CCE-82214-8
1015 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11015 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1016 Remediation_OSBuild_Blueprint_snippet_⇲1016 Remediation_OSBuild_Blueprint_snippet_⇲
  
1017 [[packages]]1017 [[packages]]
1018 name·=·"sudo"1018 name·=·"sudo"
1019 version·=·"*"1019 version·=·"*"
1020 Remediation_Anaconda_snippet_⇲ 
1021 Complexity:·low 
1022 Disruption:·low 
1023 Strategy:···enable 
  
1024 package·--add=sudo 
1025 Remediation_Puppet_snippet_⇲1020 Remediation_Puppet_snippet_⇲
1026 Complexity:·low1021 Complexity:·low
1027 Disruption:·low1022 Disruption:·low
1028 Strategy:···enable1023 Strategy:···enable
1029 include·install_sudo1024 include·install_sudo
  
1030 class·install_sudo·{1025 class·install_sudo·{
Offset 1045, 14 lines modifiedOffset 1039, 20 lines modified
1045 if·!·rpm·-q·--quiet·"sudo"·;·then1039 if·!·rpm·-q·--quiet·"sudo"·;·then
1046 ····yum·install·-y·"sudo"1040 ····yum·install·-y·"sudo"
1047 fi1041 fi
  
1048 else1042 else
1049 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1043 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1050 fi1044 fi
 1045 Remediation_Anaconda_snippet_⇲
 1046 Complexity:·low
 1047 Disruption:·low
 1048 Strategy:···enable
  
 1049 package·--add=sudo
1051 Remediation_Ansible_snippet_⇲1050 Remediation_Ansible_snippet_⇲
1052 Complexity:·low1051 Complexity:·low
1053 Disruption:·low1052 Disruption:·low
1054 Strategy:···enable1053 Strategy:···enable
1055 -·name:·Ensure·sudo·is·installed1054 -·name:·Ensure·sudo·is·installed
1056 ··package:1055 ··package:
1057 ····name:·sudo1056 ····name:·sudo
Offset 1335, 20 lines modifiedOffset 1335, 14 lines modified
1335 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed1335 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
1336 Identifiers·and·References·Identifiers: ·CCE-82883-01336 Identifiers·and·References·Identifiers: ·CCE-82883-0
1337 Remediation_OSBuild_Blueprint_snippet_⇲1337 Remediation_OSBuild_Blueprint_snippet_⇲
  
1338 [[packages]]1338 [[packages]]
1339 name·=·"rear"1339 name·=·"rear"
1340 version·=·"*"1340 version·=·"*"
1341 Remediation_Anaconda_snippet_⇲ 
1342 Complexity:·low 
1343 Disruption:·low 
1344 Strategy:···enable 
  
1345 package·--add=rear 
1346 Remediation_Puppet_snippet_⇲1341 Remediation_Puppet_snippet_⇲
1347 Complexity:·low1342 Complexity:·low
1348 Disruption:·low1343 Disruption:·low
1349 Strategy:···enable1344 Strategy:···enable
1350 include·install_rear1345 include·install_rear
  
1351 class·install_rear·{1346 class·install_rear·{
Offset 1360, 14 lines modifiedOffset 1354, 20 lines modified
1360 Complexity:·low1354 Complexity:·low
1361 Disruption:·low1355 Disruption:·low
1362 Strategy:···enable1356 Strategy:···enable
  
1363 if·!·rpm·-q·--quiet·"rear"·;·then1357 if·!·rpm·-q·--quiet·"rear"·;·then
1364 ····yum·install·-y·"rear"1358 ····yum·install·-y·"rear"
1365 fi1359 fi
 1360 Remediation_Anaconda_snippet_⇲
 1361 Complexity:·low
 1362 Disruption:·low
 1363 Strategy:···enable
  
 1364 package·--add=rear
1366 Remediation_Ansible_snippet_⇲1365 Remediation_Ansible_snippet_⇲
1367 Complexity:·low1366 Complexity:·low
1368 Disruption:·low1367 Disruption:·low
1369 Strategy:···enable1368 Strategy:···enable
1370 -·name:·Ensure·rear·is·installed1369 -·name:·Ensure·rear·is·installed
1371 ··package:1370 ··package:
1372 ····name:·rear1371 ····name:·rear
Offset 6491, 15 lines modifiedOffset 6491, 15 lines modified
6491 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.6491 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
Max diff block lines reached; 168752/172533 bytes (97.81%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-ospp.html
    
Offset 15443, 116 lines modifiedOffset 15443, 116 lines modified
0003c520:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003c520:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c530:·2223·6964·6d38·3532·3222·2074·6162·696e··"#idm8522"·tabin0003c530:·2223·6964·6d38·3532·3222·2074·6162·696e··"#idm8522"·tabin
0003c540:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003c540:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c550:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003c550:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c560:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003c560:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c570:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003c570:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c580:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003c580:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c590:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003c590:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
0003c5a0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003c5a0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
0003c5b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c5b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003c5c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003c5c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003c5d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003c5d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003c5e0:·3d22·6964·6d38·3532·3222·3e3c·7461·626c··="idm8522"><tabl0003c5e0:·6964·6d38·3532·3222·3e3c·7461·626c·6520··idm8522"><table·
0003c5f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003c5f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003c600:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003c600:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003c610:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003c610:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003c620:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003c620:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003c630:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003c630:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003c640:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c640:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003c650:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003c650:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003c660:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003c660:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003c670:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c670:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c680:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003c680:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003c690:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c690:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003c6a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003c6a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003c6b0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac0003c6b0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
0003c6c0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.0003c6c0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003c6d0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003c6e0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003c6f0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003c700:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003c710:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003c720:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003c730:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003c740:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003c750:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003c760:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003c770:·6964·6d38·3532·3322·2074·6162·696e·6465··idm8523"·tabinde
 0003c780:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003c790:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003c7a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003c7b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003c7c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003c7d0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003c7e0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003c7f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003c800:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003c810:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 0003c820:·3532·3322·3e3c·7461·626c·6520·636c·6173··523"><table·clas
 0003c830:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003c840:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003c850:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003c860:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003c870:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003c880:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003c890:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003c8a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003c8b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003c8c0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003c8d0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003c8e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003c8f0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003c900:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003c910:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003c920:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 0003c930:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
 0003c940:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
 0003c950:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
 0003c960:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
 0003c970:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003c980:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003c990:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 0003c9a0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003c9b0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003c9c0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003c9d0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003c9e0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003c9f0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
0003c6d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003ca00:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003c6e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003ca10:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003c6f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003ca20:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003c700:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003ca30:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003c710:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003ca40:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003c720:·3d22·2369·646d·3835·3233·2220·7461·6269··="#idm8523"·tabi0003ca50:·3d22·2369·646d·3835·3234·2220·7461·6269··="#idm8524"·tabi
0003c730:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ca60:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003c740:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003ca70:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003c750:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003ca80:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003c760:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003ca90:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003c770:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003caa0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003c780:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003cab0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003c790:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003cac0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003c7a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003cad0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003c7b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003cae0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003c7c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003caf0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003c7d0:·2269·646d·3835·3233·223e·3c74·6162·6c65··"idm8523"><table0003cb00:·643d·2269·646d·3835·3234·223e·3c74·6162··d="idm8524"><tab
0003c7e0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003cb10:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003c7f0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003cb20:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003c800:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003cb30:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003c810:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003cb40:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003c820:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003cb50:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003c830:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003cb60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c840:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003cb70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003c850:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003cb80:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003c860:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003cb90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c870:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003cba0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003c880:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003cbb0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003c890:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003cbc0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003cbd0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003cbe0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
0003c8a0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003c8b0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003c8c0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003c8d0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003c8e0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003c8f0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003c900:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003c910:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003c920:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003c930:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003c940:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003c950:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003c960:·2369·646d·3835·3234·2220·7461·6269·6e64··#idm8524"·tabind 
0003c970:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003c980:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003c990:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003c9a0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003c9b0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
Max diff block lines reached; 974338/988994 bytes (98.52%) of diff not shown.
96.0 KB
html2text {}
    
Offset 101, 20 lines modifiedOffset 101, 14 lines modified
101 Identifiers·and·References·Identifiers: ·CCE-80844-4101 Identifiers·and·References·Identifiers: ·CCE-80844-4
102 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule102 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
103 Remediation_OSBuild_Blueprint_snippet_⇲103 Remediation_OSBuild_Blueprint_snippet_⇲
  
104 [[packages]]104 [[packages]]
105 name·=·"aide"105 name·=·"aide"
106 version·=·"*"106 version·=·"*"
107 Remediation_Anaconda_snippet_⇲ 
108 Complexity:·low 
109 Disruption:·low 
110 Strategy:···enable 
  
111 package·--add=aide 
112 Remediation_Puppet_snippet_⇲107 Remediation_Puppet_snippet_⇲
113 Complexity:·low108 Complexity:·low
114 Disruption:·low109 Disruption:·low
115 Strategy:···enable110 Strategy:···enable
116 include·install_aide111 include·install_aide
  
117 class·install_aide·{112 class·install_aide·{
Offset 132, 14 lines modifiedOffset 126, 20 lines modified
132 if·!·rpm·-q·--quiet·"aide"·;·then126 if·!·rpm·-q·--quiet·"aide"·;·then
133 ····yum·install·-y·"aide"127 ····yum·install·-y·"aide"
134 fi128 fi
  
135 else129 else
136 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'130 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
137 fi131 fi
 132 Remediation_Anaconda_snippet_⇲
 133 Complexity:·low
 134 Disruption:·low
 135 Strategy:···enable
  
 136 package·--add=aide
138 Remediation_Ansible_snippet_⇲137 Remediation_Ansible_snippet_⇲
139 Complexity:·low138 Complexity:·low
140 Disruption:·low139 Disruption:·low
141 Strategy:···enable140 Strategy:···enable
142 -·name:·Ensure·aide·is·installed141 -·name:·Ensure·aide·is·installed
143 ··package:142 ··package:
144 ····name:·aide143 ····name:·aide
Offset 415, 20 lines modifiedOffset 415, 14 lines modified
415 Identifiers·and·References·Identifiers: ·CCE-82723-8415 Identifiers·and·References·Identifiers: ·CCE-82723-8
416 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174416 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
417 Remediation_OSBuild_Blueprint_snippet_⇲417 Remediation_OSBuild_Blueprint_snippet_⇲
  
418 [[packages]]418 [[packages]]
419 name·=·"crypto-policies"419 name·=·"crypto-policies"
420 version·=·"*"420 version·=·"*"
421 Remediation_Anaconda_snippet_⇲ 
422 Complexity:·low 
423 Disruption:·low 
424 Strategy:···enable 
  
425 package·--add=crypto-policies 
426 Remediation_Puppet_snippet_⇲421 Remediation_Puppet_snippet_⇲
427 Complexity:·low422 Complexity:·low
428 Disruption:·low423 Disruption:·low
429 Strategy:···enable424 Strategy:···enable
430 include·install_crypto-policies425 include·install_crypto-policies
  
431 class·install_crypto-policies·{426 class·install_crypto-policies·{
Offset 440, 14 lines modifiedOffset 434, 20 lines modified
440 Complexity:·low434 Complexity:·low
441 Disruption:·low435 Disruption:·low
442 Strategy:···enable436 Strategy:···enable
  
443 if·!·rpm·-q·--quiet·"crypto-policies"·;·then437 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
444 ····yum·install·-y·"crypto-policies"438 ····yum·install·-y·"crypto-policies"
445 fi439 fi
 440 Remediation_Anaconda_snippet_⇲
 441 Complexity:·low
 442 Disruption:·low
 443 Strategy:···enable
  
 444 package·--add=crypto-policies
446 Remediation_Ansible_snippet_⇲445 Remediation_Ansible_snippet_⇲
447 Complexity:·low446 Complexity:·low
448 Disruption:·low447 Disruption:·low
449 Strategy:···enable448 Strategy:···enable
450 -·name:·Ensure·crypto-policies·is·installed449 -·name:·Ensure·crypto-policies·is·installed
451 ··package:450 ··package:
452 ····name:·crypto-policies451 ····name:·crypto-policies
Offset 1040, 20 lines modifiedOffset 1040, 14 lines modified
1040 Identifiers·and·References·Identifiers: ·CCE-82214-81040 Identifiers·and·References·Identifiers: ·CCE-82214-8
1041 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.11041 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125,·5.3.1
1042 Remediation_OSBuild_Blueprint_snippet_⇲1042 Remediation_OSBuild_Blueprint_snippet_⇲
  
1043 [[packages]]1043 [[packages]]
1044 name·=·"sudo"1044 name·=·"sudo"
1045 version·=·"*"1045 version·=·"*"
1046 Remediation_Anaconda_snippet_⇲ 
1047 Complexity:·low 
1048 Disruption:·low 
1049 Strategy:···enable 
  
1050 package·--add=sudo 
1051 Remediation_Puppet_snippet_⇲1046 Remediation_Puppet_snippet_⇲
1052 Complexity:·low1047 Complexity:·low
1053 Disruption:·low1048 Disruption:·low
1054 Strategy:···enable1049 Strategy:···enable
1055 include·install_sudo1050 include·install_sudo
  
1056 class·install_sudo·{1051 class·install_sudo·{
Offset 1071, 14 lines modifiedOffset 1065, 20 lines modified
1071 if·!·rpm·-q·--quiet·"sudo"·;·then1065 if·!·rpm·-q·--quiet·"sudo"·;·then
1072 ····yum·install·-y·"sudo"1066 ····yum·install·-y·"sudo"
1073 fi1067 fi
  
1074 else1068 else
1075 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1069 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1076 fi1070 fi
 1071 Remediation_Anaconda_snippet_⇲
 1072 Complexity:·low
 1073 Disruption:·low
 1074 Strategy:···enable
  
 1075 package·--add=sudo
1077 Remediation_Ansible_snippet_⇲1076 Remediation_Ansible_snippet_⇲
1078 Complexity:·low1077 Complexity:·low
1079 Disruption:·low1078 Disruption:·low
1080 Strategy:···enable1079 Strategy:···enable
1081 -·name:·Ensure·sudo·is·installed1080 -·name:·Ensure·sudo·is·installed
1082 ··package:1081 ··package:
1083 ····name:·sudo1082 ····name:·sudo
Offset 1105, 20 lines modifiedOffset 1105, 14 lines modified
1105 Identifiers·and·References·Identifiers: ·CCE-82315-31105 Identifiers·and·References·Identifiers: ·CCE-82315-3
Max diff block lines reached; 94445/98316 bytes (96.06%) of diff not shown.
972 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-pci-dss.html
    
Offset 17349, 116 lines modifiedOffset 17349, 116 lines modified
00043c40:·6172·6765·743d·2223·6964·6d38·3532·3222··arget="#idm8522"00043c40:·6172·6765·743d·2223·6964·6d38·3532·3222··arget="#idm8522"
00043c50:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00043c50:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00043c60:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00043c60:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00043c70:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00043c70:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00043c80:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00043c80:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00043c90:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00043c90:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00043ca0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00043ca0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
00043cb0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip00043cb0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe
00043cc0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><00043cc0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
00043cd0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel00043cd0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00043ce0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap00043ce0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
00043cf0:·7365·2220·6964·3d22·6964·6d38·3532·3222··se"·id="idm8522"00043cf0:·2220·6964·3d22·6964·6d38·3532·3222·3e3c··"·id="idm8522"><
00043d00:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t00043d00:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
00043d10:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip00043d10:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
00043d20:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere00043d20:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
00043d30:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense00043d30:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
00043d40:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl00043d40:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
00043d50:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l00043d50:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00043d60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00043d60:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00043d70:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<00043d70:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
00043d80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00043d80:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
00043d90:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str00043d90:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
00043da0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e00043da0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
00043db0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><00043db0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
00043dc0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod00043dc0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
00043dd0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add00043dd0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_
 00043de0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst
 00043df0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac
 00043e00:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.·
 00043e10:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 00043e20:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 00043e30:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 00043e40:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 00043e50:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00043e60:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00043e70:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 00043e80:·6765·743d·2223·6964·6d38·3532·3322·2074··get="#idm8523"·t
 00043e90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 00043ea0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 00043eb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 00043ec0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 00043ed0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 00043ee0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 00043ef0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 00043f00:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00043f10:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00043f20:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00043f30:·3d22·6964·6d38·3532·3322·3e3c·7461·626c··="idm8523"><tabl
 00043f40:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00043f50:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00043f60:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00043f70:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00043f80:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00043f90:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00043fa0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00043fb0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00043fc0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00043fd0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 00043fe0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 00043ff0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00044000:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 00044010:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 00044020:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 00044030:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 00044040:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do
 00044050:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&
 00044060:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run
 00044070:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]
 00044080:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 00044090:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid
 000440a0:·6522·203b·2074·6865·6e0a·2020·2020·7975··e"·;·then.····yu
 000440b0:·6d20·696e·7374·616c·6c20·2d79·2022·6169··m·install·-y·"ai
 000440c0:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.···
 000440d0:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo
 000440e0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is
 000440f0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable,
 00044100:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don
00043de0:·3d61·6964·650a·3c2f·636f·6465·3e3c·2f70··=aide.</code></p00044110:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p
00043df0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas00044120:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
00043e00:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe00044130:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
00043e10:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=00044140:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
00043e20:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-00044150:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
00043e30:·7461·7267·6574·3d22·2369·646d·3835·3233··target="#idm852300044160:·7461·7267·6574·3d22·2369·646d·3835·3234··target="#idm8524
00043e40:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00044170:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00043e50:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00044180:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00043e60:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00044190:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00043e70:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa000441a0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00043e80:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr000441b0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00043e90:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat000441c0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00043ea0:·696f·6e20·5075·7070·6574·2073·6e69·7070··ion·Puppet·snipp000441d0:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
00043eb0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d000441e0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
00043ec0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-000441f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00043ed0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00044200:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00043ee0:·6522·2069·643d·2269·646d·3835·3233·223e··e"·id="idm8523">00044210:·7073·6522·2069·643d·2269·646d·3835·3234··pse"·id="idm8524
00043ef0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta00044220:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
00043f00:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00044230:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00043f10:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00044240:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
00043f20:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed00044250:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
00043f30:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00044260:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
00043f40:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo00044270:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
00043f50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00044280:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00043f60:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</00044290:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
00043f70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><000442a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00043f80:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra000442b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
00043f90:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en000442c0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
00043fa0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></000442d0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
00043fb0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code000442e0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 000442f0:·6465·3e0a·7061·636b·6167·6520·2d2d·6164··de>.package·--ad
00043fc0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
00043fd0:·5f61·6964·650a·0a63·6c61·7373·2069·6e73··_aide..class·ins 
00043fe0:·7461·6c6c·5f61·6964·6520·7b0a·2020·7061··tall_aide·{.··pa 
00043ff0:·636b·6167·6520·7b20·2761·6964·6527·3a0a··ckage·{·'aide':. 
00044000:·2020·2020·656e·7375·7265·203d·2667·743b······ensure·=&gt; 
00044010:·2027·696e·7374·616c·6c65·6427·2c0a·2020···'installed',.·· 
00044020:·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70·7265··}.}.</code></pre 
00044030:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00044040:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00044050:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00044060:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00044070:·7267·6574·3d22·2369·646d·3835·3234·2220··rget="#idm8524"· 
00044080:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00044090:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
000440a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
000440b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
000440c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
000440d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
000440e0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
Max diff block lines reached; 706600/721256 bytes (97.97%) of diff not shown.
267 KB
html2text {}
    
Offset 401, 20 lines modifiedOffset 401, 14 lines modified
401 Identifiers·and·References·Identifiers: ·CCE-80844-4401 Identifiers·and·References·Identifiers: ·CCE-80844-4
402 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule402 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
403 Remediation_OSBuild_Blueprint_snippet_⇲403 Remediation_OSBuild_Blueprint_snippet_⇲
  
404 [[packages]]404 [[packages]]
405 name·=·"aide"405 name·=·"aide"
406 version·=·"*"406 version·=·"*"
407 Remediation_Anaconda_snippet_⇲ 
408 Complexity:·low 
409 Disruption:·low 
410 Strategy:···enable 
  
411 package·--add=aide 
412 Remediation_Puppet_snippet_⇲407 Remediation_Puppet_snippet_⇲
413 Complexity:·low408 Complexity:·low
414 Disruption:·low409 Disruption:·low
415 Strategy:···enable410 Strategy:···enable
416 include·install_aide411 include·install_aide
  
417 class·install_aide·{412 class·install_aide·{
Offset 432, 14 lines modifiedOffset 426, 20 lines modified
432 if·!·rpm·-q·--quiet·"aide"·;·then426 if·!·rpm·-q·--quiet·"aide"·;·then
433 ····yum·install·-y·"aide"427 ····yum·install·-y·"aide"
434 fi428 fi
  
435 else429 else
436 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'430 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
437 fi431 fi
 432 Remediation_Anaconda_snippet_⇲
 433 Complexity:·low
 434 Disruption:·low
 435 Strategy:···enable
  
 436 package·--add=aide
438 Remediation_Ansible_snippet_⇲437 Remediation_Ansible_snippet_⇲
439 Complexity:·low438 Complexity:·low
440 Disruption:·low439 Disruption:·low
441 Strategy:···enable440 Strategy:···enable
442 -·name:·Ensure·aide·is·installed441 -·name:·Ensure·aide·is·installed
443 ··package:442 ··package:
444 ····name:·aide443 ····name:·aide
Offset 6535, 20 lines modifiedOffset 6535, 14 lines modified
6535 Identifiers·and·References·Identifiers: ·CCE-80846-96535 Identifiers·and·References·Identifiers: ·CCE-80846-9
6536 ···························References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520,·RHEL-08-010410,·SV-230275r854030_rule6536 ···························References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520,·RHEL-08-010410,·SV-230275r854030_rule
6537 Remediation_OSBuild_Blueprint_snippet_⇲6537 Remediation_OSBuild_Blueprint_snippet_⇲
  
6538 [[packages]]6538 [[packages]]
6539 name·=·"opensc"6539 name·=·"opensc"
6540 version·=·"*"6540 version·=·"*"
6541 Remediation_Anaconda_snippet_⇲ 
6542 Complexity:·low 
6543 Disruption:·low 
6544 Strategy:···enable 
  
6545 package·--add=opensc 
6546 Remediation_Puppet_snippet_⇲6541 Remediation_Puppet_snippet_⇲
6547 Complexity:·low6542 Complexity:·low
6548 Disruption:·low6543 Disruption:·low
6549 Strategy:···enable6544 Strategy:···enable
6550 include·install_opensc6545 include·install_opensc
  
6551 class·install_opensc·{6546 class·install_opensc·{
Offset 6566, 14 lines modifiedOffset 6560, 20 lines modified
6566 if·!·rpm·-q·--quiet·"opensc"·;·then6560 if·!·rpm·-q·--quiet·"opensc"·;·then
6567 ····yum·install·-y·"opensc"6561 ····yum·install·-y·"opensc"
6568 fi6562 fi
  
6569 else6563 else
6570 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6564 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6571 fi6565 fi
 6566 Remediation_Anaconda_snippet_⇲
 6567 Complexity:·low
 6568 Disruption:·low
 6569 Strategy:···enable
  
 6570 package·--add=opensc
6572 Remediation_Ansible_snippet_⇲6571 Remediation_Ansible_snippet_⇲
6573 Complexity:·low6572 Complexity:·low
6574 Disruption:·low6573 Disruption:·low
6575 Strategy:···enable6574 Strategy:···enable
6576 -·name:·Ensure·opensc·is·installed6575 -·name:·Ensure·opensc·is·installed
6577 ··package:6576 ··package:
6578 ····name:·opensc6577 ····name:·opensc
Offset 6598, 20 lines modifiedOffset 6598, 14 lines modified
6598 Identifiers·and·References·Identifiers: ·CCE-80993-96598 Identifiers·and·References·Identifiers: ·CCE-80993-9
6599 ···························References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015306599 ···························References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
6600 Remediation_OSBuild_Blueprint_snippet_⇲6600 Remediation_OSBuild_Blueprint_snippet_⇲
  
6601 [[packages]]6601 [[packages]]
6602 name·=·"pcsc-lite"6602 name·=·"pcsc-lite"
6603 version·=·"*"6603 version·=·"*"
6604 Remediation_Anaconda_snippet_⇲ 
6605 Complexity:·low 
6606 Disruption:·low 
6607 Strategy:···enable 
  
6608 package·--add=pcsc-lite 
6609 Remediation_Puppet_snippet_⇲6604 Remediation_Puppet_snippet_⇲
6610 Complexity:·low6605 Complexity:·low
6611 Disruption:·low6606 Disruption:·low
6612 Strategy:···enable6607 Strategy:···enable
6613 include·install_pcsc-lite6608 include·install_pcsc-lite
  
6614 class·install_pcsc-lite·{6609 class·install_pcsc-lite·{
Offset 6629, 14 lines modifiedOffset 6623, 20 lines modified
6629 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then6623 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
6630 ····yum·install·-y·"pcsc-lite"6624 ····yum·install·-y·"pcsc-lite"
6631 fi6625 fi
  
6632 else6626 else
6633 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6627 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6634 fi6628 fi
 6629 Remediation_Anaconda_snippet_⇲
 6630 Complexity:·low
 6631 Disruption:·low
 6632 Strategy:···enable
  
 6633 package·--add=pcsc-lite
6635 Remediation_Ansible_snippet_⇲6634 Remediation_Ansible_snippet_⇲
6636 Complexity:·low6635 Complexity:·low
6637 Disruption:·low6636 Disruption:·low
6638 Strategy:···enable6637 Strategy:···enable
6639 -·name:·Ensure·pcsc-lite·is·installed6638 -·name:·Ensure·pcsc-lite·is·installed
6640 ··package:6639 ··package:
6641 ····name:·pcsc-lite6640 ····name:·pcsc-lite
Offset 7501, 15 lines modifiedOffset 7501, 15 lines modified
7501 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.7501 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
Max diff block lines reached; 269585/273563 bytes (98.55%) of diff not shown.
113 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-rht-ccp.html
    
Offset 15390, 116 lines modifiedOffset 15390, 116 lines modified
0003c1d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003c1d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003c1e0:·2369·646d·3835·3232·2220·7461·6269·6e64··#idm8522"·tabind0003c1e0:·2369·646d·3835·3232·2220·7461·6269·6e64··#idm8522"·tabind
0003c1f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003c1f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003c200:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003c200:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003c210:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003c210:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c220:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003c220:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c230:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003c230:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c240:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac0003c240:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp
0003c250:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...0003c250:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</
0003c260:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003c260:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003c270:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003c270:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003c280:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003c280:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003c290:·2269·646d·3835·3232·223e·3c74·6162·6c65··"idm8522"><table0003c290:·646d·3835·3232·223e·3c74·6162·6c65·2063··dm8522"><table·c
0003c2a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003c2a0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003c2b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003c2b0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003c2c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003c2c0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003c2d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003c2d0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003c2e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003c2e0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003c2f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c2f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003c300:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003c300:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003c310:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003c310:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003c320:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003c320:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003c330:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003c330:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003c340:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003c340:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003c350:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003c350:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0003c360:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack 
0003c370:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<0003c360:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include
 0003c370:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c
 0003c380:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid
 0003c390:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{·
 0003c3a0:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu
 0003c3b0:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal
 0003c3c0:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co
 0003c3d0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003c3e0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003c3f0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003c400:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003c410:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003c420:·646d·3835·3233·2220·7461·6269·6e64·6578··dm8523"·tabindex
 0003c430:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003c440:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003c450:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003c460:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003c470:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003c480:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 0003c490:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003c4a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003c4b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003c4c0:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm85
 0003c4d0:·3233·223e·3c74·6162·6c65·2063·6c61·7373··23"><table·class
 0003c4e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003c4f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003c500:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003c510:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003c520:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003c530:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003c540:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003c550:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003c560:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003c570:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003c580:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003c590:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003c5a0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0003c5b0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0003c5c0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0003c5d0:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
 0003c5e0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
 0003c5f0:·205d·2026·616d·703b·2661·6d70·3b20·5b20···]·&amp;&amp;·[·
 0003c600:·2120·2d66·202f·7275·6e2f·2e63·6f6e·7461··!·-f·/run/.conta
 0003c610:·696e·6572·656e·7620·5d3b·2074·6865·6e0a··inerenv·];·then.
 0003c620:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 0003c630:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 0003c640:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta
 0003c650:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 0003c660:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 0003c670:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 0003c680:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 0003c690:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 0003c6a0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
0003c380:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003c6b0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003c390:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003c6c0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003c3a0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003c6d0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003c3b0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003c6e0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003c3c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003c6f0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c3d0:·2223·6964·6d38·3532·3322·2074·6162·696e··"#idm8523"·tabin0003c700:·2223·6964·6d38·3532·3422·2074·6162·696e··"#idm8524"·tabin
0003c3e0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003c710:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c3f0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003c720:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c400:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003c730:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c410:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003c740:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c420:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003c750:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c430:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup0003c760:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana
0003c440:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<0003c770:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..
0003c450:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003c780:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003c460:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003c790:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003c470:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003c7a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003c480:·6964·6d38·3532·3322·3e3c·7461·626c·6520··idm8523"><table·0003c7b0:·3d22·6964·6d38·3532·3422·3e3c·7461·626c··="idm8524"><tabl
0003c490:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003c7c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003c4a0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003c7d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003c4b0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003c7e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003c4c0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003c7f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003c4d0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003c800:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003c4e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003c810:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c4f0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003c820:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003c500:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003c830:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003c510:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003c840:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c520:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003c850:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003c530:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003c860:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003c540:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003c870:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003c880:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003c890:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.
0003c550:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ 
0003c560:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide.. 
0003c570:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai 
0003c580:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{ 
0003c590:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens 
0003c5a0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta 
0003c5b0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c 
0003c5c0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003c5d0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003c5e0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003c5f0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003c600:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003c610:·6964·6d38·3532·3422·2074·6162·696e·6465··idm8524"·tabinde 
0003c620:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003c630:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003c640:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003c650:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
Max diff block lines reached; 79998/94654 bytes (84.52%) of diff not shown.
20.4 KB
html2text {}
    
Offset 91, 20 lines modifiedOffset 91, 14 lines modified
91 Identifiers·and·References·Identifiers: ·CCE-80844-491 Identifiers·and·References·Identifiers: ·CCE-80844-4
92 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule92 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
93 Remediation_OSBuild_Blueprint_snippet_⇲93 Remediation_OSBuild_Blueprint_snippet_⇲
  
94 [[packages]]94 [[packages]]
95 name·=·"aide"95 name·=·"aide"
96 version·=·"*"96 version·=·"*"
97 Remediation_Anaconda_snippet_⇲ 
98 Complexity:·low 
99 Disruption:·low 
100 Strategy:···enable 
  
101 package·--add=aide 
102 Remediation_Puppet_snippet_⇲97 Remediation_Puppet_snippet_⇲
103 Complexity:·low98 Complexity:·low
104 Disruption:·low99 Disruption:·low
105 Strategy:···enable100 Strategy:···enable
106 include·install_aide101 include·install_aide
  
107 class·install_aide·{102 class·install_aide·{
Offset 122, 14 lines modifiedOffset 116, 20 lines modified
122 if·!·rpm·-q·--quiet·"aide"·;·then116 if·!·rpm·-q·--quiet·"aide"·;·then
123 ····yum·install·-y·"aide"117 ····yum·install·-y·"aide"
124 fi118 fi
  
125 else119 else
126 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'120 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
127 fi121 fi
 122 Remediation_Anaconda_snippet_⇲
 123 Complexity:·low
 124 Disruption:·low
 125 Strategy:···enable
  
 126 package·--add=aide
128 Remediation_Ansible_snippet_⇲127 Remediation_Ansible_snippet_⇲
129 Complexity:·low128 Complexity:·low
130 Disruption:·low129 Disruption:·low
131 Strategy:···enable130 Strategy:···enable
132 -·name:·Ensure·aide·is·installed131 -·name:·Ensure·aide·is·installed
133 ··package:132 ··package:
134 ····name:·aide133 ····name:·aide
Offset 4845, 15 lines modifiedOffset 4845, 15 lines modified
4845 Rationale:·················If·users·can·write·to·audit·logs,·audit·trails·can·be·modified·or·destroyed.4845 Rationale:·················If·users·can·write·to·audit·logs,·audit·trails·can·be·modified·or·destroyed.
4846 Severity: ················medium4846 Severity: ················medium
4847 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit4847 Rule·ID:···················xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit
4848 Identifiers·and·References·Identifiers: ·CCE-80819-64848 Identifiers·and·References·Identifiers: ·CCE-80819-6
4849 ···························References: ·1,·11,·12,·13,·14,·15,·16,·18,·19,·3,·4,·5,·6,·7,·8,·5.4.1.1,·APO01.06,·APO11.04,·APO12.06,·BAI03.05,·BAI08.02,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS05.04,·DSS05.07,·DSS06.02,·MEA02.01,·3.3.1,·CCI-000162,·CCI-000163,·CCI-000164,·CCI-001314,·4.2.3.10,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.7.3,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.1,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_5.2,·SR_6.1,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CIP-003-8_R5.1.1,·CIP-003-8_R5.3,·CIP-004-6_R2.3,·CIP-007-3_R2.1,·CIP-007-3_R2.2,·CIP-007-3_R2.3,·CIP-007-3_R5.1,·CIP-007-3_R5.1.1,·CIP-007-3_R5.1.2,·CM-6(a),·AC-6(1),·AU-9(4),·DE.AE-3,·DE.AE-5,·PR.AC-4,·PR.DS-5,·PR.PT-1,·RS.AN-1,·RS.AN-4,·Req-10.5,·SRG-OS-000057-GPOS-00027,·SRG-OS-000058-GPOS-00028,·SRG-OS-000059-GPOS-00029,·SRG-OS-000206-GPOS-00084,·RHEL-08-030070,·SV-230396r627750_rule4849 ···························References: ·1,·11,·12,·13,·14,·15,·16,·18,·19,·3,·4,·5,·6,·7,·8,·5.4.1.1,·APO01.06,·APO11.04,·APO12.06,·BAI03.05,·BAI08.02,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS05.04,·DSS05.07,·DSS06.02,·MEA02.01,·3.3.1,·CCI-000162,·CCI-000163,·CCI-000164,·CCI-001314,·4.2.3.10,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.7.3,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_2.1,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.8,·SR_2.9,·SR_5.2,·SR_6.1,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CIP-003-8_R5.1.1,·CIP-003-8_R5.3,·CIP-004-6_R2.3,·CIP-007-3_R2.1,·CIP-007-3_R2.2,·CIP-007-3_R2.3,·CIP-007-3_R5.1,·CIP-007-3_R5.1.1,·CIP-007-3_R5.1.2,·CM-6(a),·AC-6(1),·AU-9(4),·DE.AE-3,·DE.AE-5,·PR.AC-4,·PR.DS-5,·PR.PT-1,·RS.AN-1,·RS.AN-4,·Req-10.5,·SRG-OS-000057-GPOS-00027,·SRG-OS-000058-GPOS-00028,·SRG-OS-000059-GPOS-00029,·SRG-OS-000206-GPOS-00084,·RHEL-08-030070,·SV-230396r627750_rule
4850 Remediation_Shell_script_⇲4850 Remediation_Shell_script_⇲
4851 #·Remediation·is·applicable·only·in·certain·platforms4851 #·Remediation·is·applicable·only·in·certain·platforms
4852 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then4852 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
4853 if·LC_ALL=C·grep·-iw·^log_file·/etc/audit/auditd.conf;·then4853 if·LC_ALL=C·grep·-iw·^log_file·/etc/audit/auditd.conf;·then
4854 ····FILE=$(awk·-F·"="·'/^log_file/·{print·$2}'·/etc/audit/auditd.conf·|·tr·-d·'·')4854 ····FILE=$(awk·-F·"="·'/^log_file/·{print·$2}'·/etc/audit/auditd.conf·|·tr·-d·'·')
4855 else4855 else
4856 ····FILE="/var/log/audit/audit.log"4856 ····FILE="/var/log/audit/audit.log"
4857 fi4857 fi
  
Offset 4876, 15 lines modifiedOffset 4876, 15 lines modified
4876 Identifiers·and·References·Identifiers: ·CCE-80800-64876 Identifiers·and·References·Identifiers: ·CCE-80800-6
4877 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.24877 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227,·1.4.2
4878 Remediation_Shell_script_⇲4878 Remediation_Shell_script_⇲
4879 Complexity:·low4879 Complexity:·low
4880 Disruption:·low4880 Disruption:·low
4881 Strategy:···configure4881 Strategy:···configure
4882 #·Remediation·is·applicable·only·in·certain·platforms4882 #·Remediation·is·applicable·only·in·certain·platforms
4883 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then4883 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
4884 chgrp·0·/boot/grub2/grub.cfg4884 chgrp·0·/boot/grub2/grub.cfg
  
4885 else4885 else
4886 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4886 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4887 fi4887 fi
4888 Remediation_Ansible_snippet_⇲4888 Remediation_Ansible_snippet_⇲
Offset 4909, 16 lines modifiedOffset 4909, 16 lines modified
4909 ··-·no_reboot_needed4909 ··-·no_reboot_needed
  
4910 -·name:·Test·for·existence·/boot/grub2/grub.cfg4910 -·name:·Test·for·existence·/boot/grub2/grub.cfg
4911 ··stat:4911 ··stat:
4912 ····path:·/boot/grub2/grub.cfg4912 ····path:·/boot/grub2/grub.cfg
4913 ··register:·file_exists4913 ··register:·file_exists
4914 ··when:4914 ··when:
4915 ··-·'"grub2-common"·in·ansible_facts.packages' 
4916 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'4915 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 4916 ··-·'"grub2-common"·in·ansible_facts.packages'
4917 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4917 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4918 ··tags:4918 ··tags:
4919 ··-·CCE-80800-64919 ··-·CCE-80800-6
4920 ··-·CJIS-5.5.2.24920 ··-·CJIS-5.5.2.2
4921 ··-·NIST-800-171-3.4.54921 ··-·NIST-800-171-3.4.5
4922 ··-·NIST-800-53-AC-6(1)4922 ··-·NIST-800-53-AC-6(1)
4923 ··-·NIST-800-53-CM-6(a)4923 ··-·NIST-800-53-CM-6(a)
Offset 4931, 16 lines modifiedOffset 4931, 16 lines modified
4931 ··-·no_reboot_needed4931 ··-·no_reboot_needed
  
4932 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg4932 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
4933 ··file:4933 ··file:
4934 ····path:·/boot/grub2/grub.cfg4934 ····path:·/boot/grub2/grub.cfg
4935 ····group:·'0'4935 ····group:·'0'
4936 ··when:4936 ··when:
4937 ··-·'"grub2-common"·in·ansible_facts.packages' 
4938 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'4937 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 4938 ··-·'"grub2-common"·in·ansible_facts.packages'
4939 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4939 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4940 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists4940 ··-·file_exists.stat·is·defined·and·file_exists.stat.exists
4941 ··tags:4941 ··tags:
4942 ··-·CCE-80800-64942 ··-·CCE-80800-6
4943 ··-·CJIS-5.5.2.24943 ··-·CJIS-5.5.2.2
4944 ··-·NIST-800-171-3.4.54944 ··-·NIST-800-171-3.4.5
4945 ··-·NIST-800-53-AC-6(1)4945 ··-·NIST-800-53-AC-6(1)
Offset 4961, 15 lines modifiedOffset 4961, 15 lines modified
4961 Identifiers·and·References·Identifiers: ·CCE-80805-54961 Identifiers·and·References·Identifiers: ·CCE-80805-5
4962 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.24962 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·1.4.2
4963 Remediation_Shell_script_⇲4963 Remediation_Shell_script_⇲
4964 Complexity:·low4964 Complexity:·low
4965 Disruption:·low4965 Disruption:·low
4966 Strategy:···configure4966 Strategy:···configure
4967 #·Remediation·is·applicable·only·in·certain·platforms4967 #·Remediation·is·applicable·only·in·certain·platforms
4968 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then4968 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
4969 chown·0·/boot/grub2/grub.cfg4969 chown·0·/boot/grub2/grub.cfg
  
4970 else4970 else
4971 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'4971 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
4972 fi4972 fi
4973 Remediation_Ansible_snippet_⇲4973 Remediation_Ansible_snippet_⇲
Offset 4994, 16 lines modifiedOffset 4994, 16 lines modified
4994 ··-·no_reboot_needed4994 ··-·no_reboot_needed
Max diff block lines reached; 13648/20828 bytes (65.53%) of diff not shown.
562 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-standard.html
    
Offset 26904, 21 lines modifiedOffset 26904, 21 lines modified
00069170:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00069170:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
00069180:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00069180:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
00069190:·6170·7365·2220·6964·3d22·6964·6d32·3538··apse"·id="idm25800069190:·6170·7365·2220·6964·3d22·6964·6d32·3538··apse"·id="idm258
000691a0:·3239·223e·3c70·7265·3e3c·636f·6465·3e23··29"><pre><code>#000691a0:·3239·223e·3c70·7265·3e3c·636f·6465·3e23··29"><pre><code>#
000691b0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·000691b0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
000691c0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·000691c0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
000691d0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf000691d0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
000691e0:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu000691e0:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
000691f0:·6965·7420·2d71·2061·7564·6974·2026·616d··iet·-q·audit·&am000691f0:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
00069200:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/00069200:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
00069210:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
00069220:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
00069230:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren00069210:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 00069220:·7620·5d20·2661·6d70·3b26·616d·703b·2072··v·]·&amp;&amp;·r
 00069230:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au
00069240:·7620·5d3b·2074·6865·6e0a·0a23·2046·6972··v·];·then..#·Fir00069240:·6469·743b·2074·6865·6e0a·0a23·2046·6972··dit;·then..#·Fir
00069250:·7374·2070·6572·666f·726d·2074·6865·2072··st·perform·the·r00069250:·7374·2070·6572·666f·726d·2074·6865·2072··st·perform·the·r
00069260:·656d·6564·6961·7469·6f6e·206f·6620·7468··emediation·of·th00069260:·656d·6564·6961·7469·6f6e·206f·6620·7468··emediation·of·th
00069270:·6520·7379·7363·616c·6c20·7275·6c65·0a23··e·syscall·rule.#00069270:·6520·7379·7363·616c·6c20·7275·6c65·0a23··e·syscall·rule.#
00069280:·2052·6574·7269·6576·6520·6861·7264·7761···Retrieve·hardwa00069280:·2052·6574·7269·6576·6520·6861·7264·7761···Retrieve·hardwa
00069290:·7265·2061·7263·6869·7465·6374·7572·6520··re·architecture·00069290:·7265·2061·7263·6869·7465·6374·7572·6520··re·architecture·
000692a0:·6f66·2074·6865·2075·6e64·6572·6c79·696e··of·the·underlyin000692a0:·6f66·2074·6865·2075·6e64·6572·6c79·696e··of·the·underlyin
000692b0:·6720·7379·7374·656d·0a5b·2022·2428·6765··g·system.[·"$(ge000692b0:·6720·7379·7374·656d·0a5b·2022·2428·6765··g·system.[·"$(ge
Offset 27799, 22 lines modifiedOffset 27799, 22 lines modified
0006c960:·0a20·202d·2072·6573·7472·6963·745f·7374··.··-·restrict_st0006c960:·0a20·202d·2072·6573·7472·6963·745f·7374··.··-·restrict_st
0006c970:·7261·7465·6779·0a0a·2d20·6e61·6d65·3a20··rategy..-·name:·0006c970:·7261·7465·6779·0a0a·2d20·6e61·6d65·3a20··rategy..-·name:·
0006c980:·5365·7420·6172·6368·6974·6563·7475·7265··Set·architecture0006c980:·5365·7420·6172·6368·6974·6563·7475·7265··Set·architecture
0006c990:·2066·6f72·2061·7564·6974·2063·686d·6f64···for·audit·chmod0006c990:·2066·6f72·2061·7564·6974·2063·686d·6f64···for·audit·chmod
0006c9a0:·2074·6173·6b73·0a20·2073·6574·5f66·6163···tasks.··set_fac0006c9a0:·2074·6173·6b73·0a20·2073·6574·5f66·6163···tasks.··set_fac
0006c9b0:·743a·0a20·2020·2061·7564·6974·5f61·7263··t:.····audit_arc0006c9b0:·743a·0a20·2020·2061·7564·6974·5f61·7263··t:.····audit_arc
0006c9c0:·683a·2062·3634·0a20·2077·6865·6e3a·0a20··h:·b64.··when:.·0006c9c0:·683a·2062·3634·0a20·2077·6865·6e3a·0a20··h:·b64.··when:.·
0006c9d0:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a 
0006c9e0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
0006c9f0:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib 
0006ca00:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
0006ca10:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
0006ca20:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
0006ca30:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
0006ca40:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]0006c9d0:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu
 0006c9e0:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 0006c9f0:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 0006ca00:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 0006ca10:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 0006ca20:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a
 0006ca30:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible
 0006ca40:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
0006ca50:·0a20·202d·2061·6e73·6962·6c65·5f61·7263··.··-·ansible_arc0006ca50:·0a20·202d·2061·6e73·6962·6c65·5f61·7263··.··-·ansible_arc
0006ca60:·6869·7465·6374·7572·6520·3d3d·2022·6161··hitecture·==·"aa0006ca60:·6869·7465·6374·7572·6520·3d3d·2022·6161··hitecture·==·"aa
0006ca70:·7263·6836·3422·206f·7220·616e·7369·626c··rch64"·or·ansibl0006ca70:·7263·6836·3422·206f·7220·616e·7369·626c··rch64"·or·ansibl
0006ca80:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=0006ca80:·655f·6172·6368·6974·6563·7475·7265·203d··e_architecture·=
0006ca90:·3d20·2270·7063·3634·2220·6f72·2061·6e73··=·"ppc64"·or·ans0006ca90:·3d20·2270·7063·3634·2220·6f72·2061·6e73··=·"ppc64"·or·ans
0006caa0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur0006caa0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
0006cab0:·650a·2020·2020·3d3d·2022·7070·6336·346c··e.····==·"ppc64l0006cab0:·650a·2020·2020·3d3d·2022·7070·6336·346c··e.····==·"ppc64l
Offset 28123, 23 lines modifiedOffset 28123, 23 lines modified
0006dda0:·7065·726d·5f6d·6f64·0a20·2020·2020·2063··perm_mod.······c0006dda0:·7065·726d·5f6d·6f64·0a20·2020·2020·2063··perm_mod.······c
0006ddb0:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····0006ddb0:·7265·6174·653a·2074·7275·650a·2020·2020··reate:·true.····
0006ddc0:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··0006ddc0:·2020·6d6f·6465·3a20·6f2d·7277·780a·2020····mode:·o-rwx.··
0006ddd0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese0006ddd0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese
0006dde0:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys0006dde0:·6e74·0a20·2020·2077·6865·6e3a·2073·7973··nt.····when:·sys
0006ddf0:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le0006ddf0:·6361·6c6c·735f·666f·756e·6420·7c20·6c65··calls_found·|·le
0006de00:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when0006de00:·6e67·7468·203d·3d20·300a·2020·7768·656e··ngth·==·0.··when
0006de10:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i 
0006de20:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
0006de30:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an 
0006de40:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
0006de50:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
0006de60:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
0006de70:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
0006de80:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe0006de10:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi
 0006de20:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 0006de30:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 0006de40:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 0006de50:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 0006de60:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·
 0006de70:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi
 0006de80:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
0006de90:·7222·5d0a·2020·7461·6773·3a0a·2020·2d20··r"].··tags:.··-·0006de90:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·
0006dea0:·4343·452d·3830·3638·352d·310a·2020·2d20··CCE-80685-1.··-·0006dea0:·4343·452d·3830·3638·352d·310a·2020·2d20··CCE-80685-1.··-·
0006deb0:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-0006deb0:·434a·4953·2d35·2e34·2e31·2e31·0a20·202d··CJIS-5.4.1.1.··-
0006dec0:·2044·4953·412d·5354·4947·2d52·4845·4c2d···DISA-STIG-RHEL-0006dec0:·2044·4953·412d·5354·4947·2d52·4845·4c2d···DISA-STIG-RHEL-
0006ded0:·3038·2d30·3330·3439·300a·2020·2d20·4e49··08-030490.··-·NI0006ded0:·3038·2d30·3330·3439·300a·2020·2d20·4e49··08-030490.··-·NI
0006dee0:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.70006dee0:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.7
0006def0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-530006def0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
0006df00:·2d41·552d·3132·2863·290a·2020·2d20·4e49··-AU-12(c).··-·NI0006df00:·2d41·552d·3132·2863·290a·2020·2d20·4e49··-AU-12(c).··-·NI
Offset 28436, 22 lines modifiedOffset 28436, 22 lines modified
0006f130:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:0006f130:·6f64·0a20·2020·2020·2063·7265·6174·653a··od.······create:
0006f140:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode0006f140:·2074·7275·650a·2020·2020·2020·6d6f·6465···true.······mode
0006f150:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st0006f150:·3a20·6f2d·7277·780a·2020·2020·2020·7374··:·o-rwx.······st
0006f160:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···0006f160:·6174·653a·2070·7265·7365·6e74·0a20·2020··ate:·present.···
0006f170:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_0006f170:·2077·6865·6e3a·2073·7973·6361·6c6c·735f···when:·syscalls_
0006f180:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=0006f180:·666f·756e·6420·7c20·6c65·6e67·7468·203d··found·|·length·=
0006f190:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·0006f190:·3d20·300a·2020·7768·656e·3a0a·2020·2d20··=·0.··when:.··-·
0006f1a0:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi 
0006f1b0:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag 
0006f1c0:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_ 
0006f1d0:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
0006f1e0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
0006f1f0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
0006f200:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
0006f210:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··0006f1a0:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 0006f1b0:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 0006f1c0:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 0006f1d0:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 0006f1e0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
 0006f1f0:·6e65·7222·5d0a·2020·2d20·2722·6175·6469··ner"].··-·'"audi
 0006f200:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa
 0006f210:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
0006f220:·2d20·6175·6469·745f·6172·6368·203d·3d20··-·audit_arch·==·0006f220:·2d20·6175·6469·745f·6172·6368·203d·3d20··-·audit_arch·==·
0006f230:·2262·3634·220a·2020·7461·6773·3a0a·2020··"b64".··tags:.··0006f230:·2262·3634·220a·2020·7461·6773·3a0a·2020··"b64".··tags:.··
0006f240:·2d20·4343·452d·3830·3638·352d·310a·2020··-·CCE-80685-1.··0006f240:·2d20·4343·452d·3830·3638·352d·310a·2020··-·CCE-80685-1.··
0006f250:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·0006f250:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
0006f260:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE0006f260:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE
0006f270:·4c2d·3038·2d30·3330·3439·300a·2020·2d20··L-08-030490.··-·0006f270:·4c2d·3038·2d30·3330·3439·300a·2020·2d20··L-08-030490.··-·
0006f280:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.10006f280:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
Offset 29440, 21 lines modifiedOffset 29440, 21 lines modified
00072ff0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00072ff0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
00073000:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00073000:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
00073010:·6170·7365·2220·6964·3d22·6964·6d32·3539··apse"·id="idm25900073010:·6170·7365·2220·6964·3d22·6964·6d32·3539··apse"·id="idm259
00073020:·3839·223e·3c70·7265·3e3c·636f·6465·3e23··89"><pre><code>#00073020:·3839·223e·3c70·7265·3e3c·636f·6465·3e23··89"><pre><code>#
00073030:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·00073030:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
00073040:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·00073040:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
00073050:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf00073050:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
00073060:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu00073060:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
00073070:·6965·7420·2d71·2061·7564·6974·2026·616d··iet·-q·audit·&am00073070:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
00073080:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/00073080:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
00073090:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
000730a0:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
Max diff block lines reached; 417167/426957 bytes (97.71%) of diff not shown.
145 KB
html2text {}
    
Offset 1458, 15 lines modifiedOffset 1458, 15 lines modified
1458 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1458 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1459 Severity: ················medium1459 Severity: ················medium
1460 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1460 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1461 Identifiers·and·References·Identifiers: ·CCE-80685-11461 Identifiers·and·References·Identifiers: ·CCE-80685-1
1462 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule1462 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030490,·4.1.3.9,·SV-230456r810462_rule
1463 Remediation_Shell_script_⇲1463 Remediation_Shell_script_⇲
1464 #·Remediation·is·applicable·only·in·certain·platforms1464 #·Remediation·is·applicable·only·in·certain·platforms
1465 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1465 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1466 #·First·perform·the·remediation·of·the·syscall·rule1466 #·First·perform·the·remediation·of·the·syscall·rule
1467 #·Retrieve·hardware·architecture·of·the·underlying·system1467 #·Retrieve·hardware·architecture·of·the·underlying·system
1468 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1468 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1469 for·ARCH·in·"${RULE_ARCHS[@]}"1469 for·ARCH·in·"${RULE_ARCHS[@]}"
1470 do1470 do
Offset 1814, 16 lines modifiedOffset 1814, 16 lines modified
1814 ··-·reboot_required1814 ··-·reboot_required
1815 ··-·restrict_strategy1815 ··-·restrict_strategy
  
1816 -·name:·Set·architecture·for·audit·chmod·tasks1816 -·name:·Set·architecture·for·audit·chmod·tasks
1817 ··set_fact:1817 ··set_fact:
1818 ····audit_arch:·b641818 ····audit_arch:·b64
1819 ··when:1819 ··when:
1820 ··-·'"audit"·in·ansible_facts.packages' 
1821 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1820 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1821 ··-·'"audit"·in·ansible_facts.packages'
1822 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1822 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1823 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1823 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1824 ··tags:1824 ··tags:
1825 ··-·CCE-80685-11825 ··-·CCE-80685-1
1826 ··-·CJIS-5.4.1.11826 ··-·CJIS-5.4.1.1
1827 ··-·DISA-STIG-RHEL-08-0304901827 ··-·DISA-STIG-RHEL-08-030490
1828 ··-·NIST-800-171-3.1.71828 ··-·NIST-800-171-3.1.7
Offset 1961, 16 lines modifiedOffset 1961, 16 lines modified
1961 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001961 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1962 ········-F·auid!=unset·-F·key=perm_mod1962 ········-F·auid!=unset·-F·key=perm_mod
1963 ······create:·true1963 ······create:·true
1964 ······mode:·o-rwx1964 ······mode:·o-rwx
1965 ······state:·present1965 ······state:·present
1966 ····when:·syscalls_found·|·length·==·01966 ····when:·syscalls_found·|·length·==·0
1967 ··when:1967 ··when:
1968 ··-·'"audit"·in·ansible_facts.packages' 
1969 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1968 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1969 ··-·'"audit"·in·ansible_facts.packages'
1970 ··tags:1970 ··tags:
1971 ··-·CCE-80685-11971 ··-·CCE-80685-1
1972 ··-·CJIS-5.4.1.11972 ··-·CJIS-5.4.1.1
1973 ··-·DISA-STIG-RHEL-08-0304901973 ··-·DISA-STIG-RHEL-08-030490
1974 ··-·NIST-800-171-3.1.71974 ··-·NIST-800-171-3.1.7
1975 ··-·NIST-800-53-AU-12(c)1975 ··-·NIST-800-53-AU-12(c)
1976 ··-·NIST-800-53-AU-2(d)1976 ··-·NIST-800-53-AU-2(d)
Offset 2106, 16 lines modifiedOffset 2106, 16 lines modified
2106 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002106 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2107 ········-F·auid!=unset·-F·key=perm_mod2107 ········-F·auid!=unset·-F·key=perm_mod
2108 ······create:·true2108 ······create:·true
2109 ······mode:·o-rwx2109 ······mode:·o-rwx
2110 ······state:·present2110 ······state:·present
2111 ····when:·syscalls_found·|·length·==·02111 ····when:·syscalls_found·|·length·==·0
2112 ··when:2112 ··when:
2113 ··-·'"audit"·in·ansible_facts.packages' 
2114 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2113 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2114 ··-·'"audit"·in·ansible_facts.packages'
2115 ··-·audit_arch·==·"b64"2115 ··-·audit_arch·==·"b64"
2116 ··tags:2116 ··tags:
2117 ··-·CCE-80685-12117 ··-·CCE-80685-1
2118 ··-·CJIS-5.4.1.12118 ··-·CJIS-5.4.1.1
2119 ··-·DISA-STIG-RHEL-08-0304902119 ··-·DISA-STIG-RHEL-08-030490
2120 ··-·NIST-800-171-3.1.72120 ··-·NIST-800-171-3.1.7
2121 ··-·NIST-800-53-AU-12(c)2121 ··-·NIST-800-53-AU-12(c)
Offset 2141, 15 lines modifiedOffset 2141, 15 lines modified
2141 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2141 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2142 Severity: ················medium2142 Severity: ················medium
2143 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2143 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2144 Identifiers·and·References·Identifiers: ·CCE-80686-92144 Identifiers·and·References·Identifiers: ·CCE-80686-9
2145 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030480,·4.1.3.9,·SV-230455r810459_rule2145 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·RHEL-08-030480,·4.1.3.9,·SV-230455r810459_rule
2146 Remediation_Shell_script_⇲2146 Remediation_Shell_script_⇲
2147 #·Remediation·is·applicable·only·in·certain·platforms2147 #·Remediation·is·applicable·only·in·certain·platforms
2148 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2148 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2149 #·First·perform·the·remediation·of·the·syscall·rule2149 #·First·perform·the·remediation·of·the·syscall·rule
2150 #·Retrieve·hardware·architecture·of·the·underlying·system2150 #·Retrieve·hardware·architecture·of·the·underlying·system
2151 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2151 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2152 for·ARCH·in·"${RULE_ARCHS[@]}"2152 for·ARCH·in·"${RULE_ARCHS[@]}"
2153 do2153 do
Offset 2497, 16 lines modifiedOffset 2497, 16 lines modified
2497 ··-·reboot_required2497 ··-·reboot_required
2498 ··-·restrict_strategy2498 ··-·restrict_strategy
  
2499 -·name:·Set·architecture·for·audit·chown·tasks2499 -·name:·Set·architecture·for·audit·chown·tasks
2500 ··set_fact:2500 ··set_fact:
2501 ····audit_arch:·b642501 ····audit_arch:·b64
2502 ··when:2502 ··when:
2503 ··-·'"audit"·in·ansible_facts.packages' 
2504 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2503 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2504 ··-·'"audit"·in·ansible_facts.packages'
2505 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2505 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2506 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2506 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2507 ··tags:2507 ··tags:
2508 ··-·CCE-80686-92508 ··-·CCE-80686-9
2509 ··-·CJIS-5.4.1.12509 ··-·CJIS-5.4.1.1
2510 ··-·DISA-STIG-RHEL-08-0304802510 ··-·DISA-STIG-RHEL-08-030480
2511 ··-·NIST-800-171-3.1.72511 ··-·NIST-800-171-3.1.7
Offset 2646, 16 lines modifiedOffset 2646, 16 lines modified
2646 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002646 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2647 ········-F·auid!=unset·-F·key=perm_mod2647 ········-F·auid!=unset·-F·key=perm_mod
2648 ······create:·true2648 ······create:·true
2649 ······mode:·o-rwx2649 ······mode:·o-rwx
2650 ······state:·present2650 ······state:·present
2651 ····when:·syscalls_found·|·length·==·02651 ····when:·syscalls_found·|·length·==·0
2652 ··when:2652 ··when:
2653 ··-·'"audit"·in·ansible_facts.packages' 
2654 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2653 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2654 ··-·'"audit"·in·ansible_facts.packages'
2655 ··tags:2655 ··tags:
2656 ··-·CCE-80686-92656 ··-·CCE-80686-9
2657 ··-·CJIS-5.4.1.12657 ··-·CJIS-5.4.1.1
2658 ··-·DISA-STIG-RHEL-08-0304802658 ··-·DISA-STIG-RHEL-08-030480
2659 ··-·NIST-800-171-3.1.72659 ··-·NIST-800-171-3.1.7
2660 ··-·NIST-800-53-AU-12(c)2660 ··-·NIST-800-53-AU-12(c)
2661 ··-·NIST-800-53-AU-2(d)2661 ··-·NIST-800-53-AU-2(d)
Offset 2793, 16 lines modifiedOffset 2793, 16 lines modified
2793 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002793 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2794 ········-F·auid!=unset·-F·key=perm_mod2794 ········-F·auid!=unset·-F·key=perm_mod
2795 ······create:·true2795 ······create:·true
2796 ······mode:·o-rwx2796 ······mode:·o-rwx
2797 ······state:·present2797 ······state:·present
Max diff block lines reached; 139832/148097 bytes (94.42%) of diff not shown.
1.81 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-stig.html
    
Offset 15468, 116 lines modifiedOffset 15468, 116 lines modified
0003c6b0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003c6b0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003c6c0:·3532·3222·2074·6162·696e·6465·783d·2230··522"·tabindex="00003c6c0:·3532·3222·2074·6162·696e·6465·783d·2230··522"·tabindex="0
0003c6d0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c6d0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c6e0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c6e0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c6f0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c6f0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c700:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c700:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c710:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c710:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c720:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003c720:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003c730:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003c730:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003c740:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003c740:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003c750:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003c750:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003c760:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003c760:·6170·7365·2220·6964·3d22·6964·6d38·3532··apse"·id="idm852
0003c770:·3532·3222·3e3c·7461·626c·6520·636c·6173··522"><table·clas0003c770:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
0003c780:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003c780:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003c790:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003c790:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003c7a0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003c7a0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003c7b0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003c7b0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003c7c0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003c7c0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003c7d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c7d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c7e0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c7e0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c7f0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c7f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c800:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c800:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003c810:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c810:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c820:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c820:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003c830:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c830:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003c840:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003c850:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003c840:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003c850:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003c860:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003c870:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003c880:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003c890:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003c8a0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003c8b0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003c8c0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003c8d0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003c8e0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003c8f0:·2d74·6172·6765·743d·2223·6964·6d38·3532··-target="#idm852
 0003c900:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·
 0003c910:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003c920:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003c930:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003c940:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003c950:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003c960:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003c970:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003c980:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003c990:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003c9a0:·2220·6964·3d22·6964·6d38·3532·3322·3e3c··"·id="idm8523"><
 0003c9b0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003c9c0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003c9d0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003c9e0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003c9f0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003ca00:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003ca10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003ca20:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003ca30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003ca40:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003ca50:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003ca60:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003ca70:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003ca80:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003ca90:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003caa0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003cab0:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003cac0:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003cad0:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003cae0:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003caf0:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003cb00:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003cb10:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003cb20:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 0003cb30:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003cb40:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003cb50:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003cb60:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003cb70:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003cb80:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003c860:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003cb90:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003c870:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003cba0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003c880:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003cbb0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003c890:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003cbc0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003c8a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003cbd0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c8b0:·3835·3233·2220·7461·6269·6e64·6578·3d22··8523"·tabindex="0003cbe0:·3835·3234·2220·7461·6269·6e64·6578·3d22··8524"·tabindex="
0003c8c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003cbf0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c8d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003cc00:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c8e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003cc10:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c8f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003cc20:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c900:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003cc30:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c910:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003cc40:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003c920:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003cc50:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003c930:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003cc60:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003c940:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003cc70:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003c950:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm850003cc80:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003c960:·3233·223e·3c74·6162·6c65·2063·6c61·7373··23"><table·class0003cc90:·3835·3234·223e·3c74·6162·6c65·2063·6c61··8524"><table·cla
0003c970:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003cca0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003c980:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003ccb0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c990:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003ccc0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003c9a0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003ccd0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003c9b0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003cce0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003c9c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003ccf0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c9d0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003cd00:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003c9e0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003cd10:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003c9f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003cd20:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003ca00:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003cd30:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003ca10:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003cd40:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003ca20:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003cd50:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003cd60:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003cd70:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003ca30:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003ca40:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003ca50:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003ca60:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003ca70:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003ca80:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003ca90:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003caa0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003cab0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003cac0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003cad0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003cae0:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm85 
0003caf0:·3234·2220·7461·6269·6e64·6578·3d22·3022··24"·tabindex="0" 
0003cb00:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003cb10:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003cb20:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003cb30:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 1503693/1518349 bytes (99.03%) of diff not shown.
367 KB
html2text {}
    
Offset 106, 20 lines modifiedOffset 106, 14 lines modified
106 Identifiers·and·References·Identifiers: ·CCE-80844-4106 Identifiers·and·References·Identifiers: ·CCE-80844-4
107 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule107 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
108 Remediation_OSBuild_Blueprint_snippet_⇲108 Remediation_OSBuild_Blueprint_snippet_⇲
  
109 [[packages]]109 [[packages]]
110 name·=·"aide"110 name·=·"aide"
111 version·=·"*"111 version·=·"*"
112 Remediation_Anaconda_snippet_⇲ 
113 Complexity:·low 
114 Disruption:·low 
115 Strategy:···enable 
  
116 package·--add=aide 
117 Remediation_Puppet_snippet_⇲112 Remediation_Puppet_snippet_⇲
118 Complexity:·low113 Complexity:·low
119 Disruption:·low114 Disruption:·low
120 Strategy:···enable115 Strategy:···enable
121 include·install_aide116 include·install_aide
  
122 class·install_aide·{117 class·install_aide·{
Offset 137, 14 lines modifiedOffset 131, 20 lines modified
137 if·!·rpm·-q·--quiet·"aide"·;·then131 if·!·rpm·-q·--quiet·"aide"·;·then
138 ····yum·install·-y·"aide"132 ····yum·install·-y·"aide"
139 fi133 fi
  
140 else134 else
141 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
142 fi136 fi
 137 Remediation_Anaconda_snippet_⇲
 138 Complexity:·low
 139 Disruption:·low
 140 Strategy:···enable
  
 141 package·--add=aide
143 Remediation_Ansible_snippet_⇲142 Remediation_Ansible_snippet_⇲
144 Complexity:·low143 Complexity:·low
145 Disruption:·low144 Disruption:·low
146 Strategy:···enable145 Strategy:···enable
147 -·name:·Ensure·aide·is·installed146 -·name:·Ensure·aide·is·installed
148 ··package:147 ··package:
149 ····name:·aide148 ····name:·aide
Offset 4878, 20 lines modifiedOffset 4878, 14 lines modified
4878 Identifiers·and·References·Identifiers: ·CCE-82968-94878 Identifiers·and·References·Identifiers: ·CCE-82968-9
4879 ···························References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·RHEL-08-010472,·SV-244527r743830_rule4879 ···························References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·RHEL-08-010472,·SV-244527r743830_rule
4880 Remediation_OSBuild_Blueprint_snippet_⇲4880 Remediation_OSBuild_Blueprint_snippet_⇲
  
4881 [[packages]]4881 [[packages]]
4882 name·=·"rng-tools"4882 name·=·"rng-tools"
4883 version·=·"*"4883 version·=·"*"
4884 Remediation_Anaconda_snippet_⇲ 
4885 Complexity:·low 
4886 Disruption:·low 
4887 Strategy:···enable 
  
4888 package·--add=rng-tools 
4889 Remediation_Puppet_snippet_⇲4884 Remediation_Puppet_snippet_⇲
4890 Complexity:·low4885 Complexity:·low
4891 Disruption:·low4886 Disruption:·low
4892 Strategy:···enable4887 Strategy:···enable
4893 include·install_rng-tools4888 include·install_rng-tools
  
4894 class·install_rng-tools·{4889 class·install_rng-tools·{
Offset 4903, 14 lines modifiedOffset 4897, 20 lines modified
4903 Complexity:·low4897 Complexity:·low
4904 Disruption:·low4898 Disruption:·low
4905 Strategy:···enable4899 Strategy:···enable
  
4906 if·!·rpm·-q·--quiet·"rng-tools"·;·then4900 if·!·rpm·-q·--quiet·"rng-tools"·;·then
4907 ····yum·install·-y·"rng-tools"4901 ····yum·install·-y·"rng-tools"
4908 fi4902 fi
 4903 Remediation_Anaconda_snippet_⇲
 4904 Complexity:·low
 4905 Disruption:·low
 4906 Strategy:···enable
  
 4907 package·--add=rng-tools
4909 Remediation_Ansible_snippet_⇲4908 Remediation_Ansible_snippet_⇲
4910 Complexity:·low4909 Complexity:·low
4911 Disruption:·low4910 Disruption:·low
4912 Strategy:···enable4911 Strategy:···enable
4913 -·name:·Ensure·rng-tools·is·installed4912 -·name:·Ensure·rng-tools·is·installed
4914 ··package:4913 ··package:
4915 ····name:·rng-tools4914 ····name:·rng-tools
Offset 4928, 20 lines modifiedOffset 4928, 14 lines modified
4928 The·abrt-addon-ccpp·package·can·be·removed·with·the·following·command:4928 The·abrt-addon-ccpp·package·can·be·removed·with·the·following·command:
4929 $·sudo·yum·erase·abrt-addon-ccpp4929 $·sudo·yum·erase·abrt-addon-ccpp
4930 Rationale:·················abrt-addon-ccpp·contains·hooks·for·C/C++·crashed·programs·and·abrt's·C/C++·analyzer·plugin.4930 Rationale:·················abrt-addon-ccpp·contains·hooks·for·C/C++·crashed·programs·and·abrt's·C/C++·analyzer·plugin.
4931 Severity: ················low4931 Severity: ················low
4932 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed4932 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed
4933 Identifiers·and·References·Identifiers: ·CCE-82919-24933 Identifiers·and·References·Identifiers: ·CCE-82919-2
4934 ···························References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·RHEL-08-040001,·SV-230488r627750_rule4934 ···························References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·RHEL-08-040001,·SV-230488r627750_rule
4935 Remediation_Anaconda_snippet_⇲ 
4936 Complexity:·low 
4937 Disruption:·low 
4938 Strategy:···disable 
  
4939 package·--remove=abrt-addon-ccpp 
4940 Remediation_Puppet_snippet_⇲4935 Remediation_Puppet_snippet_⇲
4941 Complexity:·low4936 Complexity:·low
4942 Disruption:·low4937 Disruption:·low
4943 Strategy:···disable4938 Strategy:···disable
4944 include·remove_abrt-addon-ccpp4939 include·remove_abrt-addon-ccpp
  
4945 class·remove_abrt-addon-ccpp·{4940 class·remove_abrt-addon-ccpp·{
Offset 4961, 14 lines modifiedOffset 4955, 20 lines modified
4961 #»      ···system!4955 #»      ···system!
  
4962 if·rpm·-q·--quiet·"abrt-addon-ccpp"·;·then4956 if·rpm·-q·--quiet·"abrt-addon-ccpp"·;·then
  
4963 ····yum·remove·-y·"abrt-addon-ccpp"4957 ····yum·remove·-y·"abrt-addon-ccpp"
  
4964 fi4958 fi
 4959 Remediation_Anaconda_snippet_⇲
 4960 Complexity:·low
 4961 Disruption:·low
 4962 Strategy:···disable
  
 4963 package·--remove=abrt-addon-ccpp
4965 Remediation_Ansible_snippet_⇲4964 Remediation_Ansible_snippet_⇲
4966 Complexity:·low4965 Complexity:·low
4967 Disruption:·low4966 Disruption:·low
4968 Strategy:···disable4967 Strategy:···disable
4969 -·name:·Ensure·abrt-addon-ccpp·is·removed4968 -·name:·Ensure·abrt-addon-ccpp·is·removed
4970 ··package:4969 ··package:
4971 ····name:·abrt-addon-ccpp4970 ····name:·abrt-addon-ccpp
Offset 4986, 20 lines modifiedOffset 4986, 14 lines modified
4986 The·abrt-addon-kerneloops·package·can·be·removed·with·the·following·command:4986 The·abrt-addon-kerneloops·package·can·be·removed·with·the·following·command:
Max diff block lines reached; 372110/376032 bytes (98.96%) of diff not shown.
1.78 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-stig_gui.html
    
Offset 15487, 116 lines modifiedOffset 15487, 116 lines modified
0003c7e0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c7e0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003c7f0:·3835·3232·2220·7461·6269·6e64·6578·3d22··8522"·tabindex="0003c7f0:·3835·3232·2220·7461·6269·6e64·6578·3d22··8522"·tabindex="
0003c800:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c800:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003c810:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c810:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003c820:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c820:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003c830:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c830:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003c840:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c840:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003c850:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003c850:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003c860:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003c860:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003c870:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003c870:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003c880:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003c880:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003c890:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003c890:·6c61·7073·6522·2069·643d·2269·646d·3835··lapse"·id="idm85
0003c8a0:·3835·3232·223e·3c74·6162·6c65·2063·6c61··8522"><table·cla0003c8a0:·3232·223e·3c74·6162·6c65·2063·6c61·7373··22"><table·class
0003c8b0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003c8b0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003c8c0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003c8c0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003c8d0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003c8d0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003c8e0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003c8e0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003c8f0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003c8f0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003c900:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c900:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003c910:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003c910:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003c920:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003c920:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003c930:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c930:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c940:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003c940:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003c950:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003c950:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003c960:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003c960:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003c970:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003c980:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod0003c970:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003c980:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003c990:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003c9a0:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003c9b0:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003c9c0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003c9d0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003c9e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003c9f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003ca00:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003ca10:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003ca20:·612d·7461·7267·6574·3d22·2369·646d·3835··a-target="#idm85
 0003ca30:·3233·2220·7461·6269·6e64·6578·3d22·3022··23"·tabindex="0"
 0003ca40:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003ca50:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003ca60:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003ca70:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003ca80:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003ca90:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003caa0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003cab0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003cac0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003cad0:·6522·2069·643d·2269·646d·3835·3233·223e··e"·id="idm8523">
 0003cae0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003caf0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003cb00:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003cb10:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003cb20:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003cb30:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003cb40:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003cb50:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003cb60:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003cb70:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003cb80:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003cb90:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003cba0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003cbb0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003cbc0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003cbd0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003cbe0:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f
 0003cbf0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 0003cc00:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 0003cc10:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
 0003cc20:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if·
 0003cc30:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003cc40:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 0003cc50:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·-
 0003cc60:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 0003cc70:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003cc80:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003cc90:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003cca0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003ccb0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
0003c990:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003ccc0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003c9a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003ccd0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003c9b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003cce0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003c9c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003ccf0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003c9d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003cd00:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003c9e0:·6d38·3532·3322·2074·6162·696e·6465·783d··m8523"·tabindex=0003cd10:·6d38·3532·3422·2074·6162·696e·6465·783d··m8524"·tabindex=
0003c9f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003cd20:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003ca00:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003cd30:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003ca10:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003cd40:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003ca20:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003cd50:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003ca30:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003cd60:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003ca40:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003cd70:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003ca50:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003cd80:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003ca60:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003cd90:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003ca70:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003cda0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003ca80:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003cdb0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003ca90:·3532·3322·3e3c·7461·626c·6520·636c·6173··523"><table·clas0003cdc0:·6d38·3532·3422·3e3c·7461·626c·6520·636c··m8524"><table·cl
0003caa0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003cdd0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003cab0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003cde0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003cac0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003cdf0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003cad0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003ce00:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003cae0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003ce10:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003caf0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003ce20:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003cb00:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003ce30:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003cb10:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003ce40:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003cb20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003ce50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003cb30:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003ce60:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003cb40:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003ce70:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003cb50:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003ce80:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003ce90:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003cea0:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co
0003cb60:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003cb70:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas 
0003cb80:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{ 
0003cb90:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai 
0003cba0:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure· 
0003cbb0:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0003cbc0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0003cbd0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003cbe0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003cbf0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003cc00:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003cc10:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
0003cc20:·3532·3422·2074·6162·696e·6465·783d·2230··524"·tabindex="0 
0003cc30:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003cc40:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003cc50:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003cc60:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
Max diff block lines reached; 1473898/1488554 bytes (99.02%) of diff not shown.
364 KB
html2text {}
    
Offset 111, 20 lines modifiedOffset 111, 14 lines modified
111 Identifiers·and·References·Identifiers: ·CCE-80844-4111 Identifiers·and·References·Identifiers: ·CCE-80844-4
112 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule112 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·RHEL-08-010359,·1.3.1,·SV-251710r854081_rule
113 Remediation_OSBuild_Blueprint_snippet_⇲113 Remediation_OSBuild_Blueprint_snippet_⇲
  
114 [[packages]]114 [[packages]]
115 name·=·"aide"115 name·=·"aide"
116 version·=·"*"116 version·=·"*"
117 Remediation_Anaconda_snippet_⇲ 
118 Complexity:·low 
119 Disruption:·low 
120 Strategy:···enable 
  
121 package·--add=aide 
122 Remediation_Puppet_snippet_⇲117 Remediation_Puppet_snippet_⇲
123 Complexity:·low118 Complexity:·low
124 Disruption:·low119 Disruption:·low
125 Strategy:···enable120 Strategy:···enable
126 include·install_aide121 include·install_aide
  
127 class·install_aide·{122 class·install_aide·{
Offset 142, 14 lines modifiedOffset 136, 20 lines modified
142 if·!·rpm·-q·--quiet·"aide"·;·then136 if·!·rpm·-q·--quiet·"aide"·;·then
143 ····yum·install·-y·"aide"137 ····yum·install·-y·"aide"
144 fi138 fi
  
145 else139 else
146 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
147 fi141 fi
 142 Remediation_Anaconda_snippet_⇲
 143 Complexity:·low
 144 Disruption:·low
 145 Strategy:···enable
  
 146 package·--add=aide
148 Remediation_Ansible_snippet_⇲147 Remediation_Ansible_snippet_⇲
149 Complexity:·low148 Complexity:·low
150 Disruption:·low149 Disruption:·low
151 Strategy:···enable150 Strategy:···enable
152 -·name:·Ensure·aide·is·installed151 -·name:·Ensure·aide·is·installed
153 ··package:152 ··package:
154 ····name:·aide153 ····name:·aide
Offset 4883, 20 lines modifiedOffset 4883, 14 lines modified
4883 Identifiers·and·References·Identifiers: ·CCE-82968-94883 Identifiers·and·References·Identifiers: ·CCE-82968-9
4884 ···························References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·RHEL-08-010472,·SV-244527r743830_rule4884 ···························References: ·CCI-000366,·SRG-OS-000480-GPOS-00227,·RHEL-08-010472,·SV-244527r743830_rule
4885 Remediation_OSBuild_Blueprint_snippet_⇲4885 Remediation_OSBuild_Blueprint_snippet_⇲
  
4886 [[packages]]4886 [[packages]]
4887 name·=·"rng-tools"4887 name·=·"rng-tools"
4888 version·=·"*"4888 version·=·"*"
4889 Remediation_Anaconda_snippet_⇲ 
4890 Complexity:·low 
4891 Disruption:·low 
4892 Strategy:···enable 
  
4893 package·--add=rng-tools 
4894 Remediation_Puppet_snippet_⇲4889 Remediation_Puppet_snippet_⇲
4895 Complexity:·low4890 Complexity:·low
4896 Disruption:·low4891 Disruption:·low
4897 Strategy:···enable4892 Strategy:···enable
4898 include·install_rng-tools4893 include·install_rng-tools
  
4899 class·install_rng-tools·{4894 class·install_rng-tools·{
Offset 4908, 14 lines modifiedOffset 4902, 20 lines modified
4908 Complexity:·low4902 Complexity:·low
4909 Disruption:·low4903 Disruption:·low
4910 Strategy:···enable4904 Strategy:···enable
  
4911 if·!·rpm·-q·--quiet·"rng-tools"·;·then4905 if·!·rpm·-q·--quiet·"rng-tools"·;·then
4912 ····yum·install·-y·"rng-tools"4906 ····yum·install·-y·"rng-tools"
4913 fi4907 fi
 4908 Remediation_Anaconda_snippet_⇲
 4909 Complexity:·low
 4910 Disruption:·low
 4911 Strategy:···enable
  
 4912 package·--add=rng-tools
4914 Remediation_Ansible_snippet_⇲4913 Remediation_Ansible_snippet_⇲
4915 Complexity:·low4914 Complexity:·low
4916 Disruption:·low4915 Disruption:·low
4917 Strategy:···enable4916 Strategy:···enable
4918 -·name:·Ensure·rng-tools·is·installed4917 -·name:·Ensure·rng-tools·is·installed
4919 ··package:4918 ··package:
4920 ····name:·rng-tools4919 ····name:·rng-tools
Offset 4933, 20 lines modifiedOffset 4933, 14 lines modified
4933 The·abrt-addon-ccpp·package·can·be·removed·with·the·following·command:4933 The·abrt-addon-ccpp·package·can·be·removed·with·the·following·command:
4934 $·sudo·yum·erase·abrt-addon-ccpp4934 $·sudo·yum·erase·abrt-addon-ccpp
4935 Rationale:·················abrt-addon-ccpp·contains·hooks·for·C/C++·crashed·programs·and·abrt's·C/C++·analyzer·plugin.4935 Rationale:·················abrt-addon-ccpp·contains·hooks·for·C/C++·crashed·programs·and·abrt's·C/C++·analyzer·plugin.
4936 Severity: ················low4936 Severity: ················low
4937 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed4937 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed
4938 Identifiers·and·References·Identifiers: ·CCE-82919-24938 Identifiers·and·References·Identifiers: ·CCE-82919-2
4939 ···························References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·RHEL-08-040001,·SV-230488r627750_rule4939 ···························References: ·CCI-000381,·SRG-OS-000095-GPOS-00049,·RHEL-08-040001,·SV-230488r627750_rule
4940 Remediation_Anaconda_snippet_⇲ 
4941 Complexity:·low 
4942 Disruption:·low 
4943 Strategy:···disable 
  
4944 package·--remove=abrt-addon-ccpp 
4945 Remediation_Puppet_snippet_⇲4940 Remediation_Puppet_snippet_⇲
4946 Complexity:·low4941 Complexity:·low
4947 Disruption:·low4942 Disruption:·low
4948 Strategy:···disable4943 Strategy:···disable
4949 include·remove_abrt-addon-ccpp4944 include·remove_abrt-addon-ccpp
  
4950 class·remove_abrt-addon-ccpp·{4945 class·remove_abrt-addon-ccpp·{
Offset 4966, 14 lines modifiedOffset 4960, 20 lines modified
4966 #»      ···system!4960 #»      ···system!
  
4967 if·rpm·-q·--quiet·"abrt-addon-ccpp"·;·then4961 if·rpm·-q·--quiet·"abrt-addon-ccpp"·;·then
  
4968 ····yum·remove·-y·"abrt-addon-ccpp"4962 ····yum·remove·-y·"abrt-addon-ccpp"
  
4969 fi4963 fi
 4964 Remediation_Anaconda_snippet_⇲
 4965 Complexity:·low
 4966 Disruption:·low
 4967 Strategy:···disable
  
 4968 package·--remove=abrt-addon-ccpp
4970 Remediation_Ansible_snippet_⇲4969 Remediation_Ansible_snippet_⇲
4971 Complexity:·low4970 Complexity:·low
4972 Disruption:·low4971 Disruption:·low
4973 Strategy:···disable4972 Strategy:···disable
4974 -·name:·Ensure·abrt-addon-ccpp·is·removed4973 -·name:·Ensure·abrt-addon-ccpp·is·removed
4975 ··package:4974 ··package:
4976 ····name:·abrt-addon-ccpp4975 ····name:·abrt-addon-ccpp
Offset 4991, 20 lines modifiedOffset 4991, 14 lines modified
4991 The·abrt-addon-kerneloops·package·can·be·removed·with·the·following·command:4991 The·abrt-addon-kerneloops·package·can·be·removed·with·the·following·command:
Max diff block lines reached; 368652/372574 bytes (98.95%) of diff not shown.
655 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_enhanced.html
    
Offset 15267, 116 lines modifiedOffset 15267, 116 lines modified
0003ba20:·7267·6574·3d22·2369·646d·3735·3835·2220··rget="#idm7585"·0003ba20:·7267·6574·3d22·2369·646d·3735·3835·2220··rget="#idm7585"·
0003ba30:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003ba30:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003ba40:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003ba40:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003ba50:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003ba50:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003ba60:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003ba60:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003ba70:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003ba70:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003ba80:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003ba80:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003ba90:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp0003ba90:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003baa0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003baa0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bab0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003bab0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bac0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003bac0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bad0:·6522·2069·643d·2269·646d·3735·3835·223e··e"·id="idm7585">0003bad0:·2069·643d·2269·646d·3735·3835·223e·3c74···id="idm7585"><t
0003bae0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003bae0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003baf0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003baf0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bb00:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003bb00:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bb10:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003bb10:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bb20:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003bb20:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bb30:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003bb30:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003bb40:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003bb40:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bb50:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003bb50:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003bb60:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bb60:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bb70:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003bb70:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bb80:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003bb80:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bb90:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003bb90:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bba0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003bba0:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
0003bbb0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=0003bbb0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003bbc0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003bbd0:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003bbe0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003bbf0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003bc00:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003bc10:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003bc20:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003bc30:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003bc40:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003bc50:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003bc60:·6574·3d22·2369·646d·3735·3836·2220·7461··et="#idm7586"·ta
 0003bc70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003bc80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003bc90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003bca0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003bcb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003bcc0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003bcd0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003bce0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003bcf0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003bd00:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003bd10:·2269·646d·3735·3836·223e·3c74·6162·6c65··"idm7586"><table
 0003bd20:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003bd30:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003bd40:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003bd50:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003bd60:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003bd70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003bd80:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003bd90:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003bda0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003bdb0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003bdc0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003bdd0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003bde0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003bdf0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003be00:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003be10:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003be20:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0003be30:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0003be40:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0003be50:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0003be60:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003be70:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 0003be80:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf
 0003be90:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003bea0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 0003beb0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003bec0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003bed0:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003bee0:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
0003bbc0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003bef0:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003bbd0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003bf00:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003bbe0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003bf10:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003bbf0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003bf20:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003bc00:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003bf30:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003bc10:·6172·6765·743d·2223·6964·6d37·3538·3622··arget="#idm7586"0003bf40:·6172·6765·743d·2223·6964·6d37·3538·3722··arget="#idm7587"
0003bc20:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003bf50:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003bc30:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003bf60:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003bc40:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003bf70:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003bc50:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003bf80:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003bc60:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003bf90:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003bc70:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003bfa0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003bc80:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003bfb0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003bc90:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bfc0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003bca0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bfd0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003bcb0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bfe0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bcc0:·2220·6964·3d22·6964·6d37·3538·3622·3e3c··"·id="idm7586"><0003bff0:·7365·2220·6964·3d22·6964·6d37·3538·3722··se"·id="idm7587"
0003bcd0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003c000:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bce0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003c010:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bcf0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003c020:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bd00:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003c030:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bd10:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003c040:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bd20:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003c050:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bd30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c060:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bd40:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003c070:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bd50:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c080:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bd60:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003c090:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bd70:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003c0a0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bd80:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003c0b0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bd90:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003c0c0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c0d0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
0003bda0:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003bdb0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003bdc0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003bdd0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003bde0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003bdf0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003be00:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003be10:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003be20:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003be30:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003be40:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003be50:·6765·743d·2223·6964·6d37·3538·3722·2074··get="#idm7587"·t 
0003be60:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003be70:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003be80:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003be90:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003bea0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003beb0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003bec0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 598398/613054 bytes (97.61%) of diff not shown.
56.7 KB
html2text {}
    
Offset 89, 20 lines modifiedOffset 89, 14 lines modified
89 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,89 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
90 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019990 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
91 Remediation_OSBuild_Blueprint_snippet_⇲91 Remediation_OSBuild_Blueprint_snippet_⇲
  
92 [[packages]]92 [[packages]]
93 name·=·"aide"93 name·=·"aide"
94 version·=·"*"94 version·=·"*"
95 Remediation_Anaconda_snippet_⇲ 
96 Complexity:·low 
97 Disruption:·low 
98 Strategy:···enable 
  
99 package·--add=aide 
100 Remediation_Puppet_snippet_⇲95 Remediation_Puppet_snippet_⇲
101 Complexity:·low96 Complexity:·low
102 Disruption:·low97 Disruption:·low
103 Strategy:···enable98 Strategy:···enable
104 include·install_aide99 include·install_aide
  
105 class·install_aide·{100 class·install_aide·{
Offset 120, 14 lines modifiedOffset 114, 20 lines modified
120 if·!·rpm·-q·--quiet·"aide"·;·then114 if·!·rpm·-q·--quiet·"aide"·;·then
121 ····dnf·install·-y·"aide"115 ····dnf·install·-y·"aide"
122 fi116 fi
  
123 else117 else
124 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'118 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
125 fi119 fi
 120 Remediation_Anaconda_snippet_⇲
 121 Complexity:·low
 122 Disruption:·low
 123 Strategy:···enable
  
 124 package·--add=aide
126 Remediation_Ansible_snippet_⇲125 Remediation_Ansible_snippet_⇲
127 Complexity:·low126 Complexity:·low
128 Disruption:·low127 Disruption:·low
129 Strategy:···enable128 Strategy:···enable
130 -·name:·Ensure·aide·is·installed129 -·name:·Ensure·aide·is·installed
131 ··package:130 ··package:
132 ····name:·aide131 ····name:·aide
Offset 393, 20 lines modifiedOffset 393, 14 lines modified
393 Identifiers·and·References·Identifiers: ·CCE-83523-1393 Identifiers·and·References·Identifiers: ·CCE-83523-1
394 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125394 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
395 Remediation_OSBuild_Blueprint_snippet_⇲395 Remediation_OSBuild_Blueprint_snippet_⇲
  
396 [[packages]]396 [[packages]]
397 name·=·"sudo"397 name·=·"sudo"
398 version·=·"*"398 version·=·"*"
399 Remediation_Anaconda_snippet_⇲ 
400 Complexity:·low 
401 Disruption:·low 
402 Strategy:···enable 
  
403 package·--add=sudo 
404 Remediation_Puppet_snippet_⇲399 Remediation_Puppet_snippet_⇲
405 Complexity:·low400 Complexity:·low
406 Disruption:·low401 Disruption:·low
407 Strategy:···enable402 Strategy:···enable
408 include·install_sudo403 include·install_sudo
  
409 class·install_sudo·{404 class·install_sudo·{
Offset 424, 14 lines modifiedOffset 418, 20 lines modified
424 if·!·rpm·-q·--quiet·"sudo"·;·then418 if·!·rpm·-q·--quiet·"sudo"·;·then
425 ····dnf·install·-y·"sudo"419 ····dnf·install·-y·"sudo"
426 fi420 fi
  
427 else421 else
428 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'422 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
429 fi423 fi
 424 Remediation_Anaconda_snippet_⇲
 425 Complexity:·low
 426 Disruption:·low
 427 Strategy:···enable
  
 428 package·--add=sudo
430 Remediation_Ansible_snippet_⇲429 Remediation_Ansible_snippet_⇲
431 Complexity:·low430 Complexity:·low
432 Disruption:·low431 Disruption:·low
433 Strategy:···enable432 Strategy:···enable
434 -·name:·Ensure·sudo·is·installed433 -·name:·Ensure·sudo·is·installed
435 ··package:434 ··package:
436 ····name:·sudo435 ····name:·sudo
Offset 775, 20 lines modifiedOffset 775, 14 lines modified
775 Identifiers·and·References·Identifiers: ·CCE-83454-9775 Identifiers·and·References·Identifiers: ·CCE-83454-9
776 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080776 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
777 Remediation_OSBuild_Blueprint_snippet_⇲777 Remediation_OSBuild_Blueprint_snippet_⇲
  
778 [[packages]]778 [[packages]]
779 name·=·"dnf-automatic"779 name·=·"dnf-automatic"
780 version·=·"*"780 version·=·"*"
781 Remediation_Anaconda_snippet_⇲ 
782 Complexity:·low 
783 Disruption:·low 
784 Strategy:···enable 
  
785 package·--add=dnf-automatic 
786 Remediation_Puppet_snippet_⇲781 Remediation_Puppet_snippet_⇲
787 Complexity:·low782 Complexity:·low
788 Disruption:·low783 Disruption:·low
789 Strategy:···enable784 Strategy:···enable
790 include·install_dnf-automatic785 include·install_dnf-automatic
  
791 class·install_dnf-automatic·{786 class·install_dnf-automatic·{
Offset 800, 14 lines modifiedOffset 794, 20 lines modified
800 Complexity:·low794 Complexity:·low
801 Disruption:·low795 Disruption:·low
802 Strategy:···enable796 Strategy:···enable
  
803 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then797 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
804 ····dnf·install·-y·"dnf-automatic"798 ····dnf·install·-y·"dnf-automatic"
805 fi799 fi
 800 Remediation_Anaconda_snippet_⇲
 801 Complexity:·low
 802 Disruption:·low
 803 Strategy:···enable
  
 804 package·--add=dnf-automatic
806 Remediation_Ansible_snippet_⇲805 Remediation_Ansible_snippet_⇲
807 Complexity:·low806 Complexity:·low
808 Disruption:·low807 Disruption:·low
809 Strategy:···enable808 Strategy:···enable
810 -·name:·Ensure·dnf-automatic·is·installed809 -·name:·Ensure·dnf-automatic·is·installed
811 ··package:810 ··package:
812 ····name:·dnf-automatic811 ····name:·dnf-automatic
Offset 7578, 15 lines modifiedOffset 7578, 15 lines modified
7578 Severity: ·medium7578 Severity: ·medium
Max diff block lines reached; 54504/58011 bytes (93.95%) of diff not shown.
713 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_high.html
    
Offset 15266, 116 lines modifiedOffset 15266, 116 lines modified
0003ba10:·7267·6574·3d22·2369·646d·3735·3835·2220··rget="#idm7585"·0003ba10:·7267·6574·3d22·2369·646d·3735·3835·2220··rget="#idm7585"·
0003ba20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003ba20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003ba30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003ba30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003ba40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003ba40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003ba50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003ba50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003ba60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003ba60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003ba70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003ba70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003ba80:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp0003ba80:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003ba90:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003ba90:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003baa0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003baa0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bab0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003bab0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bac0:·6522·2069·643d·2269·646d·3735·3835·223e··e"·id="idm7585">0003bac0:·2069·643d·2269·646d·3735·3835·223e·3c74···id="idm7585"><t
0003bad0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003bad0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bae0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003bae0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003baf0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003baf0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bb00:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003bb00:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bb10:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003bb10:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bb20:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003bb20:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003bb30:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003bb30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bb40:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003bb40:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003bb50:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bb50:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bb60:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003bb60:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bb70:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003bb70:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bb80:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003bb80:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bb90:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003bb90:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
0003bba0:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=0003bba0:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003bbb0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003bbc0:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003bbd0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003bbe0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003bbf0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003bc00:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003bc10:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003bc20:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003bc30:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003bc40:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003bc50:·6574·3d22·2369·646d·3735·3836·2220·7461··et="#idm7586"·ta
 0003bc60:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003bc70:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003bc80:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003bc90:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003bca0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003bcb0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003bcc0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003bcd0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003bce0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003bcf0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003bd00:·2269·646d·3735·3836·223e·3c74·6162·6c65··"idm7586"><table
 0003bd10:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003bd20:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003bd30:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003bd40:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003bd50:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003bd60:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003bd70:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003bd80:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003bd90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003bda0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003bdb0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003bdc0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003bdd0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003bde0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003bdf0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003be00:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003be10:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0003be20:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0003be30:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0003be40:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0003be50:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003be60:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 0003be70:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf
 0003be80:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003be90:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 0003bea0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003beb0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003bec0:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003bed0:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
0003bbb0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003bee0:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003bbc0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003bef0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003bbd0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003bf00:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003bbe0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003bf10:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003bbf0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003bf20:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003bc00:·6172·6765·743d·2223·6964·6d37·3538·3622··arget="#idm7586"0003bf30:·6172·6765·743d·2223·6964·6d37·3538·3722··arget="#idm7587"
0003bc10:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003bf40:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003bc20:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003bf50:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003bc30:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003bf60:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003bc40:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003bf70:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003bc50:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003bf80:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003bc60:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003bf90:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003bc70:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003bfa0:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003bc80:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003bfb0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003bc90:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bfc0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003bca0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003bfd0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bcb0:·2220·6964·3d22·6964·6d37·3538·3622·3e3c··"·id="idm7586"><0003bfe0:·7365·2220·6964·3d22·6964·6d37·3538·3722··se"·id="idm7587"
0003bcc0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003bff0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bcd0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003c000:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bce0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003c010:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bcf0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003c020:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bd00:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003c030:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bd10:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003c040:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bd20:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c050:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bd30:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003c060:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bd40:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c070:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bd50:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003c080:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bd60:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003c090:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bd70:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003c0a0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bd80:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003c0b0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c0c0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
0003bd90:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003bda0:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003bdb0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003bdc0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003bdd0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003bde0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003bdf0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003be00:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003be10:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003be20:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003be30:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003be40:·6765·743d·2223·6964·6d37·3538·3722·2074··get="#idm7587"·t 
0003be50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003be60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003be70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003be80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003be90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003bea0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003beb0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 652590/667246 bytes (97.80%) of diff not shown.
60.8 KB
html2text {}
    
Offset 89, 20 lines modifiedOffset 89, 14 lines modified
89 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,89 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
90 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019990 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
91 Remediation_OSBuild_Blueprint_snippet_⇲91 Remediation_OSBuild_Blueprint_snippet_⇲
  
92 [[packages]]92 [[packages]]
93 name·=·"aide"93 name·=·"aide"
94 version·=·"*"94 version·=·"*"
95 Remediation_Anaconda_snippet_⇲ 
96 Complexity:·low 
97 Disruption:·low 
98 Strategy:···enable 
  
99 package·--add=aide 
100 Remediation_Puppet_snippet_⇲95 Remediation_Puppet_snippet_⇲
101 Complexity:·low96 Complexity:·low
102 Disruption:·low97 Disruption:·low
103 Strategy:···enable98 Strategy:···enable
104 include·install_aide99 include·install_aide
  
105 class·install_aide·{100 class·install_aide·{
Offset 120, 14 lines modifiedOffset 114, 20 lines modified
120 if·!·rpm·-q·--quiet·"aide"·;·then114 if·!·rpm·-q·--quiet·"aide"·;·then
121 ····dnf·install·-y·"aide"115 ····dnf·install·-y·"aide"
122 fi116 fi
  
123 else117 else
124 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'118 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
125 fi119 fi
 120 Remediation_Anaconda_snippet_⇲
 121 Complexity:·low
 122 Disruption:·low
 123 Strategy:···enable
  
 124 package·--add=aide
126 Remediation_Ansible_snippet_⇲125 Remediation_Ansible_snippet_⇲
127 Complexity:·low126 Complexity:·low
128 Disruption:·low127 Disruption:·low
129 Strategy:···enable128 Strategy:···enable
130 -·name:·Ensure·aide·is·installed129 -·name:·Ensure·aide·is·installed
131 ··package:130 ··package:
132 ····name:·aide131 ····name:·aide
Offset 655, 20 lines modifiedOffset 655, 14 lines modified
655 Identifiers·and·References·Identifiers: ·CCE-83523-1655 Identifiers·and·References·Identifiers: ·CCE-83523-1
656 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125656 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
657 Remediation_OSBuild_Blueprint_snippet_⇲657 Remediation_OSBuild_Blueprint_snippet_⇲
  
658 [[packages]]658 [[packages]]
659 name·=·"sudo"659 name·=·"sudo"
660 version·=·"*"660 version·=·"*"
661 Remediation_Anaconda_snippet_⇲ 
662 Complexity:·low 
663 Disruption:·low 
664 Strategy:···enable 
  
665 package·--add=sudo 
666 Remediation_Puppet_snippet_⇲661 Remediation_Puppet_snippet_⇲
667 Complexity:·low662 Complexity:·low
668 Disruption:·low663 Disruption:·low
669 Strategy:···enable664 Strategy:···enable
670 include·install_sudo665 include·install_sudo
  
671 class·install_sudo·{666 class·install_sudo·{
Offset 686, 14 lines modifiedOffset 680, 20 lines modified
686 if·!·rpm·-q·--quiet·"sudo"·;·then680 if·!·rpm·-q·--quiet·"sudo"·;·then
687 ····dnf·install·-y·"sudo"681 ····dnf·install·-y·"sudo"
688 fi682 fi
  
689 else683 else
690 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'684 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
691 fi685 fi
 686 Remediation_Anaconda_snippet_⇲
 687 Complexity:·low
 688 Disruption:·low
 689 Strategy:···enable
  
 690 package·--add=sudo
692 Remediation_Ansible_snippet_⇲691 Remediation_Ansible_snippet_⇲
693 Complexity:·low692 Complexity:·low
694 Disruption:·low693 Disruption:·low
695 Strategy:···enable694 Strategy:···enable
696 -·name:·Ensure·sudo·is·installed695 -·name:·Ensure·sudo·is·installed
697 ··package:696 ··package:
698 ····name:·sudo697 ····name:·sudo
Offset 1037, 20 lines modifiedOffset 1037, 14 lines modified
1037 Identifiers·and·References·Identifiers: ·CCE-83454-91037 Identifiers·and·References·Identifiers: ·CCE-83454-9
1038 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-000801038 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
1039 Remediation_OSBuild_Blueprint_snippet_⇲1039 Remediation_OSBuild_Blueprint_snippet_⇲
  
1040 [[packages]]1040 [[packages]]
1041 name·=·"dnf-automatic"1041 name·=·"dnf-automatic"
1042 version·=·"*"1042 version·=·"*"
1043 Remediation_Anaconda_snippet_⇲ 
1044 Complexity:·low 
1045 Disruption:·low 
1046 Strategy:···enable 
  
1047 package·--add=dnf-automatic 
1048 Remediation_Puppet_snippet_⇲1043 Remediation_Puppet_snippet_⇲
1049 Complexity:·low1044 Complexity:·low
1050 Disruption:·low1045 Disruption:·low
1051 Strategy:···enable1046 Strategy:···enable
1052 include·install_dnf-automatic1047 include·install_dnf-automatic
  
1053 class·install_dnf-automatic·{1048 class·install_dnf-automatic·{
Offset 1062, 14 lines modifiedOffset 1056, 20 lines modified
1062 Complexity:·low1056 Complexity:·low
1063 Disruption:·low1057 Disruption:·low
1064 Strategy:···enable1058 Strategy:···enable
  
1065 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then1059 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
1066 ····dnf·install·-y·"dnf-automatic"1060 ····dnf·install·-y·"dnf-automatic"
1067 fi1061 fi
 1062 Remediation_Anaconda_snippet_⇲
 1063 Complexity:·low
 1064 Disruption:·low
 1065 Strategy:···enable
  
 1066 package·--add=dnf-automatic
1068 Remediation_Ansible_snippet_⇲1067 Remediation_Ansible_snippet_⇲
1069 Complexity:·low1068 Complexity:·low
1070 Disruption:·low1069 Disruption:·low
1071 Strategy:···enable1070 Strategy:···enable
1072 -·name:·Ensure·dnf-automatic·is·installed1071 -·name:·Ensure·dnf-automatic·is·installed
1073 ··package:1072 ··package:
1074 ····name:·dnf-automatic1073 ····name:·dnf-automatic
Offset 7840, 15 lines modifiedOffset 7840, 15 lines modified
7840 Severity: ·medium7840 Severity: ·medium
Max diff block lines reached; 58765/62276 bytes (94.36%) of diff not shown.
656 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_intermediary.html
    
Offset 15261, 116 lines modifiedOffset 15261, 116 lines modified
0003b9c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b9c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b9d0:·3735·3835·2220·7461·6269·6e64·6578·3d22··7585"·tabindex="0003b9d0:·3735·3835·2220·7461·6269·6e64·6578·3d22··7585"·tabindex="
0003b9e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b9e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b9f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b9f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003ba00:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003ba00:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003ba10:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003ba10:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003ba20:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003ba20:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003ba30:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda0003ba30:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s
0003ba40:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0003ba40:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003ba50:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003ba50:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003ba60:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003ba60:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003ba70:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003ba70:·6c61·7073·6522·2069·643d·2269·646d·3735··lapse"·id="idm75
0003ba80:·3735·3835·223e·3c74·6162·6c65·2063·6c61··7585"><table·cla0003ba80:·3835·223e·3c74·6162·6c65·2063·6c61·7373··85"><table·class
0003ba90:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003ba90:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003baa0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003baa0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003bab0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003bab0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003bac0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003bac0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003bad0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003bad0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003bae0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bae0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003baf0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003baf0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003bb00:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003bb00:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003bb10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bb10:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bb20:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003bb20:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003bb30:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003bb30:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003bb40:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003bb40:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003bb50:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003bb60:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod0003bb50:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003bb60:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class
 0003bb70:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{.
 0003bb80:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid
 0003bb90:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·=
 0003bba0:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed'
 0003bbb0:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code><
 0003bbc0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003bbd0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003bbe0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003bbf0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003bc00:·612d·7461·7267·6574·3d22·2369·646d·3735··a-target="#idm75
 0003bc10:·3836·2220·7461·6269·6e64·6578·3d22·3022··86"·tabindex="0"
 0003bc20:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003bc30:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003bc40:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003bc50:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003bc60:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003bc70:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003bc80:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003bc90:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003bca0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003bcb0:·6522·2069·643d·2269·646d·3735·3836·223e··e"·id="idm7586">
 0003bcc0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003bcd0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003bce0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003bcf0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003bd00:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003bd10:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003bd20:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003bd30:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003bd40:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bd50:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003bd60:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003bd70:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003bd80:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bd90:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003bda0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003bdb0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003bdc0:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f
 0003bdd0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
 0003bde0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
 0003bdf0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
 0003be00:·656e·7620·5d3b·2074·6865·6e0a·0a69·6620··env·];·then..if·
 0003be10:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003be20:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 0003be30:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·-
 0003be40:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 0003be50:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003be60:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003be70:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003be80:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003be90:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
0003bb70:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003bea0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003bb80:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003beb0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003bb90:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003bec0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003bba0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003bed0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003bbb0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003bee0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bbc0:·6d37·3538·3622·2074·6162·696e·6465·783d··m7586"·tabindex=0003bef0:·6d37·3538·3722·2074·6162·696e·6465·783d··m7587"·tabindex=
0003bbd0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003bf00:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bbe0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bf10:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bbf0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bf20:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bc00:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003bf30:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bc10:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bf40:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003bc20:·6564·6961·7469·6f6e·2050·7570·7065·7420··ediation·Puppet·0003bf50:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond
0003bc30:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003bf60:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a
0003bc40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003bf70:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003bc50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003bf80:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003bc60:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003bf90:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003bc70:·3538·3622·3e3c·7461·626c·6520·636c·6173··586"><table·clas0003bfa0:·6d37·3538·3722·3e3c·7461·626c·6520·636c··m7587"><table·cl
0003bc80:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003bfb0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003bc90:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003bfc0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bca0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003bfd0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003bcb0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003bfe0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003bcc0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003bff0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003bcd0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003c000:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bce0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003c010:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bcf0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003c020:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003bd00:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003c030:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bd10:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003c040:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003bd20:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003c050:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003bd30:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003c060:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c070:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003c080:·202d·2d61·6464·3d61·6964·650a·3c2f·636f···--add=aide.</co
0003bd40:·3c63·6f64·653e·696e·636c·7564·6520·696e··<code>include·in 
0003bd50:·7374·616c·6c5f·6169·6465·0a0a·636c·6173··stall_aide..clas 
0003bd60:·7320·696e·7374·616c·6c5f·6169·6465·207b··s·install_aide·{ 
0003bd70:·0a20·2070·6163·6b61·6765·207b·2027·6169··.··package·{·'ai 
0003bd80:·6465·273a·0a20·2020·2065·6e73·7572·6520··de':.····ensure· 
0003bd90:·3d26·6774·3b20·2769·6e73·7461·6c6c·6564··=&gt;·'installed 
0003bda0:·272c·0a20·207d·0a7d·0a3c·2f63·6f64·653e··',.··}.}.</code> 
0003bdb0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bdc0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bdd0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bde0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bdf0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003be00:·3538·3722·2074·6162·696e·6465·783d·2230··587"·tabindex="0 
0003be10:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003be20:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003be30:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003be40:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
Max diff block lines reached; 598735/613391 bytes (97.61%) of diff not shown.
56.7 KB
html2text {}
    
Offset 88, 20 lines modifiedOffset 88, 14 lines modified
88 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,88 and·········References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,
89 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019989 References··A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
90 Remediation_OSBuild_Blueprint_snippet_⇲90 Remediation_OSBuild_Blueprint_snippet_⇲
  
91 [[packages]]91 [[packages]]
92 name·=·"aide"92 name·=·"aide"
93 version·=·"*"93 version·=·"*"
94 Remediation_Anaconda_snippet_⇲ 
95 Complexity:·low 
96 Disruption:·low 
97 Strategy:···enable 
  
98 package·--add=aide 
99 Remediation_Puppet_snippet_⇲94 Remediation_Puppet_snippet_⇲
100 Complexity:·low95 Complexity:·low
101 Disruption:·low96 Disruption:·low
102 Strategy:···enable97 Strategy:···enable
103 include·install_aide98 include·install_aide
  
104 class·install_aide·{99 class·install_aide·{
Offset 119, 14 lines modifiedOffset 113, 20 lines modified
119 if·!·rpm·-q·--quiet·"aide"·;·then113 if·!·rpm·-q·--quiet·"aide"·;·then
120 ····dnf·install·-y·"aide"114 ····dnf·install·-y·"aide"
121 fi115 fi
  
122 else116 else
123 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'117 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
124 fi118 fi
 119 Remediation_Anaconda_snippet_⇲
 120 Complexity:·low
 121 Disruption:·low
 122 Strategy:···enable
  
 123 package·--add=aide
125 Remediation_Ansible_snippet_⇲124 Remediation_Ansible_snippet_⇲
126 Complexity:·low125 Complexity:·low
127 Disruption:·low126 Disruption:·low
128 Strategy:···enable127 Strategy:···enable
129 -·name:·Ensure·aide·is·installed128 -·name:·Ensure·aide·is·installed
130 ··package:129 ··package:
131 ····name:·aide130 ····name:·aide
Offset 392, 20 lines modifiedOffset 392, 14 lines modified
392 Identifiers·and·References·Identifiers: ·CCE-83523-1392 Identifiers·and·References·Identifiers: ·CCE-83523-1
393 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125393 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
394 Remediation_OSBuild_Blueprint_snippet_⇲394 Remediation_OSBuild_Blueprint_snippet_⇲
  
395 [[packages]]395 [[packages]]
396 name·=·"sudo"396 name·=·"sudo"
397 version·=·"*"397 version·=·"*"
398 Remediation_Anaconda_snippet_⇲ 
399 Complexity:·low 
400 Disruption:·low 
401 Strategy:···enable 
  
402 package·--add=sudo 
403 Remediation_Puppet_snippet_⇲398 Remediation_Puppet_snippet_⇲
404 Complexity:·low399 Complexity:·low
405 Disruption:·low400 Disruption:·low
406 Strategy:···enable401 Strategy:···enable
407 include·install_sudo402 include·install_sudo
  
408 class·install_sudo·{403 class·install_sudo·{
Offset 423, 14 lines modifiedOffset 417, 20 lines modified
423 if·!·rpm·-q·--quiet·"sudo"·;·then417 if·!·rpm·-q·--quiet·"sudo"·;·then
424 ····dnf·install·-y·"sudo"418 ····dnf·install·-y·"sudo"
425 fi419 fi
  
426 else420 else
427 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'421 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
428 fi422 fi
 423 Remediation_Anaconda_snippet_⇲
 424 Complexity:·low
 425 Disruption:·low
 426 Strategy:···enable
  
 427 package·--add=sudo
429 Remediation_Ansible_snippet_⇲428 Remediation_Ansible_snippet_⇲
430 Complexity:·low429 Complexity:·low
431 Disruption:·low430 Disruption:·low
432 Strategy:···enable431 Strategy:···enable
433 -·name:·Ensure·sudo·is·installed432 -·name:·Ensure·sudo·is·installed
434 ··package:433 ··package:
435 ····name:·sudo434 ····name:·sudo
Offset 774, 20 lines modifiedOffset 774, 14 lines modified
774 Identifiers·and·References·Identifiers: ·CCE-83454-9774 Identifiers·and·References·Identifiers: ·CCE-83454-9
775 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080775 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
776 Remediation_OSBuild_Blueprint_snippet_⇲776 Remediation_OSBuild_Blueprint_snippet_⇲
  
777 [[packages]]777 [[packages]]
778 name·=·"dnf-automatic"778 name·=·"dnf-automatic"
779 version·=·"*"779 version·=·"*"
780 Remediation_Anaconda_snippet_⇲ 
781 Complexity:·low 
782 Disruption:·low 
783 Strategy:···enable 
  
784 package·--add=dnf-automatic 
785 Remediation_Puppet_snippet_⇲780 Remediation_Puppet_snippet_⇲
786 Complexity:·low781 Complexity:·low
787 Disruption:·low782 Disruption:·low
788 Strategy:···enable783 Strategy:···enable
789 include·install_dnf-automatic784 include·install_dnf-automatic
  
790 class·install_dnf-automatic·{785 class·install_dnf-automatic·{
Offset 799, 14 lines modifiedOffset 793, 20 lines modified
799 Complexity:·low793 Complexity:·low
800 Disruption:·low794 Disruption:·low
801 Strategy:···enable795 Strategy:···enable
  
802 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then796 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
803 ····dnf·install·-y·"dnf-automatic"797 ····dnf·install·-y·"dnf-automatic"
804 fi798 fi
 799 Remediation_Anaconda_snippet_⇲
 800 Complexity:·low
 801 Disruption:·low
 802 Strategy:···enable
  
 803 package·--add=dnf-automatic
805 Remediation_Ansible_snippet_⇲804 Remediation_Ansible_snippet_⇲
806 Complexity:·low805 Complexity:·low
807 Disruption:·low806 Disruption:·low
808 Strategy:···enable807 Strategy:···enable
809 -·name:·Ensure·dnf-automatic·is·installed808 -·name:·Ensure·dnf-automatic·is·installed
810 ··package:809 ··package:
811 ····name:·dnf-automatic810 ····name:·dnf-automatic
Offset 7160, 15 lines modifiedOffset 7160, 15 lines modified
7160 Severity: ·medium7160 Severity: ·medium
Max diff block lines reached; 54504/58011 bytes (93.95%) of diff not shown.
245 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_minimal.html
    
Offset 15975, 107 lines modifiedOffset 15975, 107 lines modified
0003e660:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm110003e660:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm11
0003e670:·3537·3722·2074·6162·696e·6465·783d·2230··577"·tabindex="00003e670:·3537·3722·2074·6162·696e·6465·783d·2230··577"·tabindex="0
0003e680:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003e680:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003e690:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003e690:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003e6a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003e6a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003e6b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003e6b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003e6c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003e6c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003e6d0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003e6d0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003e6e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003e6e0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003e6f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003e6f0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003e700:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003e700:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003e710:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10003e710:·6170·7365·2220·6964·3d22·6964·6d31·3135··apse"·id="idm115
0003e720:·3135·3737·223e·3c74·6162·6c65·2063·6c61··1577"><table·cla0003e720:·3737·223e·3c74·6162·6c65·2063·6c61·7373··77"><table·class
0003e730:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003e730:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003e740:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003e740:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003e750:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003e750:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003e760:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003e760:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003e770:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003e770:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003e780:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003e790:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003e7a0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003e7b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003e7c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003e7d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003e7e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003e7f0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins
 0003e800:·7461·6c6c·5f64·6e66·2d61·7574·6f6d·6174··tall_dnf-automat
 0003e810:·6963·0a0a·636c·6173·7320·696e·7374·616c··ic..class·instal
 0003e820:·6c5f·646e·662d·6175·746f·6d61·7469·6320··l_dnf-automatic·
 0003e830:·7b0a·2020·7061·636b·6167·6520·7b20·2764··{.··package·{·'d
 0003e840:·6e66·2d61·7574·6f6d·6174·6963·273a·0a20··nf-automatic':.·
 0003e850:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 0003e860:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 0003e870:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 0003e880:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003e890:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003e8a0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003e8b0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003e8c0:·6765·743d·2223·6964·6d31·3135·3738·2220··get="#idm11578"·
 0003e8d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003e8e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003e8f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003e900:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003e910:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003e920:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003e930:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0003e940:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003e950:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003e960:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003e970:·643d·2269·646d·3131·3537·3822·3e3c·7461··d="idm11578"><ta
 0003e980:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003e990:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003e9a0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003e9b0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003e9c0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003e9d0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003e9e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003e9f0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003e780:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003ea00:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003e790:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003e7a0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003e7b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003e7c0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003e7d0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003e7e0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003e7f0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package· 
0003e800:·2d2d·6164·643d·646e·662d·6175·746f·6d61··--add=dnf-automa0003ea10:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003ea20:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003ea30:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003ea40:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a69··le><pre><code>.i
 0003ea50:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 0003ea60:·6574·2022·646e·662d·6175·746f·6d61·7469··et·"dnf-automati
 0003ea70:·6322·203b·2074·6865·6e0a·2020·2020·646e··c"·;·then.····dn
 0003ea80:·6620·696e·7374·616c·6c20·2d79·2022·646e··f·install·-y·"dn
 0003ea90:·662d·6175·746f·6d61·7469·6322·0a66·690a··f-automatic".fi.
0003e810:·7469·630a·3c2f·636f·6465·3e3c·2f70·7265··tic.</code></pre0003eaa0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003e820:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003eab0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003e830:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003eac0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003e840:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003ead0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003e850:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003eae0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003e860:·7267·6574·3d22·2369·646d·3131·3537·3822··rget="#idm11578"0003eaf0:·3d22·2369·646d·3131·3537·3922·2074·6162··="#idm11579"·tab
0003e870:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003eb00:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003e880:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003eb10:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003e890:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003eb20:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003e8a0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003eb30:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003e8b0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003eb40:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003e8c0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003eb50:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003e8d0:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003eb60:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003e8e0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003eb70:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003e8f0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003eb80:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003e900:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003eb90:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003e910:·2220·6964·3d22·6964·6d31·3135·3738·223e··"·id="idm11578">0003eba0:·6964·3d22·6964·6d31·3135·3739·223e·3c74··id="idm11579"><t
0003e920:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003ebb0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003e930:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003ebc0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003e940:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003ebd0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003e950:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003ebe0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003e960:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003ebf0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003e970:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003ec00:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003e980:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003ec10:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003e990:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003ec20:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003e9a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003ec30:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003e9b0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003ec40:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003e9c0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003ec50:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003e9d0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003ec60:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003e9e0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003ec70:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003ec80:·7061·636b·6167·6520·2d2d·6164·643d·646e··package·--add=dn
0003e9f0:·3e69·6e63·6c75·6465·2069·6e73·7461·6c6c··>include·install 
0003ea00:·5f64·6e66·2d61·7574·6f6d·6174·6963·0a0a··_dnf-automatic.. 
0003ea10:·636c·6173·7320·696e·7374·616c·6c5f·646e··class·install_dn 
0003ea20:·662d·6175·746f·6d61·7469·6320·7b0a·2020··f-automatic·{.··0003ec90:·662d·6175·746f·6d61·7469·630a·3c2f·636f··f-automatic.</co
0003ea30:·7061·636b·6167·6520·7b20·2764·6e66·2d61··package·{·'dnf-a 
0003ea40:·7574·6f6d·6174·6963·273a·0a20·2020·2065··utomatic':.····e 
0003ea50:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003ea60:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003ea70:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003ea80:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003ea90:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003eaa0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003eab0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003eac0:·2223·6964·6d31·3135·3739·2220·7461·6269··"#idm11579"·tabi 
0003ead0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003eae0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003eaf0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003eb00:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003eb10:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003eb20:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003eb30:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
Max diff block lines reached; 219674/233088 bytes (94.25%) of diff not shown.
17.4 KB
html2text {}
    
Offset 248, 20 lines modifiedOffset 248, 14 lines modified
248 Identifiers·and·References·Identifiers: ·CCE-83454-9248 Identifiers·and·References·Identifiers: ·CCE-83454-9
249 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080249 ···························References: ·BP28(R8),·SRG-OS-000191-GPOS-00080
250 Remediation_OSBuild_Blueprint_snippet_⇲250 Remediation_OSBuild_Blueprint_snippet_⇲
  
251 [[packages]]251 [[packages]]
252 name·=·"dnf-automatic"252 name·=·"dnf-automatic"
253 version·=·"*"253 version·=·"*"
254 Remediation_Anaconda_snippet_⇲ 
255 Complexity:·low 
256 Disruption:·low 
257 Strategy:···enable 
  
258 package·--add=dnf-automatic 
259 Remediation_Puppet_snippet_⇲254 Remediation_Puppet_snippet_⇲
260 Complexity:·low255 Complexity:·low
261 Disruption:·low256 Disruption:·low
262 Strategy:···enable257 Strategy:···enable
263 include·install_dnf-automatic258 include·install_dnf-automatic
  
264 class·install_dnf-automatic·{259 class·install_dnf-automatic·{
Offset 273, 14 lines modifiedOffset 267, 20 lines modified
273 Complexity:·low267 Complexity:·low
274 Disruption:·low268 Disruption:·low
275 Strategy:···enable269 Strategy:···enable
  
276 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then270 if·!·rpm·-q·--quiet·"dnf-automatic"·;·then
277 ····dnf·install·-y·"dnf-automatic"271 ····dnf·install·-y·"dnf-automatic"
278 fi272 fi
 273 Remediation_Anaconda_snippet_⇲
 274 Complexity:·low
 275 Disruption:·low
 276 Strategy:···enable
  
 277 package·--add=dnf-automatic
279 Remediation_Ansible_snippet_⇲278 Remediation_Ansible_snippet_⇲
280 Complexity:·low279 Complexity:·low
281 Disruption:·low280 Disruption:·low
282 Strategy:···enable281 Strategy:···enable
283 -·name:·Ensure·dnf-automatic·is·installed282 -·name:·Ensure·dnf-automatic·is·installed
284 ··package:283 ··package:
285 ····name:·dnf-automatic284 ····name:·dnf-automatic
Offset 6940, 20 lines modifiedOffset 6940, 14 lines modified
6940 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-6940 ············FTP_ITC_EXT.1.1,·SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
6941 ············002276941 ············00227
6942 Remediation_OSBuild_Blueprint_snippet_⇲6942 Remediation_OSBuild_Blueprint_snippet_⇲
  
6943 [[packages]]6943 [[packages]]
6944 name·=·"rsyslog"6944 name·=·"rsyslog"
6945 version·=·"*"6945 version·=·"*"
6946 Remediation_Anaconda_snippet_⇲ 
6947 Complexity:·low 
6948 Disruption:·low 
6949 Strategy:···enable 
  
6950 package·--add=rsyslog 
6951 Remediation_Puppet_snippet_⇲6946 Remediation_Puppet_snippet_⇲
6952 Complexity:·low6947 Complexity:·low
6953 Disruption:·low6948 Disruption:·low
6954 Strategy:···enable6949 Strategy:···enable
6955 include·install_rsyslog6950 include·install_rsyslog
  
6956 class·install_rsyslog·{6951 class·install_rsyslog·{
Offset 6971, 14 lines modifiedOffset 6965, 20 lines modified
6971 if·!·rpm·-q·--quiet·"rsyslog"·;·then6965 if·!·rpm·-q·--quiet·"rsyslog"·;·then
6972 ····dnf·install·-y·"rsyslog"6966 ····dnf·install·-y·"rsyslog"
6973 fi6967 fi
  
6974 else6968 else
6975 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6969 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6976 fi6970 fi
 6971 Remediation_Anaconda_snippet_⇲
 6972 Complexity:·low
 6973 Disruption:·low
 6974 Strategy:···enable
  
 6975 package·--add=rsyslog
6977 Remediation_Ansible_snippet_⇲6976 Remediation_Ansible_snippet_⇲
6978 Complexity:·low6977 Complexity:·low
6979 Disruption:·low6978 Disruption:·low
6980 Strategy:···enable6979 Strategy:···enable
6981 -·name:·Ensure·rsyslog·is·installed6980 -·name:·Ensure·rsyslog·is·installed
6982 ··package:6981 ··package:
6983 ····name:·rsyslog6982 ····name:·rsyslog
Offset 7169, 20 lines modifiedOffset 7169, 14 lines modified
7169 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,7169 ············DSS05.05,·DSS06.06,·CCI-000366,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,
7170 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7170 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
7171 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,7171 and·········4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,
7172 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR7172 References··4.3.4.3.2,·4.3.4.3.3,·SR_1.1,·SR_1.10,·SR_1.11,·SR_1.12,·SR_1.13,·SR_1.2,·SR_1.3,·SR
7173 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR7173 ············1.4,·SR_1.5,·SR_1.6,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·SR_2.2,·SR_2.3,·SR_2.4,·SR_2.5,·SR
7174 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,7174 ············2.6,·SR_2.7,·SR_7.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
7175 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-37175 ············A.9.1.2,·CM-7(a),·CM-7(b),·CM-6(a),·PR.IP-1,·PR.PT-3
7176 Remediation_Anaconda_snippet_⇲ 
7177 Complexity:·low 
7178 Disruption:·low 
7179 Strategy:···disable 
  
7180 package·--remove=dhcp-server 
7181 Remediation_Puppet_snippet_⇲7176 Remediation_Puppet_snippet_⇲
7182 Complexity:·low7177 Complexity:·low
7183 Disruption:·low7178 Disruption:·low
7184 Strategy:···disable7179 Strategy:···disable
7185 include·remove_dhcp-server7180 include·remove_dhcp-server
  
7186 class·remove_dhcp-server·{7181 class·remove_dhcp-server·{
Offset 7202, 14 lines modifiedOffset 7196, 20 lines modified
7202 #»      ···system!7196 #»      ···system!
  
7203 if·rpm·-q·--quiet·"dhcp-server"·;·then7197 if·rpm·-q·--quiet·"dhcp-server"·;·then
  
7204 ····dnf·remove·-y·"dhcp-server"7198 ····dnf·remove·-y·"dhcp-server"
  
7205 fi7199 fi
 7200 Remediation_Anaconda_snippet_⇲
 7201 Complexity:·low
 7202 Disruption:·low
 7203 Strategy:···disable
  
 7204 package·--remove=dhcp-server
7206 Remediation_Ansible_snippet_⇲7205 Remediation_Ansible_snippet_⇲
7207 Complexity:·low7206 Complexity:·low
7208 Disruption:·low7207 Disruption:·low
7209 Strategy:···disable7208 Strategy:···disable
7210 -·name:·Ensure·dhcp-server·is·removed7209 -·name:·Ensure·dhcp-server·is·removed
7211 ··package:7210 ··package:
7212 ····name:·dhcp-server7211 ····name:·dhcp-server
Offset 7258, 20 lines modifiedOffset 7258, 14 lines modified
7258 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,7258 Identifiers·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,
Max diff block lines reached; 14385/17833 bytes (80.67%) of diff not shown.
1.74 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis.html
    
Offset 15300, 116 lines modifiedOffset 15300, 116 lines modified
0003bc30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003bc30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003bc40:·2223·6964·6d37·3538·3522·2074·6162·696e··"#idm7585"·tabin0003bc40:·2223·6964·6d37·3538·3522·2074·6162·696e··"#idm7585"·tabin
0003bc50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003bc50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003bc60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003bc60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003bc70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003bc70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003bc80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003bc80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003bc90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003bc90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003bca0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana0003bca0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
0003bcb0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..0003bcb0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
0003bcc0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003bcc0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003bcd0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003bcd0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003bce0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003bce0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003bcf0:·3d22·6964·6d37·3538·3522·3e3c·7461·626c··="idm7585"><tabl0003bcf0:·6964·6d37·3538·3522·3e3c·7461·626c·6520··idm7585"><table·
0003bd00:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003bd00:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003bd10:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003bd10:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003bd20:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003bd20:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003bd30:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003bd30:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003bd40:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003bd40:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003bd50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003bd50:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003bd60:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003bd60:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003bd70:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003bd70:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003bd80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003bd80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bd90:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003bd90:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003bda0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003bda0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003bdb0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003bdb0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003bdc0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac0003bdc0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
0003bdd0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.0003bdd0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 0003bde0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 0003bdf0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 0003be00:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 0003be10:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 0003be20:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 0003be30:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003be40:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003be50:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003be60:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003be70:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003be80:·6964·6d37·3538·3622·2074·6162·696e·6465··idm7586"·tabinde
 0003be90:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003bea0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003beb0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003bec0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003bed0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003bee0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003bef0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003bf00:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003bf10:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003bf20:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
 0003bf30:·3538·3622·3e3c·7461·626c·6520·636c·6173··586"><table·clas
 0003bf40:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003bf50:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003bf60:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003bf70:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003bf80:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003bf90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003bfa0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003bfb0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003bfc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bfd0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003bfe0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003bff0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003c000:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003c010:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003c020:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003c030:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 0003c040:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
 0003c050:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
 0003c060:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
 0003c070:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
 0003c080:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003c090:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003c0a0:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst
 0003c0b0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003c0c0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003c0d0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003c0e0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003c0f0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003c100:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
0003bde0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003c110:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003bdf0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003c120:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003be00:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003c130:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003be10:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003c140:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003be20:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003c150:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003be30:·3d22·2369·646d·3735·3836·2220·7461·6269··="#idm7586"·tabi0003c160:·3d22·2369·646d·3735·3837·2220·7461·6269··="#idm7587"·tabi
0003be40:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003c170:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003be50:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003c180:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003be60:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003c190:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003be70:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003c1a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003be80:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003c1b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003be90:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu0003c1c0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003bea0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...0003c1d0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
0003beb0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003c1e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003bec0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003c1f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003bed0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003c200:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003bee0:·2269·646d·3735·3836·223e·3c74·6162·6c65··"idm7586"><table0003c210:·643d·2269·646d·3735·3837·223e·3c74·6162··d="idm7587"><tab
0003bef0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003c220:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003bf00:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003c230:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003bf10:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003c240:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003bf20:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003c250:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003bf30:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003c260:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003bf40:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003c270:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003bf50:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003c280:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003bf60:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003c290:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003bf70:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003c2a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003bf80:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003c2b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003bf90:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003c2c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003bfa0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003c2d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003c2e0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003c2f0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
0003bfb0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
0003bfc0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
0003bfd0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
0003bfe0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
0003bff0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
0003c000:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
0003c010:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
0003c020:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003c030:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003c040:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003c050:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003c060:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003c070:·2369·646d·3735·3837·2220·7461·6269·6e64··#idm7587"·tabind 
0003c080:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003c090:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003c0a0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003c0b0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003c0c0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
Max diff block lines reached; 1469106/1483762 bytes (99.01%) of diff not shown.
330 KB
html2text {}
    
Offset 93, 20 lines modifiedOffset 93, 14 lines modified
93 Identifiers·and·References·Identifiers: ·CCE-90843-493 Identifiers·and·References·Identifiers: ·CCE-90843-4
94 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019994 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
95 Remediation_OSBuild_Blueprint_snippet_⇲95 Remediation_OSBuild_Blueprint_snippet_⇲
  
96 [[packages]]96 [[packages]]
97 name·=·"aide"97 name·=·"aide"
98 version·=·"*"98 version·=·"*"
99 Remediation_Anaconda_snippet_⇲ 
100 Complexity:·low 
101 Disruption:·low 
102 Strategy:···enable 
  
103 package·--add=aide 
104 Remediation_Puppet_snippet_⇲99 Remediation_Puppet_snippet_⇲
105 Complexity:·low100 Complexity:·low
106 Disruption:·low101 Disruption:·low
107 Strategy:···enable102 Strategy:···enable
108 include·install_aide103 include·install_aide
  
109 class·install_aide·{104 class·install_aide·{
Offset 124, 14 lines modifiedOffset 118, 20 lines modified
124 if·!·rpm·-q·--quiet·"aide"·;·then118 if·!·rpm·-q·--quiet·"aide"·;·then
125 ····dnf·install·-y·"aide"119 ····dnf·install·-y·"aide"
126 fi120 fi
  
127 else121 else
128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'122 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
129 fi123 fi
 124 Remediation_Anaconda_snippet_⇲
 125 Complexity:·low
 126 Disruption:·low
 127 Strategy:···enable
  
 128 package·--add=aide
130 Remediation_Ansible_snippet_⇲129 Remediation_Ansible_snippet_⇲
131 Complexity:·low130 Complexity:·low
132 Disruption:·low131 Disruption:·low
133 Strategy:···enable132 Strategy:···enable
134 -·name:·Ensure·aide·is·installed133 -·name:·Ensure·aide·is·installed
135 ··package:134 ··package:
136 ····name:·aide135 ····name:·aide
Offset 1225, 20 lines modifiedOffset 1225, 14 lines modified
1225 Identifiers·and·References·Identifiers: ·CCE-83523-11225 Identifiers·and·References·Identifiers: ·CCE-83523-1
1226 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001251226 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
1227 Remediation_OSBuild_Blueprint_snippet_⇲1227 Remediation_OSBuild_Blueprint_snippet_⇲
  
1228 [[packages]]1228 [[packages]]
1229 name·=·"sudo"1229 name·=·"sudo"
1230 version·=·"*"1230 version·=·"*"
1231 Remediation_Anaconda_snippet_⇲ 
1232 Complexity:·low 
1233 Disruption:·low 
1234 Strategy:···enable 
  
1235 package·--add=sudo 
1236 Remediation_Puppet_snippet_⇲1231 Remediation_Puppet_snippet_⇲
1237 Complexity:·low1232 Complexity:·low
1238 Disruption:·low1233 Disruption:·low
1239 Strategy:···enable1234 Strategy:···enable
1240 include·install_sudo1235 include·install_sudo
  
1241 class·install_sudo·{1236 class·install_sudo·{
Offset 1256, 14 lines modifiedOffset 1250, 20 lines modified
1256 if·!·rpm·-q·--quiet·"sudo"·;·then1250 if·!·rpm·-q·--quiet·"sudo"·;·then
1257 ····dnf·install·-y·"sudo"1251 ····dnf·install·-y·"sudo"
1258 fi1252 fi
  
1259 else1253 else
1260 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1254 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1261 fi1255 fi
 1256 Remediation_Anaconda_snippet_⇲
 1257 Complexity:·low
 1258 Disruption:·low
 1259 Strategy:···enable
  
 1260 package·--add=sudo
1262 Remediation_Ansible_snippet_⇲1261 Remediation_Ansible_snippet_⇲
1263 Complexity:·low1262 Complexity:·low
1264 Disruption:·low1263 Disruption:·low
1265 Strategy:···enable1264 Strategy:···enable
1266 -·name:·Ensure·sudo·is·installed1265 -·name:·Ensure·sudo·is·installed
1267 ··package:1266 ··package:
1268 ····name:·sudo1267 ····name:·sudo
Offset 8074, 15 lines modifiedOffset 8074, 15 lines modified
8074 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.8074 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
8075 Severity: ················medium8075 Severity: ················medium
8076 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod8076 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
8077 Identifiers·and·References·Identifiers: ·CCE-83830-08077 Identifiers·and·References·Identifiers: ·CCE-83830-0
8078 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019408078 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
8079 Remediation_Shell_script_⇲8079 Remediation_Shell_script_⇲
8080 #·Remediation·is·applicable·only·in·certain·platforms8080 #·Remediation·is·applicable·only·in·certain·platforms
8081 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8081 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8082 #·First·perform·the·remediation·of·the·syscall·rule8082 #·First·perform·the·remediation·of·the·syscall·rule
8083 #·Retrieve·hardware·architecture·of·the·underlying·system8083 #·Retrieve·hardware·architecture·of·the·underlying·system
8084 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8084 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8085 for·ARCH·in·"${RULE_ARCHS[@]}"8085 for·ARCH·in·"${RULE_ARCHS[@]}"
8086 do8086 do
Offset 8429, 16 lines modifiedOffset 8429, 16 lines modified
8429 ··-·reboot_required8429 ··-·reboot_required
8430 ··-·restrict_strategy8430 ··-·restrict_strategy
  
8431 -·name:·Set·architecture·for·audit·chmod·tasks8431 -·name:·Set·architecture·for·audit·chmod·tasks
8432 ··set_fact:8432 ··set_fact:
8433 ····audit_arch:·b648433 ····audit_arch:·b64
8434 ··when:8434 ··when:
8435 ··-·'"audit"·in·ansible_facts.packages' 
8436 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8435 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8436 ··-·'"audit"·in·ansible_facts.packages'
8437 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8437 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8438 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8438 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8439 ··tags:8439 ··tags:
8440 ··-·CCE-83830-08440 ··-·CCE-83830-0
8441 ··-·CJIS-5.4.1.18441 ··-·CJIS-5.4.1.1
8442 ··-·NIST-800-171-3.1.78442 ··-·NIST-800-171-3.1.7
8443 ··-·NIST-800-53-AU-12(c)8443 ··-·NIST-800-53-AU-12(c)
Offset 8575, 16 lines modifiedOffset 8575, 16 lines modified
8575 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008575 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8576 ········-F·auid!=unset·-F·key=perm_mod8576 ········-F·auid!=unset·-F·key=perm_mod
8577 ······create:·true8577 ······create:·true
8578 ······mode:·o-rwx8578 ······mode:·o-rwx
8579 ······state:·present8579 ······state:·present
8580 ····when:·syscalls_found·|·length·==·08580 ····when:·syscalls_found·|·length·==·0
8581 ··when:8581 ··when:
8582 ··-·'"audit"·in·ansible_facts.packages' 
8583 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8582 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
Max diff block lines reached; 331561/337557 bytes (98.22%) of diff not shown.
885 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_server_l1.html
    
Offset 15290, 116 lines modifiedOffset 15290, 116 lines modified
0003bb90:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bb90:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003bba0:·6964·6d37·3538·3522·2074·6162·696e·6465··idm7585"·tabinde0003bba0:·6964·6d37·3538·3522·2074·6162·696e·6465··idm7585"·tabinde
0003bbb0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bbb0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003bbc0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bbc0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003bbd0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bbd0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003bbe0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bbe0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003bbf0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bbf0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003bc00:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco0003bc00:·656d·6564·6961·7469·6f6e·2050·7570·7065··emediation·Puppe
0003bc10:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...<0003bc10:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
0003bc20:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003bc20:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003bc30:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003bc30:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003bc40:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003bc40:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003bc50:·6964·6d37·3538·3522·3e3c·7461·626c·6520··idm7585"><table·0003bc50:·6d37·3538·3522·3e3c·7461·626c·6520·636c··m7585"><table·cl
0003bc60:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003bc60:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003bc70:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003bc70:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bc80:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003bc80:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003bc90:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003bc90:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003bca0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003bca0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003bcb0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bcb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bcc0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003bcc0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003bcd0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003bcd0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003bce0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bce0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bcf0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003bcf0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003bd00:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003bd00:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003bd10:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003bd10:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0003bd20:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa 
0003bd30:·6765·202d·2d61·6464·3d61·6964·650a·3c2f··ge·--add=aide.</0003bd20:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include·
 0003bd30:·696e·7374·616c·6c5f·6169·6465·0a0a·636c··install_aide..cl
 0003bd40:·6173·7320·696e·7374·616c·6c5f·6169·6465··ass·install_aide
 0003bd50:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003bd60:·6169·6465·273a·0a20·2020·2065·6e73·7572··aide':.····ensur
 0003bd70:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install
 0003bd80:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
 0003bd90:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003bda0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003bdb0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003bdc0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003bdd0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003bde0:·6d37·3538·3622·2074·6162·696e·6465·783d··m7586"·tabindex=
 0003bdf0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003be00:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003be10:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003be20:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003be30:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003be40:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003be50:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003be60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003be70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003be80:·6170·7365·2220·6964·3d22·6964·6d37·3538··apse"·id="idm758
 0003be90:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=
 0003bea0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003beb0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003bec0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003bed0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003bee0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003bef0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003bf00:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003bf10:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003bf20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003bf30:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003bf40:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003bf50:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003bf60:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 0003bf70:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 0003bf80:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 0003bf90:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
 0003bfa0:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
 0003bfb0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
 0003bfc0:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
 0003bfd0:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..
 0003bfe0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003bff0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003c000:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal
 0003c010:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003c020:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003c030:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003c040:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003c050:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003c060:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
0003bd40:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003c070:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003bd50:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003c080:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003bd60:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003c090:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003bd70:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003c0a0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003bd80:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003c0b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bd90:·2369·646d·3735·3836·2220·7461·6269·6e64··#idm7586"·tabind0003c0c0:·2369·646d·3735·3837·2220·7461·6269·6e64··#idm7587"·tabind
0003bda0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003c0d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bdb0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003c0e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bdc0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003c0f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003bdd0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003c100:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003bde0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003c110:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003bdf0:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp0003c120:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
0003be00:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</0003c130:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
0003be10:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c140:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003be20:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c150:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003be30:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003c160:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003be40:·646d·3735·3836·223e·3c74·6162·6c65·2063··dm7586"><table·c0003c170:·2269·646d·3735·3837·223e·3c74·6162·6c65··"idm7587"><table
0003be50:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003c180:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003be60:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003c190:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003be70:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003c1a0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003be80:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003c1b0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003be90:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003c1c0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003bea0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c1d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003beb0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003c1e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003bec0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003c1f0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003bed0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003c200:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bee0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003c210:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003bef0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003c220:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003bf00:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003c230:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003c240:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003c250:·6167·6520·2d2d·6164·643d·6169·6465·0a3c··age·--add=aide.<
0003bf10:·7265·3e3c·636f·6465·3e69·6e63·6c75·6465··re><code>include 
0003bf20:·2069·6e73·7461·6c6c·5f61·6964·650a·0a63···install_aide..c 
0003bf30:·6c61·7373·2069·6e73·7461·6c6c·5f61·6964··lass·install_aid 
0003bf40:·6520·7b0a·2020·7061·636b·6167·6520·7b20··e·{.··package·{· 
0003bf50:·2761·6964·6527·3a0a·2020·2020·656e·7375··'aide':.····ensu 
0003bf60:·7265·203d·2667·743b·2027·696e·7374·616c··re·=&gt;·'instal 
0003bf70:·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··led',.··}.}.</co 
0003bf80:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003bf90:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003bfa0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003bfb0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003bfc0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003bfd0:·646d·3735·3837·2220·7461·6269·6e64·6578··dm7587"·tabindex 
0003bfe0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003bff0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003c000:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003c010:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
Max diff block lines reached; 800986/815642 bytes (98.20%) of diff not shown.
88.1 KB
html2text {}
    
Offset 91, 20 lines modifiedOffset 91, 14 lines modified
91 Identifiers·and·References·Identifiers: ·CCE-90843-491 Identifiers·and·References·Identifiers: ·CCE-90843-4
92 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019992 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
93 Remediation_OSBuild_Blueprint_snippet_⇲93 Remediation_OSBuild_Blueprint_snippet_⇲
  
94 [[packages]]94 [[packages]]
95 name·=·"aide"95 name·=·"aide"
96 version·=·"*"96 version·=·"*"
97 Remediation_Anaconda_snippet_⇲ 
98 Complexity:·low 
99 Disruption:·low 
100 Strategy:···enable 
  
101 package·--add=aide 
102 Remediation_Puppet_snippet_⇲97 Remediation_Puppet_snippet_⇲
103 Complexity:·low98 Complexity:·low
104 Disruption:·low99 Disruption:·low
105 Strategy:···enable100 Strategy:···enable
106 include·install_aide101 include·install_aide
  
107 class·install_aide·{102 class·install_aide·{
Offset 122, 14 lines modifiedOffset 116, 20 lines modified
122 if·!·rpm·-q·--quiet·"aide"·;·then116 if·!·rpm·-q·--quiet·"aide"·;·then
123 ····dnf·install·-y·"aide"117 ····dnf·install·-y·"aide"
124 fi118 fi
  
125 else119 else
126 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'120 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
127 fi121 fi
 122 Remediation_Anaconda_snippet_⇲
 123 Complexity:·low
 124 Disruption:·low
 125 Strategy:···enable
  
 126 package·--add=aide
128 Remediation_Ansible_snippet_⇲127 Remediation_Ansible_snippet_⇲
129 Complexity:·low128 Complexity:·low
130 Disruption:·low129 Disruption:·low
131 Strategy:···enable130 Strategy:···enable
132 -·name:·Ensure·aide·is·installed131 -·name:·Ensure·aide·is·installed
133 ··package:132 ··package:
134 ····name:·aide133 ····name:·aide
Offset 1133, 20 lines modifiedOffset 1133, 14 lines modified
1133 Identifiers·and·References·Identifiers: ·CCE-83523-11133 Identifiers·and·References·Identifiers: ·CCE-83523-1
1134 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001251134 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
1135 Remediation_OSBuild_Blueprint_snippet_⇲1135 Remediation_OSBuild_Blueprint_snippet_⇲
  
1136 [[packages]]1136 [[packages]]
1137 name·=·"sudo"1137 name·=·"sudo"
1138 version·=·"*"1138 version·=·"*"
1139 Remediation_Anaconda_snippet_⇲ 
1140 Complexity:·low 
1141 Disruption:·low 
1142 Strategy:···enable 
  
1143 package·--add=sudo 
1144 Remediation_Puppet_snippet_⇲1139 Remediation_Puppet_snippet_⇲
1145 Complexity:·low1140 Complexity:·low
1146 Disruption:·low1141 Disruption:·low
1147 Strategy:···enable1142 Strategy:···enable
1148 include·install_sudo1143 include·install_sudo
  
1149 class·install_sudo·{1144 class·install_sudo·{
Offset 1164, 14 lines modifiedOffset 1158, 20 lines modified
1164 if·!·rpm·-q·--quiet·"sudo"·;·then1158 if·!·rpm·-q·--quiet·"sudo"·;·then
1165 ····dnf·install·-y·"sudo"1159 ····dnf·install·-y·"sudo"
1166 fi1160 fi
  
1167 else1161 else
1168 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1162 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1169 fi1163 fi
 1164 Remediation_Anaconda_snippet_⇲
 1165 Complexity:·low
 1166 Disruption:·low
 1167 Strategy:···enable
  
 1168 package·--add=sudo
1170 Remediation_Ansible_snippet_⇲1169 Remediation_Ansible_snippet_⇲
1171 Complexity:·low1170 Complexity:·low
1172 Disruption:·low1171 Disruption:·low
1173 Strategy:···enable1172 Strategy:···enable
1174 -·name:·Ensure·sudo·is·installed1173 -·name:·Ensure·sudo·is·installed
1175 ··package:1174 ··package:
1176 ····name:·sudo1175 ····name:·sudo
Offset 7926, 15 lines modifiedOffset 7926, 15 lines modified
7926 Identifiers·and·References·Identifiers: ·CCE-83848-27926 Identifiers·and·References·Identifiers: ·CCE-83848-2
7927 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-002277927 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227
7928 Remediation_Shell_script_⇲7928 Remediation_Shell_script_⇲
7929 Complexity:·low7929 Complexity:·low
7930 Disruption:·low7930 Disruption:·low
7931 Strategy:···configure7931 Strategy:···configure
7932 #·Remediation·is·applicable·only·in·certain·platforms7932 #·Remediation·is·applicable·only·in·certain·platforms
7933 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then7933 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
7934 chgrp·0·/boot/grub2/grub.cfg7934 chgrp·0·/boot/grub2/grub.cfg
  
7935 else7935 else
7936 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7936 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7937 fi7937 fi
7938 Remediation_Ansible_snippet_⇲7938 Remediation_Ansible_snippet_⇲
Offset 7959, 16 lines modifiedOffset 7959, 16 lines modified
7959 ··-·no_reboot_needed7959 ··-·no_reboot_needed
  
7960 -·name:·Test·for·existence·/boot/grub2/grub.cfg7960 -·name:·Test·for·existence·/boot/grub2/grub.cfg
7961 ··stat:7961 ··stat:
7962 ····path:·/boot/grub2/grub.cfg7962 ····path:·/boot/grub2/grub.cfg
7963 ··register:·file_exists7963 ··register:·file_exists
7964 ··when:7964 ··when:
7965 ··-·'"grub2-common"·in·ansible_facts.packages' 
7966 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'7965 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 7966 ··-·'"grub2-common"·in·ansible_facts.packages'
7967 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7967 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
7968 ··tags:7968 ··tags:
7969 ··-·CCE-83848-27969 ··-·CCE-83848-2
7970 ··-·CJIS-5.5.2.27970 ··-·CJIS-5.5.2.2
7971 ··-·NIST-800-171-3.4.57971 ··-·NIST-800-171-3.4.5
7972 ··-·NIST-800-53-AC-6(1)7972 ··-·NIST-800-53-AC-6(1)
7973 ··-·NIST-800-53-CM-6(a)7973 ··-·NIST-800-53-CM-6(a)
Offset 7981, 16 lines modifiedOffset 7981, 16 lines modified
7981 ··-·no_reboot_needed7981 ··-·no_reboot_needed
  
7982 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg7982 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
7983 ··file:7983 ··file:
7984 ····path:·/boot/grub2/grub.cfg7984 ····path:·/boot/grub2/grub.cfg
7985 ····group:·'0'7985 ····group:·'0'
7986 ··when:7986 ··when:
7987 ··-·'"grub2-common"·in·ansible_facts.packages' 
7988 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'7987 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
Max diff block lines reached; 85449/90170 bytes (94.76%) of diff not shown.
854 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_workstation_l1.html
    
Offset 15286, 116 lines modifiedOffset 15286, 116 lines modified
0003bb50:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003bb50:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003bb60:·3538·3522·2074·6162·696e·6465·783d·2230··585"·tabindex="00003bb60:·3538·3522·2074·6162·696e·6465·783d·2230··585"·tabindex="0
0003bb70:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bb70:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bb80:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bb80:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003bb90:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003bb90:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003bba0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003bba0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003bbb0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003bbb0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003bbc0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·0003bbc0:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn
0003bbd0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003bbd0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
0003bbe0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003bbe0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bbf0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003bbf0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bc00:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003bc00:·6170·7365·2220·6964·3d22·6964·6d37·3538··apse"·id="idm758
0003bc10:·3538·3522·3e3c·7461·626c·6520·636c·6173··585"><table·clas0003bc10:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=
0003bc20:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003bc20:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bc30:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003bc30:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bc40:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003bc40:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003bc50:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003bc50:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003bc60:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003bc60:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bc70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bc70:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bc80:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003bc80:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003bc90:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003bc90:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003bca0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003bca0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003bcb0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003bcb0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003bcc0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003bcc0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003bcd0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003bcd0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003bce0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·- 
0003bcf0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code0003bce0:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst
 0003bcf0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class·
 0003bd00:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.·
 0003bd10:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide
 0003bd20:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=&
 0003bd30:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed',
 0003bd40:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></
 0003bd50:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003bd60:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003bd70:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003bd80:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003bd90:·2d74·6172·6765·743d·2223·6964·6d37·3538··-target="#idm758
 0003bda0:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
 0003bdb0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003bdc0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003bdd0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003bde0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003bdf0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003be00:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003be10:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003be20:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003be30:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003be40:·2220·6964·3d22·6964·6d37·3538·3622·3e3c··"·id="idm7586"><
 0003be50:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003be60:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003be70:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003be80:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003be90:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003bea0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003beb0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bec0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003bed0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bee0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bef0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003bf00:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003bf10:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bf20:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003bf30:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003bf40:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003bf50:·666f·726d·730a·6966·205b·2021·202d·6620··forms.if·[·!·-f·
 0003bf60:·2f2e·646f·636b·6572·656e·7620·5d20·2661··/.dockerenv·]·&a
 0003bf70:·6d70·3b26·616d·703b·205b·2021·202d·6620··mp;&amp;·[·!·-f·
 0003bf80:·2f72·756e·2f2e·636f·6e74·6169·6e65·7265··/run/.containere
 0003bf90:·6e76·205d·3b20·7468·656e·0a0a·6966·2021··nv·];·then..if·!
 0003bfa0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003bfb0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003bfc0:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y
 0003bfd0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003bfe0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003bff0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003c000:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003c010:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003c020:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
0003bd00:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003c030:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003bd10:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003c040:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003bd20:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003c050:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003bd30:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003c060:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003bd40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003c070:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003bd50:·3735·3836·2220·7461·6269·6e64·6578·3d22··7586"·tabindex="0003c080:·3735·3837·2220·7461·6269·6e64·6578·3d22··7587"·tabindex="
0003bd60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003c090:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003bd70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003c0a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003bd80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003c0b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003bd90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003c0c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003bda0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003c0d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003bdb0:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s0003c0e0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
0003bdc0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003c0f0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003bdd0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003c100:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003bde0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003c110:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003bdf0:·6c61·7073·6522·2069·643d·2269·646d·3735··lapse"·id="idm750003c120:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003be00:·3836·223e·3c74·6162·6c65·2063·6c61·7373··86"><table·class0003c130:·3735·3837·223e·3c74·6162·6c65·2063·6c61··7587"><table·cla
0003be10:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003c140:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003be20:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003c150:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003be30:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003c160:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003be40:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003c170:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003be50:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003c180:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003be60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c190:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003be70:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003c1a0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003be80:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003c1b0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003be90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c1c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003bea0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003c1d0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003beb0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003c1e0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003bec0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003c1f0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c200:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003c210:·2d2d·6164·643d·6169·6465·0a3c·2f63·6f64··--add=aide.</cod
0003bed0:·636f·6465·3e69·6e63·6c75·6465·2069·6e73··code>include·ins 
0003bee0:·7461·6c6c·5f61·6964·650a·0a63·6c61·7373··tall_aide..class 
0003bef0:·2069·6e73·7461·6c6c·5f61·6964·6520·7b0a···install_aide·{. 
0003bf00:·2020·7061·636b·6167·6520·7b20·2761·6964····package·{·'aid 
0003bf10:·6527·3a0a·2020·2020·656e·7375·7265·203d··e':.····ensure·= 
0003bf20:·2667·743b·2027·696e·7374·616c·6c65·6427··&gt;·'installed' 
0003bf30:·2c0a·2020·7d0a·7d0a·3c2f·636f·6465·3e3c··,.··}.}.</code>< 
0003bf40:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003bf50:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003bf60:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003bf70:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003bf80:·612d·7461·7267·6574·3d22·2369·646d·3735··a-target="#idm75 
0003bf90:·3837·2220·7461·6269·6e64·6578·3d22·3022··87"·tabindex="0" 
0003bfa0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003bfb0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003bfc0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003bfd0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
Max diff block lines reached; 773604/788260 bytes (98.14%) of diff not shown.
83.8 KB
html2text {}
    
Offset 90, 20 lines modifiedOffset 90, 14 lines modified
90 Identifiers·and·References·Identifiers: ·CCE-90843-490 Identifiers·and·References·Identifiers: ·CCE-90843-4
91 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019991 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
92 Remediation_OSBuild_Blueprint_snippet_⇲92 Remediation_OSBuild_Blueprint_snippet_⇲
  
93 [[packages]]93 [[packages]]
94 name·=·"aide"94 name·=·"aide"
95 version·=·"*"95 version·=·"*"
96 Remediation_Anaconda_snippet_⇲ 
97 Complexity:·low 
98 Disruption:·low 
99 Strategy:···enable 
  
100 package·--add=aide 
101 Remediation_Puppet_snippet_⇲96 Remediation_Puppet_snippet_⇲
102 Complexity:·low97 Complexity:·low
103 Disruption:·low98 Disruption:·low
104 Strategy:···enable99 Strategy:···enable
105 include·install_aide100 include·install_aide
  
106 class·install_aide·{101 class·install_aide·{
Offset 121, 14 lines modifiedOffset 115, 20 lines modified
121 if·!·rpm·-q·--quiet·"aide"·;·then115 if·!·rpm·-q·--quiet·"aide"·;·then
122 ····dnf·install·-y·"aide"116 ····dnf·install·-y·"aide"
123 fi117 fi
  
124 else118 else
125 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'119 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
126 fi120 fi
 121 Remediation_Anaconda_snippet_⇲
 122 Complexity:·low
 123 Disruption:·low
 124 Strategy:···enable
  
 125 package·--add=aide
127 Remediation_Ansible_snippet_⇲126 Remediation_Ansible_snippet_⇲
128 Complexity:·low127 Complexity:·low
129 Disruption:·low128 Disruption:·low
130 Strategy:···enable129 Strategy:···enable
131 -·name:·Ensure·aide·is·installed130 -·name:·Ensure·aide·is·installed
132 ··package:131 ··package:
133 ····name:·aide132 ····name:·aide
Offset 1132, 20 lines modifiedOffset 1132, 14 lines modified
1132 Identifiers·and·References·Identifiers: ·CCE-83523-11132 Identifiers·and·References·Identifiers: ·CCE-83523-1
1133 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001251133 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
1134 Remediation_OSBuild_Blueprint_snippet_⇲1134 Remediation_OSBuild_Blueprint_snippet_⇲
  
1135 [[packages]]1135 [[packages]]
1136 name·=·"sudo"1136 name·=·"sudo"
1137 version·=·"*"1137 version·=·"*"
1138 Remediation_Anaconda_snippet_⇲ 
1139 Complexity:·low 
1140 Disruption:·low 
1141 Strategy:···enable 
  
1142 package·--add=sudo 
1143 Remediation_Puppet_snippet_⇲1138 Remediation_Puppet_snippet_⇲
1144 Complexity:·low1139 Complexity:·low
1145 Disruption:·low1140 Disruption:·low
1146 Strategy:···enable1141 Strategy:···enable
1147 include·install_sudo1142 include·install_sudo
  
1148 class·install_sudo·{1143 class·install_sudo·{
Offset 1163, 14 lines modifiedOffset 1157, 20 lines modified
1163 if·!·rpm·-q·--quiet·"sudo"·;·then1157 if·!·rpm·-q·--quiet·"sudo"·;·then
1164 ····dnf·install·-y·"sudo"1158 ····dnf·install·-y·"sudo"
1165 fi1159 fi
  
1166 else1160 else
1167 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1161 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1168 fi1162 fi
 1163 Remediation_Anaconda_snippet_⇲
 1164 Complexity:·low
 1165 Disruption:·low
 1166 Strategy:···enable
  
 1167 package·--add=sudo
1169 Remediation_Ansible_snippet_⇲1168 Remediation_Ansible_snippet_⇲
1170 Complexity:·low1169 Complexity:·low
1171 Disruption:·low1170 Disruption:·low
1172 Strategy:···enable1171 Strategy:···enable
1173 -·name:·Ensure·sudo·is·installed1172 -·name:·Ensure·sudo·is·installed
1174 ··package:1173 ··package:
1175 ····name:·sudo1174 ····name:·sudo
Offset 7925, 15 lines modifiedOffset 7925, 15 lines modified
7925 Identifiers·and·References·Identifiers: ·CCE-83848-27925 Identifiers·and·References·Identifiers: ·CCE-83848-2
7926 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-002277926 ···························References: ·12,·13,·14,·15,·16,·18,·3,·5,·5.5.2.2,·APO01.06,·DSS05.04,·DSS05.07,·DSS06.02,·3.4.5,·CCI-000225,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·4.3.3.7.3,·SR_2.1,·SR_5.2,·A.10.1.1,·A.11.1.4,·A.11.1.5,·A.11.2.1,·A.13.1.1,·A.13.1.3,·A.13.2.1,·A.13.2.3,·A.13.2.4,·A.14.1.2,·A.14.1.3,·A.6.1.2,·A.7.1.1,·A.7.1.2,·A.7.3.1,·A.8.2.2,·A.8.2.3,·A.9.1.1,·A.9.1.2,·A.9.2.3,·A.9.4.1,·A.9.4.4,·A.9.4.5,·CM-6(a),·AC-6(1),·PR.AC-4,·PR.DS-5,·Req-7.1,·SRG-OS-000480-GPOS-00227
7927 Remediation_Shell_script_⇲7927 Remediation_Shell_script_⇲
7928 Complexity:·low7928 Complexity:·low
7929 Disruption:·low7929 Disruption:·low
7930 Strategy:···configure7930 Strategy:···configure
7931 #·Remediation·is·applicable·only·in·certain·platforms7931 #·Remediation·is·applicable·only·in·certain·platforms
7932 if·rpm·--quiet·-q·grub2-common·&&·[·!·-f·/sys/firmware/efi·]·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then7932 if·[·!·-f·/sys/firmware/efi·]·&&·rpm·--quiet·-q·grub2-common·&&·{·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·};·then
  
7933 chgrp·0·/boot/grub2/grub.cfg7933 chgrp·0·/boot/grub2/grub.cfg
  
7934 else7934 else
7935 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'7935 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
7936 fi7936 fi
7937 Remediation_Ansible_snippet_⇲7937 Remediation_Ansible_snippet_⇲
Offset 7958, 16 lines modifiedOffset 7958, 16 lines modified
7958 ··-·no_reboot_needed7958 ··-·no_reboot_needed
  
7959 -·name:·Test·for·existence·/boot/grub2/grub.cfg7959 -·name:·Test·for·existence·/boot/grub2/grub.cfg
7960 ··stat:7960 ··stat:
7961 ····path:·/boot/grub2/grub.cfg7961 ····path:·/boot/grub2/grub.cfg
7962 ··register:·file_exists7962 ··register:·file_exists
7963 ··when:7963 ··when:
7964 ··-·'"grub2-common"·in·ansible_facts.packages' 
7965 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'7964 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 7965 ··-·'"grub2-common"·in·ansible_facts.packages'
7966 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7966 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
7967 ··tags:7967 ··tags:
7968 ··-·CCE-83848-27968 ··-·CCE-83848-2
7969 ··-·CJIS-5.5.2.27969 ··-·CJIS-5.5.2.2
7970 ··-·NIST-800-171-3.4.57970 ··-·NIST-800-171-3.4.5
7971 ··-·NIST-800-53-AC-6(1)7971 ··-·NIST-800-53-AC-6(1)
7972 ··-·NIST-800-53-CM-6(a)7972 ··-·NIST-800-53-CM-6(a)
Offset 7980, 16 lines modifiedOffset 7980, 16 lines modified
7980 ··-·no_reboot_needed7980 ··-·no_reboot_needed
  
7981 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg7981 -·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
7982 ··file:7982 ··file:
7983 ····path:·/boot/grub2/grub.cfg7983 ····path:·/boot/grub2/grub.cfg
7984 ····group:·'0'7984 ····group:·'0'
7985 ··when:7985 ··when:
7986 ··-·'"grub2-common"·in·ansible_facts.packages' 
7987 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'7986 ··-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
Max diff block lines reached; 81037/85758 bytes (94.49%) of diff not shown.
1.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_workstation_l2.html
    
Offset 15297, 116 lines modifiedOffset 15297, 116 lines modified
0003bc00:·7267·6574·3d22·2369·646d·3735·3835·2220··rget="#idm7585"·0003bc00:·7267·6574·3d22·2369·646d·3735·3835·2220··rget="#idm7585"·
0003bc10:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003bc10:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bc20:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003bc20:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003bc30:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003bc30:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003bc40:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003bc40:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003bc50:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003bc50:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003bc60:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003bc60:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003bc70:·6e20·416e·6163·6f6e·6461·2073·6e69·7070··n·Anaconda·snipp0003bc70:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet
0003bc80:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003bc80:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bc90:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003bc90:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bca0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003bca0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bcb0:·6522·2069·643d·2269·646d·3735·3835·223e··e"·id="idm7585">0003bcb0:·2069·643d·2269·646d·3735·3835·223e·3c74···id="idm7585"><t
0003bcc0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003bcc0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bcd0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003bcd0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bce0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003bce0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bcf0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003bcf0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bd00:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003bd00:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bd10:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003bd10:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003bd20:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003bd20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bd30:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003bd30:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003bd40:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bd40:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003bd50:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003bd50:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bd60:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003bd60:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bd70:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003bd70:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bd80:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003bd80:·626c·653e·3c70·7265·3e3c·636f·6465·3e69··ble><pre><code>i
0003bd90:·3e0a·7061·636b·6167·6520·2d2d·6164·643d··>.package·--add=0003bd90:·6e63·6c75·6465·2069·6e73·7461·6c6c·5f61··nclude·install_a
 0003bda0:·6964·650a·0a63·6c61·7373·2069·6e73·7461··ide..class·insta
 0003bdb0:·6c6c·5f61·6964·6520·7b0a·2020·7061·636b··ll_aide·{.··pack
 0003bdc0:·6167·6520·7b20·2761·6964·6527·3a0a·2020··age·{·'aide':.··
 0003bdd0:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·'
 0003bde0:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}.
 0003bdf0:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre><
 0003be00:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003be10:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003be20:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003be30:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003be40:·6574·3d22·2369·646d·3735·3836·2220·7461··et="#idm7586"·ta
 0003be50:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003be60:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003be70:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003be80:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003be90:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003bea0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003beb0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003bec0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003bed0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003bee0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003bef0:·2269·646d·3735·3836·223e·3c74·6162·6c65··"idm7586"><table
 0003bf00:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003bf10:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003bf20:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003bf30:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003bf40:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003bf50:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003bf60:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003bf70:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003bf80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003bf90:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003bfa0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003bfb0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003bfc0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003bfd0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003bfe0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003bff0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003c000:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
 0003c010:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
 0003c020:·6d70·3b20·5b20·2120·2d66·202f·7275·6e2f··mp;·[·!·-f·/run/
 0003c030:·2e63·6f6e·7461·696e·6572·656e·7620·5d3b··.containerenv·];
 0003c040:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003c050:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 0003c060:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf
 0003c070:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003c080:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 0003c090:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003c0a0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003c0b0:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003c0c0:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
0003bda0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr0003c0d0:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003bdb0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003c0e0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003bdc0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003c0f0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003bdd0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003c100:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003bde0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003c110:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003bdf0:·6172·6765·743d·2223·6964·6d37·3538·3622··arget="#idm7586"0003c120:·6172·6765·743d·2223·6964·6d37·3538·3722··arget="#idm7587"
0003be00:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c130:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003be10:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c140:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003be20:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c150:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003be30:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c160:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003be40:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c170:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003be50:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c180:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003be60:·6f6e·2050·7570·7065·7420·736e·6970·7065··on·Puppet·snippe0003c190:·6f6e·2041·6e61·636f·6e64·6120·736e·6970··on·Anaconda·snip
0003be70:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003c1a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003be80:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003c1b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003be90:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003c1c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bea0:·2220·6964·3d22·6964·6d37·3538·3622·3e3c··"·id="idm7586"><0003c1d0:·7365·2220·6964·3d22·6964·6d37·3538·3722··se"·id="idm7587"
0003beb0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003c1e0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bec0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003c1f0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bed0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003c200:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bee0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003c210:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bef0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003c220:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bf00:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003c230:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bf10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c240:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bf20:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003c250:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bf30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003c260:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bf40:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003c270:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bf50:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003c280:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bf60:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003c290:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bf70:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003c2a0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c2b0:·653e·0a70·6163·6b61·6765·202d·2d61·6464··e>.package·--add
0003bf80:·696e·636c·7564·6520·696e·7374·616c·6c5f··include·install_ 
0003bf90:·6169·6465·0a0a·636c·6173·7320·696e·7374··aide..class·inst 
0003bfa0:·616c·6c5f·6169·6465·207b·0a20·2070·6163··all_aide·{.··pac 
0003bfb0:·6b61·6765·207b·2027·6169·6465·273a·0a20··kage·{·'aide':.· 
0003bfc0:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;· 
0003bfd0:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··} 
0003bfe0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre> 
0003bff0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c000:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c010:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003c020:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c030:·6765·743d·2223·6964·6d37·3538·3722·2074··get="#idm7587"·t 
0003c040:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c050:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c060:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c070:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c080:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c090:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c0a0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
Max diff block lines reached; 1435029/1449685 bytes (98.99%) of diff not shown.
326 KB
html2text {}
    
Offset 92, 20 lines modifiedOffset 92, 14 lines modified
92 Identifiers·and·References·Identifiers: ·CCE-90843-492 Identifiers·and·References·Identifiers: ·CCE-90843-4
93 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019993 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
94 Remediation_OSBuild_Blueprint_snippet_⇲94 Remediation_OSBuild_Blueprint_snippet_⇲
  
95 [[packages]]95 [[packages]]
96 name·=·"aide"96 name·=·"aide"
97 version·=·"*"97 version·=·"*"
98 Remediation_Anaconda_snippet_⇲ 
99 Complexity:·low 
100 Disruption:·low 
101 Strategy:···enable 
  
102 package·--add=aide 
103 Remediation_Puppet_snippet_⇲98 Remediation_Puppet_snippet_⇲
104 Complexity:·low99 Complexity:·low
105 Disruption:·low100 Disruption:·low
106 Strategy:···enable101 Strategy:···enable
107 include·install_aide102 include·install_aide
  
108 class·install_aide·{103 class·install_aide·{
Offset 123, 14 lines modifiedOffset 117, 20 lines modified
123 if·!·rpm·-q·--quiet·"aide"·;·then117 if·!·rpm·-q·--quiet·"aide"·;·then
124 ····dnf·install·-y·"aide"118 ····dnf·install·-y·"aide"
125 fi119 fi
  
126 else120 else
127 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'121 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
128 fi122 fi
 123 Remediation_Anaconda_snippet_⇲
 124 Complexity:·low
 125 Disruption:·low
 126 Strategy:···enable
  
 127 package·--add=aide
129 Remediation_Ansible_snippet_⇲128 Remediation_Ansible_snippet_⇲
130 Complexity:·low129 Complexity:·low
131 Disruption:·low130 Disruption:·low
132 Strategy:···enable131 Strategy:···enable
133 -·name:·Ensure·aide·is·installed132 -·name:·Ensure·aide·is·installed
134 ··package:133 ··package:
135 ····name:·aide134 ····name:·aide
Offset 1224, 20 lines modifiedOffset 1224, 14 lines modified
1224 Identifiers·and·References·Identifiers: ·CCE-83523-11224 Identifiers·and·References·Identifiers: ·CCE-83523-1
1225 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001251225 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
1226 Remediation_OSBuild_Blueprint_snippet_⇲1226 Remediation_OSBuild_Blueprint_snippet_⇲
  
1227 [[packages]]1227 [[packages]]
1228 name·=·"sudo"1228 name·=·"sudo"
1229 version·=·"*"1229 version·=·"*"
1230 Remediation_Anaconda_snippet_⇲ 
1231 Complexity:·low 
1232 Disruption:·low 
1233 Strategy:···enable 
  
1234 package·--add=sudo 
1235 Remediation_Puppet_snippet_⇲1230 Remediation_Puppet_snippet_⇲
1236 Complexity:·low1231 Complexity:·low
1237 Disruption:·low1232 Disruption:·low
1238 Strategy:···enable1233 Strategy:···enable
1239 include·install_sudo1234 include·install_sudo
  
1240 class·install_sudo·{1235 class·install_sudo·{
Offset 1255, 14 lines modifiedOffset 1249, 20 lines modified
1255 if·!·rpm·-q·--quiet·"sudo"·;·then1249 if·!·rpm·-q·--quiet·"sudo"·;·then
1256 ····dnf·install·-y·"sudo"1250 ····dnf·install·-y·"sudo"
1257 fi1251 fi
  
1258 else1252 else
1259 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1253 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1260 fi1254 fi
 1255 Remediation_Anaconda_snippet_⇲
 1256 Complexity:·low
 1257 Disruption:·low
 1258 Strategy:···enable
  
 1259 package·--add=sudo
1261 Remediation_Ansible_snippet_⇲1260 Remediation_Ansible_snippet_⇲
1262 Complexity:·low1261 Complexity:·low
1263 Disruption:·low1262 Disruption:·low
1264 Strategy:···enable1263 Strategy:···enable
1265 -·name:·Ensure·sudo·is·installed1264 -·name:·Ensure·sudo·is·installed
1266 ··package:1265 ··package:
1267 ····name:·sudo1266 ····name:·sudo
Offset 8073, 15 lines modifiedOffset 8073, 15 lines modified
8073 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.8073 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
8074 Severity: ················medium8074 Severity: ················medium
8075 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod8075 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
8076 Identifiers·and·References·Identifiers: ·CCE-83830-08076 Identifiers·and·References·Identifiers: ·CCE-83830-0
8077 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019408077 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
8078 Remediation_Shell_script_⇲8078 Remediation_Shell_script_⇲
8079 #·Remediation·is·applicable·only·in·certain·platforms8079 #·Remediation·is·applicable·only·in·certain·platforms
8080 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8080 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8081 #·First·perform·the·remediation·of·the·syscall·rule8081 #·First·perform·the·remediation·of·the·syscall·rule
8082 #·Retrieve·hardware·architecture·of·the·underlying·system8082 #·Retrieve·hardware·architecture·of·the·underlying·system
8083 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8083 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8084 for·ARCH·in·"${RULE_ARCHS[@]}"8084 for·ARCH·in·"${RULE_ARCHS[@]}"
8085 do8085 do
Offset 8428, 16 lines modifiedOffset 8428, 16 lines modified
8428 ··-·reboot_required8428 ··-·reboot_required
8429 ··-·restrict_strategy8429 ··-·restrict_strategy
  
8430 -·name:·Set·architecture·for·audit·chmod·tasks8430 -·name:·Set·architecture·for·audit·chmod·tasks
8431 ··set_fact:8431 ··set_fact:
8432 ····audit_arch:·b648432 ····audit_arch:·b64
8433 ··when:8433 ··when:
8434 ··-·'"audit"·in·ansible_facts.packages' 
8435 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8434 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8435 ··-·'"audit"·in·ansible_facts.packages'
8436 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8436 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8437 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8437 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8438 ··tags:8438 ··tags:
8439 ··-·CCE-83830-08439 ··-·CCE-83830-0
8440 ··-·CJIS-5.4.1.18440 ··-·CJIS-5.4.1.1
8441 ··-·NIST-800-171-3.1.78441 ··-·NIST-800-171-3.1.7
8442 ··-·NIST-800-53-AU-12(c)8442 ··-·NIST-800-53-AU-12(c)
Offset 8574, 16 lines modifiedOffset 8574, 16 lines modified
8574 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008574 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8575 ········-F·auid!=unset·-F·key=perm_mod8575 ········-F·auid!=unset·-F·key=perm_mod
8576 ······create:·true8576 ······create:·true
8577 ······mode:·o-rwx8577 ······mode:·o-rwx
8578 ······state:·present8578 ······state:·present
8579 ····when:·syscalls_found·|·length·==·08579 ····when:·syscalls_found·|·length·==·0
8580 ··when:8580 ··when:
8581 ··-·'"audit"·in·ansible_facts.packages' 
8582 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8581 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
Max diff block lines reached; 328091/334087 bytes (98.21%) of diff not shown.
427 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cui.html
    
Offset 16053, 107 lines modifiedOffset 16053, 107 lines modified
0003eb40:·2d74·6172·6765·743d·2223·6964·6d38·3236··-target="#idm8260003eb40:·2d74·6172·6765·743d·2223·6964·6d38·3236··-target="#idm826
0003eb50:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·0003eb50:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·
0003eb60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003eb60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003eb70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003eb70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003eb80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003eb80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003eb90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003eb90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003eba0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003eba0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003ebb0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn0003ebb0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
0003ebc0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003ebc0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0003ebd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003ebd0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003ebe0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003ebe0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003ebf0:·6170·7365·2220·6964·3d22·6964·6d38·3236··apse"·id="idm8260003ebf0:·7365·2220·6964·3d22·6964·6d38·3236·3522··se"·id="idm8265"
0003ec00:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=0003ec00:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003ec10:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003ec10:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003ec20:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003ec20:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003ec30:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003ec30:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003ec40:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003ec40:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003ec50:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003ec50:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003ec60:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003ec60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003ec70:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003ec70:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003ec80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ec90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003eca0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003ecb0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003ecc0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003ecd0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
0003ece0:·6464·3d63·7279·7074·6f2d·706f·6c69·6369··dd=crypto-polici 
0003ecf0:·6573·0a3c·2f63·6f64·653e·3c2f·7072·653e··es.</code></pre> 
0003ed00:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003ed10:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003ed20:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003ed30:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003ed40:·6765·743d·2223·6964·6d38·3236·3622·2074··get="#idm8266"·t 
0003ed50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003ed60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003ed70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003ed80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003ed90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003eda0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003edb0:·2050·7570·7065·7420·736e·6970·7065·7420···Puppet·snippet· 
0003edc0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003edd0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003ede0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003edf0:·6964·3d22·6964·6d38·3236·3622·3e3c·7461··id="idm8266"><ta 
0003ee00:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003ee10:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003ee20:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003ee30:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003ee40:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003ee50:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003ee60:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003ee70:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003ee80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003ee90:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003eea0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003eeb0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003eec0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in 
0003eed0:·636c·7564·6520·696e·7374·616c·6c5f·6372··clude·install_cr 
0003eee0:·7970·746f·2d70·6f6c·6963·6965·730a·0a63··ypto-policies..c 
0003eef0:·6c61·7373·2069·6e73·7461·6c6c·5f63·7279··lass·install_cry 
0003ef00:·7074·6f2d·706f·6c69·6369·6573·207b·0a20··pto-policies·{.· 
0003ef10:·2070·6163·6b61·6765·207b·2027·6372·7970···package·{·'cryp 
0003ef20:·746f·2d70·6f6c·6963·6965·7327·3a0a·2020··to-policies':.·· 
0003ef30:·2020·656e·7375·7265·203d·2667·743b·2027····ensure·=&gt;·' 
0003ef40:·696e·7374·616c·6c65·6427·2c0a·2020·7d0a··installed',.··}. 
0003ef50:·7d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··}.</code></pre>< 
0003ef60:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003ef70:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003ef80:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003ef90:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003efa0:·6574·3d22·2369·646d·3832·3637·2220·7461··et="#idm8267"·ta 
0003efb0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003efc0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003efd0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003efe0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003eff0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003f000:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003f010:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003f020:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003f030:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003f040:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003f050:·2269·646d·3832·3637·223e·3c74·6162·6c65··"idm8267"><table 
0003f060:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003f070:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003f080:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003f090:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003f0a0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003f0b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003ec80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003f0c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003ec90:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003eca0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 0003ecb0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003ecc0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003ecd0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 0003ece0:·6c5f·6372·7970·746f·2d70·6f6c·6963·6965··l_crypto-policie
 0003ecf0:·730a·0a63·6c61·7373·2069·6e73·7461·6c6c··s..class·install
 0003ed00:·5f63·7279·7074·6f2d·706f·6c69·6369·6573··_crypto-policies
 0003ed10:·207b·0a20·2070·6163·6b61·6765·207b·2027···{.··package·{·'
 0003ed20:·6372·7970·746f·2d70·6f6c·6963·6965·7327··crypto-policies'
 0003ed30:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 0003ed40:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 0003ed50:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 0003ed60:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003ed70:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003ed80:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003ed90:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003eda0:·7461·7267·6574·3d22·2369·646d·3832·3636··target="#idm8266
 0003edb0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003edc0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003edd0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003ede0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003edf0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003ee00:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003ee10:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 0003ee20:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003ee30:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003ee40:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003ee50:·2069·643d·2269·646d·3832·3636·223e·3c74···id="idm8266"><t
 0003ee60:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003ee70:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003ee80:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003ee90:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003eea0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003eeb0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003eec0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003f0d0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003eed0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003eee0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003eef0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
Max diff block lines reached; 380468/393882 bytes (96.59%) of diff not shown.
42.2 KB
html2text {}
    
Offset 236, 20 lines modifiedOffset 236, 14 lines modified
236 Identifiers·and·References·Identifiers: ·CCE-83442-4236 Identifiers·and·References·Identifiers: ·CCE-83442-4
237 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174237 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
238 Remediation_OSBuild_Blueprint_snippet_⇲238 Remediation_OSBuild_Blueprint_snippet_⇲
  
239 [[packages]]239 [[packages]]
240 name·=·"crypto-policies"240 name·=·"crypto-policies"
241 version·=·"*"241 version·=·"*"
242 Remediation_Anaconda_snippet_⇲ 
243 Complexity:·low 
244 Disruption:·low 
245 Strategy:···enable 
  
246 package·--add=crypto-policies 
247 Remediation_Puppet_snippet_⇲242 Remediation_Puppet_snippet_⇲
248 Complexity:·low243 Complexity:·low
249 Disruption:·low244 Disruption:·low
250 Strategy:···enable245 Strategy:···enable
251 include·install_crypto-policies246 include·install_crypto-policies
  
252 class·install_crypto-policies·{247 class·install_crypto-policies·{
Offset 261, 14 lines modifiedOffset 255, 20 lines modified
261 Complexity:·low255 Complexity:·low
262 Disruption:·low256 Disruption:·low
263 Strategy:···enable257 Strategy:···enable
  
264 if·!·rpm·-q·--quiet·"crypto-policies"·;·then258 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
265 ····dnf·install·-y·"crypto-policies"259 ····dnf·install·-y·"crypto-policies"
266 fi260 fi
 261 Remediation_Anaconda_snippet_⇲
 262 Complexity:·low
 263 Disruption:·low
 264 Strategy:···enable
  
 265 package·--add=crypto-policies
267 Remediation_Ansible_snippet_⇲266 Remediation_Ansible_snippet_⇲
268 Complexity:·low267 Complexity:·low
269 Disruption:·low268 Disruption:·low
270 Strategy:···enable269 Strategy:···enable
271 -·name:·Ensure·crypto-policies·is·installed270 -·name:·Ensure·crypto-policies·is·installed
272 ··package:271 ··package:
273 ····name:·crypto-policies272 ····name:·crypto-policies
Offset 570, 20 lines modifiedOffset 570, 14 lines modified
570 Identifiers·and·References·Identifiers: ·CCE-83523-1570 Identifiers·and·References·Identifiers: ·CCE-83523-1
571 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125571 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
572 Remediation_OSBuild_Blueprint_snippet_⇲572 Remediation_OSBuild_Blueprint_snippet_⇲
  
573 [[packages]]573 [[packages]]
574 name·=·"sudo"574 name·=·"sudo"
575 version·=·"*"575 version·=·"*"
576 Remediation_Anaconda_snippet_⇲ 
577 Complexity:·low 
578 Disruption:·low 
579 Strategy:···enable 
  
580 package·--add=sudo 
581 Remediation_Puppet_snippet_⇲576 Remediation_Puppet_snippet_⇲
582 Complexity:·low577 Complexity:·low
583 Disruption:·low578 Disruption:·low
584 Strategy:···enable579 Strategy:···enable
585 include·install_sudo580 include·install_sudo
  
586 class·install_sudo·{581 class·install_sudo·{
Offset 601, 14 lines modifiedOffset 595, 20 lines modified
601 if·!·rpm·-q·--quiet·"sudo"·;·then595 if·!·rpm·-q·--quiet·"sudo"·;·then
602 ····dnf·install·-y·"sudo"596 ····dnf·install·-y·"sudo"
603 fi597 fi
  
604 else598 else
605 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'599 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
606 fi600 fi
 601 Remediation_Anaconda_snippet_⇲
 602 Complexity:·low
 603 Disruption:·low
 604 Strategy:···enable
  
 605 package·--add=sudo
607 Remediation_Ansible_snippet_⇲606 Remediation_Ansible_snippet_⇲
608 Complexity:·low607 Complexity:·low
609 Disruption:·low608 Disruption:·low
610 Strategy:···enable609 Strategy:···enable
611 -·name:·Ensure·sudo·is·installed610 -·name:·Ensure·sudo·is·installed
612 ··package:611 ··package:
613 ····name:·sudo612 ····name:·sudo
Offset 635, 20 lines modifiedOffset 635, 14 lines modified
635 Identifiers·and·References·Identifiers: ·CCE-83494-5635 Identifiers·and·References·Identifiers: ·CCE-83494-5
636 ···························References: ·FIA_X509_EXT.1,·FIA_X509_EXT.2,·SRG-OS-000480-GPOS-00227636 ···························References: ·FIA_X509_EXT.1,·FIA_X509_EXT.2,·SRG-OS-000480-GPOS-00227
637 Remediation_OSBuild_Blueprint_snippet_⇲637 Remediation_OSBuild_Blueprint_snippet_⇲
  
638 [[packages]]638 [[packages]]
639 name·=·"gnutls-utils"639 name·=·"gnutls-utils"
640 version·=·"*"640 version·=·"*"
641 Remediation_Anaconda_snippet_⇲ 
642 Complexity:·low 
643 Disruption:·low 
644 Strategy:···enable 
  
645 package·--add=gnutls-utils 
646 Remediation_Puppet_snippet_⇲641 Remediation_Puppet_snippet_⇲
647 Complexity:·low642 Complexity:·low
648 Disruption:·low643 Disruption:·low
649 Strategy:···enable644 Strategy:···enable
650 include·install_gnutls-utils645 include·install_gnutls-utils
  
651 class·install_gnutls-utils·{646 class·install_gnutls-utils·{
Offset 660, 14 lines modifiedOffset 654, 20 lines modified
660 Complexity:·low654 Complexity:·low
661 Disruption:·low655 Disruption:·low
662 Strategy:···enable656 Strategy:···enable
  
663 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then657 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then
664 ····dnf·install·-y·"gnutls-utils"658 ····dnf·install·-y·"gnutls-utils"
665 fi659 fi
 660 Remediation_Anaconda_snippet_⇲
 661 Complexity:·low
 662 Disruption:·low
 663 Strategy:···enable
  
 664 package·--add=gnutls-utils
666 Remediation_Ansible_snippet_⇲665 Remediation_Ansible_snippet_⇲
667 Complexity:·low666 Complexity:·low
668 Disruption:·low667 Disruption:·low
669 Strategy:···enable668 Strategy:···enable
670 -·name:·Ensure·gnutls-utils·is·installed669 -·name:·Ensure·gnutls-utils·is·installed
671 ··package:670 ··package:
672 ····name:·gnutls-utils671 ····name:·gnutls-utils
Offset 689, 20 lines modifiedOffset 689, 14 lines modified
689 Identifiers·and·References·Identifiers: ·CCE-83502-5689 Identifiers·and·References·Identifiers: ·CCE-83502-5
Max diff block lines reached; 39996/43220 bytes (92.54%) of diff not shown.
689 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-e8.html
    
Offset 20705, 116 lines modifiedOffset 20705, 116 lines modified
00050e00:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00050e00:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00050e10:·3d22·2369·646d·3131·3336·3422·2074·6162··="#idm11364"·tab00050e10:·3d22·2369·646d·3131·3336·3422·2074·6162··="#idm11364"·tab
00050e20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00050e20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00050e30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00050e30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00050e40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00050e40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00050e50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00050e50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00050e60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00050e60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00050e70:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00050e70:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P
00050e80:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·00050e80:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..
00050e90:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·00050e90:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
00050ea0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col00050ea0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
00050eb0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·00050eb0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
00050ec0:·6964·3d22·6964·6d31·3133·3634·223e·3c74··id="idm11364"><t00050ec0:·3d22·6964·6d31·3133·3634·223e·3c74·6162··="idm11364"><tab
00050ed0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00050ed0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00050ee0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00050ee0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00050ef0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00050ef0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00050f00:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00050f00:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00050f10:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00050f10:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00050f20:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<00050f20:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00050f30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00050f30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00050f40:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th00050f40:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00050f50:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t00050f50:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00050f60:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate00050f60:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
00050f70:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab00050f70:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
00050f80:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta00050f80:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
00050f90:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.00050f90:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc
00050fa0:·7061·636b·6167·6520·2d2d·6164·643d·7265··package·--add=re 
00050fb0:·6172·0a3c·2f63·6f64·653e·3c2f·7072·653e··ar.</code></pre> 
00050fc0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00050fd0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00050fe0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00050ff0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00051000:·6765·743d·2223·6964·6d31·3133·3635·2220··get="#idm11365"· 
00051010:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00051020:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00051030:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00051040:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00051050:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00051060:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00051070:·6e20·5075·7070·6574·2073·6e69·7070·6574··n·Puppet·snippet 
00051080:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00051090:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
000510a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
000510b0:·2069·643d·2269·646d·3131·3336·3522·3e3c···id="idm11365">< 
000510c0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
000510d0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
000510e0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
000510f0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
00051100:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
00051110:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
00051120:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00051130:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t00050fa0:·6c75·6465·2069·6e73·7461·6c6c·5f72·6561··lude·install_rea
 00050fb0:·720a·0a63·6c61·7373·2069·6e73·7461·6c6c··r..class·install
 00050fc0:·5f72·6561·7220·7b0a·2020·7061·636b·6167··_rear·{.··packag
 00050fd0:·6520·7b20·2772·6561·7227·3a0a·2020·2020··e·{·'rear':.····
 00050fe0:·656e·7375·7265·203d·2667·743b·2027·696e··ensure·=&gt;·'in
 00050ff0:·7374·616c·6c65·6427·2c0a·2020·7d0a·7d0a··stalled',.··}.}.
 00051000:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 00051010:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 00051020:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00051030:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00051040:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00051050:·3d22·2369·646d·3131·3336·3522·2074·6162··="#idm11365"·tab
 00051060:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 00051070:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 00051080:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 00051090:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 000510a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 000510b0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 000510c0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 000510d0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 000510e0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 000510f0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00051100:·6964·6d31·3133·3635·223e·3c74·6162·6c65··idm11365"><table
 00051110:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00051120:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00051130:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00051140:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00051150:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
00051140:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00051160:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00051150:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
00051160:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena00051170:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00051180:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00051190:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 000511a0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 000511b0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 000511c0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 000511d0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 000511e0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 000511f0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 00051200:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 00051210:·0a69·6620·2120·6772·6570·202d·7120·6161··.if·!·grep·-q·aa
 00051220:·7263·6836·3420·2f70·726f·632f·7379·732f··rch64·/proc/sys/
 00051230:·6b65·726e·656c·2f6f·7372·656c·6561·7365··kernel/osrelease
 00051240:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 00051250:·202d·7120·2d2d·7175·6965·7420·2272·6561···-q·--quiet·"rea
 00051260:·7222·203b·2074·6865·6e0a·2020·2020·646e··r"·;·then.····dn
 00051270:·6620·696e·7374·616c·6c20·2d79·2022·7265··f·install·-y·"re
 00051280:·6172·220a·6669·0a0a·656c·7365·0a20·2020··ar".fi..else.···
 00051290:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo
 000512a0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is
 000512b0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable,
 000512c0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don
 000512d0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p
 000512e0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 000512f0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 00051300:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 00051310:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 00051320:·7461·7267·6574·3d22·2369·646d·3131·3336··target="#idm1136
 00051330:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
 00051340:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 00051350:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 00051360:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 00051370:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 00051380:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00051390:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn
 000513a0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 000513b0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 000513c0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 000513d0:·6170·7365·2220·6964·3d22·6964·6d31·3133··apse"·id="idm113
 000513e0:·3636·223e·3c74·6162·6c65·2063·6c61·7373··66"><table·class
 000513f0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00051400:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00051410:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00051420:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 00051430:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00051170:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t00051440:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
Max diff block lines reached; 551177/565833 bytes (97.41%) of diff not shown.
136 KB
html2text {}
    
Offset 921, 20 lines modifiedOffset 921, 14 lines modified
921 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed921 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
922 Identifiers·and·References·Identifiers: ·CCE-83503-3922 Identifiers·and·References·Identifiers: ·CCE-83503-3
923 Remediation_OSBuild_Blueprint_snippet_⇲923 Remediation_OSBuild_Blueprint_snippet_⇲
  
924 [[packages]]924 [[packages]]
925 name·=·"rear"925 name·=·"rear"
926 version·=·"*"926 version·=·"*"
927 Remediation_Anaconda_snippet_⇲ 
928 Complexity:·low 
929 Disruption:·low 
930 Strategy:···enable 
  
931 package·--add=rear 
932 Remediation_Puppet_snippet_⇲927 Remediation_Puppet_snippet_⇲
933 Complexity:·low928 Complexity:·low
934 Disruption:·low929 Disruption:·low
935 Strategy:···enable930 Strategy:···enable
936 include·install_rear931 include·install_rear
  
937 class·install_rear·{932 class·install_rear·{
Offset 952, 14 lines modifiedOffset 946, 20 lines modified
952 if·!·rpm·-q·--quiet·"rear"·;·then946 if·!·rpm·-q·--quiet·"rear"·;·then
953 ····dnf·install·-y·"rear"947 ····dnf·install·-y·"rear"
954 fi948 fi
  
955 else949 else
956 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'950 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
957 fi951 fi
 952 Remediation_Anaconda_snippet_⇲
 953 Complexity:·low
 954 Disruption:·low
 955 Strategy:···enable
  
 956 package·--add=rear
958 Remediation_Ansible_snippet_⇲957 Remediation_Ansible_snippet_⇲
959 Complexity:·low958 Complexity:·low
960 Disruption:·low959 Disruption:·low
961 Strategy:···enable960 Strategy:···enable
962 -·name:·Ensure·rear·is·installed961 -·name:·Ensure·rear·is·installed
963 ··package:962 ··package:
964 ····name:·rear963 ····name:·rear
Offset 1863, 15 lines modifiedOffset 1863, 15 lines modified
1863 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1863 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1864 Severity: ················medium1864 Severity: ················medium
1865 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1865 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1866 Identifiers·and·References·Identifiers: ·CCE-83830-01866 Identifiers·and·References·Identifiers: ·CCE-83830-0
1867 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019401867 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
1868 Remediation_Shell_script_⇲1868 Remediation_Shell_script_⇲
1869 #·Remediation·is·applicable·only·in·certain·platforms1869 #·Remediation·is·applicable·only·in·certain·platforms
1870 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1870 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
1871 #·First·perform·the·remediation·of·the·syscall·rule1871 #·First·perform·the·remediation·of·the·syscall·rule
1872 #·Retrieve·hardware·architecture·of·the·underlying·system1872 #·Retrieve·hardware·architecture·of·the·underlying·system
1873 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1873 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1874 for·ARCH·in·"${RULE_ARCHS[@]}"1874 for·ARCH·in·"${RULE_ARCHS[@]}"
1875 do1875 do
Offset 2218, 16 lines modifiedOffset 2218, 16 lines modified
2218 ··-·reboot_required2218 ··-·reboot_required
2219 ··-·restrict_strategy2219 ··-·restrict_strategy
  
2220 -·name:·Set·architecture·for·audit·chmod·tasks2220 -·name:·Set·architecture·for·audit·chmod·tasks
2221 ··set_fact:2221 ··set_fact:
2222 ····audit_arch:·b642222 ····audit_arch:·b64
2223 ··when:2223 ··when:
2224 ··-·'"audit"·in·ansible_facts.packages' 
2225 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2224 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2225 ··-·'"audit"·in·ansible_facts.packages'
2226 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2226 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2227 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2227 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2228 ··tags:2228 ··tags:
2229 ··-·CCE-83830-02229 ··-·CCE-83830-0
2230 ··-·CJIS-5.4.1.12230 ··-·CJIS-5.4.1.1
2231 ··-·NIST-800-171-3.1.72231 ··-·NIST-800-171-3.1.7
2232 ··-·NIST-800-53-AU-12(c)2232 ··-·NIST-800-53-AU-12(c)
Offset 2364, 16 lines modifiedOffset 2364, 16 lines modified
2364 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002364 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2365 ········-F·auid!=unset·-F·key=perm_mod2365 ········-F·auid!=unset·-F·key=perm_mod
2366 ······create:·true2366 ······create:·true
2367 ······mode:·o-rwx2367 ······mode:·o-rwx
2368 ······state:·present2368 ······state:·present
2369 ····when:·syscalls_found·|·length·==·02369 ····when:·syscalls_found·|·length·==·0
2370 ··when:2370 ··when:
2371 ··-·'"audit"·in·ansible_facts.packages' 
2372 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2371 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2372 ··-·'"audit"·in·ansible_facts.packages'
2373 ··tags:2373 ··tags:
2374 ··-·CCE-83830-02374 ··-·CCE-83830-0
2375 ··-·CJIS-5.4.1.12375 ··-·CJIS-5.4.1.1
2376 ··-·NIST-800-171-3.1.72376 ··-·NIST-800-171-3.1.7
2377 ··-·NIST-800-53-AU-12(c)2377 ··-·NIST-800-53-AU-12(c)
2378 ··-·NIST-800-53-AU-2(d)2378 ··-·NIST-800-53-AU-2(d)
2379 ··-·NIST-800-53-CM-6(a)2379 ··-·NIST-800-53-CM-6(a)
Offset 2508, 16 lines modifiedOffset 2508, 16 lines modified
2508 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002508 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2509 ········-F·auid!=unset·-F·key=perm_mod2509 ········-F·auid!=unset·-F·key=perm_mod
2510 ······create:·true2510 ······create:·true
2511 ······mode:·o-rwx2511 ······mode:·o-rwx
2512 ······state:·present2512 ······state:·present
2513 ····when:·syscalls_found·|·length·==·02513 ····when:·syscalls_found·|·length·==·0
2514 ··when:2514 ··when:
2515 ··-·'"audit"·in·ansible_facts.packages' 
2516 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2515 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2516 ··-·'"audit"·in·ansible_facts.packages'
2517 ··-·audit_arch·==·"b64"2517 ··-·audit_arch·==·"b64"
2518 ··tags:2518 ··tags:
2519 ··-·CCE-83830-02519 ··-·CCE-83830-0
2520 ··-·CJIS-5.4.1.12520 ··-·CJIS-5.4.1.1
2521 ··-·NIST-800-171-3.1.72521 ··-·NIST-800-171-3.1.7
2522 ··-·NIST-800-53-AU-12(c)2522 ··-·NIST-800-53-AU-12(c)
2523 ··-·NIST-800-53-AU-2(d)2523 ··-·NIST-800-53-AU-2(d)
Offset 2542, 15 lines modifiedOffset 2542, 15 lines modified
2542 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2542 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2543 Severity: ················medium2543 Severity: ················medium
2544 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2544 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
2545 Identifiers·and·References·Identifiers: ·CCE-83812-82545 Identifiers·and·References·Identifiers: ·CCE-83812-8
2546 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019402546 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
2547 Remediation_Shell_script_⇲2547 Remediation_Shell_script_⇲
2548 #·Remediation·is·applicable·only·in·certain·platforms2548 #·Remediation·is·applicable·only·in·certain·platforms
2549 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2549 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2550 #·First·perform·the·remediation·of·the·syscall·rule2550 #·First·perform·the·remediation·of·the·syscall·rule
2551 #·Retrieve·hardware·architecture·of·the·underlying·system2551 #·Retrieve·hardware·architecture·of·the·underlying·system
2552 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2552 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2553 for·ARCH·in·"${RULE_ARCHS[@]}"2553 for·ARCH·in·"${RULE_ARCHS[@]}"
2554 do2554 do
Max diff block lines reached; 131901/139537 bytes (94.53%) of diff not shown.
1.21 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-hipaa.html
    
Offset 23378, 94 lines modifiedOffset 23378, 94 lines modified
0005b510:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm10005b510:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
0005b520:·3439·3036·2220·7461·6269·6e64·6578·3d22··4906"·tabindex="0005b520:·3439·3036·2220·7461·6269·6e64·6578·3d22··4906"·tabindex="
0005b530:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0005b530:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0005b540:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0005b540:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0005b550:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0005b550:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0005b560:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0005b560:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0005b570:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0005b570:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0005b580:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0005b590:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0005b5a0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0005b5b0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0005b5c0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0005b5d0:·2220·6964·3d22·6964·6d31·3439·3036·223e··"·id="idm14906">
 0005b5e0:·3c70·7265·3e3c·636f·6465·3e0a·5b63·7573··<pre><code>.[cus
 0005b5f0:·746f·6d69·7a61·7469·6f6e·732e·7365·7276··tomizations.serv
 0005b600:·6963·6573·5d0a·6469·7361·626c·6564·203d··ices].disabled·=
 0005b610:·205b·2264·6562·7567·2d73·6865·6c6c·225d···["debug-shell"]
0005b580:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet 
0005b590:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</ 
0005b5a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0005b5b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0005b5c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0005b5d0:·646d·3134·3930·3622·3e3c·7072·653e·3c63··dm14906"><pre><c 
0005b5e0:·6f64·653e·2d2d·2d0a·6170·6956·6572·7369··ode>---.apiVersi 
0005b5f0:·6f6e·3a20·6d61·6368·696e·6563·6f6e·6669··on:·machineconfi 
0005b600:·6775·7261·7469·6f6e·2e6f·7065·6e73·6869··guration.openshi 
0005b610:·6674·2e69·6f2f·7631·0a6b·696e·643a·204d··ft.io/v1.kind:·M 
0005b620:·6163·6869·6e65·436f·6e66·6967·0a73·7065··achineConfig.spe 
0005b630:·633a·0a20·2063·6f6e·6669·673a·0a20·2020··c:.··config:.··· 
0005b640:·2069·676e·6974·696f·6e3a·0a20·2020·2020···ignition:.····· 
0005b650:·2076·6572·7369·6f6e·3a20·332e·312e·300a···version:·3.1.0. 
0005b660:·2020·2020·7379·7374·656d·643a·0a20·2020······systemd:.··· 
0005b670:·2020·2075·6e69·7473·3a0a·2020·2020·2020·····units:.······ 
0005b680:·2d20·656e·6162·6c65·643a·2066·616c·7365··-·enabled:·false 
0005b690:·0a20·2020·2020·2020·206e·616d·653a·2064··.········name:·d 
0005b6a0:·6562·7567·2d73·6865·6c6c·2e73·6572·7669··ebug-shell.servi 
0005b6b0:·6365·0a3c·2f63·6f64·653e·3c2f·7072·653e··ce.</code></pre>0005b620:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0005b6c0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0005b630:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0005b6d0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0005b640:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0005b6e0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0005b650:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0005b6f0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0005b660:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0005b700:·6765·743d·2223·6964·6d31·3439·3037·2220··get="#idm14907"·0005b670:·743d·2223·6964·6d31·3439·3037·2220·7461··t="#idm14907"·ta
0005b710:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0005b680:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0005b720:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0005b690:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0005b730:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0005b6a0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0005b740:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0005b6b0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0005b750:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0005b6c0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0005b760:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0005b6d0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0005b770:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0005b780:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
0005b790:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0005b7a0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0005b7b0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0005b7c0:·6964·6d31·3439·3037·223e·3c70·7265·3e3c··idm14907"><pre>< 
0005b7d0:·636f·6465·3e0a·5b63·7573·746f·6d69·7a61··code>.[customiza 
0005b7e0:·7469·6f6e·732e·7365·7276·6963·6573·5d0a··tions.services]. 
0005b7f0:·6469·7361·626c·6564·203d·205b·2264·6562··disabled·=·["deb 
0005b800:·7567·2d73·6865·6c6c·225d·0a3c·2f63·6f64··ug-shell"].</cod0005b6e0:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·.
 0005b6f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0005b700:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0005b710:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0005b720:·643d·2269·646d·3134·3930·3722·3e3c·7461··d="idm14907"><ta
 0005b730:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0005b740:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0005b750:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0005b760:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0005b770:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0005b780:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0005b790:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0005b7a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0005b7b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0005b7c0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0005b7d0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0005b7e0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0005b7f0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in
 0005b800:·636c·7564·6520·6469·7361·626c·655f·6465··clude·disable_de
 0005b810:·6275·672d·7368·656c·6c0a·0a63·6c61·7373··bug-shell..class
 0005b820:·2064·6973·6162·6c65·5f64·6562·7567·2d73···disable_debug-s
 0005b830:·6865·6c6c·207b·0a20·2073·6572·7669·6365··hell·{.··service
 0005b840:·207b·2764·6562·7567·2d73·6865·6c6c·273a···{'debug-shell':
 0005b850:·0a20·2020·2065·6e61·626c·6520·3d26·6774··.····enable·=&gt
 0005b860:·3b20·6661·6c73·652c·0a20·2020·2065·6e73··;·false,.····ens
 0005b870:·7572·6520·3d26·6774·3b20·2773·746f·7070··ure·=&gt;·'stopp
 0005b880:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod
0005b810:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0005b890:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0005b820:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0005b8a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0005b830:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0005b8b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0005b840:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0005b8c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0005b850:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0005b8d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0005b860:·6d31·3439·3038·2220·7461·6269·6e64·6578··m14908"·tabindex0005b8e0:·6d31·3439·3038·2220·7461·6269·6e64·6578··m14908"·tabindex
0005b870:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0005b8f0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0005b880:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0005b900:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0005b890:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0005b910:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0005b8a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0005b920:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0005b8b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0005b930:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0005b8c0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet0005b940:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern
0005b8d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>0005b950:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·...
0005b8e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0005b960:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0005b8f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0005b970:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0005b900:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0005b980:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0005b990:·2269·646d·3134·3930·3822·3e3c·7072·653e··"idm14908"><pre>
 0005b9a0:·3c63·6f64·653e·2d2d·2d0a·6170·6956·6572··<code>---.apiVer
 0005b9b0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
 0005b9c0:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens
 0005b9d0:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:
 0005b9e0:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s
 0005b9f0:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·
 0005ba00:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···
 0005ba10:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.
 0005ba20:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·
 0005ba30:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····
 0005ba40:·2020·2d20·656e·6162·6c65·643a·2066·616c····-·enabled:·fal
 0005ba50:·7365·0a20·2020·2020·2020·206e·616d·653a··se.········name:
0005b910:·3134·3930·3822·3e3c·7461·626c·6520·636c··14908"><table·cl 
0005b920:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0005b930:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0005b940:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0005b950:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0005b960:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0005b970:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0005b980:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0005b990:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0005b9a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0005b9b0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0005b9c0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0005b9d0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0005b9e0:·653e·3c63·6f64·653e·696e·636c·7564·6520··e><code>include· 
Max diff block lines reached; 916252/927870 bytes (98.75%) of diff not shown.
333 KB
html2text {}
    
Offset 1341, 26 lines modifiedOffset 1341, 14 lines modified
1341 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:1341 By·default,·the·debug-shell·SystemD·service·is·already·disabled.·The·debug-shell·service·can·be·disabled·with·the·following·command:
1342 $·sudo·systemctl·mask·--now·debug-shell.service1342 $·sudo·systemctl·mask·--now·debug-shell.service
1343 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.1343 Rationale:·················This·prevents·attackers·with·physical·access·from·trivially·bypassing·security·on·the·machine·through·valid·troubleshooting·configurations·and·gaining·root·access·when·the·system·is·rebooted.
1344 Severity: ················medium1344 Severity: ················medium
1345 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1345 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1346 Identifiers·and·References·Identifiers: ·CCE-90724-61346 Identifiers·and·References·Identifiers: ·CCE-90724-6
1347 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271347 ···························References: ·3.4.5,·CCI-000366,·164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii),·CM-6,·FIA_UAU.1,·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1348 Remediation_Kubernetes_snippet_⇲ 
1349 --- 
1350 apiVersion:·machineconfiguration.openshift.io/v1 
1351 kind:·MachineConfig 
1352 spec: 
1353 ··config: 
1354 ····ignition: 
1355 ······version:·3.1.0 
1356 ····systemd: 
1357 ······units: 
1358 ······-·enabled:·false 
1359 ········name:·debug-shell.service 
1360 Remediation_OSBuild_Blueprint_snippet_⇲1348 Remediation_OSBuild_Blueprint_snippet_⇲
  
1361 [customizations.services]1349 [customizations.services]
1362 disabled·=·["debug-shell"]1350 disabled·=·["debug-shell"]
1363 Remediation_Puppet_snippet_⇲1351 Remediation_Puppet_snippet_⇲
1364 Complexity:·low1352 Complexity:·low
1365 Disruption:·low1353 Disruption:·low
Offset 1369, 14 lines modifiedOffset 1357, 26 lines modified
  
1369 class·disable_debug-shell·{1357 class·disable_debug-shell·{
1370 ··service·{'debug-shell':1358 ··service·{'debug-shell':
1371 ····enable·=>·false,1359 ····enable·=>·false,
1372 ····ensure·=>·'stopped',1360 ····ensure·=>·'stopped',
1373 ··}1361 ··}
1374 }1362 }
 1363 Remediation_Kubernetes_snippet_⇲
 1364 ---
 1365 apiVersion:·machineconfiguration.openshift.io/v1
 1366 kind:·MachineConfig
 1367 spec:
 1368 ··config:
 1369 ····ignition:
 1370 ······version:·3.1.0
 1371 ····systemd:
 1372 ······units:
 1373 ······-·enabled:·false
 1374 ········name:·debug-shell.service
1375 Remediation_Shell_script_⇲1375 Remediation_Shell_script_⇲
1376 Complexity:·low1376 Complexity:·low
1377 Disruption:·low1377 Disruption:·low
1378 Strategy:···disable1378 Strategy:···disable
1379 #·Remediation·is·applicable·only·in·certain·platforms1379 #·Remediation·is·applicable·only·in·certain·platforms
1380 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then1380 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
Offset 2238, 15 lines modifiedOffset 2238, 15 lines modified
2238 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2238 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2239 Severity: ················medium2239 Severity: ················medium
2240 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod2240 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
2241 Identifiers·and·References·Identifiers: ·CCE-83830-02241 Identifiers·and·References·Identifiers: ·CCE-83830-0
2242 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-0019402242 ···························References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940
2243 Remediation_Shell_script_⇲2243 Remediation_Shell_script_⇲
2244 #·Remediation·is·applicable·only·in·certain·platforms2244 #·Remediation·is·applicable·only·in·certain·platforms
2245 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2245 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2246 #·First·perform·the·remediation·of·the·syscall·rule2246 #·First·perform·the·remediation·of·the·syscall·rule
2247 #·Retrieve·hardware·architecture·of·the·underlying·system2247 #·Retrieve·hardware·architecture·of·the·underlying·system
2248 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2248 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2249 for·ARCH·in·"${RULE_ARCHS[@]}"2249 for·ARCH·in·"${RULE_ARCHS[@]}"
2250 do2250 do
Offset 2593, 16 lines modifiedOffset 2593, 16 lines modified
2593 ··-·reboot_required2593 ··-·reboot_required
2594 ··-·restrict_strategy2594 ··-·restrict_strategy
  
2595 -·name:·Set·architecture·for·audit·chmod·tasks2595 -·name:·Set·architecture·for·audit·chmod·tasks
2596 ··set_fact:2596 ··set_fact:
2597 ····audit_arch:·b642597 ····audit_arch:·b64
2598 ··when:2598 ··when:
2599 ··-·'"audit"·in·ansible_facts.packages' 
2600 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2599 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2600 ··-·'"audit"·in·ansible_facts.packages'
2601 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2601 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2602 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2602 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2603 ··tags:2603 ··tags:
2604 ··-·CCE-83830-02604 ··-·CCE-83830-0
2605 ··-·CJIS-5.4.1.12605 ··-·CJIS-5.4.1.1
2606 ··-·NIST-800-171-3.1.72606 ··-·NIST-800-171-3.1.7
2607 ··-·NIST-800-53-AU-12(c)2607 ··-·NIST-800-53-AU-12(c)
Offset 2739, 16 lines modifiedOffset 2739, 16 lines modified
2739 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002739 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2740 ········-F·auid!=unset·-F·key=perm_mod2740 ········-F·auid!=unset·-F·key=perm_mod
2741 ······create:·true2741 ······create:·true
2742 ······mode:·o-rwx2742 ······mode:·o-rwx
2743 ······state:·present2743 ······state:·present
2744 ····when:·syscalls_found·|·length·==·02744 ····when:·syscalls_found·|·length·==·0
2745 ··when:2745 ··when:
2746 ··-·'"audit"·in·ansible_facts.packages' 
2747 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2746 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2747 ··-·'"audit"·in·ansible_facts.packages'
2748 ··tags:2748 ··tags:
2749 ··-·CCE-83830-02749 ··-·CCE-83830-0
2750 ··-·CJIS-5.4.1.12750 ··-·CJIS-5.4.1.1
2751 ··-·NIST-800-171-3.1.72751 ··-·NIST-800-171-3.1.7
2752 ··-·NIST-800-53-AU-12(c)2752 ··-·NIST-800-53-AU-12(c)
2753 ··-·NIST-800-53-AU-2(d)2753 ··-·NIST-800-53-AU-2(d)
2754 ··-·NIST-800-53-CM-6(a)2754 ··-·NIST-800-53-CM-6(a)
Offset 2883, 16 lines modifiedOffset 2883, 16 lines modified
2883 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002883 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2884 ········-F·auid!=unset·-F·key=perm_mod2884 ········-F·auid!=unset·-F·key=perm_mod
2885 ······create:·true2885 ······create:·true
2886 ······mode:·o-rwx2886 ······mode:·o-rwx
2887 ······state:·present2887 ······state:·present
2888 ····when:·syscalls_found·|·length·==·02888 ····when:·syscalls_found·|·length·==·0
2889 ··when:2889 ··when:
2890 ··-·'"audit"·in·ansible_facts.packages' 
2891 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2890 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2891 ··-·'"audit"·in·ansible_facts.packages'
2892 ··-·audit_arch·==·"b64"2892 ··-·audit_arch·==·"b64"
2893 ··tags:2893 ··tags:
2894 ··-·CCE-83830-02894 ··-·CCE-83830-0
2895 ··-·CJIS-5.4.1.12895 ··-·CJIS-5.4.1.1
2896 ··-·NIST-800-171-3.1.72896 ··-·NIST-800-171-3.1.7
2897 ··-·NIST-800-53-AU-12(c)2897 ··-·NIST-800-53-AU-12(c)
2898 ··-·NIST-800-53-AU-2(d)2898 ··-·NIST-800-53-AU-2(d)
Offset 2917, 15 lines modifiedOffset 2917, 15 lines modified
2917 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.2917 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
2918 Severity: ················medium2918 Severity: ················medium
2919 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown2919 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
Max diff block lines reached; 334306/340967 bytes (98.05%) of diff not shown.
872 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ism_o.html
    
Offset 18117, 116 lines modifiedOffset 18117, 116 lines modified
00046c40:·2d74·6172·6765·743d·2223·6964·6d37·3538··-target="#idm75800046c40:·2d74·6172·6765·743d·2223·6964·6d37·3538··-target="#idm758
00046c50:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·00046c50:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·
00046c60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00046c60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00046c70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00046c70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00046c80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00046c80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00046c90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00046c90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00046ca0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00046ca0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00046cb0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn00046cb0:·7469·6f6e·2050·7570·7065·7420·736e·6970··tion·Puppet·snip
00046cc0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br00046cc0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
00046cd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00046cd0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00046ce0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00046ce0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00046cf0:·6170·7365·2220·6964·3d22·6964·6d37·3538··apse"·id="idm75800046cf0:·7365·2220·6964·3d22·6964·6d37·3538·3522··se"·id="idm7585"
00046d00:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class=00046d00:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00046d10:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str00046d10:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00046d20:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde00046d20:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
00046d30:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden00046d30:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
00046d40:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com00046d40:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00046d50:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td00046d50:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
00046d60:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00046d60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00046d70:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption00046d70:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
00046d80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00046d80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00046d90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00046d90:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
00046da0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00046da0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00046db0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00046db0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00046dc0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00046dc0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
00046dd0:·6f64·653e·0a70·6163·6b61·6765·202d·2d61··ode>.package·--a 
00046de0:·6464·3d61·6964·650a·3c2f·636f·6465·3e3c··dd=aide.</code><00046dd0:·653e·696e·636c·7564·6520·696e·7374·616c··e>include·instal
 00046de0:·6c5f·6169·6465·0a0a·636c·6173·7320·696e··l_aide..class·in
 00046df0:·7374·616c·6c5f·6169·6465·207b·0a20·2070··stall_aide·{.··p
 00046e00:·6163·6b61·6765·207b·2027·6169·6465·273a··ackage·{·'aide':
 00046e10:·0a20·2020·2065·6e73·7572·6520·3d26·6774··.····ensure·=&gt
 00046e20:·3b20·2769·6e73·7461·6c6c·6564·272c·0a20··;·'installed',.·
 00046e30:·207d·0a7d·0a3c·2f63·6f64·653e·3c2f·7072···}.}.</code></pr
 00046e40:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00046e50:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00046e60:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00046e70:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00046e80:·6172·6765·743d·2223·6964·6d37·3538·3622··arget="#idm7586"
 00046e90:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00046ea0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00046eb0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00046ec0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00046ed0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00046ee0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00046ef0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 00046f00:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00046f10:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00046f20:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00046f30:·6964·3d22·6964·6d37·3538·3622·3e3c·7461··id="idm7586"><ta
 00046f40:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 00046f50:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 00046f60:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 00046f70:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00046f80:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 00046f90:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 00046fa0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00046fb0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00046fc0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00046fd0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 00046fe0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 00046ff0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 00047000:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 00047010:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 00047020:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 00047030:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 00047040:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
 00047050:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
 00047060:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
 00047070:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 00047080:·205d·3b20·7468·656e·0a0a·6966·2021·2072···];·then..if·!·r
 00047090:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 000470a0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 000470b0:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·"
 000470c0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 000470d0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 000470e0:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 000470f0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 00047100:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 00047110:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
00046df0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl00047120:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
00046e00:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc00047130:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
00046e10:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl00047140:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
00046e20:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat00047150:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
00046e30:·612d·7461·7267·6574·3d22·2369·646d·3735··a-target="#idm7500047160:·612d·7461·7267·6574·3d22·2369·646d·3735··a-target="#idm75
00046e40:·3836·2220·7461·6269·6e64·6578·3d22·3022··86"·tabindex="0"00047170:·3837·2220·7461·6269·6e64·6578·3d22·3022··87"·tabindex="0"
00046e50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00047180:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00046e60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00047190:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00046e70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti000471a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00046e80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·000471b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00046e90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi000471c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00046ea0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni000471d0:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s
00046eb0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>000471e0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
00046ec0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane000471f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00046ed0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00047200:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00046ee0:·7073·6522·2069·643d·2269·646d·3735·3836··pse"·id="idm758600047210:·6c61·7073·6522·2069·643d·2269·646d·3735··lapse"·id="idm75
00046ef0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="00047220:·3837·223e·3c74·6162·6c65·2063·6c61·7373··87"><table·class
00046f00:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri00047230:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
00046f10:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border00047240:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00046f20:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens00047250:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
00046f30:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp00047260:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
00046f40:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>00047270:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00046f50:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00047280:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00046f60:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:00047290:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00046f70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td000472a0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00046f80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St000472b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00046f90:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>000472c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00046fa0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>000472d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
00046fb0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co000472e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 000472f0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·--
 00047300:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>
00046fc0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta 
00046fd0:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i 
00046fe0:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.·· 
00046ff0:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide' 
00047000:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
00047010:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
00047020:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
00047030:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
00047040:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
00047050:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
00047060:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
00047070:·7461·7267·6574·3d22·2369·646d·3735·3837··target="#idm7587 
00047080:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
00047090:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
000470a0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
000470b0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
000470c0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
Max diff block lines reached; 709073/723729 bytes (97.97%) of diff not shown.
166 KB
html2text {}
    
Offset 522, 20 lines modifiedOffset 522, 14 lines modified
522 Identifiers·and·References·Identifiers: ·CCE-90843-4522 Identifiers·and·References·Identifiers: ·CCE-90843-4
523 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199523 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
524 Remediation_OSBuild_Blueprint_snippet_⇲524 Remediation_OSBuild_Blueprint_snippet_⇲
  
525 [[packages]]525 [[packages]]
526 name·=·"aide"526 name·=·"aide"
527 version·=·"*"527 version·=·"*"
528 Remediation_Anaconda_snippet_⇲ 
529 Complexity:·low 
530 Disruption:·low 
531 Strategy:···enable 
  
532 package·--add=aide 
533 Remediation_Puppet_snippet_⇲528 Remediation_Puppet_snippet_⇲
534 Complexity:·low529 Complexity:·low
535 Disruption:·low530 Disruption:·low
536 Strategy:···enable531 Strategy:···enable
537 include·install_aide532 include·install_aide
  
538 class·install_aide·{533 class·install_aide·{
Offset 553, 14 lines modifiedOffset 547, 20 lines modified
553 if·!·rpm·-q·--quiet·"aide"·;·then547 if·!·rpm·-q·--quiet·"aide"·;·then
554 ····dnf·install·-y·"aide"548 ····dnf·install·-y·"aide"
555 fi549 fi
  
556 else550 else
557 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'551 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
558 fi552 fi
 553 Remediation_Anaconda_snippet_⇲
 554 Complexity:·low
 555 Disruption:·low
 556 Strategy:···enable
  
 557 package·--add=aide
559 Remediation_Ansible_snippet_⇲558 Remediation_Ansible_snippet_⇲
560 Complexity:·low559 Complexity:·low
561 Disruption:·low560 Disruption:·low
562 Strategy:···enable561 Strategy:···enable
563 -·name:·Ensure·aide·is·installed562 -·name:·Ensure·aide·is·installed
564 ··package:563 ··package:
565 ····name:·aide564 ····name:·aide
Offset 789, 20 lines modifiedOffset 789, 14 lines modified
789 Identifiers·and·References·Identifiers: ·CCE-83523-1789 Identifiers·and·References·Identifiers: ·CCE-83523-1
790 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125790 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
791 Remediation_OSBuild_Blueprint_snippet_⇲791 Remediation_OSBuild_Blueprint_snippet_⇲
  
792 [[packages]]792 [[packages]]
793 name·=·"sudo"793 name·=·"sudo"
794 version·=·"*"794 version·=·"*"
795 Remediation_Anaconda_snippet_⇲ 
796 Complexity:·low 
797 Disruption:·low 
798 Strategy:···enable 
  
799 package·--add=sudo 
800 Remediation_Puppet_snippet_⇲795 Remediation_Puppet_snippet_⇲
801 Complexity:·low796 Complexity:·low
802 Disruption:·low797 Disruption:·low
803 Strategy:···enable798 Strategy:···enable
804 include·install_sudo799 include·install_sudo
  
805 class·install_sudo·{800 class·install_sudo·{
Offset 820, 14 lines modifiedOffset 814, 20 lines modified
820 if·!·rpm·-q·--quiet·"sudo"·;·then814 if·!·rpm·-q·--quiet·"sudo"·;·then
821 ····dnf·install·-y·"sudo"815 ····dnf·install·-y·"sudo"
822 fi816 fi
  
823 else817 else
824 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'818 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
825 fi819 fi
 820 Remediation_Anaconda_snippet_⇲
 821 Complexity:·low
 822 Disruption:·low
 823 Strategy:···enable
  
 824 package·--add=sudo
826 Remediation_Ansible_snippet_⇲825 Remediation_Ansible_snippet_⇲
827 Complexity:·low826 Complexity:·low
828 Disruption:·low827 Disruption:·low
829 Strategy:···enable828 Strategy:···enable
830 -·name:·Ensure·sudo·is·installed829 -·name:·Ensure·sudo·is·installed
831 ··package:830 ··package:
832 ····name:·sudo831 ····name:·sudo
Offset 1105, 20 lines modifiedOffset 1105, 14 lines modified
1105 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed1105 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_rear_installed
1106 Identifiers·and·References·Identifiers: ·CCE-83503-31106 Identifiers·and·References·Identifiers: ·CCE-83503-3
1107 Remediation_OSBuild_Blueprint_snippet_⇲1107 Remediation_OSBuild_Blueprint_snippet_⇲
  
1108 [[packages]]1108 [[packages]]
1109 name·=·"rear"1109 name·=·"rear"
1110 version·=·"*"1110 version·=·"*"
1111 Remediation_Anaconda_snippet_⇲ 
1112 Complexity:·low 
1113 Disruption:·low 
1114 Strategy:···enable 
  
1115 package·--add=rear 
1116 Remediation_Puppet_snippet_⇲1111 Remediation_Puppet_snippet_⇲
1117 Complexity:·low1112 Complexity:·low
1118 Disruption:·low1113 Disruption:·low
1119 Strategy:···enable1114 Strategy:···enable
1120 include·install_rear1115 include·install_rear
  
1121 class·install_rear·{1116 class·install_rear·{
Offset 1136, 14 lines modifiedOffset 1130, 20 lines modified
1136 if·!·rpm·-q·--quiet·"rear"·;·then1130 if·!·rpm·-q·--quiet·"rear"·;·then
1137 ····dnf·install·-y·"rear"1131 ····dnf·install·-y·"rear"
1138 fi1132 fi
  
1139 else1133 else
1140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1134 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1141 fi1135 fi
 1136 Remediation_Anaconda_snippet_⇲
 1137 Complexity:·low
 1138 Disruption:·low
 1139 Strategy:···enable
  
 1140 package·--add=rear
1142 Remediation_Ansible_snippet_⇲1141 Remediation_Ansible_snippet_⇲
1143 Complexity:·low1142 Complexity:·low
1144 Disruption:·low1143 Disruption:·low
1145 Strategy:···enable1144 Strategy:···enable
1146 -·name:·Ensure·rear·is·installed1145 -·name:·Ensure·rear·is·installed
1147 ··package:1146 ··package:
1148 ····name:·rear1147 ····name:·rear
Offset 6190, 15 lines modifiedOffset 6190, 15 lines modified
6190 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.6190 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
Max diff block lines reached; 165749/169493 bytes (97.79%) of diff not shown.
427 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ospp.html
    
Offset 16020, 108 lines modifiedOffset 16020, 108 lines modified
0003e930:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003e930:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003e940:·3d22·2369·646d·3832·3635·2220·7461·6269··="#idm8265"·tabi0003e940:·3d22·2369·646d·3832·3635·2220·7461·6269··="#idm8265"·tabi
0003e950:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003e950:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003e960:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003e960:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003e970:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003e970:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003e980:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003e980:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003e990:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003e990:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003e9a0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003e9a0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003e9b0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003e9b0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003e9c0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003e9c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003e9d0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003e9d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003e9e0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003e9e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003e9f0:·643d·2269·646d·3832·3635·223e·3c74·6162··d="idm8265"><tab0003e9f0:·2269·646d·3832·3635·223e·3c74·6162·6c65··"idm8265"><table
0003ea00:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003ea00:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003ea10:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003ea10:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003ea20:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003ea20:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003ea30:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003ea30:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003ea40:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003ea40:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003ea50:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003ea50:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003ea60:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003ea60:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003ea70:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003ea70:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003ea80:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003ea90:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003eaa0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003eab0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003eac0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa 
0003ead0:·636b·6167·6520·2d2d·6164·643d·6372·7970··ckage·--add=cryp 
0003eae0:·746f·2d70·6f6c·6963·6965·730a·3c2f·636f··to-policies.</co 
0003eaf0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003eb00:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003eb10:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003eb20:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003eb30:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003eb40:·646d·3832·3636·2220·7461·6269·6e64·6578··dm8266"·tabindex 
0003eb50:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003eb60:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003eb70:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003eb80:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003eb90:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003eba0:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet 
0003ebb0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003ebc0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003ebd0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003ebe0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ebf0:·3832·3636·223e·3c74·6162·6c65·2063·6c61··8266"><table·cla 
0003ec00:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003ec10:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003ec20:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003ec30:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003ec40:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003ec50:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003ec60:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003ec70:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003ec80:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003ec90:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003eca0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003ecb0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003ecc0:·3e3c·636f·6465·3e69·6e63·6c75·6465·2069··><code>include·i 
0003ecd0:·6e73·7461·6c6c·5f63·7279·7074·6f2d·706f··nstall_crypto-po 
0003ece0:·6c69·6369·6573·0a0a·636c·6173·7320·696e··licies..class·in 
0003ecf0:·7374·616c·6c5f·6372·7970·746f·2d70·6f6c··stall_crypto-pol 
0003ed00:·6963·6965·7320·7b0a·2020·7061·636b·6167··icies·{.··packag 
0003ed10:·6520·7b20·2763·7279·7074·6f2d·706f·6c69··e·{·'crypto-poli 
0003ed20:·6369·6573·273a·0a20·2020·2065·6e73·7572··cies':.····ensur 
0003ed30:·6520·3d26·6774·3b20·2769·6e73·7461·6c6c··e·=&gt;·'install 
0003ed40:·6564·272c·0a20·207d·0a7d·0a3c·2f63·6f64··ed',.··}.}.</cod 
0003ed50:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003ed60:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ed70:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ed80:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ed90:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003eda0:·6d38·3236·3722·2074·6162·696e·6465·783d··m8267"·tabindex= 
0003edb0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003edc0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003edd0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003ede0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003edf0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003ee00:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003ee10:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003ee20:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003ee30:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003ee40:·6170·7365·2220·6964·3d22·6964·6d38·3236··apse"·id="idm826 
0003ee50:·3722·3e3c·7461·626c·6520·636c·6173·733d··7"><table·class= 
0003ee60:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003ee70:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003ee80:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003ee90:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003eea0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003eeb0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003ea80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003ea90:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003eaa0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003eab0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003eac0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
 0003ead0:·6465·2069·6e73·7461·6c6c·5f63·7279·7074··de·install_crypt
 0003eae0:·6f2d·706f·6c69·6369·6573·0a0a·636c·6173··o-policies..clas
 0003eaf0:·7320·696e·7374·616c·6c5f·6372·7970·746f··s·install_crypto
 0003eb00:·2d70·6f6c·6963·6965·7320·7b0a·2020·7061··-policies·{.··pa
 0003eb10:·636b·6167·6520·7b20·2763·7279·7074·6f2d··ckage·{·'crypto-
 0003eb20:·706f·6c69·6369·6573·273a·0a20·2020·2065··policies':.····e
 0003eb30:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins
 0003eb40:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.<
 0003eb50:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003eb60:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003eb70:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003eb80:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003eb90:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003eba0:·2223·6964·6d38·3236·3622·2074·6162·696e··"#idm8266"·tabin
 0003ebb0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003ebc0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003ebd0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003ebe0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003ebf0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003ec00:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003ec10:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003ec20:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003ec30:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003ec40:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003ec50:·6d38·3236·3622·3e3c·7461·626c·6520·636c··m8266"><table·cl
 0003ec60:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003ec70:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003ec80:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003ec90:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003eca0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003ecb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003eec0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003ecc0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003ecd0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003ece0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
Max diff block lines reached; 380537/394089 bytes (96.56%) of diff not shown.
42.2 KB
html2text {}
    
Offset 227, 20 lines modifiedOffset 227, 14 lines modified
227 Identifiers·and·References·Identifiers: ·CCE-83442-4227 Identifiers·and·References·Identifiers: ·CCE-83442-4
228 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174228 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
229 Remediation_OSBuild_Blueprint_snippet_⇲229 Remediation_OSBuild_Blueprint_snippet_⇲
  
230 [[packages]]230 [[packages]]
231 name·=·"crypto-policies"231 name·=·"crypto-policies"
232 version·=·"*"232 version·=·"*"
233 Remediation_Anaconda_snippet_⇲ 
234 Complexity:·low 
235 Disruption:·low 
236 Strategy:···enable 
  
237 package·--add=crypto-policies 
238 Remediation_Puppet_snippet_⇲233 Remediation_Puppet_snippet_⇲
239 Complexity:·low234 Complexity:·low
240 Disruption:·low235 Disruption:·low
241 Strategy:···enable236 Strategy:···enable
242 include·install_crypto-policies237 include·install_crypto-policies
  
243 class·install_crypto-policies·{238 class·install_crypto-policies·{
Offset 252, 14 lines modifiedOffset 246, 20 lines modified
252 Complexity:·low246 Complexity:·low
253 Disruption:·low247 Disruption:·low
254 Strategy:···enable248 Strategy:···enable
  
255 if·!·rpm·-q·--quiet·"crypto-policies"·;·then249 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
256 ····dnf·install·-y·"crypto-policies"250 ····dnf·install·-y·"crypto-policies"
257 fi251 fi
 252 Remediation_Anaconda_snippet_⇲
 253 Complexity:·low
 254 Disruption:·low
 255 Strategy:···enable
  
 256 package·--add=crypto-policies
258 Remediation_Ansible_snippet_⇲257 Remediation_Ansible_snippet_⇲
259 Complexity:·low258 Complexity:·low
260 Disruption:·low259 Disruption:·low
261 Strategy:···enable260 Strategy:···enable
262 -·name:·Ensure·crypto-policies·is·installed261 -·name:·Ensure·crypto-policies·is·installed
263 ··package:262 ··package:
264 ····name:·crypto-policies263 ····name:·crypto-policies
Offset 561, 20 lines modifiedOffset 561, 14 lines modified
561 Identifiers·and·References·Identifiers: ·CCE-83523-1561 Identifiers·and·References·Identifiers: ·CCE-83523-1
562 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125562 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
563 Remediation_OSBuild_Blueprint_snippet_⇲563 Remediation_OSBuild_Blueprint_snippet_⇲
  
564 [[packages]]564 [[packages]]
565 name·=·"sudo"565 name·=·"sudo"
566 version·=·"*"566 version·=·"*"
567 Remediation_Anaconda_snippet_⇲ 
568 Complexity:·low 
569 Disruption:·low 
570 Strategy:···enable 
  
571 package·--add=sudo 
572 Remediation_Puppet_snippet_⇲567 Remediation_Puppet_snippet_⇲
573 Complexity:·low568 Complexity:·low
574 Disruption:·low569 Disruption:·low
575 Strategy:···enable570 Strategy:···enable
576 include·install_sudo571 include·install_sudo
  
577 class·install_sudo·{572 class·install_sudo·{
Offset 592, 14 lines modifiedOffset 586, 20 lines modified
592 if·!·rpm·-q·--quiet·"sudo"·;·then586 if·!·rpm·-q·--quiet·"sudo"·;·then
593 ····dnf·install·-y·"sudo"587 ····dnf·install·-y·"sudo"
594 fi588 fi
  
595 else589 else
596 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'590 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
597 fi591 fi
 592 Remediation_Anaconda_snippet_⇲
 593 Complexity:·low
 594 Disruption:·low
 595 Strategy:···enable
  
 596 package·--add=sudo
598 Remediation_Ansible_snippet_⇲597 Remediation_Ansible_snippet_⇲
599 Complexity:·low598 Complexity:·low
600 Disruption:·low599 Disruption:·low
601 Strategy:···enable600 Strategy:···enable
602 -·name:·Ensure·sudo·is·installed601 -·name:·Ensure·sudo·is·installed
603 ··package:602 ··package:
604 ····name:·sudo603 ····name:·sudo
Offset 626, 20 lines modifiedOffset 626, 14 lines modified
626 Identifiers·and·References·Identifiers: ·CCE-83494-5626 Identifiers·and·References·Identifiers: ·CCE-83494-5
627 ···························References: ·FIA_X509_EXT.1,·FIA_X509_EXT.2,·SRG-OS-000480-GPOS-00227627 ···························References: ·FIA_X509_EXT.1,·FIA_X509_EXT.2,·SRG-OS-000480-GPOS-00227
628 Remediation_OSBuild_Blueprint_snippet_⇲628 Remediation_OSBuild_Blueprint_snippet_⇲
  
629 [[packages]]629 [[packages]]
630 name·=·"gnutls-utils"630 name·=·"gnutls-utils"
631 version·=·"*"631 version·=·"*"
632 Remediation_Anaconda_snippet_⇲ 
633 Complexity:·low 
634 Disruption:·low 
635 Strategy:···enable 
  
636 package·--add=gnutls-utils 
637 Remediation_Puppet_snippet_⇲632 Remediation_Puppet_snippet_⇲
638 Complexity:·low633 Complexity:·low
639 Disruption:·low634 Disruption:·low
640 Strategy:···enable635 Strategy:···enable
641 include·install_gnutls-utils636 include·install_gnutls-utils
  
642 class·install_gnutls-utils·{637 class·install_gnutls-utils·{
Offset 651, 14 lines modifiedOffset 645, 20 lines modified
651 Complexity:·low645 Complexity:·low
652 Disruption:·low646 Disruption:·low
653 Strategy:···enable647 Strategy:···enable
  
654 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then648 if·!·rpm·-q·--quiet·"gnutls-utils"·;·then
655 ····dnf·install·-y·"gnutls-utils"649 ····dnf·install·-y·"gnutls-utils"
656 fi650 fi
 651 Remediation_Anaconda_snippet_⇲
 652 Complexity:·low
 653 Disruption:·low
 654 Strategy:···enable
  
 655 package·--add=gnutls-utils
657 Remediation_Ansible_snippet_⇲656 Remediation_Ansible_snippet_⇲
658 Complexity:·low657 Complexity:·low
659 Disruption:·low658 Disruption:·low
660 Strategy:···enable659 Strategy:···enable
661 -·name:·Ensure·gnutls-utils·is·installed660 -·name:·Ensure·gnutls-utils·is·installed
662 ··package:661 ··package:
663 ····name:·gnutls-utils662 ····name:·gnutls-utils
Offset 680, 20 lines modifiedOffset 680, 14 lines modified
680 Identifiers·and·References·Identifiers: ·CCE-83502-5680 Identifiers·and·References·Identifiers: ·CCE-83502-5
Max diff block lines reached; 39996/43220 bytes (92.54%) of diff not shown.
968 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-pci-dss.html
    
Offset 17137, 116 lines modifiedOffset 17137, 116 lines modified
00042f00:·612d·7461·7267·6574·3d22·2369·646d·3735··a-target="#idm7500042f00:·612d·7461·7267·6574·3d22·2369·646d·3735··a-target="#idm75
00042f10:·3835·2220·7461·6269·6e64·6578·3d22·3022··85"·tabindex="0"00042f10:·3835·2220·7461·6269·6e64·6578·3d22·3022··85"·tabindex="0"
00042f20:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00042f20:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00042f30:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00042f30:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00042f40:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00042f40:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00042f50:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00042f50:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00042f60:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00042f60:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00042f70:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s00042f70:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
00042f80:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b00042f80:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
00042f90:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00042f90:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00042fa0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00042fa0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00042fb0:·6c61·7073·6522·2069·643d·2269·646d·3735··lapse"·id="idm7500042fb0:·7073·6522·2069·643d·2269·646d·3735·3835··pse"·id="idm7585
00042fc0:·3835·223e·3c74·6162·6c65·2063·6c61·7373··85"><table·class00042fc0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
00042fd0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00042fd0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00042fe0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00042fe0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
00042ff0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00042ff0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
00043000:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00043000:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
00043010:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00043010:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
00043020:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00043020:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00043030:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio00043030:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
00043040:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00043040:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00043050:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00043050:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
00043060:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t00043060:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
00043070:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t00043070:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
00043080:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><00043080:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
00043090:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
000430a0:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>00043090:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 000430a0:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 000430b0:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 000430c0:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 000430d0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 000430e0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 000430f0:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 00043100:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 00043110:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 00043120:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 00043130:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 00043140:·7461·7267·6574·3d22·2369·646d·3735·3836··target="#idm7586
 00043150:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 00043160:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 00043170:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 00043180:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 00043190:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 000431a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 000431b0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 000431c0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 000431d0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 000431e0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 000431f0:·2069·643d·2269·646d·3735·3836·223e·3c74···id="idm7586"><t
 00043200:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00043210:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00043220:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00043230:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00043240:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00043250:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00043260:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00043270:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00043280:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00043290:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 000432a0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 000432b0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 000432c0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 000432d0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 000432e0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 000432f0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 00043300:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
 00043310:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
 00043320:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
 00043330:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 00043340:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!·
 00043350:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"
 00043360:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.···
 00043370:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y·
 00043380:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else.
 00043390:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 000433a0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 000433b0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 000433c0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 000433d0:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
000430b0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c000433e0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
000430c0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su000433f0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
000430d0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg00043400:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
000430e0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da00043410:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
000430f0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm700043420:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
00043100:·3538·3622·2074·6162·696e·6465·783d·2230··586"·tabindex="000043430:·3538·3722·2074·6162·696e·6465·783d·2230··587"·tabindex="0
00043110:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00043440:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00043120:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00043450:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00043130:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00043460:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00043140:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00043470:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00043150:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00043480:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00043160:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn00043490:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
00043170:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br000434a0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
00043180:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan000434b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00043190:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll000434c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000431a0:·6170·7365·2220·6964·3d22·6964·6d37·3538··apse"·id="idm758000434d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
000431b0:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=000434e0:·3538·3722·3e3c·7461·626c·6520·636c·6173··587"><table·clas
000431c0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str000434f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
000431d0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde00043500:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
000431e0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden00043510:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
000431f0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com00043520:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
00043200:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td00043530:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
00043210:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00043540:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00043220:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption00043550:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
00043230:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00043560:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
00043240:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00043570:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00043250:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00043580:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00043260:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00043590:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
00043270:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c000435a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 000435b0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 000435c0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code
00043280:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
00043290:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class· 
000432a0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.· 
000432b0:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide 
000432c0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
000432d0:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
000432e0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
000432f0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00043300:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00043310:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00043320:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00043330:·2d74·6172·6765·743d·2223·6964·6d37·3538··-target="#idm758 
00043340:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"· 
00043350:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00043360:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00043370:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00043380:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
Max diff block lines reached; 705423/720079 bytes (97.96%) of diff not shown.
265 KB
html2text {}
    
Offset 390, 20 lines modifiedOffset 390, 14 lines modified
390 Identifiers·and·References·Identifiers: ·CCE-90843-4390 Identifiers·and·References·Identifiers: ·CCE-90843-4
391 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199391 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
392 Remediation_OSBuild_Blueprint_snippet_⇲392 Remediation_OSBuild_Blueprint_snippet_⇲
  
393 [[packages]]393 [[packages]]
394 name·=·"aide"394 name·=·"aide"
395 version·=·"*"395 version·=·"*"
396 Remediation_Anaconda_snippet_⇲ 
397 Complexity:·low 
398 Disruption:·low 
399 Strategy:···enable 
  
400 package·--add=aide 
401 Remediation_Puppet_snippet_⇲396 Remediation_Puppet_snippet_⇲
402 Complexity:·low397 Complexity:·low
403 Disruption:·low398 Disruption:·low
404 Strategy:···enable399 Strategy:···enable
405 include·install_aide400 include·install_aide
  
406 class·install_aide·{401 class·install_aide·{
Offset 421, 14 lines modifiedOffset 415, 20 lines modified
421 if·!·rpm·-q·--quiet·"aide"·;·then415 if·!·rpm·-q·--quiet·"aide"·;·then
422 ····dnf·install·-y·"aide"416 ····dnf·install·-y·"aide"
423 fi417 fi
  
424 else418 else
425 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'419 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
426 fi420 fi
 421 Remediation_Anaconda_snippet_⇲
 422 Complexity:·low
 423 Disruption:·low
 424 Strategy:···enable
  
 425 package·--add=aide
427 Remediation_Ansible_snippet_⇲426 Remediation_Ansible_snippet_⇲
428 Complexity:·low427 Complexity:·low
429 Disruption:·low428 Disruption:·low
430 Strategy:···enable429 Strategy:···enable
431 -·name:·Ensure·aide·is·installed430 -·name:·Ensure·aide·is·installed
432 ··package:431 ··package:
433 ····name:·aide432 ····name:·aide
Offset 6456, 20 lines modifiedOffset 6456, 14 lines modified
6456 Identifiers·and·References·Identifiers: ·CCE-83595-96456 Identifiers·and·References·Identifiers: ·CCE-83595-9
6457 ···························References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-0015206457 ···························References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520
6458 Remediation_OSBuild_Blueprint_snippet_⇲6458 Remediation_OSBuild_Blueprint_snippet_⇲
  
6459 [[packages]]6459 [[packages]]
6460 name·=·"opensc"6460 name·=·"opensc"
6461 version·=·"*"6461 version·=·"*"
6462 Remediation_Anaconda_snippet_⇲ 
6463 Complexity:·low 
6464 Disruption:·low 
6465 Strategy:···enable 
  
6466 package·--add=opensc 
6467 Remediation_Puppet_snippet_⇲6462 Remediation_Puppet_snippet_⇲
6468 Complexity:·low6463 Complexity:·low
6469 Disruption:·low6464 Disruption:·low
6470 Strategy:···enable6465 Strategy:···enable
6471 include·install_opensc6466 include·install_opensc
  
6472 class·install_opensc·{6467 class·install_opensc·{
Offset 6487, 14 lines modifiedOffset 6481, 20 lines modified
6487 if·!·rpm·-q·--quiet·"opensc"·;·then6481 if·!·rpm·-q·--quiet·"opensc"·;·then
6488 ····dnf·install·-y·"opensc"6482 ····dnf·install·-y·"opensc"
6489 fi6483 fi
  
6490 else6484 else
6491 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6485 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6492 fi6486 fi
 6487 Remediation_Anaconda_snippet_⇲
 6488 Complexity:·low
 6489 Disruption:·low
 6490 Strategy:···enable
  
 6491 package·--add=opensc
6493 Remediation_Ansible_snippet_⇲6492 Remediation_Ansible_snippet_⇲
6494 Complexity:·low6493 Complexity:·low
6495 Disruption:·low6494 Disruption:·low
6496 Strategy:···enable6495 Strategy:···enable
6497 -·name:·Ensure·opensc·is·installed6496 -·name:·Ensure·opensc·is·installed
6498 ··package:6497 ··package:
6499 ····name:·opensc6498 ····name:·opensc
Offset 6518, 20 lines modifiedOffset 6518, 14 lines modified
6518 Identifiers·and·References·Identifiers: ·CCE-86280-56518 Identifiers·and·References·Identifiers: ·CCE-86280-5
6519 ···························References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015306519 ···························References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
6520 Remediation_OSBuild_Blueprint_snippet_⇲6520 Remediation_OSBuild_Blueprint_snippet_⇲
  
6521 [[packages]]6521 [[packages]]
6522 name·=·"pcsc-lite"6522 name·=·"pcsc-lite"
6523 version·=·"*"6523 version·=·"*"
6524 Remediation_Anaconda_snippet_⇲ 
6525 Complexity:·low 
6526 Disruption:·low 
6527 Strategy:···enable 
  
6528 package·--add=pcsc-lite 
6529 Remediation_Puppet_snippet_⇲6524 Remediation_Puppet_snippet_⇲
6530 Complexity:·low6525 Complexity:·low
6531 Disruption:·low6526 Disruption:·low
6532 Strategy:···enable6527 Strategy:···enable
6533 include·install_pcsc-lite6528 include·install_pcsc-lite
  
6534 class·install_pcsc-lite·{6529 class·install_pcsc-lite·{
Offset 6549, 14 lines modifiedOffset 6543, 20 lines modified
6549 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then6543 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
6550 ····dnf·install·-y·"pcsc-lite"6544 ····dnf·install·-y·"pcsc-lite"
6551 fi6545 fi
  
6552 else6546 else
6553 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6547 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6554 fi6548 fi
 6549 Remediation_Anaconda_snippet_⇲
 6550 Complexity:·low
 6551 Disruption:·low
 6552 Strategy:···enable
  
 6553 package·--add=pcsc-lite
6555 Remediation_Ansible_snippet_⇲6554 Remediation_Ansible_snippet_⇲
6556 Complexity:·low6555 Complexity:·low
6557 Disruption:·low6556 Disruption:·low
6558 Strategy:···enable6557 Strategy:···enable
6559 -·name:·Ensure·pcsc-lite·is·installed6558 -·name:·Ensure·pcsc-lite·is·installed
6560 ··package:6559 ··package:
6561 ····name:·pcsc-lite6560 ····name:·pcsc-lite
Offset 7282, 15 lines modifiedOffset 7282, 15 lines modified
7282 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.7282 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
Max diff block lines reached; 267302/271195 bytes (98.56%) of diff not shown.
2.09 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-stig.html
    
Offset 15327, 117 lines modifiedOffset 15327, 117 lines modified
0003bde0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003bde0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003bdf0:·3d22·2369·646d·3735·3835·2220·7461·6269··="#idm7585"·tabi0003bdf0:·3d22·2369·646d·3735·3835·2220·7461·6269··="#idm7585"·tabi
0003be00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003be00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003be10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003be10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003be20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003be20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003be30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003be30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003be40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003be40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003be50:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003be50:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu
0003be60:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.0003be60:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...
0003be70:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003be70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003be80:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003be80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003be90:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003be90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003bea0:·643d·2269·646d·3735·3835·223e·3c74·6162··d="idm7585"><tab0003bea0:·2269·646d·3735·3835·223e·3c74·6162·6c65··"idm7585"><table
0003beb0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003beb0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003bec0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003bec0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003bed0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003bed0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003bee0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bee0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003bef0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003bef0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003bf00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bf00:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bf10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003bf10:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003bf20:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003bf20:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003bf30:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bf30:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bf40:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bf40:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003bf50:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003bf50:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003bf60:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003bf60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003bf70:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa0003bf70:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu
0003bf80:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide0003bf80:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide.
 0003bf90:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a
 0003bfa0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package·
 0003bfb0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en
 0003bfc0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst
 0003bfd0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</
 0003bfe0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bff0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003c000:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003c010:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003c020:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003c030:·2369·646d·3735·3836·2220·7461·6269·6e64··#idm7586"·tabind
 0003c040:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003c050:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003c060:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003c070:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003c080:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003c090:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003c0a0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003c0b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003c0c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003c0d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003c0e0:·3735·3836·223e·3c74·6162·6c65·2063·6c61··7586"><table·cla
 0003c0f0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003c100:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003c110:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003c120:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003c130:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003c140:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c150:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003c160:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003c170:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c180:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003c190:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003c1a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003c1b0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003c1c0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003c1d0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003c1e0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003c1f0:·5b20·2120·2d66·202f·2e64·6f63·6b65·7265··[·!·-f·/.dockere
 0003c200:·6e76·205d·2026·616d·703b·2661·6d70·3b20··nv·]·&amp;&amp;·
 0003c210:·5b20·2120·2d66·202f·7275·6e2f·2e63·6f6e··[·!·-f·/run/.con
 0003c220:·7461·696e·6572·656e·7620·5d3b·2074·6865··tainerenv·];·the
 0003c230:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003c240:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003c250:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins
 0003c260:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003c270:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003c280:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003c290:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003c2a0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003c2b0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
0003bf90:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003c2c0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003bfa0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003c2d0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003bfb0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003c2e0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003bfc0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003c2f0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003bfd0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003c300:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003bfe0:·743d·2223·6964·6d37·3538·3622·2074·6162··t="#idm7586"·tab0003c310:·743d·2223·6964·6d37·3538·3722·2074·6162··t="#idm7587"·tab
0003bff0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003c320:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c000:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003c330:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c010:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003c340:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c020:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003c350:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c030:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003c360:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c040:·2122·3e52·656d·6564·6961·7469·6f6e·2050··!">Remediation·P0003c370:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003c050:·7570·7065·7420·736e·6970·7065·7420·e287··uppet·snippet·..0003c380:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·
0003c060:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c390:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003c070:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003c3a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003c080:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003c3b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003c090:·3d22·6964·6d37·3538·3622·3e3c·7461·626c··="idm7586"><tabl0003c3c0:·6964·3d22·6964·6d37·3538·3722·3e3c·7461··id="idm7587"><ta
0003c0a0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003c3d0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003c0b0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003c3e0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003c0c0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003c3f0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003c0d0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003c400:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003c0e0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003c410:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003c0f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c420:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003c100:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003c430:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003c110:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003c440:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003c120:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c450:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c130:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003c460:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003c140:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003c470:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003c150:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003c480:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003c160:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl0003c490:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003c4a0:·6163·6b61·6765·202d·2d61·6464·3d61·6964··ackage·--add=aid
0003c170:·7564·6520·696e·7374·616c·6c5f·6169·6465··ude·install_aide 
0003c180:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_ 
0003c190:·6169·6465·207b·0a20·2070·6163·6b61·6765··aide·{.··package 
0003c1a0:·207b·2027·6169·6465·273a·0a20·2020·2065···{·'aide':.····e 
0003c1b0:·6e73·7572·6520·3d26·6774·3b20·2769·6e73··nsure·=&gt;·'ins 
0003c1c0:·7461·6c6c·6564·272c·0a20·207d·0a7d·0a3c··talled',.··}.}.< 
0003c1d0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c1e0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c1f0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c200:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c210:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c220:·2223·6964·6d37·3538·3722·2074·6162·696e··"#idm7587"·tabin 
0003c230:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c240:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c250:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c260:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c270:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c280:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
Max diff block lines reached; 1735674/1750468 bytes (99.15%) of diff not shown.
432 KB
html2text {}
    
Offset 97, 20 lines modifiedOffset 97, 14 lines modified
97 Identifiers·and·References·Identifiers: ·CCE-90843-497 Identifiers·and·References·Identifiers: ·CCE-90843-4
98 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-0019998 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
99 Remediation_OSBuild_Blueprint_snippet_⇲99 Remediation_OSBuild_Blueprint_snippet_⇲
  
100 [[packages]]100 [[packages]]
101 name·=·"aide"101 name·=·"aide"
102 version·=·"*"102 version·=·"*"
103 Remediation_Anaconda_snippet_⇲ 
104 Complexity:·low 
105 Disruption:·low 
106 Strategy:···enable 
  
107 package·--add=aide 
108 Remediation_Puppet_snippet_⇲103 Remediation_Puppet_snippet_⇲
109 Complexity:·low104 Complexity:·low
110 Disruption:·low105 Disruption:·low
111 Strategy:···enable106 Strategy:···enable
112 include·install_aide107 include·install_aide
  
113 class·install_aide·{108 class·install_aide·{
Offset 128, 14 lines modifiedOffset 122, 20 lines modified
128 if·!·rpm·-q·--quiet·"aide"·;·then122 if·!·rpm·-q·--quiet·"aide"·;·then
129 ····dnf·install·-y·"aide"123 ····dnf·install·-y·"aide"
130 fi124 fi
  
131 else125 else
132 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'126 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
133 fi127 fi
 128 Remediation_Anaconda_snippet_⇲
 129 Complexity:·low
 130 Disruption:·low
 131 Strategy:···enable
  
 132 package·--add=aide
134 Remediation_Ansible_snippet_⇲133 Remediation_Ansible_snippet_⇲
135 Complexity:·low134 Complexity:·low
136 Disruption:·low135 Disruption:·low
137 Strategy:···enable136 Strategy:···enable
138 -·name:·Ensure·aide·is·installed137 -·name:·Ensure·aide·is·installed
139 ··package:138 ··package:
140 ····name:·aide139 ····name:·aide
Offset 1519, 20 lines modifiedOffset 1519, 14 lines modified
1519 Identifiers·and·References·Identifiers: ·CCE-83442-41519 Identifiers·and·References·Identifiers: ·CCE-83442-4
1520 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001741520 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
1521 Remediation_OSBuild_Blueprint_snippet_⇲1521 Remediation_OSBuild_Blueprint_snippet_⇲
  
1522 [[packages]]1522 [[packages]]
1523 name·=·"crypto-policies"1523 name·=·"crypto-policies"
1524 version·=·"*"1524 version·=·"*"
1525 Remediation_Anaconda_snippet_⇲ 
1526 Complexity:·low 
1527 Disruption:·low 
1528 Strategy:···enable 
  
1529 package·--add=crypto-policies 
1530 Remediation_Puppet_snippet_⇲1525 Remediation_Puppet_snippet_⇲
1531 Complexity:·low1526 Complexity:·low
1532 Disruption:·low1527 Disruption:·low
1533 Strategy:···enable1528 Strategy:···enable
1534 include·install_crypto-policies1529 include·install_crypto-policies
  
1535 class·install_crypto-policies·{1530 class·install_crypto-policies·{
Offset 1544, 14 lines modifiedOffset 1538, 20 lines modified
1544 Complexity:·low1538 Complexity:·low
1545 Disruption:·low1539 Disruption:·low
1546 Strategy:···enable1540 Strategy:···enable
  
1547 if·!·rpm·-q·--quiet·"crypto-policies"·;·then1541 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
1548 ····dnf·install·-y·"crypto-policies"1542 ····dnf·install·-y·"crypto-policies"
1549 fi1543 fi
 1544 Remediation_Anaconda_snippet_⇲
 1545 Complexity:·low
 1546 Disruption:·low
 1547 Strategy:···enable
  
 1548 package·--add=crypto-policies
1550 Remediation_Ansible_snippet_⇲1549 Remediation_Ansible_snippet_⇲
1551 Complexity:·low1550 Complexity:·low
1552 Disruption:·low1551 Disruption:·low
1553 Strategy:···enable1552 Strategy:···enable
1554 -·name:·Ensure·crypto-policies·is·installed1553 -·name:·Ensure·crypto-policies·is·installed
1555 ··package:1554 ··package:
1556 ····name:·crypto-policies1555 ····name:·crypto-policies
Offset 3851, 20 lines modifiedOffset 3851, 14 lines modified
3851 By·removing·the·gdm·package,·the·system·no·longer·has·GNOME·installed·installed.·If·X·Windows·is·not·installed·then·the·system·cannot·boot·into·graphical·user·mode.·This·prevents·the·system·from·being·accidentally·or·maliciously·booted·into·a·graphical.target·mode.·To·do·so,·run·the·following·command:3851 By·removing·the·gdm·package,·the·system·no·longer·has·GNOME·installed·installed.·If·X·Windows·is·not·installed·then·the·system·cannot·boot·into·graphical·user·mode.·This·prevents·the·system·from·being·accidentally·or·maliciously·booted·into·a·graphical.target·mode.·To·do·so,·run·the·following·command:
3852 $·sudo·yum·remove·gdm3852 $·sudo·yum·remove·gdm
3853 Rationale:·················Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack·surface·of·the·system.·A·graphical·environment·is·unnecessary·for·certain·types·of·systems·including·a·virtualization·hypervisor.3853 Rationale:·················Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack·surface·of·the·system.·A·graphical·environment·is·unnecessary·for·certain·types·of·systems·including·a·virtualization·hypervisor.
3854 Severity: ················medium3854 Severity: ················medium
3855 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gdm_removed3855 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gdm_removed
3856 Identifiers·and·References·Identifiers: ·CCE-83549-63856 Identifiers·and·References·Identifiers: ·CCE-83549-6
3857 ···························References: ·CM-7(a),·CM-7(b),·CM-6(a),·SRG-OS-000480-GPOS-002273857 ···························References: ·CM-7(a),·CM-7(b),·CM-6(a),·SRG-OS-000480-GPOS-00227
3858 Remediation_Anaconda_snippet_⇲ 
3859 Complexity:·low 
3860 Disruption:·low 
3861 Strategy:···disable 
  
3862 package·--remove=gdm 
3863 Remediation_Puppet_snippet_⇲3858 Remediation_Puppet_snippet_⇲
3864 Complexity:·low3859 Complexity:·low
3865 Disruption:·low3860 Disruption:·low
3866 Strategy:···disable3861 Strategy:···disable
3867 include·remove_gdm3862 include·remove_gdm
  
3868 class·remove_gdm·{3863 class·remove_gdm·{
Offset 3890, 14 lines modifiedOffset 3884, 20 lines modified
3890 ····dnf·remove·-y·"gdm"3884 ····dnf·remove·-y·"gdm"
  
3891 fi3885 fi
  
3892 else3886 else
3893 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3887 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3894 fi3888 fi
 3889 Remediation_Anaconda_snippet_⇲
 3890 Complexity:·low
 3891 Disruption:·low
 3892 Strategy:···disable
  
 3893 package·--remove=gdm
3895 Remediation_Ansible_snippet_⇲3894 Remediation_Ansible_snippet_⇲
3896 Complexity:·low3895 Complexity:·low
3897 Disruption:·low3896 Disruption:·low
3898 Strategy:···disable3897 Strategy:···disable
3899 -·name:·Gather·the·package·facts3898 -·name:·Gather·the·package·facts
3900 ··package_facts:3899 ··package_facts:
3901 ····manager:·auto3900 ····manager:·auto
Offset 3962, 20 lines modifiedOffset 3962, 14 lines modified
3962 Identifiers·and·References·Identifiers: ·CCE-83523-13962 Identifiers·and·References·Identifiers: ·CCE-83523-1
Max diff block lines reached; 437707/442042 bytes (99.02%) of diff not shown.
2.03 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-stig_gui.html
    
Offset 15346, 116 lines modifiedOffset 15346, 116 lines modified
0003bf10:·612d·7461·7267·6574·3d22·2369·646d·3735··a-target="#idm750003bf10:·612d·7461·7267·6574·3d22·2369·646d·3735··a-target="#idm75
0003bf20:·3835·2220·7461·6269·6e64·6578·3d22·3022··85"·tabindex="0"0003bf20:·3835·2220·7461·6269·6e64·6578·3d22·3022··85"·tabindex="0"
0003bf30:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bf30:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003bf40:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003bf40:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bf50:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003bf50:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003bf60:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003bf60:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003bf70:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003bf70:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003bf80:·6174·696f·6e20·416e·6163·6f6e·6461·2073··ation·Anaconda·s0003bf80:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
0003bf90:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0003bf90:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0003bfa0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003bfa0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003bfb0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003bfb0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003bfc0:·6c61·7073·6522·2069·643d·2269·646d·3735··lapse"·id="idm750003bfc0:·7073·6522·2069·643d·2269·646d·3735·3835··pse"·id="idm7585
0003bfd0:·3835·223e·3c74·6162·6c65·2063·6c61·7373··85"><table·class0003bfd0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003bfe0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003bfe0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bff0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003bff0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003c000:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003c000:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003c010:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003c010:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003c020:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003c020:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003c030:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003c030:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003c040:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003c040:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003c050:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003c050:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c060:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003c060:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003c070:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003c070:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003c080:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003c080:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003c090:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003c090:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003c0a0:·636f·6465·3e0a·7061·636b·6167·6520·2d2d··code>.package·-- 
0003c0b0:·6164·643d·6169·6465·0a3c·2f63·6f64·653e··add=aide.</code>0003c0a0:·6465·3e69·6e63·6c75·6465·2069·6e73·7461··de>include·insta
 0003c0b0:·6c6c·5f61·6964·650a·0a63·6c61·7373·2069··ll_aide..class·i
 0003c0c0:·6e73·7461·6c6c·5f61·6964·6520·7b0a·2020··nstall_aide·{.··
 0003c0d0:·7061·636b·6167·6520·7b20·2761·6964·6527··package·{·'aide'
 0003c0e0:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g
 0003c0f0:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',.
 0003c100:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p
 0003c110:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003c120:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003c130:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003c140:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003c150:·7461·7267·6574·3d22·2369·646d·3735·3836··target="#idm7586
 0003c160:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003c170:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003c180:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003c190:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003c1a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003c1b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003c1c0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 0003c1d0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003c1e0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003c1f0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003c200:·2069·643d·2269·646d·3735·3836·223e·3c74···id="idm7586"><t
 0003c210:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003c220:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003c230:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003c240:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003c250:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003c260:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003c270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003c280:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003c290:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003c2a0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003c2b0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003c2c0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0003c2d0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003c2e0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003c2f0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003c300:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003c310:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
 0003c320:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
 0003c330:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
 0003c340:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 0003c350:·7620·5d3b·2074·6865·6e0a·0a69·6620·2120··v·];·then..if·!·
 0003c360:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"
 0003c370:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.···
 0003c380:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y·
 0003c390:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else.
 0003c3a0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 0003c3b0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 0003c3c0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 0003c3d0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 0003c3e0:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
0003c0c0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003c3f0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003c0d0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003c400:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003c0e0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003c410:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003c0f0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003c420:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003c100:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003c430:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003c110:·3538·3622·2074·6162·696e·6465·783d·2230··586"·tabindex="00003c440:·3538·3722·2074·6162·696e·6465·783d·2230··587"·tabindex="0
0003c120:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003c450:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003c130:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003c460:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c140:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c470:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c150:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c480:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c160:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c490:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003c170:·6961·7469·6f6e·2050·7570·7065·7420·736e··iation·Puppet·sn0003c4a0:·6961·7469·6f6e·2041·6e61·636f·6e64·6120··iation·Anaconda·
0003c180:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003c4b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
0003c190:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003c4c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003c1a0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003c4d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003c1b0:·6170·7365·2220·6964·3d22·6964·6d37·3538··apse"·id="idm7580003c4e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003c1c0:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class=0003c4f0:·3538·3722·3e3c·7461·626c·6520·636c·6173··587"><table·clas
0003c1d0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003c500:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003c1e0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003c510:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003c1f0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003c520:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003c200:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003c530:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003c210:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003c540:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003c220:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003c550:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003c230:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003c560:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c240:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003c570:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003c250:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003c580:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003c260:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003c590:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003c270:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003c5a0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003c280:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003c5b0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003c5c0:·3c63·6f64·653e·0a70·6163·6b61·6765·202d··<code>.package·-
 0003c5d0:·2d61·6464·3d61·6964·650a·3c2f·636f·6465··-add=aide.</code
0003c290:·6f64·653e·696e·636c·7564·6520·696e·7374··ode>include·inst 
0003c2a0:·616c·6c5f·6169·6465·0a0a·636c·6173·7320··all_aide..class· 
0003c2b0:·696e·7374·616c·6c5f·6169·6465·207b·0a20··install_aide·{.· 
0003c2c0:·2070·6163·6b61·6765·207b·2027·6169·6465···package·{·'aide 
0003c2d0:·273a·0a20·2020·2065·6e73·7572·6520·3d26··':.····ensure·=& 
0003c2e0:·6774·3b20·2769·6e73·7461·6c6c·6564·272c··gt;·'installed', 
0003c2f0:·0a20·207d·0a7d·0a3c·2f63·6f64·653e·3c2f··.··}.}.</code></ 
0003c300:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003c310:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003c320:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003c330:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003c340:·2d74·6172·6765·743d·2223·6964·6d37·3538··-target="#idm758 
0003c350:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"· 
0003c360:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003c370:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003c380:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003c390:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
Max diff block lines reached; 1676977/1691633 bytes (99.13%) of diff not shown.
424 KB
html2text {}
    
Offset 103, 20 lines modifiedOffset 103, 14 lines modified
103 Identifiers·and·References·Identifiers: ·CCE-90843-4103 Identifiers·and·References·Identifiers: ·CCE-90843-4
104 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199104 ···························References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
105 Remediation_OSBuild_Blueprint_snippet_⇲105 Remediation_OSBuild_Blueprint_snippet_⇲
  
106 [[packages]]106 [[packages]]
107 name·=·"aide"107 name·=·"aide"
108 version·=·"*"108 version·=·"*"
109 Remediation_Anaconda_snippet_⇲ 
110 Complexity:·low 
111 Disruption:·low 
112 Strategy:···enable 
  
113 package·--add=aide 
114 Remediation_Puppet_snippet_⇲109 Remediation_Puppet_snippet_⇲
115 Complexity:·low110 Complexity:·low
116 Disruption:·low111 Disruption:·low
117 Strategy:···enable112 Strategy:···enable
118 include·install_aide113 include·install_aide
  
119 class·install_aide·{114 class·install_aide·{
Offset 134, 14 lines modifiedOffset 128, 20 lines modified
134 if·!·rpm·-q·--quiet·"aide"·;·then128 if·!·rpm·-q·--quiet·"aide"·;·then
135 ····dnf·install·-y·"aide"129 ····dnf·install·-y·"aide"
136 fi130 fi
  
137 else131 else
138 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'132 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
139 fi133 fi
 134 Remediation_Anaconda_snippet_⇲
 135 Complexity:·low
 136 Disruption:·low
 137 Strategy:···enable
  
 138 package·--add=aide
140 Remediation_Ansible_snippet_⇲139 Remediation_Ansible_snippet_⇲
141 Complexity:·low140 Complexity:·low
142 Disruption:·low141 Disruption:·low
143 Strategy:···enable142 Strategy:···enable
144 -·name:·Ensure·aide·is·installed143 -·name:·Ensure·aide·is·installed
145 ··package:144 ··package:
146 ····name:·aide145 ····name:·aide
Offset 1525, 20 lines modifiedOffset 1525, 14 lines modified
1525 Identifiers·and·References·Identifiers: ·CCE-83442-41525 Identifiers·and·References·Identifiers: ·CCE-83442-4
1526 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001741526 ···························References: ·FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
1527 Remediation_OSBuild_Blueprint_snippet_⇲1527 Remediation_OSBuild_Blueprint_snippet_⇲
  
1528 [[packages]]1528 [[packages]]
1529 name·=·"crypto-policies"1529 name·=·"crypto-policies"
1530 version·=·"*"1530 version·=·"*"
1531 Remediation_Anaconda_snippet_⇲ 
1532 Complexity:·low 
1533 Disruption:·low 
1534 Strategy:···enable 
  
1535 package·--add=crypto-policies 
1536 Remediation_Puppet_snippet_⇲1531 Remediation_Puppet_snippet_⇲
1537 Complexity:·low1532 Complexity:·low
1538 Disruption:·low1533 Disruption:·low
1539 Strategy:···enable1534 Strategy:···enable
1540 include·install_crypto-policies1535 include·install_crypto-policies
  
1541 class·install_crypto-policies·{1536 class·install_crypto-policies·{
Offset 1550, 14 lines modifiedOffset 1544, 20 lines modified
1550 Complexity:·low1544 Complexity:·low
1551 Disruption:·low1545 Disruption:·low
1552 Strategy:···enable1546 Strategy:···enable
  
1553 if·!·rpm·-q·--quiet·"crypto-policies"·;·then1547 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
1554 ····dnf·install·-y·"crypto-policies"1548 ····dnf·install·-y·"crypto-policies"
1555 fi1549 fi
 1550 Remediation_Anaconda_snippet_⇲
 1551 Complexity:·low
 1552 Disruption:·low
 1553 Strategy:···enable
  
 1554 package·--add=crypto-policies
1556 Remediation_Ansible_snippet_⇲1555 Remediation_Ansible_snippet_⇲
1557 Complexity:·low1556 Complexity:·low
1558 Disruption:·low1557 Disruption:·low
1559 Strategy:···enable1558 Strategy:···enable
1560 -·name:·Ensure·crypto-policies·is·installed1559 -·name:·Ensure·crypto-policies·is·installed
1561 ··package:1560 ··package:
1562 ····name:·crypto-policies1561 ····name:·crypto-policies
Offset 3886, 20 lines modifiedOffset 3886, 14 lines modified
3886 Identifiers·and·References·Identifiers: ·CCE-83523-13886 Identifiers·and·References·Identifiers: ·CCE-83523-1
3887 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-001253887 ···························References: ·BP28(R19),·1382,·1384,·1386,·CM-6(a),·FMT_MOF_EXT.1,·Req-10.2.1.5,·SRG-OS-000324-GPOS-00125
3888 Remediation_OSBuild_Blueprint_snippet_⇲3888 Remediation_OSBuild_Blueprint_snippet_⇲
  
3889 [[packages]]3889 [[packages]]
3890 name·=·"sudo"3890 name·=·"sudo"
3891 version·=·"*"3891 version·=·"*"
3892 Remediation_Anaconda_snippet_⇲ 
3893 Complexity:·low 
3894 Disruption:·low 
3895 Strategy:···enable 
  
3896 package·--add=sudo 
3897 Remediation_Puppet_snippet_⇲3892 Remediation_Puppet_snippet_⇲
3898 Complexity:·low3893 Complexity:·low
3899 Disruption:·low3894 Disruption:·low
3900 Strategy:···enable3895 Strategy:···enable
3901 include·install_sudo3896 include·install_sudo
  
3902 class·install_sudo·{3897 class·install_sudo·{
Offset 3917, 14 lines modifiedOffset 3911, 20 lines modified
3917 if·!·rpm·-q·--quiet·"sudo"·;·then3911 if·!·rpm·-q·--quiet·"sudo"·;·then
3918 ····dnf·install·-y·"sudo"3912 ····dnf·install·-y·"sudo"
3919 fi3913 fi
  
3920 else3914 else
3921 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3915 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3922 fi3916 fi
 3917 Remediation_Anaconda_snippet_⇲
 3918 Complexity:·low
 3919 Disruption:·low
 3920 Strategy:···enable
  
 3921 package·--add=sudo
3923 Remediation_Ansible_snippet_⇲3922 Remediation_Ansible_snippet_⇲
3924 Complexity:·low3923 Complexity:·low
3925 Disruption:·low3924 Disruption:·low
3926 Strategy:···enable3925 Strategy:···enable
3927 -·name:·Ensure·sudo·is·installed3926 -·name:·Ensure·sudo·is·installed
3928 ··package:3927 ··package:
3929 ····name:·sudo3928 ····name:·sudo
Offset 4622, 20 lines modifiedOffset 4622, 14 lines modified
4622 Identifiers·and·References·Identifiers: ·CCE-83494-54622 Identifiers·and·References·Identifiers: ·CCE-83494-5
Max diff block lines reached; 430648/434424 bytes (99.13%) of diff not shown.
79.8 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-pci-dss.html
    
Offset 17045, 116 lines modifiedOffset 17045, 116 lines modified
00042940:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00042940:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00042950:·2223·6964·6d32·3035·3022·2074·6162·696e··"#idm2050"·tabin00042950:·2223·6964·6d32·3035·3022·2074·6162·696e··"#idm2050"·tabin
00042960:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00042960:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00042970:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00042970:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00042980:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00042980:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00042990:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00042990:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
000429a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"000429a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
000429b0:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana000429b0:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
000429c0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..000429c0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
000429d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl000429d0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
000429e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla000429e0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
000429f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id000429f0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00042a00:·3d22·6964·6d32·3035·3022·3e3c·7461·626c··="idm2050"><tabl00042a00:·6964·6d32·3035·3022·3e3c·7461·626c·6520··idm2050"><table·
00042a10:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00042a10:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00042a20:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00042a20:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00042a30:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00042a30:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00042a40:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00042a40:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00042a50:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00042a50:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00042a60:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00042a60:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00042a70:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00042a70:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00042a80:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00042a80:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00042a90:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00042a90:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00042aa0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00042aa0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
00042ab0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<00042ab0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
00042ac0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table00042ac0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
00042ad0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac00042ad0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
00042ae0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.00042ae0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 00042af0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 00042b00:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 00042b10:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 00042b20:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 00042b30:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 00042b40:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00042b50:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00042b60:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00042b70:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 00042b80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 00042b90:·6964·6d32·3035·3122·2074·6162·696e·6465··idm2051"·tabinde
 00042ba0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00042bb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 00042bc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 00042bd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 00042be0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 00042bf0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 00042c00:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 00042c10:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00042c20:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00042c30:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
 00042c40:·3035·3122·3e3c·7461·626c·6520·636c·6173··051"><table·clas
 00042c50:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00042c60:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00042c70:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 00042c80:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 00042c90:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 00042ca0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00042cb0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 00042cc0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 00042cd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00042ce0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00042cf0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00042d00:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00042d10:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00042d20:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00042d30:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00042d40:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 00042d50:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
 00042d60:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
 00042d70:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
 00042d80:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
 00042d90:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 00042da0:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 00042db0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 00042dc0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 00042dd0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 00042de0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 00042df0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 00042e00:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 00042e10:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
00042af0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00042e20:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
00042b00:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn00042e30:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
00042b10:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da00042e40:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
00042b20:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla00042e50:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
00042b30:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00042e60:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00042b40:·3d22·2369·646d·3230·3531·2220·7461·6269··="#idm2051"·tabi00042e70:·3d22·2369·646d·3230·3532·2220·7461·6269··="#idm2052"·tabi
00042b50:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00042e80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00042b60:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00042e90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00042b70:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00042ea0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00042b80:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00042eb0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00042b90:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00042ec0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00042ba0:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu00042ed0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
00042bb0:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...00042ee0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
00042bc0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00042ef0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00042bd0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00042f00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00042be0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00042f10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00042bf0:·2269·646d·3230·3531·223e·3c74·6162·6c65··"idm2051"><table00042f20:·643d·2269·646d·3230·3532·223e·3c74·6162··d="idm2052"><tab
00042c00:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00042f30:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00042c10:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00042f40:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00042c20:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table00042f50:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00042c30:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>00042f60:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00042c40:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<00042f70:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00042c50:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00042f80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00042c60:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis00042f90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00042c70:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td00042fa0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00042c80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00042fb0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00042c90:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<00042fc0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
00042ca0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</00042fd0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
00042cb0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>00042fe0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00042ff0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 00043000:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
00042cc0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
00042cd0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
00042ce0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
00042cf0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
00042d00:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
00042d10:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
00042d20:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
00042d30:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00042d40:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00042d50:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00042d60:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00042d70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00042d80:·2369·646d·3230·3532·2220·7461·6269·6e64··#idm2052"·tabind 
00042d90:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00042da0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00042db0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00042dc0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00042dd0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
Max diff block lines reached; 58212/72868 bytes (79.89%) of diff not shown.
8.49 KB
html2text {}
    
Offset 379, 20 lines modifiedOffset 379, 14 lines modified
379 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed379 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
380 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199380 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
381 Remediation_OSBuild_Blueprint_snippet_⇲381 Remediation_OSBuild_Blueprint_snippet_⇲
  
382 [[packages]]382 [[packages]]
383 name·=·"aide"383 name·=·"aide"
384 version·=·"*"384 version·=·"*"
385 Remediation_Anaconda_snippet_⇲ 
386 Complexity:·low 
387 Disruption:·low 
388 Strategy:···enable 
  
389 package·--add=aide 
390 Remediation_Puppet_snippet_⇲385 Remediation_Puppet_snippet_⇲
391 Complexity:·low386 Complexity:·low
392 Disruption:·low387 Disruption:·low
393 Strategy:···enable388 Strategy:···enable
394 include·install_aide389 include·install_aide
  
395 class·install_aide·{390 class·install_aide·{
Offset 410, 14 lines modifiedOffset 404, 20 lines modified
410 if·!·rpm·-q·--quiet·"aide"·;·then404 if·!·rpm·-q·--quiet·"aide"·;·then
411 ····yum·install·-y·"aide"405 ····yum·install·-y·"aide"
412 fi406 fi
  
413 else407 else
414 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'408 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
415 fi409 fi
 410 Remediation_Anaconda_snippet_⇲
 411 Complexity:·low
 412 Disruption:·low
 413 Strategy:···enable
  
 414 package·--add=aide
416 Remediation_Ansible_snippet_⇲415 Remediation_Ansible_snippet_⇲
417 Complexity:·low416 Complexity:·low
418 Disruption:·low417 Disruption:·low
419 Strategy:···enable418 Strategy:···enable
420 -·name:·Ensure·aide·is·installed419 -·name:·Ensure·aide·is·installed
421 ··package:420 ··package:
422 ····name:·aide421 ····name:·aide
Offset 5431, 20 lines modifiedOffset 5431, 14 lines modified
5431 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed5431 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed
5432 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-0015205432 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520
5433 Remediation_OSBuild_Blueprint_snippet_⇲5433 Remediation_OSBuild_Blueprint_snippet_⇲
  
5434 [[packages]]5434 [[packages]]
5435 name·=·"opensc"5435 name·=·"opensc"
5436 version·=·"*"5436 version·=·"*"
5437 Remediation_Anaconda_snippet_⇲ 
5438 Complexity:·low 
5439 Disruption:·low 
5440 Strategy:···enable 
  
5441 package·--add=opensc 
5442 Remediation_Puppet_snippet_⇲5437 Remediation_Puppet_snippet_⇲
5443 Complexity:·low5438 Complexity:·low
5444 Disruption:·low5439 Disruption:·low
5445 Strategy:···enable5440 Strategy:···enable
5446 include·install_opensc5441 include·install_opensc
  
5447 class·install_opensc·{5442 class·install_opensc·{
Offset 5462, 14 lines modifiedOffset 5456, 20 lines modified
5462 if·!·rpm·-q·--quiet·"opensc"·;·then5456 if·!·rpm·-q·--quiet·"opensc"·;·then
5463 ····yum·install·-y·"opensc"5457 ····yum·install·-y·"opensc"
5464 fi5458 fi
  
5465 else5459 else
5466 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5460 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5467 fi5461 fi
 5462 Remediation_Anaconda_snippet_⇲
 5463 Complexity:·low
 5464 Disruption:·low
 5465 Strategy:···enable
  
 5466 package·--add=opensc
5468 Remediation_Ansible_snippet_⇲5467 Remediation_Ansible_snippet_⇲
5469 Complexity:·low5468 Complexity:·low
5470 Disruption:·low5469 Disruption:·low
5471 Strategy:···enable5470 Strategy:···enable
5472 -·name:·Ensure·opensc·is·installed5471 -·name:·Ensure·opensc·is·installed
5473 ··package:5472 ··package:
5474 ····name:·opensc5473 ····name:·opensc
Offset 5491, 20 lines modifiedOffset 5491, 14 lines modified
5491 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed5491 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
5492 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015305492 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
5493 Remediation_OSBuild_Blueprint_snippet_⇲5493 Remediation_OSBuild_Blueprint_snippet_⇲
  
5494 [[packages]]5494 [[packages]]
5495 name·=·"pcsc-lite"5495 name·=·"pcsc-lite"
5496 version·=·"*"5496 version·=·"*"
5497 Remediation_Anaconda_snippet_⇲ 
5498 Complexity:·low 
5499 Disruption:·low 
5500 Strategy:···enable 
  
5501 package·--add=pcsc-lite 
5502 Remediation_Puppet_snippet_⇲5497 Remediation_Puppet_snippet_⇲
5503 Complexity:·low5498 Complexity:·low
5504 Disruption:·low5499 Disruption:·low
5505 Strategy:···enable5500 Strategy:···enable
5506 include·install_pcsc-lite5501 include·install_pcsc-lite
  
5507 class·install_pcsc-lite·{5502 class·install_pcsc-lite·{
Offset 5522, 14 lines modifiedOffset 5516, 20 lines modified
5522 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then5516 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
5523 ····yum·install·-y·"pcsc-lite"5517 ····yum·install·-y·"pcsc-lite"
5524 fi5518 fi
  
5525 else5519 else
5526 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5520 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5527 fi5521 fi
 5522 Remediation_Anaconda_snippet_⇲
 5523 Complexity:·low
 5524 Disruption:·low
 5525 Strategy:···enable
  
 5526 package·--add=pcsc-lite
5528 Remediation_Ansible_snippet_⇲5527 Remediation_Ansible_snippet_⇲
5529 Complexity:·low5528 Complexity:·low
5530 Disruption:·low5529 Disruption:·low
5531 Strategy:···enable5530 Strategy:···enable
5532 -·name:·Ensure·pcsc-lite·is·installed5531 -·name:·Ensure·pcsc-lite·is·installed
5533 ··package:5532 ··package:
5534 ····name:·pcsc-lite5533 ····name:·pcsc-lite
Offset 39281, 20 lines modifiedOffset 39281, 14 lines modified
39281 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_audispd-plugins_installed39281 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_audispd-plugins_installed
Max diff block lines reached; 4829/8671 bytes (55.69%) of diff not shown.
355 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-rhvh-stig.html
    
Offset 17987, 116 lines modifiedOffset 17987, 116 lines modified
00046420:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00046420:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00046430:·2223·6964·6d32·3035·3022·2074·6162·696e··"#idm2050"·tabin00046430:·2223·6964·6d32·3035·3022·2074·6162·696e··"#idm2050"·tabin
00046440:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00046440:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00046450:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00046450:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00046460:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00046460:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00046470:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00046470:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00046480:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00046480:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00046490:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana00046490:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
000464a0:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..000464a0:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
000464b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl000464b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
000464c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla000464c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
000464d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id000464d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
000464e0:·3d22·6964·6d32·3035·3022·3e3c·7461·626c··="idm2050"><tabl000464e0:·6964·6d32·3035·3022·3e3c·7461·626c·6520··idm2050"><table·
000464f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t000464f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00046500:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00046500:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00046510:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00046510:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00046520:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00046520:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00046530:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00046530:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00046540:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00046540:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00046550:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00046550:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00046560:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00046560:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00046570:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00046570:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00046580:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00046580:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
00046590:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<00046590:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
000465a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table000465a0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
000465b0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac000465b0:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
000465c0:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.000465c0:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 000465d0:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 000465e0:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 000465f0:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 00046600:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 00046610:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 00046620:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00046630:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00046640:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00046650:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 00046660:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 00046670:·6964·6d32·3035·3122·2074·6162·696e·6465··idm2051"·tabinde
 00046680:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00046690:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 000466a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 000466b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 000466c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 000466d0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 000466e0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 000466f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00046700:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00046710:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
 00046720:·3035·3122·3e3c·7461·626c·6520·636c·6173··051"><table·clas
 00046730:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00046740:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00046750:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 00046760:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 00046770:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 00046780:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00046790:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 000467a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 000467b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000467c0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 000467d0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 000467e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 000467f0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00046800:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00046810:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00046820:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 00046830:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
 00046840:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
 00046850:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
 00046860:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
 00046870:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 00046880:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 00046890:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 000468a0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 000468b0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 000468c0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 000468d0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 000468e0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 000468f0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
000465d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00046900:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
000465e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn00046910:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
000465f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da00046920:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
00046600:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla00046930:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
00046610:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00046940:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00046620:·3d22·2369·646d·3230·3531·2220·7461·6269··="#idm2051"·tabi00046950:·3d22·2369·646d·3230·3532·2220·7461·6269··="#idm2052"·tabi
00046630:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00046960:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00046640:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00046970:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00046650:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00046980:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00046660:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00046990:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00046670:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!000469a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00046680:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu000469b0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
00046690:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...000469c0:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
000466a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla000469d0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
000466b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap000469e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
000466c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=000469f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
000466d0:·2269·646d·3230·3531·223e·3c74·6162·6c65··"idm2051"><table00046a00:·643d·2269·646d·3230·3532·223e·3c74·6162··d="idm2052"><tab
000466e0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta00046a10:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
000466f0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl00046a20:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00046700:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table00046a30:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00046710:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>00046a40:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00046720:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<00046a50:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00046730:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00046a60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00046740:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis00046a70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00046750:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td00046a80:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00046760:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00046a90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00046770:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<00046aa0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
00046780:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</00046ab0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
00046790:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>00046ac0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00046ad0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 00046ae0:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
000467a0:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
000467b0:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
000467c0:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
000467d0:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
000467e0:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
000467f0:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
00046800:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
00046810:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00046820:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00046830:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00046840:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00046850:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00046860:·2369·646d·3230·3532·2220·7461·6269·6e64··#idm2052"·tabind 
00046870:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00046880:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00046890:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
000468a0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
000468b0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
Max diff block lines reached; 308600/323256 bytes (95.47%) of diff not shown.
38.9 KB
html2text {}
    
Offset 503, 20 lines modifiedOffset 503, 14 lines modified
503 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed503 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
504 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199504 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199
505 Remediation_OSBuild_Blueprint_snippet_⇲505 Remediation_OSBuild_Blueprint_snippet_⇲
  
506 [[packages]]506 [[packages]]
507 name·=·"aide"507 name·=·"aide"
508 version·=·"*"508 version·=·"*"
509 Remediation_Anaconda_snippet_⇲ 
510 Complexity:·low 
511 Disruption:·low 
512 Strategy:···enable 
  
513 package·--add=aide 
514 Remediation_Puppet_snippet_⇲509 Remediation_Puppet_snippet_⇲
515 Complexity:·low510 Complexity:·low
516 Disruption:·low511 Disruption:·low
517 Strategy:···enable512 Strategy:···enable
518 include·install_aide513 include·install_aide
  
519 class·install_aide·{514 class·install_aide·{
Offset 534, 14 lines modifiedOffset 528, 20 lines modified
534 if·!·rpm·-q·--quiet·"aide"·;·then528 if·!·rpm·-q·--quiet·"aide"·;·then
535 ····yum·install·-y·"aide"529 ····yum·install·-y·"aide"
536 fi530 fi
  
537 else531 else
538 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'532 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
539 fi533 fi
 534 Remediation_Anaconda_snippet_⇲
 535 Complexity:·low
 536 Disruption:·low
 537 Strategy:···enable
  
 538 package·--add=aide
540 Remediation_Ansible_snippet_⇲539 Remediation_Ansible_snippet_⇲
541 Complexity:·low540 Complexity:·low
542 Disruption:·low541 Disruption:·low
543 Strategy:···enable542 Strategy:···enable
544 -·name:·Ensure·aide·is·installed543 -·name:·Ensure·aide·is·installed
545 ··package:544 ··package:
546 ····name:·aide545 ····name:·aide
Offset 1497, 20 lines modifiedOffset 1497, 14 lines modified
1497 ***·Rule  ·Remove·the·GDM·Package·Group·  [ref]·***1497 ***·Rule  ·Remove·the·GDM·Package·Group·  [ref]·***
1498 By·removing·the·gdm·package,·the·system·no·longer·has·GNOME·installed·installed.·If·X·Windows·is·not·installed·then·the·system·cannot·boot·into·graphical·user·mode.·This·prevents·the·system·from·being·accidentally·or·maliciously·booted·into·a·graphical.target·mode.·To·do·so,·run·the·following·command:1498 By·removing·the·gdm·package,·the·system·no·longer·has·GNOME·installed·installed.·If·X·Windows·is·not·installed·then·the·system·cannot·boot·into·graphical·user·mode.·This·prevents·the·system·from·being·accidentally·or·maliciously·booted·into·a·graphical.target·mode.·To·do·so,·run·the·following·command:
1499 $·sudo·yum·remove·gdm1499 $·sudo·yum·remove·gdm
1500 Rationale:·················Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack·surface·of·the·system.·A·graphical·environment·is·unnecessary·for·certain·types·of·systems·including·a·virtualization·hypervisor.1500 Rationale:·················Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack·surface·of·the·system.·A·graphical·environment·is·unnecessary·for·certain·types·of·systems·including·a·virtualization·hypervisor.
1501 Severity: ················medium1501 Severity: ················medium
1502 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gdm_removed1502 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_gdm_removed
1503 Identifiers·and·References·References: ·CM-7(a),·CM-7(b),·CM-6(a),·SRG-OS-000480-GPOS-002271503 Identifiers·and·References·References: ·CM-7(a),·CM-7(b),·CM-6(a),·SRG-OS-000480-GPOS-00227
1504 Remediation_Anaconda_snippet_⇲ 
1505 Complexity:·low 
1506 Disruption:·low 
1507 Strategy:···disable 
  
1508 package·--remove=gdm 
1509 Remediation_Puppet_snippet_⇲1504 Remediation_Puppet_snippet_⇲
1510 Complexity:·low1505 Complexity:·low
1511 Disruption:·low1506 Disruption:·low
1512 Strategy:···disable1507 Strategy:···disable
1513 include·remove_gdm1508 include·remove_gdm
  
1514 class·remove_gdm·{1509 class·remove_gdm·{
Offset 1536, 14 lines modifiedOffset 1530, 20 lines modified
1536 ····yum·remove·-y·"gdm"1530 ····yum·remove·-y·"gdm"
  
1537 fi1531 fi
  
1538 else1532 else
1539 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1533 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1540 fi1534 fi
 1535 Remediation_Anaconda_snippet_⇲
 1536 Complexity:·low
 1537 Disruption:·low
 1538 Strategy:···disable
  
 1539 package·--remove=gdm
1541 Remediation_Ansible_snippet_⇲1540 Remediation_Ansible_snippet_⇲
1542 Complexity:·low1541 Complexity:·low
1543 Disruption:·low1542 Disruption:·low
1544 Strategy:···disable1543 Strategy:···disable
1545 -·name:·Gather·the·package·facts1544 -·name:·Gather·the·package·facts
1546 ··package_facts:1545 ··package_facts:
1547 ····manager:·auto1546 ····manager:·auto
Offset 8534, 20 lines modifiedOffset 8534, 14 lines modified
8534 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_tmux_installed8534 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_tmux_installed
8535 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000058,·CCI-000056,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_SMF_EXT.1,·FMT_MOF_EXT.1,·FTA_SSL.1,·SRG-OS-000030-GPOS-00011,·SRG-OS-000028-GPOS-00009,·SRG-OS-000030-VMM-0001108535 Identifiers·and·References·References: ·1,·12,·15,·16,·DSS05.04,·DSS05.10,·DSS06.10,·3.1.10,·CCI-000058,·CCI-000056,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3,·CM-6(a),·PR.AC-7,·FMT_SMF_EXT.1,·FMT_MOF_EXT.1,·FTA_SSL.1,·SRG-OS-000030-GPOS-00011,·SRG-OS-000028-GPOS-00009,·SRG-OS-000030-VMM-000110
8536 Remediation_OSBuild_Blueprint_snippet_⇲8536 Remediation_OSBuild_Blueprint_snippet_⇲
  
8537 [[packages]]8537 [[packages]]
8538 name·=·"tmux"8538 name·=·"tmux"
8539 version·=·"*"8539 version·=·"*"
8540 Remediation_Anaconda_snippet_⇲ 
8541 Complexity:·low 
8542 Disruption:·low 
8543 Strategy:···enable 
  
8544 package·--add=tmux 
8545 Remediation_Puppet_snippet_⇲8540 Remediation_Puppet_snippet_⇲
8546 Complexity:·low8541 Complexity:·low
8547 Disruption:·low8542 Disruption:·low
8548 Strategy:···enable8543 Strategy:···enable
8549 include·install_tmux8544 include·install_tmux
  
8550 class·install_tmux·{8545 class·install_tmux·{
Offset 8565, 14 lines modifiedOffset 8559, 20 lines modified
8565 if·!·rpm·-q·--quiet·"tmux"·;·then8559 if·!·rpm·-q·--quiet·"tmux"·;·then
8566 ····yum·install·-y·"tmux"8560 ····yum·install·-y·"tmux"
8567 fi8561 fi
  
8568 else8562 else
8569 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8563 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8570 fi8564 fi
 8565 Remediation_Anaconda_snippet_⇲
 8566 Complexity:·low
 8567 Disruption:·low
 8568 Strategy:···enable
  
 8569 package·--add=tmux
8571 Remediation_Ansible_snippet_⇲8570 Remediation_Ansible_snippet_⇲
8572 Complexity:·low8571 Complexity:·low
8573 Disruption:·low8572 Disruption:·low
8574 Strategy:···enable8573 Strategy:···enable
8575 -·name:·Ensure·tmux·is·installed8574 -·name:·Ensure·tmux·is·installed
8576 ··package:8575 ··package:
8577 ····name:·tmux8576 ····name:·tmux
Offset 8599, 20 lines modifiedOffset 8599, 14 lines modified
8599 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed8599 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed
Max diff block lines reached; 35208/39849 bytes (88.35%) of diff not shown.
47.4 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-rhvh-vpp.html
    
Offset 47131, 117 lines modifiedOffset 47131, 117 lines modified
000b81a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=000b81a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
000b81b0:·2223·6964·6d37·3932·3022·2074·6162·696e··"#idm7920"·tabin000b81b0:·2223·6964·6d37·3932·3022·2074·6162·696e··"#idm7920"·tabin
000b81c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu000b81c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
000b81d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan000b81d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
000b81e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl000b81e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
000b81f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r000b81f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
000b8200:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"000b8200:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
000b8210:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana000b8210:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
000b8220:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..000b8220:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
 000b8230:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 000b8240:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 000b8250:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 000b8260:·6964·6d37·3932·3022·3e3c·7461·626c·6520··idm7920"><table·
 000b8270:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 000b8280:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 000b8290:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 000b82a0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 000b82b0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 000b82c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 000b82d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 000b82e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 000b82f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 000b8300:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 000b8310:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 000b8320:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 000b8330:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
 000b8340:·6520·696e·7374·616c·6c5f·6f70·656e·7363··e·install_opensc
 000b8350:·0a0a·636c·6173·7320·696e·7374·616c·6c5f··..class·install_
 000b8360:·6f70·656e·7363·207b·0a20·2070·6163·6b61··opensc·{.··packa
 000b8370:·6765·207b·2027·6f70·656e·7363·273a·0a20··ge·{·'opensc':.·
 000b8380:·2020·2065·6e73·7572·6520·3d26·6774·3b20·····ensure·=&gt;·
 000b8390:·2769·6e73·7461·6c6c·6564·272c·0a20·207d··'installed',.··}
 000b83a0:·0a7d·0a3c·2f63·6f64·653e·3c2f·7072·653e··.}.</code></pre>
 000b83b0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 000b83c0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 000b83d0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 000b83e0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 000b83f0:·6765·743d·2223·6964·6d37·3932·3122·2074··get="#idm7921"·t
 000b8400:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 000b8410:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 000b8420:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 000b8430:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 000b8440:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 000b8450:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 000b8460:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
000b8230:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl000b8470:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
000b8240:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla000b8480:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
000b8250:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id000b8490:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
000b8260:·3d22·6964·6d37·3932·3022·3e3c·7461·626c··="idm7920"><tabl000b84a0:·3d22·6964·6d37·3932·3122·3e3c·7461·626c··="idm7921"><tabl
000b8270:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t000b84b0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
000b8280:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab000b84c0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
000b8290:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl000b84d0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
000b82a0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr000b84e0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
000b82b0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:000b84f0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
000b82c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td000b8500:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
000b82d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di000b8510:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
000b82e0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t000b8520:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
000b82f0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><000b8530:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
000b8300:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:000b8540:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
000b8310:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<000b8550:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
000b8320:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table000b8560:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
000b8330:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac000b8570:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
000b8340:·6b61·6765·202d·2d61·6464·3d6f·7065·6e73··kage·--add=opens 
000b8350:·630a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··c.</code></pre>< 
000b8360:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
000b8370:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
000b8380:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
000b8390:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
000b83a0:·6574·3d22·2369·646d·3739·3231·2220·7461··et="#idm7921"·ta 
000b83b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
000b83c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
000b83d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
000b83e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
000b83f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
000b8400:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
000b8410:·5075·7070·6574·2073·6e69·7070·6574·20e2··Puppet·snippet·. 
000b8420:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
000b8430:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000b8580:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 000b8590:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 000b85a0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 000b85b0:·730a·6966·205b·2021·202d·6620·2f2e·646f··s.if·[·!·-f·/.do
 000b85c0:·636b·6572·656e·7620·5d20·2661·6d70·3b26··ckerenv·]·&amp;&
 000b85d0:·616d·703b·205b·2021·202d·6620·2f72·756e··amp;·[·!·-f·/run
 000b85e0:·2f2e·636f·6e74·6169·6e65·7265·6e76·205d··/.containerenv·]
 000b85f0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 000b8600:·202d·7120·2d2d·7175·6965·7420·226f·7065···-q·--quiet·"ope
 000b8610:·6e73·6322·203b·2074·6865·6e0a·2020·2020··nsc"·;·then.····
 000b8620:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 000b8630:·6f70·656e·7363·220a·6669·0a0a·656c·7365··opensc".fi..else
 000b8640:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 000b8650:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 000b8660:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 000b8670:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 000b8680:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
 000b8690:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 000b86a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 000b86b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
000b8440:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i000b86c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
000b8450:·643d·2269·646d·3739·3231·223e·3c74·6162··d="idm7921"><tab 
000b8460:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
000b8470:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
000b8480:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
000b8490:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
000b84a0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
000b84b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
000b84c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
000b84d0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
000b84e0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
000b84f0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
000b8500:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
000b8510:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
000b8520:·653e·3c70·7265·3e3c·636f·6465·3e69·6e63··e><pre><code>inc 
000b8530:·6c75·6465·2069·6e73·7461·6c6c·5f6f·7065··lude·install_ope 
000b8540:·6e73·630a·0a63·6c61·7373·2069·6e73·7461··nsc..class·insta 
000b8550:·6c6c·5f6f·7065·6e73·6320·7b0a·2020·7061··ll_opensc·{.··pa 
000b8560:·636b·6167·6520·7b20·276f·7065·6e73·6327··ckage·{·'opensc' 
000b8570:·3a0a·2020·2020·656e·7375·7265·203d·2667··:.····ensure·=&g 
000b8580:·743b·2027·696e·7374·616c·6c65·6427·2c0a··t;·'installed',. 
000b8590:·2020·7d0a·7d0a·3c2f·636f·6465·3e3c·2f70····}.}.</code></p 
000b85a0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
000b85b0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
000b85c0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
000b85d0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
000b85e0:·7461·7267·6574·3d22·2369·646d·3739·3232··target="#idm7922000b86d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
000b85f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r000b86e0:·3739·3232·2220·7461·6269·6e64·6578·3d22··7922"·tabindex="
000b8600:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari000b86f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
000b8610:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals000b8700:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
Max diff block lines reached; 27518/42312 bytes (65.04%) of diff not shown.
5.94 KB
html2text {}
    
Offset 6799, 20 lines modifiedOffset 6799, 14 lines modified
6799 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed6799 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_opensc_installed
6800 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-0015206800 Identifiers·and·References·References: ·CCI-001954,·CCI-001953,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161,·SRG-OS-000376-VMM-001520
6801 Remediation_OSBuild_Blueprint_snippet_⇲6801 Remediation_OSBuild_Blueprint_snippet_⇲
  
6802 [[packages]]6802 [[packages]]
6803 name·=·"opensc"6803 name·=·"opensc"
6804 version·=·"*"6804 version·=·"*"
6805 Remediation_Anaconda_snippet_⇲ 
6806 Complexity:·low 
6807 Disruption:·low 
6808 Strategy:···enable 
  
6809 package·--add=opensc 
6810 Remediation_Puppet_snippet_⇲6805 Remediation_Puppet_snippet_⇲
6811 Complexity:·low6806 Complexity:·low
6812 Disruption:·low6807 Disruption:·low
6813 Strategy:···enable6808 Strategy:···enable
6814 include·install_opensc6809 include·install_opensc
  
6815 class·install_opensc·{6810 class·install_opensc·{
Offset 6830, 14 lines modifiedOffset 6824, 20 lines modified
6830 if·!·rpm·-q·--quiet·"opensc"·;·then6824 if·!·rpm·-q·--quiet·"opensc"·;·then
6831 ····yum·install·-y·"opensc"6825 ····yum·install·-y·"opensc"
6832 fi6826 fi
  
6833 else6827 else
6834 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6828 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6835 fi6829 fi
 6830 Remediation_Anaconda_snippet_⇲
 6831 Complexity:·low
 6832 Disruption:·low
 6833 Strategy:···enable
  
 6834 package·--add=opensc
6836 Remediation_Ansible_snippet_⇲6835 Remediation_Ansible_snippet_⇲
6837 Complexity:·low6836 Complexity:·low
6838 Disruption:·low6837 Disruption:·low
6839 Strategy:···enable6838 Strategy:···enable
6840 -·name:·Ensure·opensc·is·installed6839 -·name:·Ensure·opensc·is·installed
6841 ··package:6840 ··package:
6842 ····name:·opensc6841 ····name:·opensc
Offset 6859, 20 lines modifiedOffset 6859, 14 lines modified
6859 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed6859 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
6860 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-0015306860 Identifiers·and·References·References: ·CCI-001954,·1382,·1384,·1386,·CM-6(a),·SRG-OS-000375-GPOS-00160,·SRG-OS-000377-VMM-001530
6861 Remediation_OSBuild_Blueprint_snippet_⇲6861 Remediation_OSBuild_Blueprint_snippet_⇲
  
6862 [[packages]]6862 [[packages]]
6863 name·=·"pcsc-lite"6863 name·=·"pcsc-lite"
6864 version·=·"*"6864 version·=·"*"
6865 Remediation_Anaconda_snippet_⇲ 
6866 Complexity:·low 
6867 Disruption:·low 
6868 Strategy:···enable 
  
6869 package·--add=pcsc-lite 
6870 Remediation_Puppet_snippet_⇲6865 Remediation_Puppet_snippet_⇲
6871 Complexity:·low6866 Complexity:·low
6872 Disruption:·low6867 Disruption:·low
6873 Strategy:···enable6868 Strategy:···enable
6874 include·install_pcsc-lite6869 include·install_pcsc-lite
  
6875 class·install_pcsc-lite·{6870 class·install_pcsc-lite·{
Offset 6890, 14 lines modifiedOffset 6884, 20 lines modified
6890 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then6884 if·!·rpm·-q·--quiet·"pcsc-lite"·;·then
6891 ····yum·install·-y·"pcsc-lite"6885 ····yum·install·-y·"pcsc-lite"
6892 fi6886 fi
  
6893 else6887 else
6894 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'6888 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
6895 fi6889 fi
 6890 Remediation_Anaconda_snippet_⇲
 6891 Complexity:·low
 6892 Disruption:·low
 6893 Strategy:···enable
  
 6894 package·--add=pcsc-lite
6896 Remediation_Ansible_snippet_⇲6895 Remediation_Ansible_snippet_⇲
6897 Complexity:·low6896 Complexity:·low
6898 Disruption:·low6897 Disruption:·low
6899 Strategy:···enable6898 Strategy:···enable
6900 -·name:·Ensure·pcsc-lite·is·installed6899 -·name:·Ensure·pcsc-lite·is·installed
6901 ··package:6900 ··package:
6902 ····name:·pcsc-lite6901 ····name:·pcsc-lite
Offset 44572, 26 lines modifiedOffset 44572, 14 lines modified
44572 $·sudo·systemctl·enable·auditd.service44572 $·sudo·systemctl·enable·auditd.service
44573 ···························Without·establishing·what·type·of·events·occurred,·it·would·be·difficult·to·establish,·correlate,·and·investigate·the·events·leading·up·to·an·outage·or·attack.·Ensuring·the·auditd·service·is·active·ensures·audit·records·generated·by·the·kernel·are·appropriately·recorded.44573 ···························Without·establishing·what·type·of·events·occurred,·it·would·be·difficult·to·establish,·correlate,·and·investigate·the·events·leading·up·to·an·outage·or·attack.·Ensuring·the·auditd·service·is·active·ensures·audit·records·generated·by·the·kernel·are·appropriately·recorded.
44574 Rationale:44574 Rationale:
44575 ···························Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of·individual·system·users·can·be·uniquely·traced·to·those·users·so·they·can·be·held·accountable·for·their·actions.44575 ···························Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of·individual·system·users·can·be·uniquely·traced·to·those·users·so·they·can·be·held·accountable·for·their·actions.
44576 Severity: ················medium44576 Severity: ················medium
44577 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_auditd_enabled44577 Rule·ID:···················xccdf_org.ssgproject.content_rule_service_auditd_enabled
44578 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·3.3.2,·3.3.6,·CCI-000126,·CCI-000130,·CCI-000131,·CCI-000132,·CCI-000133,·CCI-000134,·CCI-000135,·CCI-000154,·CCI-000158,·CCI-000172,·CCI-000366,·CCI-001464,·CCI-001487,·CCI-001814,·CCI-001875,·CCI-001876,·CCI-001877,·CCI-002884,·CCI-001878,·CCI-001879,·CCI-001880,·CCI-001881,·CCI-001882,·CCI-001889,·CCI-001914,·CCI-000169,·164.308(a)(1)(ii)(D),·164.308(a)(5)(ii)(C),·164.310(a)(2)(iv),·164.310(d)(2)(iii),·164.312(b),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·CIP-004-6_R3.3,·CIP-007-3_R6.5,·AC-2(g),·AU-3,·AU-10,·AU-2(d),·AU-12(c),·AU-14(1),·AC-6(9),·CM-6(a),·SI-4(23),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1,·Req-10.1,·SRG-OS-000062-GPOS-00031,·SRG-OS-000037-GPOS-00015,·SRG-OS-000038-GPOS-00016,·SRG-OS-000039-GPOS-00017,·SRG-OS-000040-GPOS-00018,·SRG-OS-000041-GPOS-00019,·SRG-OS-000042-GPOS-00021,·SRG-OS-000051-GPOS-00024,·SRG-OS-000054-GPOS-00025,·SRG-OS-000122-GPOS-00063,·SRG-OS-000254-GPOS-00095,·SRG-OS-000255-GPOS-00096,·SRG-OS-000337-GPOS-00129,·SRG-OS-000348-GPOS-00136,·SRG-OS-000349-GPOS-00137,·SRG-OS-000350-GPOS-00138,·SRG-OS-000351-GPOS-00139,·SRG-OS-000352-GPOS-00140,·SRG-OS-000353-GPOS-00141,·SRG-OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,·SRG-OS-000365-GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-00220,·SRG-OS-000037-VMM-000150,·SRG-OS-000063-VMM-000310,·SRG-OS-000038-VMM-000160,·SRG-OS-000039-VMM-000170,·SRG-OS-000040-VMM-000180,·SRG-OS-000041-VMM-00019044578 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.3.1,·3.3.2,·3.3.6,·CCI-000126,·CCI-000130,·CCI-000131,·CCI-000132,·CCI-000133,·CCI-000134,·CCI-000135,·CCI-000154,·CCI-000158,·CCI-000172,·CCI-000366,·CCI-001464,·CCI-001487,·CCI-001814,·CCI-001875,·CCI-001876,·CCI-001877,·CCI-002884,·CCI-001878,·CCI-001879,·CCI-001880,·CCI-001881,·CCI-001882,·CCI-001889,·CCI-001914,·CCI-000169,·164.308(a)(1)(ii)(D),·164.308(a)(5)(ii)(C),·164.310(a)(2)(iv),·164.310(d)(2)(iii),·164.312(b),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·CIP-004-6_R3.3,·CIP-007-3_R6.5,·AC-2(g),·AU-3,·AU-10,·AU-2(d),·AU-12(c),·AU-14(1),·AC-6(9),·CM-6(a),·SI-4(23),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1,·Req-10.1,·SRG-OS-000062-GPOS-00031,·SRG-OS-000037-GPOS-00015,·SRG-OS-000038-GPOS-00016,·SRG-OS-000039-GPOS-00017,·SRG-OS-000040-GPOS-00018,·SRG-OS-000041-GPOS-00019,·SRG-OS-000042-GPOS-00021,·SRG-OS-000051-GPOS-00024,·SRG-OS-000054-GPOS-00025,·SRG-OS-000122-GPOS-00063,·SRG-OS-000254-GPOS-00095,·SRG-OS-000255-GPOS-00096,·SRG-OS-000337-GPOS-00129,·SRG-OS-000348-GPOS-00136,·SRG-OS-000349-GPOS-00137,·SRG-OS-000350-GPOS-00138,·SRG-OS-000351-GPOS-00139,·SRG-OS-000352-GPOS-00140,·SRG-OS-000353-GPOS-00141,·SRG-OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,·SRG-OS-000365-GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-00220,·SRG-OS-000037-VMM-000150,·SRG-OS-000063-VMM-000310,·SRG-OS-000038-VMM-000160,·SRG-OS-000039-VMM-000170,·SRG-OS-000040-VMM-000180,·SRG-OS-000041-VMM-000190
44579 Remediation_Kubernetes_snippet_⇲ 
44580 --- 
44581 apiVersion:·machineconfiguration.openshift.io/v1 
44582 kind:·MachineConfig 
44583 spec: 
44584 ··config: 
44585 ····ignition: 
44586 ······version:·3.1.0 
44587 ····systemd: 
44588 ······units: 
44589 ······-·name:·auditd.service 
44590 ········enabled:·true 
44591 Remediation_OSBuild_Blueprint_snippet_⇲44579 Remediation_OSBuild_Blueprint_snippet_⇲
  
44592 [customizations.services]44580 [customizations.services]
44593 enabled·=·["auditd"]44581 enabled·=·["auditd"]
44594 Remediation_Puppet_snippet_⇲44582 Remediation_Puppet_snippet_⇲
44595 Complexity:·low44583 Complexity:·low
44596 Disruption:·low44584 Disruption:·low
Offset 44600, 14 lines modifiedOffset 44588, 26 lines modified
  
44600 class·enable_auditd·{44588 class·enable_auditd·{
44601 ··service·{'auditd':44589 ··service·{'auditd':
44602 ····enable·=>·true,44590 ····enable·=>·true,
44603 ····ensure·=>·'running',44591 ····ensure·=>·'running',
44604 ··}44592 ··}
44605 }44593 }
 44594 Remediation_Kubernetes_snippet_⇲
 44595 ---
 44596 apiVersion:·machineconfiguration.openshift.io/v1
 44597 kind:·MachineConfig
 44598 spec:
 44599 ··config:
 44600 ····ignition:
 44601 ······version:·3.1.0
 44602 ····systemd:
Max diff block lines reached; 202/6062 bytes (3.33%) of diff not shown.
683 KB
./usr/share/doc/ssg-nondebian/ssg-sl7-guide-pci-dss.html
    
Offset 17325, 116 lines modifiedOffset 17325, 116 lines modified
00043ac0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00043ac0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00043ad0:·2223·6964·6d31·3532·3322·2074·6162·696e··"#idm1523"·tabin00043ad0:·2223·6964·6d31·3532·3322·2074·6162·696e··"#idm1523"·tabin
00043ae0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00043ae0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00043af0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00043af0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00043b00:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00043b00:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00043b10:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00043b10:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00043b20:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00043b20:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00043b30:·3e52·656d·6564·6961·7469·6f6e·2041·6e61··>Remediation·Ana00043b30:·3e52·656d·6564·6961·7469·6f6e·2050·7570··>Remediation·Pup
00043b40:·636f·6e64·6120·736e·6970·7065·7420·e287··conda·snippet·..00043b40:·7065·7420·736e·6970·7065·7420·e287·b23c··pet·snippet·...<
00043b50:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl00043b50:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00043b60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00043b60:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00043b70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00043b70:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00043b80:·3d22·6964·6d31·3532·3322·3e3c·7461·626c··="idm1523"><tabl00043b80:·6964·6d31·3532·3322·3e3c·7461·626c·6520··idm1523"><table·
00043b90:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00043b90:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00043ba0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00043ba0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00043bb0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00043bb0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00043bc0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00043bc0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00043bd0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00043bd0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00043be0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00043be0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00043bf0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00043bf0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00043c00:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00043c00:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00043c10:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00043c10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00043c20:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00043c20:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
00043c30:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<00043c30:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
00043c40:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table00043c40:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
00043c50:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac00043c50:·7072·653e·3c63·6f64·653e·696e·636c·7564··pre><code>includ
00043c60:·6b61·6765·202d·2d61·6464·3d61·6964·650a··kage·--add=aide.00043c60:·6520·696e·7374·616c·6c5f·6169·6465·0a0a··e·install_aide..
 00043c70:·636c·6173·7320·696e·7374·616c·6c5f·6169··class·install_ai
 00043c80:·6465·207b·0a20·2070·6163·6b61·6765·207b··de·{.··package·{
 00043c90:·2027·6169·6465·273a·0a20·2020·2065·6e73···'aide':.····ens
 00043ca0:·7572·6520·3d26·6774·3b20·2769·6e73·7461··ure·=&gt;·'insta
 00043cb0:·6c6c·6564·272c·0a20·207d·0a7d·0a3c·2f63··lled',.··}.}.</c
 00043cc0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00043cd0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00043ce0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00043cf0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 00043d00:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 00043d10:·6964·6d31·3532·3422·2074·6162·696e·6465··idm1524"·tabinde
 00043d20:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00043d30:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 00043d40:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 00043d50:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 00043d60:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 00043d70:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 00043d80:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 00043d90:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00043da0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00043db0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 00043dc0:·3532·3422·3e3c·7461·626c·6520·636c·6173··524"><table·clas
 00043dd0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00043de0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00043df0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 00043e00:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 00043e10:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 00043e20:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00043e30:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 00043e40:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 00043e50:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00043e60:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00043e70:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00043e80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00043e90:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00043ea0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00043eb0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00043ec0:·6e20·706c·6174·666f·726d·730a·6966·205b··n·platforms.if·[
 00043ed0:·2021·202d·6620·2f2e·646f·636b·6572·656e···!·-f·/.dockeren
 00043ee0:·7620·5d20·2661·6d70·3b26·616d·703b·205b··v·]·&amp;&amp;·[
 00043ef0:·2021·202d·6620·2f72·756e·2f2e·636f·6e74···!·-f·/run/.cont
 00043f00:·6169·6e65·7265·6e76·205d·3b20·7468·656e··ainerenv·];·then
 00043f10:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 00043f20:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 00043f30:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst
 00043f40:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 00043f50:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 00043f60:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 00043f70:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 00043f80:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 00043f90:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
00043c70:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00043fa0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
00043c80:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn00043fb0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
00043c90:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da00043fc0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
00043ca0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla00043fd0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
00043cb0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00043fe0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00043cc0:·3d22·2369·646d·3135·3234·2220·7461·6269··="#idm1524"·tabi00043ff0:·3d22·2369·646d·3135·3235·2220·7461·6269··="#idm1525"·tabi
00043cd0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00044000:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00043ce0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00044010:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00043cf0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00044020:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00043d00:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00044030:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00043d10:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00044040:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00043d20:·223e·5265·6d65·6469·6174·696f·6e20·5075··">Remediation·Pu00044050:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
00043d30:·7070·6574·2073·6e69·7070·6574·20e2·87b2··ppet·snippet·...00044060:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
00043d40:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla00044070:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00043d50:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap00044080:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00043d60:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=00044090:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00043d70:·2269·646d·3135·3234·223e·3c74·6162·6c65··"idm1524"><table000440a0:·643d·2269·646d·3135·3235·223e·3c74·6162··d="idm1525"><tab
00043d80:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta000440b0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00043d90:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl000440c0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00043da0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table000440d0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00043db0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>000440e0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00043dc0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<000440f0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00043dd0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00044100:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00043de0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis00044110:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00043df0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td00044120:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00043e00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00044130:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00043e10:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<00044140:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
00043e20:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</00044150:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
00043e30:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>00044160:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00044170:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 00044180:·636b·6167·6520·2d2d·6164·643d·6169·6465··ckage·--add=aide
00043e40:·3c70·7265·3e3c·636f·6465·3e69·6e63·6c75··<pre><code>inclu 
00043e50:·6465·2069·6e73·7461·6c6c·5f61·6964·650a··de·install_aide. 
00043e60:·0a63·6c61·7373·2069·6e73·7461·6c6c·5f61··.class·install_a 
00043e70:·6964·6520·7b0a·2020·7061·636b·6167·6520··ide·{.··package· 
00043e80:·7b20·2761·6964·6527·3a0a·2020·2020·656e··{·'aide':.····en 
00043e90:·7375·7265·203d·2667·743b·2027·696e·7374··sure·=&gt;·'inst 
00043ea0:·616c·6c65·6427·2c0a·2020·7d0a·7d0a·3c2f··alled',.··}.}.</ 
00043eb0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00043ec0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00043ed0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00043ee0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00043ef0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00043f00:·2369·646d·3135·3235·2220·7461·6269·6e64··#idm1525"·tabind 
00043f10:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00043f20:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00043f30:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00043f40:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00043f50:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
Max diff block lines reached; 490598/505254 bytes (97.10%) of diff not shown.
190 KB
html2text {}
    
Offset 415, 20 lines modifiedOffset 415, 14 lines modified
415 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed415 Rule·ID:···················xccdf_org.ssgproject.content_rule_package_aide_installed
416 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251705r861078_rule416 Identifiers·and·References·References: ·BP28(R51),·1,·11,·12,·13,·14,·15,·16,·2,·3,·5,·7,·8,·9,·5.10.1.3,·APO01.06,·BAI01.06,·BAI02.01,·BAI03.05,·BAI06.01,·BAI10.01,·BAI10.02,·BAI10.03,·BAI10.05,·DSS01.03,·DSS03.05,·DSS04.07,·DSS05.02,·DSS05.03,·DSS05.05,·DSS05.07,·DSS06.02,·DSS06.06,·CCI-002696,·CCI-002699,·CCI-001744,·4.3.4.3.2,·4.3.4.3.3,·4.3.4.4.4,·SR_3.1,·SR_3.3,·SR_3.4,·SR_3.8,·SR_4.1,·SR_6.2,·SR_7.6,·1034,·1288,·1341,·1417,·A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3,·CM-6(a),·DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3,·Req-11.5,·SRG-OS-000363-GPOS-00150,·SRG-OS-000445-GPOS-00199,·1.3.1,·SV-251705r861078_rule
417 Remediation_OSBuild_Blueprint_snippet_⇲417 Remediation_OSBuild_Blueprint_snippet_⇲
  
418 [[packages]]418 [[packages]]
419 name·=·"aide"419 name·=·"aide"
420 version·=·"*"420 version·=·"*"
421 Remediation_Anaconda_snippet_⇲ 
422 Complexity:·low 
423 Disruption:·low 
424 Strategy:···enable 
  
425 package·--add=aide 
426 Remediation_Puppet_snippet_⇲421 Remediation_Puppet_snippet_⇲
427 Complexity:·low422 Complexity:·low
428 Disruption:·low423 Disruption:·low
429 Strategy:···enable424 Strategy:···enable
430 include·install_aide425 include·install_aide
  
431 class·install_aide·{426 class·install_aide·{
Offset 446, 14 lines modifiedOffset 440, 20 lines modified
446 if·!·rpm·-q·--quiet·"aide"·;·then440 if·!·rpm·-q·--quiet·"aide"·;·then
447 ····yum·install·-y·"aide"441 ····yum·install·-y·"aide"
448 fi442 fi
  
449 else443 else
450 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'444 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
451 fi445 fi
 446 Remediation_Anaconda_snippet_⇲
 447 Complexity:·low
 448 Disruption:·low
 449 Strategy:···enable
  
 450 package·--add=aide
452 Remediation_Ansible_snippet_⇲451 Remediation_Ansible_snippet_⇲
453 Complexity:·low452 Complexity:·low
454 Disruption:·low453 Disruption:·low
455 Strategy:···enable454 Strategy:···enable
456 -·name:·Ensure·aide·is·installed455 -·name:·Ensure·aide·is·installed
457 ··package:456 ··package:
458 ····name:·aide457 ····name:·aide
Offset 5683, 17 lines modifiedOffset 5683, 14 lines modified
5683 ····*·https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/system-level_authentication_guide/smartcards#authconfig-smartcards5683 ····*·https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/system-level_authentication_guide/smartcards#authconfig-smartcards
5684 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:5684 For·guidance·on·enabling·SSH·to·authenticate·against·a·Common·Access·Card·(CAC),·consult·documentation·at:
5685 ····*·https://access.redhat.com/solutions/822735685 ····*·https://access.redhat.com/solutions/82273
5686 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.5686 Rationale:·················Smart·card·login·provides·two-factor·authentication·stronger·than·that·provided·by·a·username·and·password·combination.·Smart·cards·leverage·PKI·(public·key·infrastructure)·in·order·to·provide·and·verify·credentials.
5687 Severity: ················medium5687 Severity: ················medium
5688 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth5688 Rule·ID:···················xccdf_org.ssgproject.content_rule_smartcard_auth
5689 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·SV-204441r818813_rule5689 Identifiers·and·References·References: ·1,·12,·15,·16,·5,·DSS05.04,·DSS05.05,·DSS05.07,·DSS05.10,·DSS06.03,·DSS06.10,·CCI-000764,·CCI-000765,·CCI-000766,·CCI-000767,·CCI-000768,·CCI-000770,·CCI-000771,·CCI-000772,·CCI-000884,·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4,·SR_1.1,·SR_1.10,·SR_1.2,·SR_1.3,·SR_1.4,·SR_1.5,·SR_1.7,·SR_1.8,·SR_1.9,·SR_2.1,·A.18.1.4,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3,·IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a),·PR.AC-1,·PR.AC-6,·PR.AC-7,·Req-8.3,·SRG-OS-000104-GPOS-00051,·SRG-OS-000106-GPOS-00053,·SRG-OS-000107-GPOS-00054,·SRG-OS-000108-GPOS-00055,·SRG-OS-000108-GPOS-00057,·SRG-OS-000108-GPOS-00058,·SRG-OS-000109-GPOS-00056,·SRG-OS-000376-GPOS-00161,·SRG-OS-000377-GPOS-00162,·SV-204441r818813_rule
5690 Remediation_Anaconda_snippet_⇲ 
  
5691 package·--add=pam_pkcs11·--add=esc 
5692 Remediation_Shell_script_⇲5690 Remediation_Shell_script_⇲
5693 #·Remediation·is·applicable·only·in·certain·platforms5691 #·Remediation·is·applicable·only·in·certain·platforms
5694 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·!·grep·-q·s390x·/proc/sys/kernel/osrelease;·};·then5692 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·{·!·grep·-q·s390x·/proc/sys/kernel/osrelease;·};·then
  
5695 #·Install·required·packages5693 #·Install·required·packages
5696 if·!·rpm·-q·--quiet·"esc"·;·then5694 if·!·rpm·-q·--quiet·"esc"·;·then
5697 ····yum·install·-y·"esc"5695 ····yum·install·-y·"esc"
Offset 5798, 14 lines modifiedOffset 5795, 17 lines modified
5798 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,5795 #·2)·Then·append·'ocsp_on'·value·setting·to·each·'cert_policy'·key·in·$PAM_PKCS11_CONF·configuration·line,
5799 #·which·does·not·contain·it·yet5796 #·which·does·not·contain·it·yet
5800 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"5797 sed·-i·"/ocsp_on/!·s/^[$SP]*cert_policy[$SP]\+=[$SP]\+\(.*\);/\t\tcert_policy·=·\1,·ocsp_on;/"·"$PAM_PKCS11_CONF"
  
5801 else5798 else
5802 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5799 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5803 fi5800 fi
 5801 Remediation_Anaconda_snippet_⇲
  
 5802 package·--add=pam_pkcs11·--add=esc
5804 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules5803 Group  ·Protect·Accounts·by·Restricting·Password-Based·Login·  Group·contains·3·groups·and·6·rules
5805 [ref]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.5804 [ref]  ·Conventionally,·Unix·shell·accounts·are·accessed·by·providing·a·username·and·password·to·a·login·program,·which·tests·these·values·for·correctness·using·the·/etc/passwd·and·/etc/shadow·files.·Password-based·login·is·vulnerable·to·guessing·of·weak·passwords,·and·to·sniffing·and·man-in-the-middle·attacks·against·passwords·entered·over·a·network·or·at·an·insecure·console.·Therefore,·mechanisms·for·accessing·accounts·by·entering·usernames·and·passwords·should·be·restricted·to·those·which·are·operationally·necessary.
5806 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules5805 Group  ·Set·Account·Expiration·Parameters·  Group·contains·2·rules
5807 [ref]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:5806 [ref]  ·Accounts·can·be·configured·to·be·automatically·disabled·after·a·certain·time·period,·meaning·that·they·will·require·administrator·interaction·to·become·usable·again.·Expiration·of·accounts·after·inactivity·can·be·set·for·all·accounts·by·default·and·also·on·a·per-account·basis,·such·as·for·accounts·that·are·known·to·be·temporary.·To·configure·automatic·expiration·of·an·account·following·the·expiration·of·its·password·(that·is,·after·the·password·has·expired·and·not·been·changed),·run·the·following·command,·substituting·NUM_DAYS·and·USER·appropriately:
5808 $·sudo·chage·-I·NUM_DAYS·USER5807 $·sudo·chage·-I·NUM_DAYS·USER
5809 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.5808 Accounts,·such·as·temporary·accounts,·can·also·be·configured·to·expire·on·an·explicitly-set·date·with·the·-E·option.·The·file·/etc/default/useradd·controls·default·settings·for·all·newly-created·accounts·created·with·the·system's·normal·command·line·utilities.
5810 Warning: ·This·will·only·apply·to·newly·created·accounts5809 Warning: ·This·will·only·apply·to·newly·created·accounts
Offset 6269, 15 lines modifiedOffset 6269, 15 lines modified
6269 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.6269 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
6270 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.6270 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
6271 Severity: ················medium6271 Severity: ················medium
6272 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod6272 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
6273 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204521r809772_rule6273 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204521r809772_rule
6274 Remediation_Shell_script_⇲6274 Remediation_Shell_script_⇲
6275 #·Remediation·is·applicable·only·in·certain·platforms6275 #·Remediation·is·applicable·only·in·certain·platforms
6276 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then6276 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
6277 #·First·perform·the·remediation·of·the·syscall·rule6277 #·First·perform·the·remediation·of·the·syscall·rule
6278 #·Retrieve·hardware·architecture·of·the·underlying·system6278 #·Retrieve·hardware·architecture·of·the·underlying·system
6279 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6279 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6280 for·ARCH·in·"${RULE_ARCHS[@]}"6280 for·ARCH·in·"${RULE_ARCHS[@]}"
6281 do6281 do
Offset 6624, 16 lines modifiedOffset 6624, 16 lines modified
6624 ··-·reboot_required6624 ··-·reboot_required
6625 ··-·restrict_strategy6625 ··-·restrict_strategy
  
6626 -·name:·Set·architecture·for·audit·chmod·tasks6626 -·name:·Set·architecture·for·audit·chmod·tasks
6627 ··set_fact:6627 ··set_fact:
6628 ····audit_arch:·b646628 ····audit_arch:·b64
6629 ··when:6629 ··when:
6630 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6631 ··-·'"audit"·in·ansible_facts.packages'6630 ··-·'"audit"·in·ansible_facts.packages'
 6631 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6632 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6632 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6633 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6633 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6634 ··tags:6634 ··tags:
6635 ··-·CJIS-5.4.1.16635 ··-·CJIS-5.4.1.1
6636 ··-·DISA-STIG-RHEL-07-0304106636 ··-·DISA-STIG-RHEL-07-030410
6637 ··-·NIST-800-171-3.1.76637 ··-·NIST-800-171-3.1.7
6638 ··-·NIST-800-53-AU-12(c)6638 ··-·NIST-800-53-AU-12(c)
Offset 6770, 16 lines modifiedOffset 6770, 16 lines modified
6770 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006770 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6771 ········-F·auid!=unset·-F·key=perm_mod6771 ········-F·auid!=unset·-F·key=perm_mod
6772 ······create:·true6772 ······create:·true
6773 ······mode:·o-rwx6773 ······mode:·o-rwx
6774 ······state:·present6774 ······state:·present
6775 ····when:·syscalls_found·|·length·==·06775 ····when:·syscalls_found·|·length·==·0
6776 ··when:6776 ··when:
6777 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6778 ··-·'"audit"·in·ansible_facts.packages'6777 ··-·'"audit"·in·ansible_facts.packages'
 6778 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6779 ··tags:6779 ··tags:
6780 ··-·CJIS-5.4.1.16780 ··-·CJIS-5.4.1.1
6781 ··-·DISA-STIG-RHEL-07-0304106781 ··-·DISA-STIG-RHEL-07-030410
6782 ··-·NIST-800-171-3.1.76782 ··-·NIST-800-171-3.1.7
6783 ··-·NIST-800-53-AU-12(c)6783 ··-·NIST-800-53-AU-12(c)
Max diff block lines reached; 184702/194301 bytes (95.06%) of diff not shown.
570 KB
./usr/share/doc/ssg-nondebian/ssg-sl7-guide-standard.html
    
Offset 23954, 21 lines modifiedOffset 23954, 21 lines modified
0005d910:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0005d910:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0005d920:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0005d920:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0005d930:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0005d930:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0005d940:·3137·3133·3622·3e3c·7072·653e·3c63·6f64··17136"><pre><cod0005d940:·3137·3133·3622·3e3c·7072·653e·3c63·6f64··17136"><pre><cod
0005d950:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·0005d950:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
0005d960:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on0005d960:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
0005d970:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl0005d970:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
0005d980:·6174·666f·726d·730a·6966·205b·2021·202d··atforms.if·[·!·-0005d980:·6174·666f·726d·730a·6966·2072·706d·202d··atforms.if·rpm·-
0005d990:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·0005d990:·2d71·7569·6574·202d·7120·6175·6469·7420··-quiet·-q·audit·
0005d9a0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-0005d9a0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-
 0005d9b0:·6620·2f2e·646f·636b·6572·656e·7620·5d20··f·/.dockerenv·]·
 0005d9c0:·2661·6d70·3b26·616d·703b·205b·2021·202d··&amp;&amp;·[·!·-
0005d9b0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe0005d9d0:·6620·2f72·756e·2f2e·636f·6e74·6169·6e65··f·/run/.containe
0005d9c0:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp 
0005d9d0:·3b20·7270·6d20·2d2d·7175·6965·7420·2d71··;·rpm·--quiet·-q 
0005d9e0:·2061·7564·6974·3b20·7468·656e·0a0a·2320···audit;·then..#·0005d9e0:·7265·6e76·205d·3b20·7468·656e·0a0a·2320··renv·];·then..#·
0005d9f0:·4669·7273·7420·7065·7266·6f72·6d20·7468··First·perform·th0005d9f0:·4669·7273·7420·7065·7266·6f72·6d20·7468··First·perform·th
0005da00:·6520·7265·6d65·6469·6174·696f·6e20·6f66··e·remediation·of0005da00:·6520·7265·6d65·6469·6174·696f·6e20·6f66··e·remediation·of
0005da10:·2074·6865·2073·7973·6361·6c6c·2072·756c···the·syscall·rul0005da10:·2074·6865·2073·7973·6361·6c6c·2072·756c···the·syscall·rul
0005da20:·650a·2320·5265·7472·6965·7665·2068·6172··e.#·Retrieve·har0005da20:·650a·2320·5265·7472·6965·7665·2068·6172··e.#·Retrieve·har
0005da30:·6477·6172·6520·6172·6368·6974·6563·7475··dware·architectu0005da30:·6477·6172·6520·6172·6368·6974·6563·7475··dware·architectu
0005da40:·7265·206f·6620·7468·6520·756e·6465·726c··re·of·the·underl0005da40:·7265·206f·6620·7468·6520·756e·6465·726c··re·of·the·underl
0005da50:·7969·6e67·2073·7973·7465·6d0a·5b20·2224··ying·system.[·"$0005da50:·7969·6e67·2073·7973·7465·6d0a·5b20·2224··ying·system.[·"$
Offset 24848, 23 lines modifiedOffset 24848, 23 lines modified
000610f0:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict000610f0:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict
00061100:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam00061100:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam
00061110:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect00061110:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect
00061120:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch00061120:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch
00061130:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_00061130:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_
00061140:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_00061140:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_
00061150:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when00061150:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when
00061160:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi 
00061170:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ 
00061180:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke 
00061190:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open 
000611a0:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·" 
000611b0:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-· 
000611c0:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi 
000611d0:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag00061160:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i
 00061170:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 00061180:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an
 00061190:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza
 000611a0:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in
 000611b0:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc
 000611c0:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po
 000611d0:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe
000611e0:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_000611e0:·7222·5d0a·2020·2d20·616e·7369·626c·655f··r"].··-·ansible_
000611f0:·6172·6368·6974·6563·7475·7265·203d·3d20··architecture·==·000611f0:·6172·6368·6974·6563·7475·7265·203d·3d20··architecture·==·
00061200:·2261·6172·6368·3634·2220·6f72·2061·6e73··"aarch64"·or·ans00061200:·2261·6172·6368·3634·2220·6f72·2061·6e73··"aarch64"·or·ans
00061210:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur00061210:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
00061220:·6520·3d3d·2022·7070·6336·3422·206f·7220··e·==·"ppc64"·or·00061220:·6520·3d3d·2022·7070·6336·3422·206f·7220··e·==·"ppc64"·or·
00061230:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec00061230:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec
00061240:·7475·7265·0a20·2020·203d·3d20·2270·7063··ture.····==·"ppc00061240:·7475·7265·0a20·2020·203d·3d20·2270·7063··ture.····==·"ppc
00061250:·3634·6c65·2220·6f72·2061·6e73·6962·6c65··64le"·or·ansible00061250:·3634·6c65·2220·6f72·2061·6e73·6962·6c65··64le"·or·ansible
Offset 25171, 23 lines modifiedOffset 25171, 23 lines modified
00062520:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····00062520:·6579·3d70·6572·6d5f·6d6f·640a·2020·2020··ey=perm_mod.····
00062530:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·00062530:·2020·6372·6561·7465·3a20·7472·7565·0a20····create:·true.·
00062540:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx00062540:·2020·2020·206d·6f64·653a·206f·2d72·7778·······mode:·o-rwx
00062550:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr00062550:·0a20·2020·2020·2073·7461·7465·3a20·7072··.······state:·pr
00062560:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·00062560:·6573·656e·740a·2020·2020·7768·656e·3a20··esent.····when:·
00062570:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|00062570:·7379·7363·616c·6c73·5f66·6f75·6e64·207c··syscalls_found·|
00062580:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w00062580:·206c·656e·6774·6820·3d3d·2030·0a20·2077···length·==·0.··w
00062590:·6865·6e3a·0a20·202d·2061·6e73·6962·6c65··hen:.··-·ansible00062590:·6865·6e3a·0a20·202d·2027·2261·7564·6974··hen:.··-·'"audit
000625a0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
000625b0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
000625c0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
000625d0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
000625e0:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].· 
000625f0:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a 
00062600:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac000625a0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 000625b0:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··-
 000625c0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
 000625d0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
 000625e0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
 000625f0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
 00062600:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
00062610:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.·00062610:·696e·6572·225d·0a20·2074·6167·733a·0a20··iner"].··tags:.·
00062620:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.00062620:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.
00062630:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH00062630:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH
00062640:·454c·2d30·372d·3033·3034·3130·0a20·202d··EL-07-030410.··-00062640:·454c·2d30·372d·3033·3034·3130·0a20·202d··EL-07-030410.··-
00062650:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.00062650:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
00062660:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-80000062660:·312e·370a·2020·2d20·4e49·5354·2d38·3030··1.7.··-·NIST-800
00062670:·2d35·332d·4155·2d31·3228·6329·0a20·202d··-53-AU-12(c).··-00062670:·2d35·332d·4155·2d31·3228·6329·0a20·202d··-53-AU-12(c).··-
00062680:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-00062680:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
Offset 25483, 22 lines modifiedOffset 25483, 22 lines modified
000638a0:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea000638a0:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea
000638b0:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m000638b0:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m
000638c0:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····000638c0:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····
000638d0:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.000638d0:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
000638e0:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal000638e0:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal
000638f0:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt000638f0:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt
00063900:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·00063900:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·
00063910:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu 
00063920:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
00063930:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
00063940:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
00063950:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
00063960:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a 
00063970:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
00063980:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'00063910:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a
 00063920:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
 00063930:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib
 00063940:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 00063950:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 00063960:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 00063970:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 00063980:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
00063990:·0a20·202d·2061·7564·6974·5f61·7263·6820··.··-·audit_arch·00063990:·0a20·202d·2061·7564·6974·5f61·7263·6820··.··-·audit_arch·
000639a0:·3d3d·2022·6236·3422·0a20·2074·6167·733a··==·"b64".··tags:000639a0:·3d3d·2022·6236·3422·0a20·2074·6167·733a··==·"b64".··tags:
000639b0:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.000639b0:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.
000639c0:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-000639c0:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-
000639d0:·5248·454c·2d30·372d·3033·3034·3130·0a20··RHEL-07-030410.·000639d0:·5248·454c·2d30·372d·3033·3034·3130·0a20··RHEL-07-030410.·
000639e0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-000639e0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
000639f0:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8000639f0:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8
Offset 26448, 21 lines modifiedOffset 26448, 21 lines modified
000674f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane000674f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00067500:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00067500:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00067510:·7073·6522·2069·643d·2269·646d·3137·3239··pse"·id="idm172900067510:·7073·6522·2069·643d·2269·646d·3137·3239··pse"·id="idm1729
00067520:·3422·3e3c·7072·653e·3c63·6f64·653e·2320··4"><pre><code>#·00067520:·3422·3e3c·7072·653e·3c63·6f64·653e·2320··4"><pre><code>#·
00067530:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a00067530:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
00067540:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i00067540:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
00067550:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo00067550:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 00067560:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 00067570:·6574·202d·7120·6175·6469·7420·2661·6d70··et·-q·audit·&amp
00067560:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.00067580:·3b26·616d·703b·205b·2021·202d·6620·2f2e··;&amp;·[·!·-f·/.
00067570:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp00067590:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
00067580:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r000675a0:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
Max diff block lines reached; 415550/425547 bytes (97.65%) of diff not shown.
155 KB
html2text {}
    
Offset 1082, 15 lines modifiedOffset 1082, 15 lines modified
1082 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1082 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1083 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1083 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1084 Severity: ················medium1084 Severity: ················medium
1085 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod1085 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod
1086 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204521r809772_rule1086 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204521r809772_rule
1087 Remediation_Shell_script_⇲1087 Remediation_Shell_script_⇲
1088 #·Remediation·is·applicable·only·in·certain·platforms1088 #·Remediation·is·applicable·only·in·certain·platforms
1089 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1089 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1090 #·First·perform·the·remediation·of·the·syscall·rule1090 #·First·perform·the·remediation·of·the·syscall·rule
1091 #·Retrieve·hardware·architecture·of·the·underlying·system1091 #·Retrieve·hardware·architecture·of·the·underlying·system
1092 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1092 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1093 for·ARCH·in·"${RULE_ARCHS[@]}"1093 for·ARCH·in·"${RULE_ARCHS[@]}"
1094 do1094 do
Offset 1437, 16 lines modifiedOffset 1437, 16 lines modified
1437 ··-·reboot_required1437 ··-·reboot_required
1438 ··-·restrict_strategy1438 ··-·restrict_strategy
  
1439 -·name:·Set·architecture·for·audit·chmod·tasks1439 -·name:·Set·architecture·for·audit·chmod·tasks
1440 ··set_fact:1440 ··set_fact:
1441 ····audit_arch:·b641441 ····audit_arch:·b64
1442 ··when:1442 ··when:
1443 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1444 ··-·'"audit"·in·ansible_facts.packages'1443 ··-·'"audit"·in·ansible_facts.packages'
 1444 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1445 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1445 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1446 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1446 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1447 ··tags:1447 ··tags:
1448 ··-·CJIS-5.4.1.11448 ··-·CJIS-5.4.1.1
1449 ··-·DISA-STIG-RHEL-07-0304101449 ··-·DISA-STIG-RHEL-07-030410
1450 ··-·NIST-800-171-3.1.71450 ··-·NIST-800-171-3.1.7
1451 ··-·NIST-800-53-AU-12(c)1451 ··-·NIST-800-53-AU-12(c)
Offset 1583, 16 lines modifiedOffset 1583, 16 lines modified
1583 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001583 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1584 ········-F·auid!=unset·-F·key=perm_mod1584 ········-F·auid!=unset·-F·key=perm_mod
1585 ······create:·true1585 ······create:·true
1586 ······mode:·o-rwx1586 ······mode:·o-rwx
1587 ······state:·present1587 ······state:·present
1588 ····when:·syscalls_found·|·length·==·01588 ····when:·syscalls_found·|·length·==·0
1589 ··when:1589 ··when:
1590 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1591 ··-·'"audit"·in·ansible_facts.packages'1590 ··-·'"audit"·in·ansible_facts.packages'
 1591 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1592 ··tags:1592 ··tags:
1593 ··-·CJIS-5.4.1.11593 ··-·CJIS-5.4.1.1
1594 ··-·DISA-STIG-RHEL-07-0304101594 ··-·DISA-STIG-RHEL-07-030410
1595 ··-·NIST-800-171-3.1.71595 ··-·NIST-800-171-3.1.7
1596 ··-·NIST-800-53-AU-12(c)1596 ··-·NIST-800-53-AU-12(c)
1597 ··-·NIST-800-53-AU-2(d)1597 ··-·NIST-800-53-AU-2(d)
1598 ··-·NIST-800-53-CM-6(a)1598 ··-·NIST-800-53-CM-6(a)
Offset 1727, 16 lines modifiedOffset 1727, 16 lines modified
1727 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10001727 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
1728 ········-F·auid!=unset·-F·key=perm_mod1728 ········-F·auid!=unset·-F·key=perm_mod
1729 ······create:·true1729 ······create:·true
1730 ······mode:·o-rwx1730 ······mode:·o-rwx
1731 ······state:·present1731 ······state:·present
1732 ····when:·syscalls_found·|·length·==·01732 ····when:·syscalls_found·|·length·==·0
1733 ··when:1733 ··when:
1734 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1735 ··-·'"audit"·in·ansible_facts.packages'1734 ··-·'"audit"·in·ansible_facts.packages'
 1735 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1736 ··-·audit_arch·==·"b64"1736 ··-·audit_arch·==·"b64"
1737 ··tags:1737 ··tags:
1738 ··-·CJIS-5.4.1.11738 ··-·CJIS-5.4.1.1
1739 ··-·DISA-STIG-RHEL-07-0304101739 ··-·DISA-STIG-RHEL-07-030410
1740 ··-·NIST-800-171-3.1.71740 ··-·NIST-800-171-3.1.7
1741 ··-·NIST-800-53-AU-12(c)1741 ··-·NIST-800-53-AU-12(c)
1742 ··-·NIST-800-53-AU-2(d)1742 ··-·NIST-800-53-AU-2(d)
Offset 1760, 15 lines modifiedOffset 1760, 15 lines modified
1760 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.1760 Warning: ·Note·that·these·rules·can·be·configured·in·a·number·of·ways·while·still·achieving·the·desired·effect.·Here·the·system·calls·have·been·placed·independent·of·other·system·calls.·Grouping·these·system·calls·with·others·as·identifying·earlier·in·this·guide·is·more·efficient.
1761 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.1761 Rationale:·················The·changing·of·file·permissions·could·indicate·that·a·user·is·attempting·to·gain·access·to·information·that·would·otherwise·be·disallowed.·Auditing·DAC·modifications·can·facilitate·the·identification·of·patterns·of·abuse·among·both·authorized·and·unauthorized·users.
1762 Severity: ················medium1762 Severity: ················medium
1763 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown1763 Rule·ID:···················xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown
1764 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204517r809570_rule1764 Identifiers·and·References·References: ·1,·11,·12,·13,·14,·15,·16,·19,·2,·3,·4,·5,·6,·7,·8,·9,·5.4.1.1,·APO10.01,·APO10.03,·APO10.04,·APO10.05,·APO11.04,·APO12.06,·APO13.01,·BAI03.05,·BAI08.02,·DSS01.03,·DSS01.04,·DSS02.02,·DSS02.04,·DSS02.07,·DSS03.01,·DSS03.05,·DSS05.02,·DSS05.03,·DSS05.04,·DSS05.05,·DSS05.07,·MEA01.01,·MEA01.02,·MEA01.03,·MEA01.04,·MEA01.05,·MEA02.01,·3.1.7,·CCI-000126,·CCI-000130,·CCI-000135,·CCI-000169,·CCI-000172,·CCI-002884,·164.308(a)(1)(ii)(D),·164.308(a)(3)(ii)(A),·164.308(a)(5)(ii)(C),·164.312(a)(2)(i),·164.312(b),·164.312(d),·164.312(e),·4.2.3.10,·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.3.6.6,·4.3.4.4.7,·4.3.4.5.6,·4.3.4.5.7,·4.3.4.5.8,·4.4.2.1,·4.4.2.2,·4.4.2.4,·SR_1.13,·SR_2.10,·SR_2.11,·SR_2.12,·SR_2.6,·SR_2.8,·SR_2.9,·SR_3.1,·SR_3.5,·SR_3.8,·SR_4.1,·SR_4.3,·SR_5.1,·SR_5.2,·SR_5.3,·SR_6.1,·SR_6.2,·SR_7.1,·SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,·A.6.2.2,·AU-2(d),·AU-12(c),·CM-6(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·4.1.9,·SV-204517r809570_rule
1765 Remediation_Shell_script_⇲1765 Remediation_Shell_script_⇲
1766 #·Remediation·is·applicable·only·in·certain·platforms1766 #·Remediation·is·applicable·only·in·certain·platforms
1767 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then1767 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
  
1768 #·First·perform·the·remediation·of·the·syscall·rule1768 #·First·perform·the·remediation·of·the·syscall·rule
1769 #·Retrieve·hardware·architecture·of·the·underlying·system1769 #·Retrieve·hardware·architecture·of·the·underlying·system
1770 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")1770 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
1771 for·ARCH·in·"${RULE_ARCHS[@]}"1771 for·ARCH·in·"${RULE_ARCHS[@]}"
1772 do1772 do
Offset 2115, 16 lines modifiedOffset 2115, 16 lines modified
2115 ··-·reboot_required2115 ··-·reboot_required
2116 ··-·restrict_strategy2116 ··-·restrict_strategy
  
2117 -·name:·Set·architecture·for·audit·chown·tasks2117 -·name:·Set·architecture·for·audit·chown·tasks
2118 ··set_fact:2118 ··set_fact:
2119 ····audit_arch:·b642119 ····audit_arch:·b64
2120 ··when:2120 ··when:
2121 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2122 ··-·'"audit"·in·ansible_facts.packages'2121 ··-·'"audit"·in·ansible_facts.packages'
 2122 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2123 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2123 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2124 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2124 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2125 ··tags:2125 ··tags:
2126 ··-·CJIS-5.4.1.12126 ··-·CJIS-5.4.1.1
2127 ··-·DISA-STIG-RHEL-07-0303702127 ··-·DISA-STIG-RHEL-07-030370
2128 ··-·NIST-800-171-3.1.72128 ··-·NIST-800-171-3.1.7
2129 ··-·NIST-800-53-AU-12(c)2129 ··-·NIST-800-53-AU-12(c)
Offset 2263, 16 lines modifiedOffset 2263, 16 lines modified
2263 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002263 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2264 ········-F·auid!=unset·-F·key=perm_mod2264 ········-F·auid!=unset·-F·key=perm_mod
2265 ······create:·true2265 ······create:·true
2266 ······mode:·o-rwx2266 ······mode:·o-rwx
2267 ······state:·present2267 ······state:·present
2268 ····when:·syscalls_found·|·length·==·02268 ····when:·syscalls_found·|·length·==·0
2269 ··when:2269 ··when:
2270 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2271 ··-·'"audit"·in·ansible_facts.packages'2270 ··-·'"audit"·in·ansible_facts.packages'
 2271 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2272 ··tags:2272 ··tags:
2273 ··-·CJIS-5.4.1.12273 ··-·CJIS-5.4.1.1
2274 ··-·DISA-STIG-RHEL-07-0303702274 ··-·DISA-STIG-RHEL-07-030370
2275 ··-·NIST-800-171-3.1.72275 ··-·NIST-800-171-3.1.7
2276 ··-·NIST-800-53-AU-12(c)2276 ··-·NIST-800-53-AU-12(c)
2277 ··-·NIST-800-53-AU-2(d)2277 ··-·NIST-800-53-AU-2(d)
2278 ··-·NIST-800-53-CM-6(a)2278 ··-·NIST-800-53-CM-6(a)
Offset 2409, 16 lines modifiedOffset 2409, 16 lines modified
2409 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002409 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2410 ········-F·auid!=unset·-F·key=perm_mod2410 ········-F·auid!=unset·-F·key=perm_mod
2411 ······create:·true2411 ······create:·true
2412 ······mode:·o-rwx2412 ······mode:·o-rwx
2413 ······state:·present2413 ······state:·present
Max diff block lines reached; 149334/158313 bytes (94.33%) of diff not shown.
10.5 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis.html
    
Offset 266818, 73 lines modifiedOffset 266818, 73 lines modified
00412410:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00412410:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00412420:·3d22·2369·646d·3531·3937·3522·2074·6162··="#idm51975"·tab00412420:·3d22·2369·646d·3531·3937·3522·2074·6162··="#idm51975"·tab
00412430:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00412430:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00412440:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00412440:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00412450:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00412450:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00412460:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00412460:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00412470:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00412470:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00412480:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00412480:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
00412490:·6e61·636f·6e64·6120·736e·6970·7065·7420··naconda·snippet·00412490:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
004124a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·004124a0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
004124b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col004124b0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
004124c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·004124c0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
004124d0:·6964·3d22·6964·6d35·3139·3735·223e·3c70··id="idm51975"><p004124d0:·6964·6d35·3139·3735·223e·3c74·6162·6c65··idm51975"><table
004124e0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag 
004124f0:·6520·2d2d·7265·6d6f·7665·3d78·6f72·672d··e·--remove=xorg-004124e0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 004124f0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00412500:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00412510:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00412520:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00412530:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00412540:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00412550:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00412560:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00412570:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00412580:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td><
 00412590:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 004125a0:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
 004125b0:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
 004125c0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 004125d0:·6465·3e0a·0a23·2072·656d·6f76·6520·7061··de>..#·remove·pa
 004125e0:·636b·6167·6573·0a7a·7970·7065·7220·7265··ckages.zypper·re
 004125f0:·6d6f·7665·202d·7920·2278·6f72·672d·7831··move·-y·"xorg-x1
00412500:·7831·312d·7365·7276·6572·2d58·6f72·6720··x11-server-Xorg·00412600:·312d·7365·7276·6572·2d58·6f72·6722·0a7a··1-server-Xorg".z
 00412610:·7970·7065·7220·7265·6d6f·7665·202d·7920··ypper·remove·-y·
 00412620:·2278·6f72·672d·7831·312d·7365·7276·6572··"xorg-x11-server
 00412630:·2d75·7469·6c73·220a·7a79·7070·6572·2072··-utils".zypper·r
00412510:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1 
00412520:·312d·7365·7276·6572·2d63·6f6d·6d6f·6e20··1-server-common· 
00412530:·2d2d·7265·6d6f·7665·3d78·6f72·672d·7831··--remove=xorg-x1 
00412540:·312d·7365·7276·6572·2d75·7469·6c73·202d··1-server-utils·- 
00412550:·2d72·656d·6f76·653d·786f·7267·2d78·3131··-remove=xorg-x11 
00412560:·2d73·6572·7665·722d·5877·6179·6c61·6e64··-server-Xwayland 
00412570:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
00412580:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
00412590:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
004125a0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
004125b0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
004125c0:·743d·2223·6964·6d35·3139·3736·2220·7461··t="#idm51976"·ta 
004125d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
004125e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
004125f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00412600:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00412610:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00412620:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00412630:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
00412640:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00412650:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00412660:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00412670:·2269·646d·3531·3937·3622·3e3c·7461·626c··"idm51976"><tabl 
00412680:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00412690:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
004126a0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
004126b0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
004126c0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
004126d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
004126e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
004126f0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00412700:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00412710:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00412720:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td> 
00412730:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
00412740:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r 
00412750:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr 
00412760:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
00412770:·6f64·653e·0a0a·2320·7265·6d6f·7665·2070··ode>..#·remove·p 
00412780:·6163·6b61·6765·730a·7a79·7070·6572·2072··ackages.zypper·r 
00412790:·656d·6f76·6520·2d79·2022·786f·7267·2d78··emove·-y·"xorg-x00412640:·656d·6f76·6520·2d79·2022·786f·7267·2d78··emove·-y·"xorg-x
 00412650:·3131·2d73·6572·7665·722d·636f·6d6d·6f6e··11-server-common
 00412660:·220a·0a7a·7970·7065·7220·7265·6d6f·7665··"..zypper·remove
 00412670:·202d·7920·2278·6f72·672d·7831·312d·7365···-y·"xorg-x11-se
 00412680:·7276·6572·2d58·7761·796c·616e·6422·0a3c··rver-Xwayland".<
 00412690:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 004126a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 004126b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 004126c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 004126d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 004126e0:·2223·6964·6d35·3139·3736·2220·7461·6269··"#idm51976"·tabi
 004126f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 00412700:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 00412710:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 00412720:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 00412730:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 00412740:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
 00412750:·6163·6f6e·6461·2073·6e69·7070·6574·20e2··aconda·snippet·.
 00412760:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00412770:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00412780:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00412790:·643d·2269·646d·3531·3937·3622·3e3c·7072··d="idm51976"><pr
 004127a0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 004127b0:·202d·2d72·656d·6f76·653d·786f·7267·2d78···--remove=xorg-x
004127a0:·3131·2d73·6572·7665·722d·586f·7267·220a··11-server-Xorg".004127c0:·3131·2d73·6572·7665·722d·586f·7267·202d··11-server-Xorg·-
 004127d0:·2d72·656d·6f76·653d·786f·7267·2d78·3131··-remove=xorg-x11
 004127e0:·2d73·6572·7665·722d·636f·6d6d·6f6e·202d··-server-common·-
 004127f0:·2d72·656d·6f76·653d·786f·7267·2d78·3131··-remove=xorg-x11
 00412800:·2d73·6572·7665·722d·7574·696c·7320·2d2d··-server-utils·--
 00412810:·7265·6d6f·7665·3d78·6f72·672d·7831·312d··remove=xorg-x11-
 00412820:·7365·7276·6572·2d58·7761·796c·616e·640a··server-Xwayland.
004127b0:·7a79·7070·6572·2072·656d·6f76·6520·2d79··zypper·remove·-y 
004127c0:·2022·786f·7267·2d78·3131·2d73·6572·7665···"xorg-x11-serve 
004127d0:·722d·7574·696c·7322·0a7a·7970·7065·7220··r-utils".zypper· 
004127e0:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg- 
004127f0:·7831·312d·7365·7276·6572·2d63·6f6d·6d6f··x11-server-commo 
00412800:·6e22·0a0a·7a79·7070·6572·2072·656d·6f76··n"..zypper·remov 
00412810:·6520·2d79·2022·786f·7267·2d78·3131·2d73··e·-y·"xorg-x11-s 
00412820:·6572·7665·722d·5877·6179·6c61·6e64·220a··erver-Xwayland". 
00412830:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00412830:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
00412840:·6976·3e3c·2f64·6976·3e3c·2f74·643e·3c2f··iv></div></td></00412840:·6976·3e3c·2f64·6976·3e3c·2f74·643e·3c2f··iv></div></td></
00412850:·7472·3e3c·2f74·626f·6479·3e3c·2f74·6162··tr></tbody></tab00412850:·7472·3e3c·2f74·626f·6479·3e3c·2f74·6162··tr></tbody></tab
00412860:·6c65·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··le></td></tr></t00412860:·6c65·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··le></td></tr></t
00412870:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f64··body></table></d00412870:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f64··body></table></d
00412880:·6976·3e3c·6469·7620·6964·3d22·7265·6172··iv><div·id="rear00412880:·6976·3e3c·6469·7620·6964·3d22·7265·6172··iv><div·id="rear
00412890:·2d6d·6174·7465·7222·3e3c·6469·7620·636c··-matter"><div·cl00412890:·2d6d·6174·7465·7222·3e3c·6469·7620·636c··-matter"><div·cl
1.46 KB
html2text {}
    
Offset 51466, 28 lines modifiedOffset 51466, 28 lines modified
51466 ···························Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack51466 ···························Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack
51467 Rationale:·················surface·of·the·system.·X·windows·has·a·long·history·of·security51467 Rationale:·················surface·of·the·system.·X·windows·has·a·long·history·of·security
51468 ···························vulnerabilities·and·should·not·be·installed·unless·approved·and51468 ···························vulnerabilities·and·should·not·be·installed·unless·approved·and
51469 ···························documented.51469 ···························documented.
51470 Severity: ················medium51470 Severity: ················medium
51471 Rule·ID:···················xccdf_org.ssgproject.content_rule_xwindows_remove_packages51471 Rule·ID:···················xccdf_org.ssgproject.content_rule_xwindows_remove_packages
51472 Identifiers·and·References·References: ·CCI-000366,·CM-6(b),·SRG-OS-000480-GPOS-00227,·2.2.251472 Identifiers·and·References·References: ·CCI-000366,·CM-6(b),·SRG-OS-000480-GPOS-00227,·2.2.2
51473 Remediation_Anaconda_snippet_⇲ 
  
51474 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils 
51475 --remove=xorg-x11-server-Xwayland 
51476 Remediation_Shell_script_⇲51473 Remediation_Shell_script_⇲
51477 Complexity:·low51474 Complexity:·low
51478 Disruption:·low51475 Disruption:·low
51479 Reboot:·····true51476 Reboot:·····true
51480 Strategy:···restrict51477 Strategy:···restrict
  
  
51481 #·remove·packages51478 #·remove·packages
51482 zypper·remove·-y·"xorg-x11-server-Xorg"51479 zypper·remove·-y·"xorg-x11-server-Xorg"
51483 zypper·remove·-y·"xorg-x11-server-utils"51480 zypper·remove·-y·"xorg-x11-server-utils"
51484 zypper·remove·-y·"xorg-x11-server-common"51481 zypper·remove·-y·"xorg-x11-server-common"
  
51485 zypper·remove·-y·"xorg-x11-server-Xwayland"51482 zypper·remove·-y·"xorg-x11-server-Xwayland"
 51483 Remediation_Anaconda_snippet_⇲
  
 51484 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils
 51485 --remove=xorg-x11-server-Xwayland
51486 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or51486 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or
51487 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other51487 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other
51488 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.51488 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.
51489 Generated·using·OpenSCAP·1.3.751489 Generated·using·OpenSCAP·1.3.7
10.5 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis_server_l1.html
    
Offset 143605, 73 lines modifiedOffset 143605, 73 lines modified
00230f40:·7461·7267·6574·3d22·2369·646d·3531·3937··target="#idm519700230f40:·7461·7267·6574·3d22·2369·646d·3531·3937··target="#idm5197
00230f50:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·00230f50:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"·
00230f60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar00230f60:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
00230f70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal00230f70:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
00230f80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ00230f80:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
00230f90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h00230f90:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00230fa0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00230fa0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00230fb0:·7469·6f6e·2041·6e61·636f·6e64·6120·736e··tion·Anaconda·sn00230fb0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
00230fc0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br00230fc0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
00230fd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00230fd0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00230fe0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00230fe0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
00230ff0:·6170·7365·2220·6964·3d22·6964·6d35·3139··apse"·id="idm51900230ff0:·2220·6964·3d22·6964·6d35·3139·3735·223e··"·id="idm51975">
00231000:·3735·223e·3c70·7265·3e3c·636f·6465·3e0a··75"><pre><code>. 
00231010:·7061·636b·6167·6520·2d2d·7265·6d6f·7665··package·--remove 
00231020:·3d78·6f72·672d·7831·312d·7365·7276·6572··=xorg-x11-server 
00231030:·2d58·6f72·6720·2d2d·7265·6d6f·7665·3d78··-Xorg·--remove=x 
00231040:·6f72·672d·7831·312d·7365·7276·6572·2d63··org-x11-server-c 
00231050:·6f6d·6d6f·6e20·2d2d·7265·6d6f·7665·3d78··ommon·--remove=x00231000:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 00231010:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 00231020:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 00231030:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 00231040:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 00231050:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 00231060:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00231070:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 00231080:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00231090:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 002310a0:·6f74·3a3c·2f74·683e·3c74·643e·7472·7565··ot:</th><td>true
 002310b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 002310c0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 002310d0:·3c74·643e·7265·7374·7269·6374·3c2f·7464··<td>restrict</td
 002310e0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 002310f0:·7265·3e3c·636f·6465·3e0a·0a23·2072·656d··re><code>..#·rem
 00231100:·6f76·6520·7061·636b·6167·6573·0a7a·7970··ove·packages.zyp
 00231110:·7065·7220·7265·6d6f·7665·202d·7920·2278··per·remove·-y·"x
00231060:·6f72·672d·7831·312d·7365·7276·6572·2d75··org-x11-server-u00231120:·6f72·672d·7831·312d·7365·7276·6572·2d58··org-x11-server-X
 00231130:·6f72·6722·0a7a·7970·7065·7220·7265·6d6f··org".zypper·remo
 00231140:·7665·202d·7920·2278·6f72·672d·7831·312d··ve·-y·"xorg-x11-
 00231150:·7365·7276·6572·2d75·7469·6c73·220a·7a79··server-utils".zy
00231070:·7469·6c73·202d·2d72·656d·6f76·653d·786f··tils·--remove=xo 
00231080:·7267·2d78·3131·2d73·6572·7665·722d·5877··rg-x11-server-Xw 
00231090:·6179·6c61·6e64·0a3c·2f63·6f64·653e·3c2f··ayland.</code></ 
002310a0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
002310b0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
002310c0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
002310d0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
002310e0:·2d74·6172·6765·743d·2223·6964·6d35·3139··-target="#idm519 
002310f0:·3736·2220·7461·6269·6e64·6578·3d22·3022··76"·tabindex="0" 
00231100:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00231110:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00231120:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00231130:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
00231140:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
00231150:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
00231160:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
00231170:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
00231180:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
00231190:·6522·2069·643d·2269·646d·3531·3937·3622··e"·id="idm51976" 
002311a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
002311b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
002311c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
002311d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
002311e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
002311f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00231200:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00231210:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00231220:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00231230:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00231240:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru 
00231250:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00231260:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00231270:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t 
00231280:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
00231290:·7072·653e·3c63·6f64·653e·0a0a·2320·7265··pre><code>..#·re 
002312a0:·6d6f·7665·2070·6163·6b61·6765·730a·7a79··move·packages.zy 
002312b0:·7070·6572·2072·656d·6f76·6520·2d79·2022··pper·remove·-y·"00231160:·7070·6572·2072·656d·6f76·6520·2d79·2022··pper·remove·-y·"
 00231170:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server-
 00231180:·636f·6d6d·6f6e·220a·0a7a·7970·7065·7220··common"..zypper·
 00231190:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg-
 002311a0:·7831·312d·7365·7276·6572·2d58·7761·796c··x11-server-Xwayl
 002311b0:·616e·6422·0a3c·2f63·6f64·653e·3c2f·7072··and".</code></pr
 002311c0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 002311d0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 002311e0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 002311f0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00231200:·6172·6765·743d·2223·6964·6d35·3139·3736··arget="#idm51976
 00231210:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 00231220:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 00231230:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 00231240:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 00231250:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 00231260:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00231270:·696f·6e20·416e·6163·6f6e·6461·2073·6e69··ion·Anaconda·sni
 00231280:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 00231290:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 002312a0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 002312b0:·7073·6522·2069·643d·2269·646d·3531·3937··pse"·id="idm5197
 002312c0:·3622·3e3c·7072·653e·3c63·6f64·653e·0a70··6"><pre><code>.p
 002312d0:·6163·6b61·6765·202d·2d72·656d·6f76·653d··ackage·--remove=
002312c0:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server-002312e0:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server-
 002312f0:·586f·7267·202d·2d72·656d·6f76·653d·786f··Xorg·--remove=xo
 00231300:·7267·2d78·3131·2d73·6572·7665·722d·636f··rg-x11-server-co
 00231310:·6d6d·6f6e·202d·2d72·656d·6f76·653d·786f··mmon·--remove=xo
002312d0:·586f·7267·220a·7a79·7070·6572·2072·656d··Xorg".zypper·rem 
002312e0:·6f76·6520·2d79·2022·786f·7267·2d78·3131··ove·-y·"xorg-x11 
002312f0:·2d73·6572·7665·722d·7574·696c·7322·0a7a··-server-utils".z 
00231300:·7970·7065·7220·7265·6d6f·7665·202d·7920··ypper·remove·-y· 
00231310:·2278·6f72·672d·7831·312d·7365·7276·6572··"xorg-x11-server 
00231320:·2d63·6f6d·6d6f·6e22·0a0a·7a79·7070·6572··-common"..zypper 
00231330:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg 
00231340:·2d78·3131·2d73·6572·7665·722d·5877·6179··-x11-server-Xway00231320:·7267·2d78·3131·2d73·6572·7665·722d·7574··rg-x11-server-ut
 00231330:·696c·7320·2d2d·7265·6d6f·7665·3d78·6f72··ils·--remove=xor
 00231340:·672d·7831·312d·7365·7276·6572·2d58·7761··g-x11-server-Xwa
00231350:·6c61·6e64·220a·3c2f·636f·6465·3e3c·2f70··land".</code></p00231350:·796c·616e·640a·3c2f·636f·6465·3e3c·2f70··yland.</code></p
00231360:·7265·3e3c·2f64·6976·3e3c·2f64·6976·3e3c··re></div></div><00231360:·7265·3e3c·2f64·6976·3e3c·2f64·6976·3e3c··re></div></div><
00231370:·2f74·643e·3c2f·7472·3e3c·2f74·626f·6479··/td></tr></tbody00231370:·2f74·643e·3c2f·7472·3e3c·2f74·626f·6479··/td></tr></tbody
00231380:·3e3c·2f74·6162·6c65·3e3c·2f74·643e·3c2f··></table></td></00231380:·3e3c·2f74·6162·6c65·3e3c·2f74·643e·3c2f··></table></td></
00231390:·7472·3e3c·2f74·626f·6479·3e3c·2f74·6162··tr></tbody></tab00231390:·7472·3e3c·2f74·626f·6479·3e3c·2f74·6162··tr></tbody></tab
002313a0:·6c65·3e3c·2f64·6976·3e3c·6469·7620·6964··le></div><div·id002313a0:·6c65·3e3c·2f64·6976·3e3c·6469·7620·6964··le></div><div·id
002313b0:·3d22·7265·6172·2d6d·6174·7465·7222·3e3c··="rear-matter"><002313b0:·3d22·7265·6172·2d6d·6174·7465·7222·3e3c··="rear-matter"><
002313c0:·6469·7620·636c·6173·733d·2272·6f77·2074··div·class="row·t002313c0:·6469·7620·636c·6173·733d·2272·6f77·2074··div·class="row·t
1.46 KB
html2text {}
    
Offset 18590, 28 lines modifiedOffset 18590, 28 lines modified
18590 ···························Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack18590 ···························Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack
18591 Rationale:·················surface·of·the·system.·X·windows·has·a·long·history·of·security18591 Rationale:·················surface·of·the·system.·X·windows·has·a·long·history·of·security
18592 ···························vulnerabilities·and·should·not·be·installed·unless·approved·and18592 ···························vulnerabilities·and·should·not·be·installed·unless·approved·and
18593 ···························documented.18593 ···························documented.
18594 Severity: ················medium18594 Severity: ················medium
18595 Rule·ID:···················xccdf_org.ssgproject.content_rule_xwindows_remove_packages18595 Rule·ID:···················xccdf_org.ssgproject.content_rule_xwindows_remove_packages
18596 Identifiers·and·References·References: ·CCI-000366,·CM-6(b),·SRG-OS-000480-GPOS-00227,·2.2.218596 Identifiers·and·References·References: ·CCI-000366,·CM-6(b),·SRG-OS-000480-GPOS-00227,·2.2.2
18597 Remediation_Anaconda_snippet_⇲ 
  
18598 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils 
18599 --remove=xorg-x11-server-Xwayland 
18600 Remediation_Shell_script_⇲18597 Remediation_Shell_script_⇲
18601 Complexity:·low18598 Complexity:·low
18602 Disruption:·low18599 Disruption:·low
18603 Reboot:·····true18600 Reboot:·····true
18604 Strategy:···restrict18601 Strategy:···restrict
  
  
18605 #·remove·packages18602 #·remove·packages
18606 zypper·remove·-y·"xorg-x11-server-Xorg"18603 zypper·remove·-y·"xorg-x11-server-Xorg"
18607 zypper·remove·-y·"xorg-x11-server-utils"18604 zypper·remove·-y·"xorg-x11-server-utils"
18608 zypper·remove·-y·"xorg-x11-server-common"18605 zypper·remove·-y·"xorg-x11-server-common"
  
18609 zypper·remove·-y·"xorg-x11-server-Xwayland"18606 zypper·remove·-y·"xorg-x11-server-Xwayland"
 18607 Remediation_Anaconda_snippet_⇲
  
 18608 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils
 18609 --remove=xorg-x11-server-Xwayland
18610 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or18610 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or
18611 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other18611 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other
18612 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.18612 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.
18613 Generated·using·OpenSCAP·1.3.718613 Generated·using·OpenSCAP·1.3.7
5.7 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_enhanced.html
    
Offset 57197, 21 lines modifiedOffset 57197, 21 lines modified
000df6c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan000df6c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
000df6d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll000df6d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
000df6e0:·6170·7365·2220·6964·3d22·6964·6d32·3830··apse"·id="idm280000df6e0:·6170·7365·2220·6964·3d22·6964·6d32·3830··apse"·id="idm280
000df6f0:·3738·223e·3c70·7265·3e3c·636f·6465·3e23··78"><pre><code>#000df6f0:·3738·223e·3c70·7265·3e3c·636f·6465·3e23··78"><pre><code>#
000df700:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·000df700:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
000df710:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·000df710:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
000df720:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf000df720:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
000df730:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu000df730:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
000df740:·6965·7420·2d71·2061·7564·6974·2026·616d··iet·-q·audit·&am000df740:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
000df750:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/000df750:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
000df760:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
000df770:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
000df780:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren000df760:·7275·6e2f·2e63·6f6e·7461·696e·6572·656e··run/.containeren
 000df770:·7620·5d20·2661·6d70·3b26·616d·703b·2072··v·]·&amp;&amp;·r
 000df780:·706d·202d·2d71·7569·6574·202d·7120·6175··pm·--quiet·-q·au
000df790:·7620·5d3b·2074·6865·6e0a·0a41·4354·494f··v·];·then..ACTIO000df790:·6469·743b·2074·6865·6e0a·0a41·4354·494f··dit;·then..ACTIO
000df7a0:·4e5f·4152·4348·5f46·494c·5445·5253·3d22··N_ARCH_FILTERS="000df7a0:·4e5f·4152·4348·5f46·494c·5445·5253·3d22··N_ARCH_FILTERS="
000df7b0:·2d61·2061·6c77·6179·732c·6578·6974·220a··-a·always,exit".000df7b0:·2d61·2061·6c77·6179·732c·6578·6974·220a··-a·always,exit".
000df7c0:·4f54·4845·525f·4649·4c54·4552·533d·222d··OTHER_FILTERS="-000df7c0:·4f54·4845·525f·4649·4c54·4552·533d·222d··OTHER_FILTERS="-
000df7d0:·4620·7061·7468·3d2f·7573·722f·6269·6e2f··F·path=/usr/bin/000df7d0:·4620·7061·7468·3d2f·7573·722f·6269·6e2f··F·path=/usr/bin/
000df7e0:·7375·646f·202d·4620·7065·726d·3d78·220a··sudo·-F·perm=x".000df7e0:·7375·646f·202d·4620·7065·726d·3d78·220a··sudo·-F·perm=x".
000df7f0:·4155·4944·5f46·494c·5445·5253·3d22·2d46··AUID_FILTERS="-F000df7f0:·4155·4944·5f46·494c·5445·5253·3d22·2d46··AUID_FILTERS="-F
000df800:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-000df800:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-
Offset 58350, 23 lines modifiedOffset 58350, 23 lines modified
000e3ed0:·206b·6579·3d70·7269·7669·6c65·6765·640a···key=privileged.000e3ed0:·206b·6579·3d70·7269·7669·6c65·6765·640a···key=privileged.
000e3ee0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr000e3ee0:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr
000e3ef0:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o000e3ef0:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o
000e3f00:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state000e3f00:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state
000e3f10:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh000e3f10:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh
000e3f20:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou000e3f20:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou
000e3f30:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0000e3f30:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0
000e3f40:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a000e3f40:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans
000e3f50:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
000e3f60:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
000e3f70:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
000e3f80:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
000e3f90:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
000e3fa0:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
000e3fb0:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
000e3fc0:·6f6e·7461·696e·6572·225d·0a20·2074·6167··ontainer"].··tag000e3f50:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 000e3f60:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 000e3f70:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 000e3f80:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 000e3f90:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
 000e3fa0:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"·
 000e3fb0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000e3fc0:·2e70·6163·6b61·6765·7327·0a20·2074·6167··.packages'.··tag
000e3fd0:·733a·0a20·202d·2043·4345·2d38·3536·3033··s:.··-·CCE-85603000e3fd0:·733a·0a20·202d·2043·4345·2d38·3536·3033··s:.··-·CCE-85603
000e3fe0:·2d39·0a20·202d·2044·4953·412d·5354·4947··-9.··-·DISA-STIG000e3fe0:·2d39·0a20·202d·2044·4953·412d·5354·4947··-9.··-·DISA-STIG
000e3ff0:·2d53·4c45·532d·3135·2d30·3330·3536·300a··-SLES-15-030560.000e3ff0:·2d53·4c45·532d·3135·2d30·3330·3536·300a··-SLES-15-030560.
000e4000:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171000e4000:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
000e4010:·2d33·2e31·2e37·0a20·202d·204e·4953·542d··-3.1.7.··-·NIST-000e4010:·2d33·2e31·2e37·0a20·202d·204e·4953·542d··-3.1.7.··-·NIST-
000e4020:·3830·302d·3533·2d41·432d·3628·3929·0a20··800-53-AC-6(9).·000e4020:·3830·302d·3533·2d41·432d·3628·3929·0a20··800-53-AC-6(9).·
000e4030:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A000e4030:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A
1.54 KB
html2text {}
    
Offset 9292, 15 lines modifiedOffset 9292, 15 lines modified
9292 ············A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),9292 ············A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
9293 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,9293 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,
9294 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-9294 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-
9295 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·SLES-15-9295 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·SLES-15-
9296 ············030560,·SV-234955r622137_rule9296 ············030560,·SV-234955r622137_rule
9297 Remediation_Shell_script_⇲9297 Remediation_Shell_script_⇲
9298 #·Remediation·is·applicable·only·in·certain·platforms9298 #·Remediation·is·applicable·only·in·certain·platforms
9299 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9299 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
9300 ACTION_ARCH_FILTERS="-a·always,exit"9300 ACTION_ARCH_FILTERS="-a·always,exit"
9301 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"9301 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
9302 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"9302 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
9303 SYSCALL=""9303 SYSCALL=""
9304 KEY="privileged"9304 KEY="privileged"
9305 SYSCALL_GROUPING=""9305 SYSCALL_GROUPING=""
Offset 9762, 16 lines modifiedOffset 9762, 16 lines modified
9762 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x9762 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
9763 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged9763 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
9764 ······create:·true9764 ······create:·true
9765 ······mode:·o-rwx9765 ······mode:·o-rwx
9766 ······state:·present9766 ······state:·present
9767 ····when:·syscalls_found·|·length·==·09767 ····when:·syscalls_found·|·length·==·0
9768 ··when:9768 ··when:
9769 ··-·'"audit"·in·ansible_facts.packages' 
9770 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]9769 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 9770 ··-·'"audit"·in·ansible_facts.packages'
9771 ··tags:9771 ··tags:
9772 ··-·CCE-85603-99772 ··-·CCE-85603-9
9773 ··-·DISA-STIG-SLES-15-0305609773 ··-·DISA-STIG-SLES-15-030560
9774 ··-·NIST-800-171-3.1.79774 ··-·NIST-800-171-3.1.7
9775 ··-·NIST-800-53-AC-6(9)9775 ··-·NIST-800-53-AC-6(9)
9776 ··-·NIST-800-53-AU-12(c)9776 ··-·NIST-800-53-AU-12(c)
9777 ··-·NIST-800-53-AU-2(d)9777 ··-·NIST-800-53-AU-2(d)
5.76 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_high.html
    
Offset 59597, 21 lines modifiedOffset 59597, 21 lines modified
000e8cc0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel000e8cc0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
000e8cd0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap000e8cd0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
000e8ce0:·7365·2220·6964·3d22·6964·6d32·3830·3738··se"·id="idm28078000e8ce0:·7365·2220·6964·3d22·6964·6d32·3830·3738··se"·id="idm28078
000e8cf0:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R000e8cf0:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R
000e8d00:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap000e8d00:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
000e8d10:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in000e8d10:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
000e8d20:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor000e8d20:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
000e8d30:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
000e8d40:·7420·2d71·2061·7564·6974·2026·616d·703b··t·-q·audit·&amp; 
000e8d50:·2661·6d70·3b20·5b20·2120·2d66·202f·2e64··&amp;·[·!·-f·/.d000e8d30:·6d73·0a69·6620·5b20·2120·2d66·202f·2e64··ms.if·[·!·-f·/.d
000e8d60:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;000e8d40:·6f63·6b65·7265·6e76·205d·2026·616d·703b··ockerenv·]·&amp;
000e8d70:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru000e8d50:·2661·6d70·3b20·5b20·2120·2d66·202f·7275··&amp;·[·!·-f·/ru
000e8d80:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·000e8d60:·6e2f·2e63·6f6e·7461·696e·6572·656e·7620··n/.containerenv·
 000e8d70:·5d20·2661·6d70·3b26·616d·703b·2072·706d··]·&amp;&amp;·rpm
 000e8d80:·202d·2d71·7569·6574·202d·7120·6175·6469···--quiet·-q·audi
000e8d90:·5d3b·2074·6865·6e0a·0a41·4354·494f·4e5f··];·then..ACTION_000e8d90:·743b·2074·6865·6e0a·0a41·4354·494f·4e5f··t;·then..ACTION_
000e8da0:·4152·4348·5f46·494c·5445·5253·3d22·2d61··ARCH_FILTERS="-a000e8da0:·4152·4348·5f46·494c·5445·5253·3d22·2d61··ARCH_FILTERS="-a
000e8db0:·2061·6c77·6179·732c·6578·6974·220a·4f54···always,exit".OT000e8db0:·2061·6c77·6179·732c·6578·6974·220a·4f54···always,exit".OT
000e8dc0:·4845·525f·4649·4c54·4552·533d·222d·4620··HER_FILTERS="-F·000e8dc0:·4845·525f·4649·4c54·4552·533d·222d·4620··HER_FILTERS="-F·
000e8dd0:·7061·7468·3d2f·7573·722f·6269·6e2f·7375··path=/usr/bin/su000e8dd0:·7061·7468·3d2f·7573·722f·6269·6e2f·7375··path=/usr/bin/su
000e8de0:·646f·202d·4620·7065·726d·3d78·220a·4155··do·-F·perm=x".AU000e8de0:·646f·202d·4620·7065·726d·3d78·220a·4155··do·-F·perm=x".AU
000e8df0:·4944·5f46·494c·5445·5253·3d22·2d46·2061··ID_FILTERS="-F·a000e8df0:·4944·5f46·494c·5445·5253·3d22·2d46·2061··ID_FILTERS="-F·a
000e8e00:·7569·6426·6774·3b3d·3130·3030·202d·4620··uid&gt;=1000·-F·000e8e00:·7569·6426·6774·3b3d·3130·3030·202d·4620··uid&gt;=1000·-F·
Offset 60750, 23 lines modifiedOffset 60750, 23 lines modified
000ed4d0:·6579·3d70·7269·7669·6c65·6765·640a·2020··ey=privileged.··000ed4d0:·6579·3d70·7269·7669·6c65·6765·640a·2020··ey=privileged.··
000ed4e0:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true000ed4e0:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true
000ed4f0:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r000ed4f0:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r
000ed500:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·000ed500:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·
000ed510:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when000ed510:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when
000ed520:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found000ed520:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found
000ed530:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·000ed530:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·
000ed540:·2077·6865·6e3a·0a20·202d·2027·2261·7564···when:.··-·'"aud000ed540:·2077·6865·6e3a·0a20·202d·2061·6e73·6962···when:.··-·ansib
000ed550:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f 
000ed560:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
000ed570:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu 
000ed580:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
000ed590:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
000ed5a0:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
000ed5b0:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
000ed5c0:·7461·696e·6572·225d·0a20·2074·6167·733a··tainer"].··tags:000ed550:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 000ed560:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 000ed570:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 000ed580:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 000ed590:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
 000ed5a0:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 000ed5b0:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 000ed5c0:·6163·6b61·6765·7327·0a20·2074·6167·733a··ackages'.··tags:
000ed5d0:·0a20·202d·2043·4345·2d38·3536·3033·2d39··.··-·CCE-85603-9000ed5d0:·0a20·202d·2043·4345·2d38·3536·3033·2d39··.··-·CCE-85603-9
000ed5e0:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S000ed5e0:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
000ed5f0:·4c45·532d·3135·2d30·3330·3536·300a·2020··LES-15-030560.··000ed5f0:·4c45·532d·3135·2d30·3330·3536·300a·2020··LES-15-030560.··
000ed600:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3000ed600:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
000ed610:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80000ed610:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80
000ed620:·302d·3533·2d41·432d·3628·3929·0a20·202d··0-53-AC-6(9).··-000ed620:·302d·3533·2d41·432d·3628·3929·0a20·202d··0-53-AC-6(9).··-
000ed630:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-000ed630:·204e·4953·542d·3830·302d·3533·2d41·552d···NIST-800-53-AU-
1.54 KB
html2text {}
    
Offset 9763, 15 lines modifiedOffset 9763, 15 lines modified
9763 ············A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),9763 ············A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
9764 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,9764 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,
9765 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-9765 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-
9766 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·SLES-15-9766 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·SLES-15-
9767 ············030560,·SV-234955r622137_rule9767 ············030560,·SV-234955r622137_rule
9768 Remediation_Shell_script_⇲9768 Remediation_Shell_script_⇲
9769 #·Remediation·is·applicable·only·in·certain·platforms9769 #·Remediation·is·applicable·only·in·certain·platforms
9770 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9770 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
9771 ACTION_ARCH_FILTERS="-a·always,exit"9771 ACTION_ARCH_FILTERS="-a·always,exit"
9772 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"9772 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
9773 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"9773 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
9774 SYSCALL=""9774 SYSCALL=""
9775 KEY="privileged"9775 KEY="privileged"
9776 SYSCALL_GROUPING=""9776 SYSCALL_GROUPING=""
Offset 10233, 16 lines modifiedOffset 10233, 16 lines modified
10233 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x10233 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
10234 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged10234 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
10235 ······create:·true10235 ······create:·true
10236 ······mode:·o-rwx10236 ······mode:·o-rwx
10237 ······state:·present10237 ······state:·present
10238 ····when:·syscalls_found·|·length·==·010238 ····when:·syscalls_found·|·length·==·0
10239 ··when:10239 ··when:
10240 ··-·'"audit"·in·ansible_facts.packages' 
10241 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]10240 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 10241 ··-·'"audit"·in·ansible_facts.packages'
10242 ··tags:10242 ··tags:
10243 ··-·CCE-85603-910243 ··-·CCE-85603-9
10244 ··-·DISA-STIG-SLES-15-03056010244 ··-·DISA-STIG-SLES-15-030560
10245 ··-·NIST-800-171-3.1.710245 ··-·NIST-800-171-3.1.7
10246 ··-·NIST-800-53-AC-6(9)10246 ··-·NIST-800-53-AC-6(9)
10247 ··-·NIST-800-53-AU-12(c)10247 ··-·NIST-800-53-AU-12(c)
10248 ··-·NIST-800-53-AU-2(d)10248 ··-·NIST-800-53-AU-2(d)
5.64 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_intermediary.html
    
Offset 54581, 20 lines modifiedOffset 54581, 20 lines modified
000d5340:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000d5340:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
000d5350:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·000d5350:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
000d5360:·6964·3d22·6964·6d32·3830·3738·223e·3c70··id="idm28078"><p000d5360:·6964·3d22·6964·6d32·3830·3738·223e·3c70··id="idm28078"><p
000d5370:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed000d5370:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
000d5380:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic000d5380:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
000d5390:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer000d5390:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
000d53a0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i000d53a0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
000d53b0:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
000d53c0:·2061·7564·6974·2026·616d·703b·2661·6d70···audit·&amp;&amp 
000d53d0:·3b20·5b20·2120·2d66·202f·2e64·6f63·6b65··;·[·!·-f·/.docke000d53b0:·6620·5b20·2120·2d66·202f·2e64·6f63·6b65··f·[·!·-f·/.docke
000d53e0:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp000d53c0:·7265·6e76·205d·2026·616d·703b·2661·6d70··renv·]·&amp;&amp
000d53f0:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c000d53d0:·3b20·5b20·2120·2d66·202f·7275·6e2f·2e63··;·[·!·-f·/run/.c
000d5400:·6f6e·7461·696e·6572·656e·7620·5d3b·2074··ontainerenv·];·t000d53e0:·6f6e·7461·696e·6572·656e·7620·5d20·2661··ontainerenv·]·&a
 000d53f0:·6d70·3b26·616d·703b·2072·706d·202d·2d71··mp;&amp;·rpm·--q
 000d5400:·7569·6574·202d·7120·6175·6469·743b·2074··uiet·-q·audit;·t
000d5410:·6865·6e0a·0a41·4354·494f·4e5f·4152·4348··hen..ACTION_ARCH000d5410:·6865·6e0a·0a41·4354·494f·4e5f·4152·4348··hen..ACTION_ARCH
000d5420:·5f46·494c·5445·5253·3d22·2d61·2061·6c77··_FILTERS="-a·alw000d5420:·5f46·494c·5445·5253·3d22·2d61·2061·6c77··_FILTERS="-a·alw
000d5430:·6179·732c·6578·6974·220a·4f54·4845·525f··ays,exit".OTHER_000d5430:·6179·732c·6578·6974·220a·4f54·4845·525f··ays,exit".OTHER_
000d5440:·4649·4c54·4552·533d·222d·4620·7061·7468··FILTERS="-F·path000d5440:·4649·4c54·4552·533d·222d·4620·7061·7468··FILTERS="-F·path
000d5450:·3d2f·7573·722f·6269·6e2f·7375·646f·202d··=/usr/bin/sudo·-000d5450:·3d2f·7573·722f·6269·6e2f·7375·646f·202d··=/usr/bin/sudo·-
000d5460:·4620·7065·726d·3d78·220a·4155·4944·5f46··F·perm=x".AUID_F000d5460:·4620·7065·726d·3d78·220a·4155·4944·5f46··F·perm=x".AUID_F
000d5470:·494c·5445·5253·3d22·2d46·2061·7569·6426··ILTERS="-F·auid&000d5470:·494c·5445·5253·3d22·2d46·2061·7569·6426··ILTERS="-F·auid&
Offset 55734, 23 lines modifiedOffset 55734, 23 lines modified
000d9b50:·7269·7669·6c65·6765·640a·2020·2020·2020··rivileged.······000d9b50:·7269·7669·6c65·6765·640a·2020·2020·2020··rivileged.······
000d9b60:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···000d9b60:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···
000d9b70:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·000d9b70:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·
000d9b80:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres000d9b80:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres
000d9b90:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy000d9b90:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy
000d9ba0:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l000d9ba0:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l
000d9bb0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe000d9bb0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe
000d9bc0:·6e3a·0a20·202d·2027·2261·7564·6974·2220··n:.··-·'"audit"· 
000d9bd0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
000d9be0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a 
000d9bf0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
000d9c00:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
000d9c10:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
000d9c20:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
000d9c30:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain000d9bc0:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v
 000d9bd0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 000d9be0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 000d9bf0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 000d9c00:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 000d9c10:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-
 000d9c20:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans
 000d9c30:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
000d9c40:·6572·225d·0a20·2074·6167·733a·0a20·202d··er"].··tags:.··-000d9c40:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
000d9c50:·2043·4345·2d38·3536·3033·2d39·0a20·202d···CCE-85603-9.··-000d9c50:·2043·4345·2d38·3536·3033·2d39·0a20·202d···CCE-85603-9.··-
000d9c60:·2044·4953·412d·5354·4947·2d53·4c45·532d···DISA-STIG-SLES-000d9c60:·2044·4953·412d·5354·4947·2d53·4c45·532d···DISA-STIG-SLES-
000d9c70:·3135·2d30·3330·3536·300a·2020·2d20·4e49··15-030560.··-·NI000d9c70:·3135·2d30·3330·3536·300a·2020·2d20·4e49··15-030560.··-·NI
000d9c80:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.7000d9c80:·5354·2d38·3030·2d31·3731·2d33·2e31·2e37··ST-800-171-3.1.7
000d9c90:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53000d9c90:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
000d9ca0:·2d41·432d·3628·3929·0a20·202d·204e·4953··-AC-6(9).··-·NIS000d9ca0:·2d41·432d·3628·3929·0a20·202d·204e·4953··-AC-6(9).··-·NIS
000d9cb0:·542d·3830·302d·3533·2d41·552d·3132·2863··T-800-53-AU-12(c000d9cb0:·542d·3830·302d·3533·2d41·552d·3132·2863··T-800-53-AU-12(c
1.54 KB
html2text {}
    
Offset 8747, 15 lines modifiedOffset 8747, 15 lines modified
8747 ············A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),8747 ············A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·AU-2(d),·AU-12(c),·AC-6(9),
8748 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,8748 ············CM-6(a),·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.PT-1,·FAU_GEN.1.1.c,·SRG-OS-000037-GPOS-00015,
8749 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-8749 ············SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-
8750 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·SLES-15-8750 ············00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000466-GPOS-00210,·SRG-OS-000471-VMM-001910,·SLES-15-
8751 ············030560,·SV-234955r622137_rule8751 ············030560,·SV-234955r622137_rule
8752 Remediation_Shell_script_⇲8752 Remediation_Shell_script_⇲
8753 #·Remediation·is·applicable·only·in·certain·platforms8753 #·Remediation·is·applicable·only·in·certain·platforms
8754 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8754 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8755 ACTION_ARCH_FILTERS="-a·always,exit"8755 ACTION_ARCH_FILTERS="-a·always,exit"
8756 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"8756 OTHER_FILTERS="-F·path=/usr/bin/sudo·-F·perm=x"
8757 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"8757 AUID_FILTERS="-F·auid>=1000·-F·auid!=unset"
8758 SYSCALL=""8758 SYSCALL=""
8759 KEY="privileged"8759 KEY="privileged"
8760 SYSCALL_GROUPING=""8760 SYSCALL_GROUPING=""
Offset 9217, 16 lines modifiedOffset 9217, 16 lines modified
9217 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x9217 ······line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
9218 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged9218 ········-F·auid>=1000·-F·auid!=unset·-F·key=privileged
9219 ······create:·true9219 ······create:·true
9220 ······mode:·o-rwx9220 ······mode:·o-rwx
9221 ······state:·present9221 ······state:·present
9222 ····when:·syscalls_found·|·length·==·09222 ····when:·syscalls_found·|·length·==·0
9223 ··when:9223 ··when:
9224 ··-·'"audit"·in·ansible_facts.packages' 
9225 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]9224 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 9225 ··-·'"audit"·in·ansible_facts.packages'
9226 ··tags:9226 ··tags:
9227 ··-·CCE-85603-99227 ··-·CCE-85603-9
9228 ··-·DISA-STIG-SLES-15-0305609228 ··-·DISA-STIG-SLES-15-030560
9229 ··-·NIST-800-171-3.1.79229 ··-·NIST-800-171-3.1.7
9230 ··-·NIST-800-53-AC-6(9)9230 ··-·NIST-800-53-AC-6(9)
9231 ··-·NIST-800-53-AU-12(c)9231 ··-·NIST-800-53-AU-12(c)
9232 ··-·NIST-800-53-AU-2(d)9232 ··-·NIST-800-53-AU-2(d)
797 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis.html
    
Offset 49720, 21 lines modifiedOffset 49720, 21 lines modified
000c2370:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane000c2370:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
000c2380:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla000c2380:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
000c2390:·7073·6522·2069·643d·2269·646d·3139·3637··pse"·id="idm1967000c2390:·7073·6522·2069·643d·2269·646d·3139·3637··pse"·id="idm1967
000c23a0:·3822·3e3c·7072·653e·3c63·6f64·653e·2320··8"><pre><code>#·000c23a0:·3822·3e3c·7072·653e·3c63·6f64·653e·2320··8"><pre><code>#·
000c23b0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a000c23b0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
000c23c0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i000c23c0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
000c23d0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo000c23d0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
000c23e0:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui 
000c23f0:·6574·202d·7120·6175·6469·7420·2661·6d70··et·-q·audit·&amp 
000c2400:·3b26·616d·703b·205b·2021·202d·6620·2f2e··;&amp;·[·!·-f·/.000c23e0:·726d·730a·6966·205b·2021·202d·6620·2f2e··rms.if·[·!·-f·/.
000c2410:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp000c23f0:·646f·636b·6572·656e·7620·5d20·2661·6d70··dockerenv·]·&amp
000c2420:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r000c2400:·3b26·616d·703b·205b·2021·202d·6620·2f72··;&amp;·[·!·-f·/r
000c2430:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv000c2410:·756e·2f2e·636f·6e74·6169·6e65·7265·6e76··un/.containerenv
 000c2420:·205d·2026·616d·703b·2661·6d70·3b20·7270···]·&amp;&amp;·rp
 000c2430:·6d20·2d2d·7175·6965·7420·2d71·2061·7564··m·--quiet·-q·aud
000c2440:·205d·3b20·7468·656e·0a0a·2320·4669·7273···];·then..#·Firs000c2440:·6974·3b20·7468·656e·0a0a·2320·4669·7273··it;·then..#·Firs
000c2450:·7420·7065·7266·6f72·6d20·7468·6520·7265··t·perform·the·re000c2450:·7420·7065·7266·6f72·6d20·7468·6520·7265··t·perform·the·re
000c2460:·6d65·6469·6174·696f·6e20·6f66·2074·6865··mediation·of·the000c2460:·6d65·6469·6174·696f·6e20·6f66·2074·6865··mediation·of·the
000c2470:·2073·7973·6361·6c6c·2072·756c·650a·2320···syscall·rule.#·000c2470:·2073·7973·6361·6c6c·2072·756c·650a·2320···syscall·rule.#·
000c2480:·5265·7472·6965·7665·2068·6172·6477·6172··Retrieve·hardwar000c2480:·5265·7472·6965·7665·2068·6172·6477·6172··Retrieve·hardwar
000c2490:·6520·6172·6368·6974·6563·7475·7265·206f··e·architecture·o000c2490:·6520·6172·6368·6974·6563·7475·7265·206f··e·architecture·o
000c24a0:·6620·7468·6520·756e·6465·726c·7969·6e67··f·the·underlying000c24a0:·6620·7468·6520·756e·6465·726c·7969·6e67··f·the·underlying
000c24b0:·2073·7973·7465·6d0a·5b20·2224·2867·6574···system.[·"$(get000c24b0:·2073·7973·7465·6d0a·5b20·2224·2867·6574···system.[·"$(get
Offset 50621, 23 lines modifiedOffset 50621, 23 lines modified
000c5bc0:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest000c5bc0:·6571·7569·7265·640a·2020·2d20·7265·7374··equired.··-·rest
000c5bd0:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-000c5bd0:·7269·6374·5f73·7472·6174·6567·790a·0a2d··rict_strategy..-
000c5be0:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi000c5be0:·206e·616d·653a·2053·6574·2061·7263·6869···name:·Set·archi
000c5bf0:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi000c5bf0:·7465·6374·7572·6520·666f·7220·6175·6469··tecture·for·audi
000c5c00:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··000c5c00:·7420·6368·6d6f·6420·7461·736b·730a·2020··t·chmod·tasks.··
000c5c10:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au000c5c10:·7365·745f·6661·6374·3a0a·2020·2020·6175··set_fact:.····au
000c5c20:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··000c5c20:·6469·745f·6172·6368·3a20·6236·340a·2020··dit_arch:·b64.··
000c5c30:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi000c5c30:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
000c5c40:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
000c5c50:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
000c5c60:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
000c5c70:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
000c5c80:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
000c5c90:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
000c5ca0:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont000c5c40:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000c5c50:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000c5c60:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000c5c70:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 000c5c80:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 000c5c90:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 000c5ca0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
000c5cb0:·6169·6e65·7222·5d0a·2020·2d20·616e·7369··ainer"].··-·ansi000c5cb0:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi
000c5cc0:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture000c5cc0:·626c·655f·6172·6368·6974·6563·7475·7265··ble_architecture
000c5cd0:·203d·3d20·2261·6172·6368·3634·2220·6f72···==·"aarch64"·or000c5cd0:·203d·3d20·2261·6172·6368·3634·2220·6f72···==·"aarch64"·or
000c5ce0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite000c5ce0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite
000c5cf0:·6374·7572·6520·3d3d·2022·7070·6336·3422··cture·==·"ppc64"000c5cf0:·6374·7572·6520·3d3d·2022·7070·6336·3422··cture·==·"ppc64"
000c5d00:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch000c5d00:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch
000c5d10:·6974·6563·7475·7265·0a20·2020·203d·3d20··itecture.····==·000c5d10:·6974·6563·7475·7265·0a20·2020·203d·3d20··itecture.····==·
000c5d20:·2270·7063·3634·6c65·2220·6f72·2061·6e73··"ppc64le"·or·ans000c5d20:·2270·7063·3634·6c65·2220·6f72·2061·6e73··"ppc64le"·or·ans
Offset 50952, 23 lines modifiedOffset 50952, 23 lines modified
000c7070:·6572·6d5f·6d6f·640a·2020·2020·2020·6372··erm_mod.······cr000c7070:·6572·6d5f·6d6f·640a·2020·2020·2020·6372··erm_mod.······cr
000c7080:·6561·7465·3a20·7472·7565·0a20·2020·2020··eate:·true.·····000c7080:·6561·7465·3a20·7472·7565·0a20·2020·2020··eate:·true.·····
000c7090:·206d·6f64·653a·206f·2d72·7778·0a20·2020···mode:·o-rwx.···000c7090:·206d·6f64·653a·206f·2d72·7778·0a20·2020···mode:·o-rwx.···
000c70a0:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen000c70a0:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen
000c70b0:·740a·2020·2020·7768·656e·3a20·7379·7363··t.····when:·sysc000c70b0:·740a·2020·2020·7768·656e·3a20·7379·7363··t.····when:·sysc
000c70c0:·616c·6c73·5f66·6f75·6e64·207c·206c·656e··alls_found·|·len000c70c0:·616c·6c73·5f66·6f75·6e64·207c·206c·656e··alls_found·|·len
000c70d0:·6774·6820·3d3d·2030·0a20·2077·6865·6e3a··gth·==·0.··when:000c70d0:·6774·6820·3d3d·2030·0a20·2077·6865·6e3a··gth·==·0.··when:
000c70e0:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in 
000c70f0:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p 
000c7100:·6163·6b61·6765·7327·0a20·202d·2061·6e73··ackages'.··-·ans 
000c7110:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat 
000c7120:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in· 
000c7130:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc" 
000c7140:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod 
000c7150:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container000c70e0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir
 000c70f0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type
 000c7100:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker
 000c7110:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv
 000c7120:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c
 000c7130:·6f6e·7461·696e·6572·225d·0a20·202d·2027··ontainer"].··-·'
 000c7140:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib
 000c7150:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
000c7160:·225d·0a20·2074·6167·733a·0a20·202d·2043··"].··tags:.··-·C000c7160:·7327·0a20·2074·6167·733a·0a20·202d·2043··s'.··tags:.··-·C
000c7170:·4345·2d38·3536·3933·2d30·0a20·202d·2043··CE-85693-0.··-·C000c7170:·4345·2d38·3536·3933·2d30·0a20·202d·2043··CE-85693-0.··-·C
000c7180:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·000c7180:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·
000c7190:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1000c7190:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1
000c71a0:·352d·3033·3032·3930·0a20·202d·204e·4953··5-030290.··-·NIS000c71a0:·352d·3033·3032·3930·0a20·202d·204e·4953··5-030290.··-·NIS
000c71b0:·542d·3830·302d·3137·312d·332e·312e·370a··T-800-171-3.1.7.000c71b0:·542d·3830·302d·3137·312d·332e·312e·370a··T-800-171-3.1.7.
000c71c0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-000c71c0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
000c71d0:·4155·2d31·3228·6129·0a20·202d·204e·4953··AU-12(a).··-·NIS000c71d0:·4155·2d31·3228·6129·0a20·202d·204e·4953··AU-12(a).··-·NIS
Offset 51271, 23 lines modifiedOffset 51271, 23 lines modified
000c8460:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······000c8460:·3d70·6572·6d5f·6d6f·640a·2020·2020·2020··=perm_mod.······
000c8470:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···000c8470:·6372·6561·7465·3a20·7472·7565·0a20·2020··create:·true.···
000c8480:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·000c8480:·2020·206d·6f64·653a·206f·2d72·7778·0a20·····mode:·o-rwx.·
000c8490:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres000c8490:·2020·2020·2073·7461·7465·3a20·7072·6573·······state:·pres
000c84a0:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy000c84a0:·656e·740a·2020·2020·7768·656e·3a20·7379··ent.····when:·sy
000c84b0:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l000c84b0:·7363·616c·6c73·5f66·6f75·6e64·207c·206c··scalls_found·|·l
000c84c0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe000c84c0:·656e·6774·6820·3d3d·2030·0a20·2077·6865··ength·==·0.··whe
000c84d0:·6e3a·0a20·202d·2027·2261·7564·6974·2220··n:.··-·'"audit"· 
000c84e0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
000c84f0:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a 
000c8500:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz 
000c8510:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i 
000c8520:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx 
000c8530:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p 
000c8540:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain000c84d0:·6e3a·0a20·202d·2061·6e73·6962·6c65·5f76··n:.··-·ansible_v
 000c84e0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty
 000c84f0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock
 000c8500:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope
 000c8510:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",·
 000c8520:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-
 000c8530:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans
 000c8540:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
000c8550:·6572·225d·0a20·202d·2061·7564·6974·5f61··er"].··-·audit_a000c8550:·6765·7327·0a20·202d·2061·7564·6974·5f61··ges'.··-·audit_a
000c8560:·7263·6820·3d3d·2022·6236·3422·0a20·2074··rch·==·"b64".··t000c8560:·7263·6820·3d3d·2022·6236·3422·0a20·2074··rch·==·"b64".··t
000c8570:·6167·733a·0a20·202d·2043·4345·2d38·3536··ags:.··-·CCE-856000c8570:·6167·733a·0a20·202d·2043·4345·2d38·3536··ags:.··-·CCE-856
000c8580:·3933·2d30·0a20·202d·2043·4a49·532d·352e··93-0.··-·CJIS-5.000c8580:·3933·2d30·0a20·202d·2043·4a49·532d·352e··93-0.··-·CJIS-5.
000c8590:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S000c8590:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S
000c85a0:·5449·472d·534c·4553·2d31·352d·3033·3032··TIG-SLES-15-0302000c85a0:·5449·472d·534c·4553·2d31·352d·3033·3032··TIG-SLES-15-0302
000c85b0:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-000c85b0:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-
000c85c0:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI000c85c0:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI
Offset 52306, 21 lines modifiedOffset 52306, 21 lines modified
000cc510:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas000cc510:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
000cc520:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps000cc520:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
000cc530:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="000cc530:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
000cc540:·6964·6d31·3938·3432·223e·3c70·7265·3e3c··idm19842"><pre><000cc540:·6964·6d31·3938·3432·223e·3c70·7265·3e3c··idm19842"><pre><
000cc550:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati000cc550:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
000cc560:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable000cc560:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
000cc570:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain000cc570:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
000cc580:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp000cc580:·2070·6c61·7466·6f72·6d73·0a69·6620·5b20···platforms.if·[·
000cc590:·6d20·2d2d·7175·6965·7420·2d71·2061·7564··m·--quiet·-q·aud 
000cc5a0:·6974·2026·616d·703b·2661·6d70·3b20·5b20··it·&amp;&amp;·[· 
000cc5b0:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv000cc590:·2120·2d66·202f·2e64·6f63·6b65·7265·6e76··!·-f·/.dockerenv
Max diff block lines reached; 609309/619513 bytes (98.35%) of diff not shown.
192 KB
html2text {}
    
Offset 5595, 15 lines modifiedOffset 5595, 15 lines modified
5595 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-5595 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
5596 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,5596 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
5597 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-5597 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
5598 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-5598 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-
5599 ············234928r622137_rule5599 ············234928r622137_rule
5600 Remediation_Shell_script_⇲5600 Remediation_Shell_script_⇲
5601 #·Remediation·is·applicable·only·in·certain·platforms5601 #·Remediation·is·applicable·only·in·certain·platforms
5602 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then5602 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
5603 #·First·perform·the·remediation·of·the·syscall·rule5603 #·First·perform·the·remediation·of·the·syscall·rule
5604 #·Retrieve·hardware·architecture·of·the·underlying·system5604 #·Retrieve·hardware·architecture·of·the·underlying·system
5605 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")5605 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
5606 for·ARCH·in·"${RULE_ARCHS[@]}"5606 for·ARCH·in·"${RULE_ARCHS[@]}"
5607 do5607 do
Offset 5964, 16 lines modifiedOffset 5964, 16 lines modified
5964 ··-·reboot_required5964 ··-·reboot_required
5965 ··-·restrict_strategy5965 ··-·restrict_strategy
  
5966 -·name:·Set·architecture·for·audit·chmod·tasks5966 -·name:·Set·architecture·for·audit·chmod·tasks
5967 ··set_fact:5967 ··set_fact:
5968 ····audit_arch:·b645968 ····audit_arch:·b64
5969 ··when:5969 ··when:
5970 ··-·'"audit"·in·ansible_facts.packages' 
5971 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5970 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5971 ··-·'"audit"·in·ansible_facts.packages'
5972 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5972 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5973 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5973 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5974 ··tags:5974 ··tags:
5975 ··-·CCE-85693-05975 ··-·CCE-85693-0
5976 ··-·CJIS-5.4.1.15976 ··-·CJIS-5.4.1.1
5977 ··-·DISA-STIG-SLES-15-0302905977 ··-·DISA-STIG-SLES-15-030290
5978 ··-·NIST-800-171-3.1.75978 ··-·NIST-800-171-3.1.7
Offset 6115, 16 lines modifiedOffset 6115, 16 lines modified
6115 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006115 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6116 ········-F·auid!=unset·-F·key=perm_mod6116 ········-F·auid!=unset·-F·key=perm_mod
6117 ······create:·true6117 ······create:·true
6118 ······mode:·o-rwx6118 ······mode:·o-rwx
6119 ······state:·present6119 ······state:·present
6120 ····when:·syscalls_found·|·length·==·06120 ····when:·syscalls_found·|·length·==·0
6121 ··when:6121 ··when:
6122 ··-·'"audit"·in·ansible_facts.packages' 
6123 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6122 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6123 ··-·'"audit"·in·ansible_facts.packages'
6124 ··tags:6124 ··tags:
6125 ··-·CCE-85693-06125 ··-·CCE-85693-0
6126 ··-·CJIS-5.4.1.16126 ··-·CJIS-5.4.1.1
6127 ··-·DISA-STIG-SLES-15-0302906127 ··-·DISA-STIG-SLES-15-030290
6128 ··-·NIST-800-171-3.1.76128 ··-·NIST-800-171-3.1.7
6129 ··-·NIST-800-53-AU-12(a)6129 ··-·NIST-800-53-AU-12(a)
6130 ··-·NIST-800-53-AU-12(c)6130 ··-·NIST-800-53-AU-12(c)
Offset 6264, 16 lines modifiedOffset 6264, 16 lines modified
6264 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006264 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6265 ········-F·auid!=unset·-F·key=perm_mod6265 ········-F·auid!=unset·-F·key=perm_mod
6266 ······create:·true6266 ······create:·true
6267 ······mode:·o-rwx6267 ······mode:·o-rwx
6268 ······state:·present6268 ······state:·present
6269 ····when:·syscalls_found·|·length·==·06269 ····when:·syscalls_found·|·length·==·0
6270 ··when:6270 ··when:
6271 ··-·'"audit"·in·ansible_facts.packages' 
6272 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6271 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6272 ··-·'"audit"·in·ansible_facts.packages'
6273 ··-·audit_arch·==·"b64"6273 ··-·audit_arch·==·"b64"
6274 ··tags:6274 ··tags:
6275 ··-·CCE-85693-06275 ··-·CCE-85693-0
6276 ··-·CJIS-5.4.1.16276 ··-·CJIS-5.4.1.1
6277 ··-·DISA-STIG-SLES-15-0302906277 ··-·DISA-STIG-SLES-15-030290
6278 ··-·NIST-800-171-3.1.76278 ··-·NIST-800-171-3.1.7
6279 ··-·NIST-800-53-AU-12(a)6279 ··-·NIST-800-53-AU-12(a)
Offset 6326, 15 lines modifiedOffset 6326, 15 lines modified
6326 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-6326 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
6327 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,6327 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
6328 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-6328 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
6329 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-6329 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-
6330 ············030250,·4.1.9,·SV-234924r622137_rule6330 ············030250,·4.1.9,·SV-234924r622137_rule
6331 Remediation_Shell_script_⇲6331 Remediation_Shell_script_⇲
6332 #·Remediation·is·applicable·only·in·certain·platforms6332 #·Remediation·is·applicable·only·in·certain·platforms
6333 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then6333 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
6334 #·First·perform·the·remediation·of·the·syscall·rule6334 #·First·perform·the·remediation·of·the·syscall·rule
6335 #·Retrieve·hardware·architecture·of·the·underlying·system6335 #·Retrieve·hardware·architecture·of·the·underlying·system
6336 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6336 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6337 for·ARCH·in·"${RULE_ARCHS[@]}"6337 for·ARCH·in·"${RULE_ARCHS[@]}"
6338 do6338 do
Offset 6695, 16 lines modifiedOffset 6695, 16 lines modified
6695 ··-·reboot_required6695 ··-·reboot_required
6696 ··-·restrict_strategy6696 ··-·restrict_strategy
  
6697 -·name:·Set·architecture·for·audit·chown·tasks6697 -·name:·Set·architecture·for·audit·chown·tasks
6698 ··set_fact:6698 ··set_fact:
6699 ····audit_arch:·b646699 ····audit_arch:·b64
6700 ··when:6700 ··when:
6701 ··-·'"audit"·in·ansible_facts.packages' 
6702 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6701 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6702 ··-·'"audit"·in·ansible_facts.packages'
6703 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6703 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6704 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6704 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6705 ··tags:6705 ··tags:
6706 ··-·CCE-85690-66706 ··-·CCE-85690-6
6707 ··-·CJIS-5.4.1.16707 ··-·CJIS-5.4.1.1
6708 ··-·DISA-STIG-SLES-15-0302506708 ··-·DISA-STIG-SLES-15-030250
6709 ··-·NIST-800-171-3.1.76709 ··-·NIST-800-171-3.1.7
Offset 6848, 16 lines modifiedOffset 6848, 16 lines modified
6848 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006848 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6849 ········-F·auid!=unset·-F·key=perm_mod6849 ········-F·auid!=unset·-F·key=perm_mod
6850 ······create:·true6850 ······create:·true
6851 ······mode:·o-rwx6851 ······mode:·o-rwx
6852 ······state:·present6852 ······state:·present
6853 ····when:·syscalls_found·|·length·==·06853 ····when:·syscalls_found·|·length·==·0
6854 ··when:6854 ··when:
6855 ··-·'"audit"·in·ansible_facts.packages' 
6856 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6855 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6856 ··-·'"audit"·in·ansible_facts.packages'
6857 ··tags:6857 ··tags:
6858 ··-·CCE-85690-66858 ··-·CCE-85690-6
6859 ··-·CJIS-5.4.1.16859 ··-·CJIS-5.4.1.1
6860 ··-·DISA-STIG-SLES-15-0302506860 ··-·DISA-STIG-SLES-15-030250
6861 ··-·NIST-800-171-3.1.76861 ··-·NIST-800-171-3.1.7
6862 ··-·NIST-800-53-AU-12(a)6862 ··-·NIST-800-53-AU-12(a)
6863 ··-·NIST-800-53-AU-12(c)6863 ··-·NIST-800-53-AU-12(c)
Offset 6999, 16 lines modifiedOffset 6999, 16 lines modified
6999 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006999 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7000 ········-F·auid!=unset·-F·key=perm_mod7000 ········-F·auid!=unset·-F·key=perm_mod
7001 ······create:·true7001 ······create:·true
7002 ······mode:·o-rwx7002 ······mode:·o-rwx
7003 ······state:·present7003 ······state:·present
Max diff block lines reached; 191444/196653 bytes (97.35%) of diff not shown.
10.5 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_server_l1.html
    
Offset 155081, 73 lines modifiedOffset 155081, 73 lines modified
0025dc80:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0025dc80:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0025dc90:·3538·3731·3522·2074·6162·696e·6465·783d··58715"·tabindex=0025dc90:·3538·3731·3522·2074·6162·696e·6465·783d··58715"·tabindex=
0025dca0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0025dca0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0025dcb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0025dcb0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0025dcc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0025dcc0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0025dcd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0025dcd0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0025dce0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0025dce0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0025dcf0:·6564·6961·7469·6f6e·2041·6e61·636f·6e64··ediation·Anacond 
0025dd00:·6120·736e·6970·7065·7420·e287·b23c·2f61··a·snippet·...</a0025dcf0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0025dd00:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
0025dd10:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0025dd10:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0025dd20:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0025dd20:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0025dd30:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0025dd30:·6170·7365·2220·6964·3d22·6964·6d35·3837··apse"·id="idm587
0025dd40:·6d35·3837·3135·223e·3c70·7265·3e3c·636f··m58715"><pre><co 
0025dd50:·6465·3e0a·7061·636b·6167·6520·2d2d·7265··de>.package·--re 
0025dd60:·6d6f·7665·3d78·6f72·672d·7831·312d·7365··move=xorg-x11-se 
0025dd70:·7276·6572·2d58·6f72·6720·2d2d·7265·6d6f··rver-Xorg·--remo0025dd40:·3135·223e·3c74·6162·6c65·2063·6c61·7373··15"><table·class
 0025dd50:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0025dd60:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0025dd70:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0025dd80:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0025dd90:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0025dda0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0025ddb0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0025ddc0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0025ddd0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0025dde0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0025ddf0:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t
 0025de00:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0025de10:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
 0025de20:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0025de30:·653e·3c70·7265·3e3c·636f·6465·3e0a·0a23··e><pre><code>..#
 0025de40:·2072·656d·6f76·6520·7061·636b·6167·6573···remove·packages
 0025de50:·0a7a·7970·7065·7220·7265·6d6f·7665·202d··.zypper·remove·-
0025dd80:·7665·3d78·6f72·672d·7831·312d·7365·7276··ve=xorg-x11-serv0025de60:·7920·2278·6f72·672d·7831·312d·7365·7276··y·"xorg-x11-serv
 0025de70:·6572·2d58·6f72·6722·0a7a·7970·7065·7220··er-Xorg".zypper·
 0025de80:·7265·6d6f·7665·202d·7920·2278·6f72·672d··remove·-y·"xorg-
 0025de90:·7831·312d·7365·7276·6572·2d75·7469·6c73··x11-server-utils
0025dd90:·6572·2d63·6f6d·6d6f·6e20·2d2d·7265·6d6f··er-common·--remo 
0025dda0:·7665·3d78·6f72·672d·7831·312d·7365·7276··ve=xorg-x11-serv 
0025ddb0:·6572·2d75·7469·6c73·202d·2d72·656d·6f76··er-utils·--remov 
0025ddc0:·653d·786f·7267·2d78·3131·2d73·6572·7665··e=xorg-x11-serve 
0025ddd0:·722d·5877·6179·6c61·6e64·0a3c·2f63·6f64··r-Xwayland.</cod 
0025dde0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0025ddf0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0025de00:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0025de10:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0025de20:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0025de30:·6d35·3837·3136·2220·7461·6269·6e64·6578··m58716"·tabindex 
0025de40:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0025de50:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0025de60:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0025de70:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0025de80:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0025de90:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0025dea0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0025deb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0025dec0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0025ded0:·6c61·7073·6522·2069·643d·2269·646d·3538··lapse"·id="idm58 
0025dee0:·3731·3622·3e3c·7461·626c·6520·636c·6173··716"><table·clas 
0025def0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0025df00:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0025df10:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0025df20:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0025df30:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0025df40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0025df50:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0025df60:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0025df70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0025df80:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0025df90:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr>< 
0025dfa0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0025dfb0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric 
0025dfc0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab 
0025dfd0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a0a··le><pre><code>.. 
0025dfe0:·2320·7265·6d6f·7665·2070·6163·6b61·6765··#·remove·package 
0025dff0:·730a·7a79·7070·6572·2072·656d·6f76·6520··s.zypper·remove·0025dea0:·220a·7a79·7070·6572·2072·656d·6f76·6520··".zypper·remove·
0025e000:·2d79·2022·786f·7267·2d78·3131·2d73·6572··-y·"xorg-x11-ser0025deb0:·2d79·2022·786f·7267·2d78·3131·2d73·6572··-y·"xorg-x11-ser
0025e010:·7665·722d·586f·7267·220a·7a79·7070·6572··ver-Xorg".zypper 
0025e020:·2072·656d·6f76·6520·2d79·2022·786f·7267···remove·-y·"xorg 
0025e030:·2d78·3131·2d73·6572·7665·722d·7574·696c··-x11-server-util 
0025e040:·7322·0a7a·7970·7065·7220·7265·6d6f·7665··s".zypper·remove 
0025e050:·202d·7920·2278·6f72·672d·7831·312d·7365···-y·"xorg-x11-se 
0025e060:·7276·6572·2d63·6f6d·6d6f·6e22·0a0a·7a79··rver-common"..zy 
0025e070:·7070·6572·2072·656d·6f76·6520·2d79·2022··pper·remove·-y·"0025dec0:·7665·722d·636f·6d6d·6f6e·220a·0a7a·7970··ver-common"..zyp
 0025ded0:·7065·7220·7265·6d6f·7665·202d·7920·2278··per·remove·-y·"x
 0025dee0:·6f72·672d·7831·312d·7365·7276·6572·2d58··org-x11-server-X
 0025def0:·7761·796c·616e·6422·0a3c·2f63·6f64·653e··wayland".</code>
 0025df00:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0025df10:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0025df20:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0025df30:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0025df40:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
 0025df50:·3837·3136·2220·7461·6269·6e64·6578·3d22··8716"·tabindex="
 0025df60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0025df70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0025df80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0025df90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0025dfa0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0025dfb0:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
 0025dfc0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0025dfd0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0025dfe0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0025dff0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0025e000:·3538·3731·3622·3e3c·7072·653e·3c63·6f64··58716"><pre><cod
 0025e010:·653e·0a70·6163·6b61·6765·202d·2d72·656d··e>.package·--rem
 0025e020:·6f76·653d·786f·7267·2d78·3131·2d73·6572··ove=xorg-x11-ser
 0025e030:·7665·722d·586f·7267·202d·2d72·656d·6f76··ver-Xorg·--remov
0025e080:·786f·7267·2d78·3131·2d73·6572·7665·722d··xorg-x11-server-0025e040:·653d·786f·7267·2d78·3131·2d73·6572·7665··e=xorg-x11-serve
 0025e050:·722d·636f·6d6d·6f6e·202d·2d72·656d·6f76··r-common·--remov
 0025e060:·653d·786f·7267·2d78·3131·2d73·6572·7665··e=xorg-x11-serve
 0025e070:·722d·7574·696c·7320·2d2d·7265·6d6f·7665··r-utils·--remove
 0025e080:·3d78·6f72·672d·7831·312d·7365·7276·6572··=xorg-x11-server
0025e090:·5877·6179·6c61·6e64·220a·3c2f·636f·6465··Xwayland".</code0025e090:·2d58·7761·796c·616e·640a·3c2f·636f·6465··-Xwayland.</code
0025e0a0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d0025e0a0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d
0025e0b0:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t0025e0b0:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t
0025e0c0:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t0025e0c0:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t
0025e0d0:·643e·3c2f·7472·3e3c·2f74·626f·6479·3e3c··d></tr></tbody><0025e0d0:·643e·3c2f·7472·3e3c·2f74·626f·6479·3e3c··d></tr></tbody><
0025e0e0:·2f74·6162·6c65·3e3c·2f64·6976·3e3c·6469··/table></div><di0025e0e0:·2f74·6162·6c65·3e3c·2f64·6976·3e3c·6469··/table></div><di
0025e0f0:·7620·6964·3d22·7265·6172·2d6d·6174·7465··v·id="rear-matte0025e0f0:·7620·6964·3d22·7265·6172·2d6d·6174·7465··v·id="rear-matte
0025e100:·7222·3e3c·6469·7620·636c·6173·733d·2272··r"><div·class="r0025e100:·7222·3e3c·6469·7620·636c·6173·733d·2272··r"><div·class="r
1.46 KB
html2text {}
    
Offset 20404, 28 lines modifiedOffset 20404, 28 lines modified
20404 ···························Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack20404 ···························Unnecessary·service·packages·must·not·be·installed·to·decrease·the·attack
20405 Rationale:·················surface·of·the·system.·X·windows·has·a·long·history·of·security20405 Rationale:·················surface·of·the·system.·X·windows·has·a·long·history·of·security
20406 ···························vulnerabilities·and·should·not·be·installed·unless·approved·and20406 ···························vulnerabilities·and·should·not·be·installed·unless·approved·and
20407 ···························documented.20407 ···························documented.
20408 Severity: ················medium20408 Severity: ················medium
20409 Rule·ID:···················xccdf_org.ssgproject.content_rule_xwindows_remove_packages20409 Rule·ID:···················xccdf_org.ssgproject.content_rule_xwindows_remove_packages
20410 Identifiers·and·References·References: ·CCI-000366,·CM-6(b),·SRG-OS-000480-GPOS-00227,·2.2.220410 Identifiers·and·References·References: ·CCI-000366,·CM-6(b),·SRG-OS-000480-GPOS-00227,·2.2.2
20411 Remediation_Anaconda_snippet_⇲ 
  
20412 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils 
20413 --remove=xorg-x11-server-Xwayland 
20414 Remediation_Shell_script_⇲20411 Remediation_Shell_script_⇲
20415 Complexity:·low20412 Complexity:·low
20416 Disruption:·low20413 Disruption:·low
20417 Reboot:·····true20414 Reboot:·····true
20418 Strategy:···restrict20415 Strategy:···restrict
  
  
20419 #·remove·packages20416 #·remove·packages
20420 zypper·remove·-y·"xorg-x11-server-Xorg"20417 zypper·remove·-y·"xorg-x11-server-Xorg"
20421 zypper·remove·-y·"xorg-x11-server-utils"20418 zypper·remove·-y·"xorg-x11-server-utils"
20422 zypper·remove·-y·"xorg-x11-server-common"20419 zypper·remove·-y·"xorg-x11-server-common"
  
20423 zypper·remove·-y·"xorg-x11-server-Xwayland"20420 zypper·remove·-y·"xorg-x11-server-Xwayland"
 20421 Remediation_Anaconda_snippet_⇲
  
 20422 package·--remove=xorg-x11-server-Xorg·--remove=xorg-x11-server-common·--remove=xorg-x11-server-utils
 20423 --remove=xorg-x11-server-Xwayland
20424 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or20424 Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered·trademarks·or
20425 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other20425 trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other·countries.·All·other
20426 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.20426 names·are·registered·trademarks·or·trademarks·of·their·respective·companies.
20427 Generated·using·OpenSCAP·1.3.720427 Generated·using·OpenSCAP·1.3.7
787 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_workstation_l2.html
    
Offset 49716, 21 lines modifiedOffset 49716, 21 lines modified
000c2330:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p000c2330:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
000c2340:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co000c2340:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000c2350:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1000c2350:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
000c2360:·3936·3738·223e·3c70·7265·3e3c·636f·6465··9678"><pre><code000c2360:·3936·3738·223e·3c70·7265·3e3c·636f·6465··9678"><pre><code
000c2370:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i000c2370:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
000c2380:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl000c2380:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
000c2390:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla000c2390:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
000c23a0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--000c23a0:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f
000c23b0:·7175·6965·7420·2d71·2061·7564·6974·2026··quiet·-q·audit·&000c23b0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
000c23c0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f000c23c0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
000c23d0:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
000c23e0:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
000c23f0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container000c23d0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
 000c23e0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 000c23f0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
000c2400:·656e·7620·5d3b·2074·6865·6e0a·0a23·2046··env·];·then..#·F000c2400:·6175·6469·743b·2074·6865·6e0a·0a23·2046··audit;·then..#·F
000c2410:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the000c2410:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the
000c2420:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·000c2420:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·
000c2430:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule000c2430:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule
000c2440:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard000c2440:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard
000c2450:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur000c2450:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur
000c2460:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly000c2460:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly
000c2470:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(000c2470:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(
Offset 50617, 23 lines modifiedOffset 50617, 23 lines modified
000c5b80:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r000c5b80:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r
000c5b90:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy000c5b90:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
000c5ba0:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar000c5ba0:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar
000c5bb0:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a000c5bb0:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a
000c5bc0:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks000c5bc0:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks
000c5bd0:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···000c5bd0:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
000c5be0:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b64000c5be0:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b64
000c5bf0:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a000c5bf0:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans
000c5c00:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
000c5c10:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
000c5c20:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
000c5c30:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
000c5c40:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
000c5c50:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
000c5c60:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
000c5c70:·6f6e·7461·696e·6572·225d·0a20·202d·2061··ontainer"].··-·a000c5c00:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 000c5c10:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 000c5c20:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 000c5c30:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 000c5c40:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
 000c5c50:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"·
 000c5c60:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000c5c70:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
000c5c80:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect000c5c80:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
000c5c90:·7572·6520·3d3d·2022·6161·7263·6836·3422··ure·==·"aarch64"000c5c90:·7572·6520·3d3d·2022·6161·7263·6836·3422··ure·==·"aarch64"
000c5ca0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch000c5ca0:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch
000c5cb0:·6974·6563·7475·7265·203d·3d20·2270·7063··itecture·==·"ppc000c5cb0:·6974·6563·7475·7265·203d·3d20·2270·7063··itecture·==·"ppc
000c5cc0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a000c5cc0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a
000c5cd0:·7263·6869·7465·6374·7572·650a·2020·2020··rchitecture.····000c5cd0:·7263·6869·7465·6374·7572·650a·2020·2020··rchitecture.····
000c5ce0:·3d3d·2022·7070·6336·346c·6522·206f·7220··==·"ppc64le"·or·000c5ce0:·3d3d·2022·7070·6336·346c·6522·206f·7220··==·"ppc64le"·or·
Offset 50948, 23 lines modifiedOffset 50948, 23 lines modified
000c7030:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····000c7030:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····
000c7040:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··000c7040:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··
000c7050:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.000c7050:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.
000c7060:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre000c7060:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre
000c7070:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s000c7070:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s
000c7080:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·000c7080:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·
000c7090:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh000c7090:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh
000c70a0:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit" 
000c70b0:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
000c70c0:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-· 
000c70d0:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali 
000c70e0:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not· 
000c70f0:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l 
000c7100:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·" 
000c7110:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai000c70a0:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_
 000c70b0:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
 000c70c0:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
 000c70d0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
 000c70e0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
 000c70f0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
 000c7100:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 000c7110:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
000c7120:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··000c7120:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··
000c7130:·2d20·4343·452d·3835·3639·332d·300a·2020··-·CCE-85693-0.··000c7130:·2d20·4343·452d·3835·3639·332d·300a·2020··-·CCE-85693-0.··
000c7140:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·000c7140:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
000c7150:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE000c7150:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE
000c7160:·532d·3135·2d30·3330·3239·300a·2020·2d20··S-15-030290.··-·000c7160:·532d·3135·2d30·3330·3239·300a·2020·2d20··S-15-030290.··-·
000c7170:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1000c7170:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
000c7180:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-000c7180:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-
000c7190:·3533·2d41·552d·3132·2861·290a·2020·2d20··53-AU-12(a).··-·000c7190:·3533·2d41·552d·3132·2861·290a·2020·2d20··53-AU-12(a).··-·
Offset 51267, 23 lines modifiedOffset 51267, 23 lines modified
000c8420:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···000c8420:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···
000c8430:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.000c8430:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.
000c8440:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw000c8440:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw
000c8450:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p000c8450:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p
000c8460:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:000c8460:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:
000c8470:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·000c8470:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·
000c8480:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··000c8480:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··
000c8490:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi000c8490:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
000c84a0:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
000c84b0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
000c84c0:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
000c84d0:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
000c84e0:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
000c84f0:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
000c8500:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont000c84a0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000c84b0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000c84c0:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000c84d0:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 000c84e0:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 000c84f0:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 000c8500:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
000c8510:·6169·6e65·7222·5d0a·2020·2d20·6175·6469··ainer"].··-·audi000c8510:·636b·6167·6573·270a·2020·2d20·6175·6469··ckages'.··-·audi
000c8520:·745f·6172·6368·203d·3d20·2262·3634·220a··t_arch·==·"b64".000c8520:·745f·6172·6368·203d·3d20·2262·3634·220a··t_arch·==·"b64".
000c8530:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE-000c8530:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE-
000c8540:·3835·3639·332d·300a·2020·2d20·434a·4953··85693-0.··-·CJIS000c8540:·3835·3639·332d·300a·2020·2d20·434a·4953··85693-0.··-·CJIS
000c8550:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS000c8550:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS
000c8560:·412d·5354·4947·2d53·4c45·532d·3135·2d30··A-STIG-SLES-15-0000c8560:·412d·5354·4947·2d53·4c45·532d·3135·2d30··A-STIG-SLES-15-0
000c8570:·3330·3239·300a·2020·2d20·4e49·5354·2d38··30290.··-·NIST-8000c8570:·3330·3239·300a·2020·2d20·4e49·5354·2d38··30290.··-·NIST-8
000c8580:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-000c8580:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-
Offset 52303, 20 lines modifiedOffset 52303, 20 lines modified
000cc4e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll000cc4e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
000cc4f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i000cc4f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
000cc500:·643d·2269·646d·3139·3834·3222·3e3c·7072··d="idm19842"><pr000cc500:·643d·2269·646d·3139·3834·3222·3e3c·7072··d="idm19842"><pr
000cc510:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi000cc510:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
000cc520:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica000cc520:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
000cc530:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert000cc530:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
000cc540:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if000cc540:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
000cc550:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
000cc560:·6175·6469·7420·2661·6d70·3b26·616d·703b··audit·&amp;&amp; 
000cc570:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker000cc550:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
000cc580:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;000cc560:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
Max diff block lines reached; 600242/610239 bytes (98.36%) of diff not shown.
191 KB
html2text {}
    
Offset 5594, 15 lines modifiedOffset 5594, 15 lines modified
5594 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-5594 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
5595 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,5595 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
5596 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-5596 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
5597 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-5597 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-
5598 ············234928r622137_rule5598 ············234928r622137_rule
5599 Remediation_Shell_script_⇲5599 Remediation_Shell_script_⇲
5600 #·Remediation·is·applicable·only·in·certain·platforms5600 #·Remediation·is·applicable·only·in·certain·platforms
5601 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then5601 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
5602 #·First·perform·the·remediation·of·the·syscall·rule5602 #·First·perform·the·remediation·of·the·syscall·rule
5603 #·Retrieve·hardware·architecture·of·the·underlying·system5603 #·Retrieve·hardware·architecture·of·the·underlying·system
5604 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")5604 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
5605 for·ARCH·in·"${RULE_ARCHS[@]}"5605 for·ARCH·in·"${RULE_ARCHS[@]}"
5606 do5606 do
Offset 5963, 16 lines modifiedOffset 5963, 16 lines modified
5963 ··-·reboot_required5963 ··-·reboot_required
5964 ··-·restrict_strategy5964 ··-·restrict_strategy
  
5965 -·name:·Set·architecture·for·audit·chmod·tasks5965 -·name:·Set·architecture·for·audit·chmod·tasks
5966 ··set_fact:5966 ··set_fact:
5967 ····audit_arch:·b645967 ····audit_arch:·b64
5968 ··when:5968 ··when:
5969 ··-·'"audit"·in·ansible_facts.packages' 
5970 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5969 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5970 ··-·'"audit"·in·ansible_facts.packages'
5971 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5971 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5972 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5972 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5973 ··tags:5973 ··tags:
5974 ··-·CCE-85693-05974 ··-·CCE-85693-0
5975 ··-·CJIS-5.4.1.15975 ··-·CJIS-5.4.1.1
5976 ··-·DISA-STIG-SLES-15-0302905976 ··-·DISA-STIG-SLES-15-030290
5977 ··-·NIST-800-171-3.1.75977 ··-·NIST-800-171-3.1.7
Offset 6114, 16 lines modifiedOffset 6114, 16 lines modified
6114 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006114 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6115 ········-F·auid!=unset·-F·key=perm_mod6115 ········-F·auid!=unset·-F·key=perm_mod
6116 ······create:·true6116 ······create:·true
6117 ······mode:·o-rwx6117 ······mode:·o-rwx
6118 ······state:·present6118 ······state:·present
6119 ····when:·syscalls_found·|·length·==·06119 ····when:·syscalls_found·|·length·==·0
6120 ··when:6120 ··when:
6121 ··-·'"audit"·in·ansible_facts.packages' 
6122 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6121 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6122 ··-·'"audit"·in·ansible_facts.packages'
6123 ··tags:6123 ··tags:
6124 ··-·CCE-85693-06124 ··-·CCE-85693-0
6125 ··-·CJIS-5.4.1.16125 ··-·CJIS-5.4.1.1
6126 ··-·DISA-STIG-SLES-15-0302906126 ··-·DISA-STIG-SLES-15-030290
6127 ··-·NIST-800-171-3.1.76127 ··-·NIST-800-171-3.1.7
6128 ··-·NIST-800-53-AU-12(a)6128 ··-·NIST-800-53-AU-12(a)
6129 ··-·NIST-800-53-AU-12(c)6129 ··-·NIST-800-53-AU-12(c)
Offset 6263, 16 lines modifiedOffset 6263, 16 lines modified
6263 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006263 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6264 ········-F·auid!=unset·-F·key=perm_mod6264 ········-F·auid!=unset·-F·key=perm_mod
6265 ······create:·true6265 ······create:·true
6266 ······mode:·o-rwx6266 ······mode:·o-rwx
6267 ······state:·present6267 ······state:·present
6268 ····when:·syscalls_found·|·length·==·06268 ····when:·syscalls_found·|·length·==·0
6269 ··when:6269 ··when:
6270 ··-·'"audit"·in·ansible_facts.packages' 
6271 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6270 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6271 ··-·'"audit"·in·ansible_facts.packages'
6272 ··-·audit_arch·==·"b64"6272 ··-·audit_arch·==·"b64"
6273 ··tags:6273 ··tags:
6274 ··-·CCE-85693-06274 ··-·CCE-85693-0
6275 ··-·CJIS-5.4.1.16275 ··-·CJIS-5.4.1.1
6276 ··-·DISA-STIG-SLES-15-0302906276 ··-·DISA-STIG-SLES-15-030290
6277 ··-·NIST-800-171-3.1.76277 ··-·NIST-800-171-3.1.7
6278 ··-·NIST-800-53-AU-12(a)6278 ··-·NIST-800-53-AU-12(a)
Offset 6325, 15 lines modifiedOffset 6325, 15 lines modified
6325 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-6325 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
6326 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,6326 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
6327 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-6327 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
6328 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-6328 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-
6329 ············030250,·4.1.9,·SV-234924r622137_rule6329 ············030250,·4.1.9,·SV-234924r622137_rule
6330 Remediation_Shell_script_⇲6330 Remediation_Shell_script_⇲
6331 #·Remediation·is·applicable·only·in·certain·platforms6331 #·Remediation·is·applicable·only·in·certain·platforms
6332 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then6332 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
6333 #·First·perform·the·remediation·of·the·syscall·rule6333 #·First·perform·the·remediation·of·the·syscall·rule
6334 #·Retrieve·hardware·architecture·of·the·underlying·system6334 #·Retrieve·hardware·architecture·of·the·underlying·system
6335 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6335 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6336 for·ARCH·in·"${RULE_ARCHS[@]}"6336 for·ARCH·in·"${RULE_ARCHS[@]}"
6337 do6337 do
Offset 6694, 16 lines modifiedOffset 6694, 16 lines modified
6694 ··-·reboot_required6694 ··-·reboot_required
6695 ··-·restrict_strategy6695 ··-·restrict_strategy
  
6696 -·name:·Set·architecture·for·audit·chown·tasks6696 -·name:·Set·architecture·for·audit·chown·tasks
6697 ··set_fact:6697 ··set_fact:
6698 ····audit_arch:·b646698 ····audit_arch:·b64
6699 ··when:6699 ··when:
6700 ··-·'"audit"·in·ansible_facts.packages' 
6701 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6700 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6701 ··-·'"audit"·in·ansible_facts.packages'
6702 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6702 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6703 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6703 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6704 ··tags:6704 ··tags:
6705 ··-·CCE-85690-66705 ··-·CCE-85690-6
6706 ··-·CJIS-5.4.1.16706 ··-·CJIS-5.4.1.1
6707 ··-·DISA-STIG-SLES-15-0302506707 ··-·DISA-STIG-SLES-15-030250
6708 ··-·NIST-800-171-3.1.76708 ··-·NIST-800-171-3.1.7
Offset 6847, 16 lines modifiedOffset 6847, 16 lines modified
6847 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006847 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6848 ········-F·auid!=unset·-F·key=perm_mod6848 ········-F·auid!=unset·-F·key=perm_mod
6849 ······create:·true6849 ······create:·true
6850 ······mode:·o-rwx6850 ······mode:·o-rwx
6851 ······state:·present6851 ······state:·present
6852 ····when:·syscalls_found·|·length·==·06852 ····when:·syscalls_found·|·length·==·0
6853 ··when:6853 ··when:
6854 ··-·'"audit"·in·ansible_facts.packages' 
6855 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6854 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6855 ··-·'"audit"·in·ansible_facts.packages'
6856 ··tags:6856 ··tags:
6857 ··-·CCE-85690-66857 ··-·CCE-85690-6
6858 ··-·CJIS-5.4.1.16858 ··-·CJIS-5.4.1.1
6859 ··-·DISA-STIG-SLES-15-0302506859 ··-·DISA-STIG-SLES-15-030250
6860 ··-·NIST-800-171-3.1.76860 ··-·NIST-800-171-3.1.7
6861 ··-·NIST-800-53-AU-12(a)6861 ··-·NIST-800-53-AU-12(a)
6862 ··-·NIST-800-53-AU-12(c)6862 ··-·NIST-800-53-AU-12(c)
Offset 6998, 16 lines modifiedOffset 6998, 16 lines modified
6998 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006998 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6999 ········-F·auid!=unset·-F·key=perm_mod6999 ········-F·auid!=unset·-F·key=perm_mod
7000 ······create:·true7000 ······create:·true
7001 ······mode:·o-rwx7001 ······mode:·o-rwx
7002 ······state:·present7002 ······state:·present
Max diff block lines reached; 189970/195179 bytes (97.33%) of diff not shown.
928 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-hipaa.html
    
Offset 31645, 21 lines modifiedOffset 31645, 21 lines modified
0007b9c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0007b9c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0007b9d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0007b9d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0007b9e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm10007b9e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
0007b9f0:·3936·3738·223e·3c70·7265·3e3c·636f·6465··9678"><pre><code0007b9f0:·3936·3738·223e·3c70·7265·3e3c·636f·6465··9678"><pre><code
0007ba00:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i0007ba00:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
0007ba10:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl0007ba10:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
0007ba20:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla0007ba20:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
0007ba30:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--0007ba30:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f
0007ba40:·7175·6965·7420·2d71·2061·7564·6974·2026··quiet·-q·audit·&0007ba40:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
0007ba50:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f0007ba50:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
0007ba60:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
0007ba70:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
0007ba80:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container0007ba60:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
 0007ba70:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
 0007ba80:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
0007ba90:·656e·7620·5d3b·2074·6865·6e0a·0a23·2046··env·];·then..#·F0007ba90:·6175·6469·743b·2074·6865·6e0a·0a23·2046··audit;·then..#·F
0007baa0:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the0007baa0:·6972·7374·2070·6572·666f·726d·2074·6865··irst·perform·the
0007bab0:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·0007bab0:·2072·656d·6564·6961·7469·6f6e·206f·6620···remediation·of·
0007bac0:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule0007bac0:·7468·6520·7379·7363·616c·6c20·7275·6c65··the·syscall·rule
0007bad0:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard0007bad0:·0a23·2052·6574·7269·6576·6520·6861·7264··.#·Retrieve·hard
0007bae0:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur0007bae0:·7761·7265·2061·7263·6869·7465·6374·7572··ware·architectur
0007baf0:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly0007baf0:·6520·6f66·2074·6865·2075·6e64·6572·6c79··e·of·the·underly
0007bb00:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(0007bb00:·696e·6720·7379·7374·656d·0a5b·2022·2428··ing·system.[·"$(
Offset 32546, 23 lines modifiedOffset 32546, 23 lines modified
0007f210:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r0007f210:·745f·7265·7175·6972·6564·0a20·202d·2072··t_required.··-·r
0007f220:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy0007f220:·6573·7472·6963·745f·7374·7261·7465·6779··estrict_strategy
0007f230:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar0007f230:·0a0a·2d20·6e61·6d65·3a20·5365·7420·6172··..-·name:·Set·ar
0007f240:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a0007f240:·6368·6974·6563·7475·7265·2066·6f72·2061··chitecture·for·a
0007f250:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks0007f250:·7564·6974·2063·686d·6f64·2074·6173·6b73··udit·chmod·tasks
0007f260:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···0007f260:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
0007f270:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b640007f270:·2061·7564·6974·5f61·7263·683a·2062·3634···audit_arch:·b64
0007f280:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a0007f280:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans
0007f290:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
0007f2a0:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
0007f2b0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
0007f2c0:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
0007f2d0:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
0007f2e0:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
0007f2f0:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
0007f300:·6f6e·7461·696e·6572·225d·0a20·202d·2061··ontainer"].··-·a0007f290:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 0007f2a0:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 0007f2b0:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 0007f2c0:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 0007f2d0:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
 0007f2e0:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"·
 0007f2f0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 0007f300:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
0007f310:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect0007f310:·6e73·6962·6c65·5f61·7263·6869·7465·6374··nsible_architect
0007f320:·7572·6520·3d3d·2022·6161·7263·6836·3422··ure·==·"aarch64"0007f320:·7572·6520·3d3d·2022·6161·7263·6836·3422··ure·==·"aarch64"
0007f330:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch0007f330:·206f·7220·616e·7369·626c·655f·6172·6368···or·ansible_arch
0007f340:·6974·6563·7475·7265·203d·3d20·2270·7063··itecture·==·"ppc0007f340:·6974·6563·7475·7265·203d·3d20·2270·7063··itecture·==·"ppc
0007f350:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a0007f350:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a
0007f360:·7263·6869·7465·6374·7572·650a·2020·2020··rchitecture.····0007f360:·7263·6869·7465·6374·7572·650a·2020·2020··rchitecture.····
0007f370:·3d3d·2022·7070·6336·346c·6522·206f·7220··==·"ppc64le"·or·0007f370:·3d3d·2022·7070·6336·346c·6522·206f·7220··==·"ppc64le"·or·
Offset 32877, 23 lines modifiedOffset 32877, 23 lines modified
000806c0:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····000806c0:·793d·7065·726d·5f6d·6f64·0a20·2020·2020··y=perm_mod.·····
000806d0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··000806d0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.··
000806e0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.000806e0:·2020·2020·6d6f·6465·3a20·6f2d·7277·780a······mode:·o-rwx.
000806f0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre000806f0:·2020·2020·2020·7374·6174·653a·2070·7265········state:·pre
00080700:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s00080700:·7365·6e74·0a20·2020·2077·6865·6e3a·2073··sent.····when:·s
00080710:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·00080710:·7973·6361·6c6c·735f·666f·756e·6420·7c20··yscalls_found·|·
00080720:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh00080720:·6c65·6e67·7468·203d·3d20·300a·2020·7768··length·==·0.··wh
00080730:·656e·3a0a·2020·2d20·2722·6175·6469·7422··en:.··-·'"audit" 
00080740:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
00080750:·732e·7061·636b·6167·6573·270a·2020·2d20··s.packages'.··-· 
00080760:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali 
00080770:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not· 
00080780:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l 
00080790:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·" 
000807a0:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai00080730:·656e·3a0a·2020·2d20·616e·7369·626c·655f··en:.··-·ansible_
 00080740:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t
 00080750:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc
 00080760:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op
 00080770:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman",
 00080780:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··
 00080790:·2d20·2722·6175·6469·7422·2069·6e20·616e··-·'"audit"·in·an
 000807a0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
000807b0:·6e65·7222·5d0a·2020·7461·6773·3a0a·2020··ner"].··tags:.··000807b0:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··
000807c0:·2d20·4343·452d·3835·3639·332d·300a·2020··-·CCE-85693-0.··000807c0:·2d20·4343·452d·3835·3639·332d·300a·2020··-·CCE-85693-0.··
000807d0:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·000807d0:·2d20·434a·4953·2d35·2e34·2e31·2e31·0a20··-·CJIS-5.4.1.1.·
000807e0:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE000807e0:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE
000807f0:·532d·3135·2d30·3330·3239·300a·2020·2d20··S-15-030290.··-·000807f0:·532d·3135·2d30·3330·3239·300a·2020·2d20··S-15-030290.··-·
00080800:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.100080800:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.1
00080810:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-00080810:·2e37·0a20·202d·204e·4953·542d·3830·302d··.7.··-·NIST-800-
00080820:·3533·2d41·552d·3132·2861·290a·2020·2d20··53-AU-12(a).··-·00080820:·3533·2d41·552d·3132·2861·290a·2020·2d20··53-AU-12(a).··-·
Offset 33196, 23 lines modifiedOffset 33196, 23 lines modified
00081ab0:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···00081ab0:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···
00081ac0:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.00081ac0:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.
00081ad0:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw00081ad0:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw
00081ae0:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p00081ae0:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p
00081af0:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:00081af0:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:
00081b00:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·00081b00:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·
00081b10:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··00081b10:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··
00081b20:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi00081b20:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
00081b30:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
00081b40:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
00081b50:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
00081b60:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
00081b70:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
00081b80:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
00081b90:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont00081b30:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 00081b40:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 00081b50:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 00081b60:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 00081b70:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 00081b80:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 00081b90:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
00081ba0:·6169·6e65·7222·5d0a·2020·2d20·6175·6469··ainer"].··-·audi00081ba0:·636b·6167·6573·270a·2020·2d20·6175·6469··ckages'.··-·audi
00081bb0:·745f·6172·6368·203d·3d20·2262·3634·220a··t_arch·==·"b64".00081bb0:·745f·6172·6368·203d·3d20·2262·3634·220a··t_arch·==·"b64".
00081bc0:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE-00081bc0:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE-
00081bd0:·3835·3639·332d·300a·2020·2d20·434a·4953··85693-0.··-·CJIS00081bd0:·3835·3639·332d·300a·2020·2d20·434a·4953··85693-0.··-·CJIS
00081be0:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS00081be0:·2d35·2e34·2e31·2e31·0a20·202d·2044·4953··-5.4.1.1.··-·DIS
00081bf0:·412d·5354·4947·2d53·4c45·532d·3135·2d30··A-STIG-SLES-15-000081bf0:·412d·5354·4947·2d53·4c45·532d·3135·2d30··A-STIG-SLES-15-0
00081c00:·3330·3239·300a·2020·2d20·4e49·5354·2d38··30290.··-·NIST-800081c00:·3330·3239·300a·2020·2d20·4e49·5354·2d38··30290.··-·NIST-8
00081c10:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-00081c10:·3030·2d31·3731·2d33·2e31·2e37·0a20·202d··00-171-3.1.7.··-
Offset 34232, 20 lines modifiedOffset 34232, 20 lines modified
00085b70:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00085b70:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00085b80:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00085b80:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00085b90:·643d·2269·646d·3139·3834·3222·3e3c·7072··d="idm19842"><pr00085b90:·643d·2269·646d·3139·3834·3222·3e3c·7072··d="idm19842"><pr
00085ba0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi00085ba0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
00085bb0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica00085bb0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
00085bc0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert00085bc0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
00085bd0:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if00085bd0:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
00085be0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
00085bf0:·6175·6469·7420·2661·6d70·3b26·616d·703b··audit·&amp;&amp; 
00085c00:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker00085be0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
00085c10:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;00085bf0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
Max diff block lines reached; 706640/716637 bytes (98.61%) of diff not shown.
228 KB
html2text {}
    
Offset 2359, 15 lines modifiedOffset 2359, 15 lines modified
2359 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-2359 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
2360 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,2360 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
2361 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-2361 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
2362 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-2362 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-
2363 ············234928r622137_rule2363 ············234928r622137_rule
2364 Remediation_Shell_script_⇲2364 Remediation_Shell_script_⇲
2365 #·Remediation·is·applicable·only·in·certain·platforms2365 #·Remediation·is·applicable·only·in·certain·platforms
2366 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then2366 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
2367 #·First·perform·the·remediation·of·the·syscall·rule2367 #·First·perform·the·remediation·of·the·syscall·rule
2368 #·Retrieve·hardware·architecture·of·the·underlying·system2368 #·Retrieve·hardware·architecture·of·the·underlying·system
2369 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")2369 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
2370 for·ARCH·in·"${RULE_ARCHS[@]}"2370 for·ARCH·in·"${RULE_ARCHS[@]}"
2371 do2371 do
Offset 2728, 16 lines modifiedOffset 2728, 16 lines modified
2728 ··-·reboot_required2728 ··-·reboot_required
2729 ··-·restrict_strategy2729 ··-·restrict_strategy
  
2730 -·name:·Set·architecture·for·audit·chmod·tasks2730 -·name:·Set·architecture·for·audit·chmod·tasks
2731 ··set_fact:2731 ··set_fact:
2732 ····audit_arch:·b642732 ····audit_arch:·b64
2733 ··when:2733 ··when:
2734 ··-·'"audit"·in·ansible_facts.packages' 
2735 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2734 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2735 ··-·'"audit"·in·ansible_facts.packages'
2736 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture2736 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
2737 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"2737 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
2738 ··tags:2738 ··tags:
2739 ··-·CCE-85693-02739 ··-·CCE-85693-0
2740 ··-·CJIS-5.4.1.12740 ··-·CJIS-5.4.1.1
2741 ··-·DISA-STIG-SLES-15-0302902741 ··-·DISA-STIG-SLES-15-030290
2742 ··-·NIST-800-171-3.1.72742 ··-·NIST-800-171-3.1.7
Offset 2879, 16 lines modifiedOffset 2879, 16 lines modified
2879 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10002879 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
2880 ········-F·auid!=unset·-F·key=perm_mod2880 ········-F·auid!=unset·-F·key=perm_mod
2881 ······create:·true2881 ······create:·true
2882 ······mode:·o-rwx2882 ······mode:·o-rwx
2883 ······state:·present2883 ······state:·present
2884 ····when:·syscalls_found·|·length·==·02884 ····when:·syscalls_found·|·length·==·0
2885 ··when:2885 ··when:
2886 ··-·'"audit"·in·ansible_facts.packages' 
2887 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2886 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2887 ··-·'"audit"·in·ansible_facts.packages'
2888 ··tags:2888 ··tags:
2889 ··-·CCE-85693-02889 ··-·CCE-85693-0
2890 ··-·CJIS-5.4.1.12890 ··-·CJIS-5.4.1.1
2891 ··-·DISA-STIG-SLES-15-0302902891 ··-·DISA-STIG-SLES-15-030290
2892 ··-·NIST-800-171-3.1.72892 ··-·NIST-800-171-3.1.7
2893 ··-·NIST-800-53-AU-12(a)2893 ··-·NIST-800-53-AU-12(a)
2894 ··-·NIST-800-53-AU-12(c)2894 ··-·NIST-800-53-AU-12(c)
Offset 3028, 16 lines modifiedOffset 3028, 16 lines modified
3028 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003028 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3029 ········-F·auid!=unset·-F·key=perm_mod3029 ········-F·auid!=unset·-F·key=perm_mod
3030 ······create:·true3030 ······create:·true
3031 ······mode:·o-rwx3031 ······mode:·o-rwx
3032 ······state:·present3032 ······state:·present
3033 ····when:·syscalls_found·|·length·==·03033 ····when:·syscalls_found·|·length·==·0
3034 ··when:3034 ··when:
3035 ··-·'"audit"·in·ansible_facts.packages' 
3036 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3035 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3036 ··-·'"audit"·in·ansible_facts.packages'
3037 ··-·audit_arch·==·"b64"3037 ··-·audit_arch·==·"b64"
3038 ··tags:3038 ··tags:
3039 ··-·CCE-85693-03039 ··-·CCE-85693-0
3040 ··-·CJIS-5.4.1.13040 ··-·CJIS-5.4.1.1
3041 ··-·DISA-STIG-SLES-15-0302903041 ··-·DISA-STIG-SLES-15-030290
3042 ··-·NIST-800-171-3.1.73042 ··-·NIST-800-171-3.1.7
3043 ··-·NIST-800-53-AU-12(a)3043 ··-·NIST-800-53-AU-12(a)
Offset 3090, 15 lines modifiedOffset 3090, 15 lines modified
3090 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-3090 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
3091 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,3091 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
3092 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-3092 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
3093 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-3093 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-
3094 ············030250,·4.1.9,·SV-234924r622137_rule3094 ············030250,·4.1.9,·SV-234924r622137_rule
3095 Remediation_Shell_script_⇲3095 Remediation_Shell_script_⇲
3096 #·Remediation·is·applicable·only·in·certain·platforms3096 #·Remediation·is·applicable·only·in·certain·platforms
3097 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then3097 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
3098 #·First·perform·the·remediation·of·the·syscall·rule3098 #·First·perform·the·remediation·of·the·syscall·rule
3099 #·Retrieve·hardware·architecture·of·the·underlying·system3099 #·Retrieve·hardware·architecture·of·the·underlying·system
3100 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")3100 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
3101 for·ARCH·in·"${RULE_ARCHS[@]}"3101 for·ARCH·in·"${RULE_ARCHS[@]}"
3102 do3102 do
Offset 3459, 16 lines modifiedOffset 3459, 16 lines modified
3459 ··-·reboot_required3459 ··-·reboot_required
3460 ··-·restrict_strategy3460 ··-·restrict_strategy
  
3461 -·name:·Set·architecture·for·audit·chown·tasks3461 -·name:·Set·architecture·for·audit·chown·tasks
3462 ··set_fact:3462 ··set_fact:
3463 ····audit_arch:·b643463 ····audit_arch:·b64
3464 ··when:3464 ··when:
3465 ··-·'"audit"·in·ansible_facts.packages' 
3466 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3465 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3466 ··-·'"audit"·in·ansible_facts.packages'
3467 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture3467 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
3468 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"3468 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
3469 ··tags:3469 ··tags:
3470 ··-·CCE-85690-63470 ··-·CCE-85690-6
3471 ··-·CJIS-5.4.1.13471 ··-·CJIS-5.4.1.1
3472 ··-·DISA-STIG-SLES-15-0302503472 ··-·DISA-STIG-SLES-15-030250
3473 ··-·NIST-800-171-3.1.73473 ··-·NIST-800-171-3.1.7
Offset 3612, 16 lines modifiedOffset 3612, 16 lines modified
3612 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003612 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3613 ········-F·auid!=unset·-F·key=perm_mod3613 ········-F·auid!=unset·-F·key=perm_mod
3614 ······create:·true3614 ······create:·true
3615 ······mode:·o-rwx3615 ······mode:·o-rwx
3616 ······state:·present3616 ······state:·present
3617 ····when:·syscalls_found·|·length·==·03617 ····when:·syscalls_found·|·length·==·0
3618 ··when:3618 ··when:
3619 ··-·'"audit"·in·ansible_facts.packages' 
3620 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3619 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3620 ··-·'"audit"·in·ansible_facts.packages'
3621 ··tags:3621 ··tags:
3622 ··-·CCE-85690-63622 ··-·CCE-85690-6
3623 ··-·CJIS-5.4.1.13623 ··-·CJIS-5.4.1.1
3624 ··-·DISA-STIG-SLES-15-0302503624 ··-·DISA-STIG-SLES-15-030250
3625 ··-·NIST-800-171-3.1.73625 ··-·NIST-800-171-3.1.7
3626 ··-·NIST-800-53-AU-12(a)3626 ··-·NIST-800-53-AU-12(a)
3627 ··-·NIST-800-53-AU-12(c)3627 ··-·NIST-800-53-AU-12(c)
Offset 3763, 16 lines modifiedOffset 3763, 16 lines modified
3763 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10003763 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
3764 ········-F·auid!=unset·-F·key=perm_mod3764 ········-F·auid!=unset·-F·key=perm_mod
3765 ······create:·true3765 ······create:·true
3766 ······mode:·o-rwx3766 ······mode:·o-rwx
3767 ······state:·present3767 ······state:·present
Max diff block lines reached; 228368/233577 bytes (97.77%) of diff not shown.
958 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pci-dss-4.html
    
Offset 68935, 21 lines modifiedOffset 68935, 21 lines modified
0010d460:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0010d460:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0010d470:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0010d470:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0010d480:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0010d480:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0010d490:·6d31·3936·3738·223e·3c70·7265·3e3c·636f··m19678"><pre><co0010d490:·6d31·3936·3738·223e·3c70·7265·3e3c·636f··m19678"><pre><co
0010d4a0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation0010d4a0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
0010d4b0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o0010d4b0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
0010d4c0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p0010d4c0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
0010d4d0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·0010d4d0:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
0010d4e0:·2d2d·7175·6965·7420·2d71·2061·7564·6974··--quiet·-q·audit0010d4e0:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
0010d4f0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·0010d4f0:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
0010d500:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
0010d510:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
0010d520:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain0010d500:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
0010d530:·6572·656e·7620·5d3b·2074·6865·6e0a·0a23··erenv·];·then..#0010d510:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
 0010d520:·703b·2072·706d·202d·2d71·7569·6574·202d··p;·rpm·--quiet·-
 0010d530:·7120·6175·6469·743b·2074·6865·6e0a·0a23··q·audit;·then..#
0010d540:·2046·6972·7374·2070·6572·666f·726d·2074···First·perform·t0010d540:·2046·6972·7374·2070·6572·666f·726d·2074···First·perform·t
0010d550:·6865·2072·656d·6564·6961·7469·6f6e·206f··he·remediation·o0010d550:·6865·2072·656d·6564·6961·7469·6f6e·206f··he·remediation·o
0010d560:·6620·7468·6520·7379·7363·616c·6c20·7275··f·the·syscall·ru0010d560:·6620·7468·6520·7379·7363·616c·6c20·7275··f·the·syscall·ru
0010d570:·6c65·0a23·2052·6574·7269·6576·6520·6861··le.#·Retrieve·ha0010d570:·6c65·0a23·2052·6574·7269·6576·6520·6861··le.#·Retrieve·ha
0010d580:·7264·7761·7265·2061·7263·6869·7465·6374··rdware·architect0010d580:·7264·7761·7265·2061·7263·6869·7465·6374··rdware·architect
0010d590:·7572·6520·6f66·2074·6865·2075·6e64·6572··ure·of·the·under0010d590:·7572·6520·6f66·2074·6865·2075·6e64·6572··ure·of·the·under
0010d5a0:·6c79·696e·6720·7379·7374·656d·0a5b·2022··lying·system.[·"0010d5a0:·6c79·696e·6720·7379·7374·656d·0a5b·2022··lying·system.[·"
Offset 69836, 23 lines modifiedOffset 69836, 23 lines modified
00110cb0:·6f6f·745f·7265·7175·6972·6564·0a20·202d··oot_required.··-00110cb0:·6f6f·745f·7265·7175·6972·6564·0a20·202d··oot_required.··-
00110cc0:·2072·6573·7472·6963·745f·7374·7261·7465···restrict_strate00110cc0:·2072·6573·7472·6963·745f·7374·7261·7465···restrict_strate
00110cd0:·6779·0a0a·2d20·6e61·6d65·3a20·5365·7420··gy..-·name:·Set·00110cd0:·6779·0a0a·2d20·6e61·6d65·3a20·5365·7420··gy..-·name:·Set·
00110ce0:·6172·6368·6974·6563·7475·7265·2066·6f72··architecture·for00110ce0:·6172·6368·6974·6563·7475·7265·2066·6f72··architecture·for
00110cf0:·2061·7564·6974·2063·686d·6f64·2074·6173···audit·chmod·tas00110cf0:·2061·7564·6974·2063·686d·6f64·2074·6173···audit·chmod·tas
00110d00:·6b73·0a20·2073·6574·5f66·6163·743a·0a20··ks.··set_fact:.·00110d00:·6b73·0a20·2073·6574·5f66·6163·743a·0a20··ks.··set_fact:.·
00110d10:·2020·2061·7564·6974·5f61·7263·683a·2062·····audit_arch:·b00110d10:·2020·2061·7564·6974·5f61·7263·683a·2062·····audit_arch:·b
00110d20:·3634·0a20·2077·6865·6e3a·0a20·202d·2027··64.··when:.··-·'00110d20:·3634·0a20·2077·6865·6e3a·0a20·202d·2061··64.··when:.··-·a
00110d30:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib 
00110d40:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
00110d50:·7327·0a20·202d·2061·6e73·6962·6c65·5f76··s'.··-·ansible_v 
00110d60:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty 
00110d70:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock 
00110d80:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope 
00110d90:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",· 
00110da0:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-00110d30:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
 00110d40:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
 00110d50:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
 00110d60:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
 00110d70:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
 00110d80:·6572·225d·0a20·202d·2027·2261·7564·6974··er"].··-·'"audit
 00110d90:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 00110da0:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··-
00110db0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite00110db0:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite
00110dc0:·6374·7572·6520·3d3d·2022·6161·7263·6836··cture·==·"aarch600110dc0:·6374·7572·6520·3d3d·2022·6161·7263·6836··cture·==·"aarch6
00110dd0:·3422·206f·7220·616e·7369·626c·655f·6172··4"·or·ansible_ar00110dd0:·3422·206f·7220·616e·7369·626c·655f·6172··4"·or·ansible_ar
00110de0:·6368·6974·6563·7475·7265·203d·3d20·2270··chitecture·==·"p00110de0:·6368·6974·6563·7475·7265·203d·3d20·2270··chitecture·==·"p
00110df0:·7063·3634·2220·6f72·2061·6e73·6962·6c65··pc64"·or·ansible00110df0:·7063·3634·2220·6f72·2061·6e73·6962·6c65··pc64"·or·ansible
00110e00:·5f61·7263·6869·7465·6374·7572·650a·2020··_architecture.··00110e00:·5f61·7263·6869·7465·6374·7572·650a·2020··_architecture.··
00110e10:·2020·3d3d·2022·7070·6336·346c·6522·206f····==·"ppc64le"·o00110e10:·2020·3d3d·2022·7070·6336·346c·6522·206f····==·"ppc64le"·o
Offset 70167, 23 lines modifiedOffset 70167, 23 lines modified
00112160:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···00112160:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···
00112170:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.00112170:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.
00112180:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw00112180:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw
00112190:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p00112190:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p
001121a0:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:001121a0:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:
001121b0:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·001121b0:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·
001121c0:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··001121c0:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··
001121d0:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi001121d0:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
001121e0:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
001121f0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
00112200:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
00112210:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
00112220:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
00112230:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
00112240:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont001121e0:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 001121f0:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 00112200:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 00112210:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 00112220:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 00112230:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 00112240:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
00112250:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.00112250:·636b·6167·6573·270a·2020·7461·6773·3a0a··ckages'.··tags:.
00112260:·2020·2d20·4343·452d·3835·3639·332d·300a····-·CCE-85693-0.00112260:·2020·2d20·4343·452d·3835·3639·332d·300a····-·CCE-85693-0.
00112270:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.100112270:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1
00112280:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S00112280:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
00112290:·4c45·532d·3135·2d30·3330·3239·300a·2020··LES-15-030290.··00112290:·4c45·532d·3135·2d30·3330·3239·300a·2020··LES-15-030290.··
001122a0:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3001122a0:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
001122b0:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80001122b0:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80
001122c0:·302d·3533·2d41·552d·3132·2861·290a·2020··0-53-AU-12(a).··001122c0:·302d·3533·2d41·552d·3132·2861·290a·2020··0-53-AU-12(a).··
Offset 70486, 23 lines modifiedOffset 70486, 23 lines modified
00113550:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·00113550:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·
00113560:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru00113560:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru
00113570:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-00113570:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-
00113580:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:00113580:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:
00113590:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe00113590:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe
001135a0:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun001135a0:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun
001135b0:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.001135b0:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.
001135c0:·2020·7768·656e·3a0a·2020·2d20·2722·6175····when:.··-·'"au001135c0:·2020·7768·656e·3a0a·2020·2d20·616e·7369····when:.··-·ansi
001135d0:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
001135e0:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
001135f0:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt 
00113600:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type· 
00113610:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker" 
00113620:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz 
00113630:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co 
00113640:·6e74·6169·6e65·7222·5d0a·2020·2d20·6175··ntainer"].··-·au001135d0:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
 001135e0:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
 001135f0:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
 00113600:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
 00113610:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
 00113620:·5d0a·2020·2d20·2722·6175·6469·7422·2069··].··-·'"audit"·i
 00113630:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 00113640:·7061·636b·6167·6573·270a·2020·2d20·6175··packages'.··-·au
00113650:·6469·745f·6172·6368·203d·3d20·2262·3634··dit_arch·==·"b6400113650:·6469·745f·6172·6368·203d·3d20·2262·3634··dit_arch·==·"b64
00113660:·220a·2020·7461·6773·3a0a·2020·2d20·4343··".··tags:.··-·CC00113660:·220a·2020·7461·6773·3a0a·2020·2d20·4343··".··tags:.··-·CC
00113670:·452d·3835·3639·332d·300a·2020·2d20·434a··E-85693-0.··-·CJ00113670:·452d·3835·3639·332d·300a·2020·2d20·434a··E-85693-0.··-·CJ
00113680:·4953·2d35·2e34·2e31·2e31·0a20·202d·2044··IS-5.4.1.1.··-·D00113680:·4953·2d35·2e34·2e31·2e31·0a20·202d·2044··IS-5.4.1.1.··-·D
00113690:·4953·412d·5354·4947·2d53·4c45·532d·3135··ISA-STIG-SLES-1500113690:·4953·412d·5354·4947·2d53·4c45·532d·3135··ISA-STIG-SLES-15
001136a0:·2d30·3330·3239·300a·2020·2d20·4e49·5354··-030290.··-·NIST001136a0:·2d30·3330·3239·300a·2020·2d20·4e49·5354··-030290.··-·NIST
001136b0:·2d38·3030·2d31·3731·2d33·2e31·2e37·0a20··-800-171-3.1.7.·001136b0:·2d38·3030·2d31·3731·2d33·2e31·2e37·0a20··-800-171-3.1.7.·
Offset 71522, 20 lines modifiedOffset 71522, 20 lines modified
00117610:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00117610:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00117620:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00117620:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00117630:·2069·643d·2269·646d·3139·3834·3222·3e3c···id="idm19842"><00117630:·2069·643d·2269·646d·3139·3834·3222·3e3c···id="idm19842"><
00117640:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme00117640:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
00117650:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli00117650:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
00117660:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce00117660:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
00117670:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.00117670:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
00117680:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
00117690:·7120·6175·6469·7420·2661·6d70·3b26·616d··q·audit·&amp;&am 
001176a0:·703b·205b·2021·202d·6620·2f2e·646f·636b··p;·[·!·-f·/.dock00117680:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
001176b0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am00117690:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
Max diff block lines reached; 730070/740067 bytes (98.65%) of diff not shown.
236 KB
html2text {}
    
Offset 10731, 15 lines modifiedOffset 10731, 15 lines modified
10731 ············AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,10731 ············AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,
10732 ············PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,10732 ············PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,
10733 ············SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,10733 ············SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,
10734 ············SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,10734 ············SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,
10735 ············SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-234928r622137_rule10735 ············SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-234928r622137_rule
10736 Remediation_Shell_script_⇲10736 Remediation_Shell_script_⇲
10737 #·Remediation·is·applicable·only·in·certain·platforms10737 #·Remediation·is·applicable·only·in·certain·platforms
10738 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then10738 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
10739 #·First·perform·the·remediation·of·the·syscall·rule10739 #·First·perform·the·remediation·of·the·syscall·rule
10740 #·Retrieve·hardware·architecture·of·the·underlying·system10740 #·Retrieve·hardware·architecture·of·the·underlying·system
10741 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")10741 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
10742 for·ARCH·in·"${RULE_ARCHS[@]}"10742 for·ARCH·in·"${RULE_ARCHS[@]}"
10743 do10743 do
Offset 11098, 16 lines modifiedOffset 11098, 16 lines modified
11098 ··-·reboot_required11098 ··-·reboot_required
11099 ··-·restrict_strategy11099 ··-·restrict_strategy
  
11100 -·name:·Set·architecture·for·audit·chmod·tasks11100 -·name:·Set·architecture·for·audit·chmod·tasks
11101 ··set_fact:11101 ··set_fact:
11102 ····audit_arch:·b6411102 ····audit_arch:·b64
11103 ··when:11103 ··when:
11104 ··-·'"audit"·in·ansible_facts.packages' 
11105 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11104 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11105 ··-·'"audit"·in·ansible_facts.packages'
11106 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture11106 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
11107 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"11107 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
11108 ··tags:11108 ··tags:
11109 ··-·CCE-85693-011109 ··-·CCE-85693-0
11110 ··-·CJIS-5.4.1.111110 ··-·CJIS-5.4.1.1
11111 ··-·DISA-STIG-SLES-15-03029011111 ··-·DISA-STIG-SLES-15-030290
11112 ··-·NIST-800-171-3.1.711112 ··-·NIST-800-171-3.1.7
Offset 11249, 16 lines modifiedOffset 11249, 16 lines modified
11249 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011249 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11250 ········-F·auid!=unset·-F·key=perm_mod11250 ········-F·auid!=unset·-F·key=perm_mod
11251 ······create:·true11251 ······create:·true
11252 ······mode:·o-rwx11252 ······mode:·o-rwx
11253 ······state:·present11253 ······state:·present
11254 ····when:·syscalls_found·|·length·==·011254 ····when:·syscalls_found·|·length·==·0
11255 ··when:11255 ··when:
11256 ··-·'"audit"·in·ansible_facts.packages' 
11257 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11256 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11257 ··-·'"audit"·in·ansible_facts.packages'
11258 ··tags:11258 ··tags:
11259 ··-·CCE-85693-011259 ··-·CCE-85693-0
11260 ··-·CJIS-5.4.1.111260 ··-·CJIS-5.4.1.1
11261 ··-·DISA-STIG-SLES-15-03029011261 ··-·DISA-STIG-SLES-15-030290
11262 ··-·NIST-800-171-3.1.711262 ··-·NIST-800-171-3.1.7
11263 ··-·NIST-800-53-AU-12(a)11263 ··-·NIST-800-53-AU-12(a)
11264 ··-·NIST-800-53-AU-12(c)11264 ··-·NIST-800-53-AU-12(c)
Offset 11398, 16 lines modifiedOffset 11398, 16 lines modified
11398 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011398 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11399 ········-F·auid!=unset·-F·key=perm_mod11399 ········-F·auid!=unset·-F·key=perm_mod
11400 ······create:·true11400 ······create:·true
11401 ······mode:·o-rwx11401 ······mode:·o-rwx
11402 ······state:·present11402 ······state:·present
11403 ····when:·syscalls_found·|·length·==·011403 ····when:·syscalls_found·|·length·==·0
11404 ··when:11404 ··when:
11405 ··-·'"audit"·in·ansible_facts.packages' 
11406 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11405 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11406 ··-·'"audit"·in·ansible_facts.packages'
11407 ··-·audit_arch·==·"b64"11407 ··-·audit_arch·==·"b64"
11408 ··tags:11408 ··tags:
11409 ··-·CCE-85693-011409 ··-·CCE-85693-0
11410 ··-·CJIS-5.4.1.111410 ··-·CJIS-5.4.1.1
11411 ··-·DISA-STIG-SLES-15-03029011411 ··-·DISA-STIG-SLES-15-030290
11412 ··-·NIST-800-171-3.1.711412 ··-·NIST-800-171-3.1.7
11413 ··-·NIST-800-53-AU-12(a)11413 ··-·NIST-800-53-AU-12(a)
Offset 11458, 15 lines modifiedOffset 11458, 15 lines modified
11458 ············AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,11458 ············AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,
11459 ············PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,11459 ············PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,
11460 ············SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,11460 ············SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,
11461 ············SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,11461 ············SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,
11462 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030250,·4.1.9,·SV-234924r622137_rule11462 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030250,·4.1.9,·SV-234924r622137_rule
11463 Remediation_Shell_script_⇲11463 Remediation_Shell_script_⇲
11464 #·Remediation·is·applicable·only·in·certain·platforms11464 #·Remediation·is·applicable·only·in·certain·platforms
11465 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then11465 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
11466 #·First·perform·the·remediation·of·the·syscall·rule11466 #·First·perform·the·remediation·of·the·syscall·rule
11467 #·Retrieve·hardware·architecture·of·the·underlying·system11467 #·Retrieve·hardware·architecture·of·the·underlying·system
11468 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")11468 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
11469 for·ARCH·in·"${RULE_ARCHS[@]}"11469 for·ARCH·in·"${RULE_ARCHS[@]}"
11470 do11470 do
Offset 11825, 16 lines modifiedOffset 11825, 16 lines modified
11825 ··-·reboot_required11825 ··-·reboot_required
11826 ··-·restrict_strategy11826 ··-·restrict_strategy
  
11827 -·name:·Set·architecture·for·audit·chown·tasks11827 -·name:·Set·architecture·for·audit·chown·tasks
11828 ··set_fact:11828 ··set_fact:
11829 ····audit_arch:·b6411829 ····audit_arch:·b64
11830 ··when:11830 ··when:
11831 ··-·'"audit"·in·ansible_facts.packages' 
11832 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11831 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11832 ··-·'"audit"·in·ansible_facts.packages'
11833 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture11833 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
11834 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"11834 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
11835 ··tags:11835 ··tags:
11836 ··-·CCE-85690-611836 ··-·CCE-85690-6
11837 ··-·CJIS-5.4.1.111837 ··-·CJIS-5.4.1.1
11838 ··-·DISA-STIG-SLES-15-03025011838 ··-·DISA-STIG-SLES-15-030250
11839 ··-·NIST-800-171-3.1.711839 ··-·NIST-800-171-3.1.7
Offset 11978, 16 lines modifiedOffset 11978, 16 lines modified
11978 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011978 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11979 ········-F·auid!=unset·-F·key=perm_mod11979 ········-F·auid!=unset·-F·key=perm_mod
11980 ······create:·true11980 ······create:·true
11981 ······mode:·o-rwx11981 ······mode:·o-rwx
11982 ······state:·present11982 ······state:·present
11983 ····when:·syscalls_found·|·length·==·011983 ····when:·syscalls_found·|·length·==·0
11984 ··when:11984 ··when:
11985 ··-·'"audit"·in·ansible_facts.packages' 
11986 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11985 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11986 ··-·'"audit"·in·ansible_facts.packages'
11987 ··tags:11987 ··tags:
11988 ··-·CCE-85690-611988 ··-·CCE-85690-6
11989 ··-·CJIS-5.4.1.111989 ··-·CJIS-5.4.1.1
11990 ··-·DISA-STIG-SLES-15-03025011990 ··-·DISA-STIG-SLES-15-030250
11991 ··-·NIST-800-171-3.1.711991 ··-·NIST-800-171-3.1.7
11992 ··-·NIST-800-53-AU-12(a)11992 ··-·NIST-800-53-AU-12(a)
11993 ··-·NIST-800-53-AU-12(c)11993 ··-·NIST-800-53-AU-12(c)
Offset 12129, 16 lines modifiedOffset 12129, 16 lines modified
12129 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012129 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12130 ········-F·auid!=unset·-F·key=perm_mod12130 ········-F·auid!=unset·-F·key=perm_mod
12131 ······create:·true12131 ······create:·true
12132 ······mode:·o-rwx12132 ······mode:·o-rwx
12133 ······state:·present12133 ······state:·present
Max diff block lines reached; 235862/241277 bytes (97.76%) of diff not shown.
957 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pci-dss.html
    
Offset 56583, 21 lines modifiedOffset 56583, 21 lines modified
000dd060:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class000dd060:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
000dd070:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse000dd070:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
000dd080:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i000dd080:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
000dd090:·646d·3139·3637·3822·3e3c·7072·653e·3c63··dm19678"><pre><c000dd090:·646d·3139·3637·3822·3e3c·7072·653e·3c63··dm19678"><pre><c
000dd0a0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio000dd0a0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
000dd0b0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·000dd0b0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
000dd0c0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·000dd0c0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
000dd0d0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm000dd0d0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
000dd0e0:·202d·2d71·7569·6574·202d·7120·6175·6469···--quiet·-q·audi 
000dd0f0:·7420·2661·6d70·3b26·616d·703b·205b·2021··t·&amp;&amp;·[·! 
000dd100:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·000dd0e0:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
000dd110:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!000dd0f0:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
000dd120:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai000dd100:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
000dd130:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..000dd110:·6e65·7265·6e76·205d·2026·616d·703b·2661··nerenv·]·&amp;&a
 000dd120:·6d70·3b20·7270·6d20·2d2d·7175·6965·7420··mp;·rpm·--quiet·
 000dd130:·2d71·2061·7564·6974·3b20·7468·656e·0a0a··-q·audit;·then..
000dd140:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·000dd140:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·
000dd150:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·000dd150:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·
000dd160:·6f66·2074·6865·2073·7973·6361·6c6c·2072··of·the·syscall·r000dd160:·6f66·2074·6865·2073·7973·6361·6c6c·2072··of·the·syscall·r
000dd170:·756c·650a·2320·5265·7472·6965·7665·2068··ule.#·Retrieve·h000dd170:·756c·650a·2320·5265·7472·6965·7665·2068··ule.#·Retrieve·h
000dd180:·6172·6477·6172·6520·6172·6368·6974·6563··ardware·architec000dd180:·6172·6477·6172·6520·6172·6368·6974·6563··ardware·architec
000dd190:·7475·7265·206f·6620·7468·6520·756e·6465··ture·of·the·unde000dd190:·7475·7265·206f·6620·7468·6520·756e·6465··ture·of·the·unde
000dd1a0:·726c·7969·6e67·2073·7973·7465·6d0a·5b20··rlying·system.[·000dd1a0:·726c·7969·6e67·2073·7973·7465·6d0a·5b20··rlying·system.[·
Offset 57485, 22 lines modifiedOffset 57485, 22 lines modified
000e08c0:·2d20·7265·7374·7269·6374·5f73·7472·6174··-·restrict_strat000e08c0:·2d20·7265·7374·7269·6374·5f73·7472·6174··-·restrict_strat
000e08d0:·6567·790a·0a2d·206e·616d·653a·2053·6574··egy..-·name:·Set000e08d0:·6567·790a·0a2d·206e·616d·653a·2053·6574··egy..-·name:·Set
000e08e0:·2061·7263·6869·7465·6374·7572·6520·666f···architecture·fo000e08e0:·2061·7263·6869·7465·6374·7572·6520·666f···architecture·fo
000e08f0:·7220·6175·6469·7420·6368·6d6f·6420·7461··r·audit·chmod·ta000e08f0:·7220·6175·6469·7420·6368·6d6f·6420·7461··r·audit·chmod·ta
000e0900:·736b·730a·2020·7365·745f·6661·6374·3a0a··sks.··set_fact:.000e0900:·736b·730a·2020·7365·745f·6661·6374·3a0a··sks.··set_fact:.
000e0910:·2020·2020·6175·6469·745f·6172·6368·3a20······audit_arch:·000e0910:·2020·2020·6175·6469·745f·6172·6368·3a20······audit_arch:·
000e0920:·6236·340a·2020·7768·656e·3a0a·2020·2d20··b64.··when:.··-·000e0920:·6236·340a·2020·7768·656e·3a0a·2020·2d20··b64.··when:.··-·
000e0930:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi 
000e0940:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag 
000e0950:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_ 
000e0960:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
000e0970:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
000e0980:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
000e0990:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
000e09a0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··000e0930:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 000e0940:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 000e0950:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 000e0960:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 000e0970:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
 000e0980:·6e65·7222·5d0a·2020·2d20·2722·6175·6469··ner"].··-·'"audi
 000e0990:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa
 000e09a0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
000e09b0:·2d20·616e·7369·626c·655f·6172·6368·6974··-·ansible_archit000e09b0:·2d20·616e·7369·626c·655f·6172·6368·6974··-·ansible_archit
000e09c0:·6563·7475·7265·203d·3d20·2261·6172·6368··ecture·==·"aarch000e09c0:·6563·7475·7265·203d·3d20·2261·6172·6368··ecture·==·"aarch
000e09d0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a000e09d0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a
000e09e0:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"000e09e0:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"
000e09f0:·7070·6336·3422·206f·7220·616e·7369·626c··ppc64"·or·ansibl000e09f0:·7070·6336·3422·206f·7220·616e·7369·626c··ppc64"·or·ansibl
000e0a00:·655f·6172·6368·6974·6563·7475·7265·0a20··e_architecture.·000e0a00:·655f·6172·6368·6974·6563·7475·7265·0a20··e_architecture.·
000e0a10:·2020·203d·3d20·2270·7063·3634·6c65·2220·····==·"ppc64le"·000e0a10:·2020·203d·3d20·2270·7063·3634·6c65·2220·····==·"ppc64le"·
Offset 57815, 23 lines modifiedOffset 57815, 23 lines modified
000e1d60:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··000e1d60:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··
000e1d70:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true000e1d70:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true
000e1d80:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r000e1d80:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r
000e1d90:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·000e1d90:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·
000e1da0:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when000e1da0:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when
000e1db0:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found000e1db0:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found
000e1dc0:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·000e1dc0:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·
000e1dd0:·2077·6865·6e3a·0a20·202d·2027·2261·7564···when:.··-·'"aud000e1dd0:·2077·6865·6e3a·0a20·202d·2061·6e73·6962···when:.··-·ansib
000e1de0:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f 
000e1df0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
000e1e00:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu 
000e1e10:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
000e1e20:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
000e1e30:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
000e1e40:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
000e1e50:·7461·696e·6572·225d·0a20·2074·6167·733a··tainer"].··tags:000e1de0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 000e1df0:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 000e1e00:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 000e1e10:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 000e1e20:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
 000e1e30:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 000e1e40:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 000e1e50:·6163·6b61·6765·7327·0a20·2074·6167·733a··ackages'.··tags:
000e1e60:·0a20·202d·2043·4345·2d38·3536·3933·2d30··.··-·CCE-85693-0000e1e60:·0a20·202d·2043·4345·2d38·3536·3933·2d30··.··-·CCE-85693-0
000e1e70:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.000e1e70:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.
000e1e80:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-000e1e80:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-
000e1e90:·534c·4553·2d31·352d·3033·3032·3930·0a20··SLES-15-030290.·000e1e90:·534c·4553·2d31·352d·3033·3032·3930·0a20··SLES-15-030290.·
000e1ea0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-000e1ea0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
000e1eb0:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8000e1eb0:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8
000e1ec0:·3030·2d35·332d·4155·2d31·3228·6129·0a20··00-53-AU-12(a).·000e1ec0:·3030·2d35·332d·4155·2d31·3228·6129·0a20··00-53-AU-12(a).·
Offset 58134, 23 lines modifiedOffset 58134, 23 lines modified
000e3150:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.000e3150:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.
000e3160:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr000e3160:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr
000e3170:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o000e3170:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o
000e3180:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state000e3180:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state
000e3190:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh000e3190:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh
000e31a0:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou000e31a0:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou
000e31b0:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0000e31b0:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0
000e31c0:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a000e31c0:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans
000e31d0:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
000e31e0:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
000e31f0:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
000e3200:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
000e3210:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
000e3220:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
000e3230:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
000e3240:·6f6e·7461·696e·6572·225d·0a20·202d·2061··ontainer"].··-·a000e31d0:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 000e31e0:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 000e31f0:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 000e3200:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 000e3210:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
 000e3220:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"·
 000e3230:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 000e3240:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
000e3250:·7564·6974·5f61·7263·6820·3d3d·2022·6236··udit_arch·==·"b6000e3250:·7564·6974·5f61·7263·6820·3d3d·2022·6236··udit_arch·==·"b6
000e3260:·3422·0a20·2074·6167·733a·0a20·202d·2043··4".··tags:.··-·C000e3260:·3422·0a20·2074·6167·733a·0a20·202d·2043··4".··tags:.··-·C
000e3270:·4345·2d38·3536·3933·2d30·0a20·202d·2043··CE-85693-0.··-·C000e3270:·4345·2d38·3536·3933·2d30·0a20·202d·2043··CE-85693-0.··-·C
000e3280:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·000e3280:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·
000e3290:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1000e3290:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1
000e32a0:·352d·3033·3032·3930·0a20·202d·204e·4953··5-030290.··-·NIS000e32a0:·352d·3033·3032·3930·0a20·202d·204e·4953··5-030290.··-·NIS
000e32b0:·542d·3830·302d·3137·312d·332e·312e·370a··T-800-171-3.1.7.000e32b0:·542d·3830·302d·3137·312d·332e·312e·370a··T-800-171-3.1.7.
Offset 59170, 20 lines modifiedOffset 59170, 20 lines modified
000e7210:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c000e7210:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
000e7220:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse000e7220:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
000e7230:·2220·6964·3d22·6964·6d31·3938·3432·223e··"·id="idm19842">000e7230:·2220·6964·3d22·6964·6d31·3938·3432·223e··"·id="idm19842">
000e7240:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem000e7240:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
000e7250:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl000e7250:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
000e7260:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c000e7260:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
000e7270:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms000e7270:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
000e7280:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet· 
000e7290:·2d71·2061·7564·6974·2026·616d·703b·2661··-q·audit·&amp;&a 
000e72a0:·6d70·3b20·5b20·2120·2d66·202f·2e64·6f63··mp;·[·!·-f·/.doc000e7280:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
000e72b0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a000e7290:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
Max diff block lines reached; 728792/738720 bytes (98.66%) of diff not shown.
236 KB
html2text {}
    
Offset 8352, 15 lines modifiedOffset 8352, 15 lines modified
8352 ············AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,8352 ············AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,
8353 ············PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,8353 ············PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,
8354 ············SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,8354 ············SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,
8355 ············SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,8355 ············SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,
8356 ············SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-234928r622137_rule8356 ············SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-234928r622137_rule
8357 Remediation_Shell_script_⇲8357 Remediation_Shell_script_⇲
8358 #·Remediation·is·applicable·only·in·certain·platforms8358 #·Remediation·is·applicable·only·in·certain·platforms
8359 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8359 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
8360 #·First·perform·the·remediation·of·the·syscall·rule8360 #·First·perform·the·remediation·of·the·syscall·rule
8361 #·Retrieve·hardware·architecture·of·the·underlying·system8361 #·Retrieve·hardware·architecture·of·the·underlying·system
8362 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")8362 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
8363 for·ARCH·in·"${RULE_ARCHS[@]}"8363 for·ARCH·in·"${RULE_ARCHS[@]}"
8364 do8364 do
Offset 8719, 16 lines modifiedOffset 8719, 16 lines modified
8719 ··-·reboot_required8719 ··-·reboot_required
8720 ··-·restrict_strategy8720 ··-·restrict_strategy
  
8721 -·name:·Set·architecture·for·audit·chmod·tasks8721 -·name:·Set·architecture·for·audit·chmod·tasks
8722 ··set_fact:8722 ··set_fact:
8723 ····audit_arch:·b648723 ····audit_arch:·b64
8724 ··when:8724 ··when:
8725 ··-·'"audit"·in·ansible_facts.packages' 
8726 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8725 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8726 ··-·'"audit"·in·ansible_facts.packages'
8727 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8727 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8728 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8728 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8729 ··tags:8729 ··tags:
8730 ··-·CCE-85693-08730 ··-·CCE-85693-0
8731 ··-·CJIS-5.4.1.18731 ··-·CJIS-5.4.1.1
8732 ··-·DISA-STIG-SLES-15-0302908732 ··-·DISA-STIG-SLES-15-030290
8733 ··-·NIST-800-171-3.1.78733 ··-·NIST-800-171-3.1.7
Offset 8870, 16 lines modifiedOffset 8870, 16 lines modified
8870 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10008870 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
8871 ········-F·auid!=unset·-F·key=perm_mod8871 ········-F·auid!=unset·-F·key=perm_mod
8872 ······create:·true8872 ······create:·true
8873 ······mode:·o-rwx8873 ······mode:·o-rwx
8874 ······state:·present8874 ······state:·present
8875 ····when:·syscalls_found·|·length·==·08875 ····when:·syscalls_found·|·length·==·0
8876 ··when:8876 ··when:
8877 ··-·'"audit"·in·ansible_facts.packages' 
8878 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]8877 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 8878 ··-·'"audit"·in·ansible_facts.packages'
8879 ··tags:8879 ··tags:
8880 ··-·CCE-85693-08880 ··-·CCE-85693-0
8881 ··-·CJIS-5.4.1.18881 ··-·CJIS-5.4.1.1
8882 ··-·DISA-STIG-SLES-15-0302908882 ··-·DISA-STIG-SLES-15-030290
8883 ··-·NIST-800-171-3.1.78883 ··-·NIST-800-171-3.1.7
8884 ··-·NIST-800-53-AU-12(a)8884 ··-·NIST-800-53-AU-12(a)
8885 ··-·NIST-800-53-AU-12(c)8885 ··-·NIST-800-53-AU-12(c)
Offset 9019, 16 lines modifiedOffset 9019, 16 lines modified
9019 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009019 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9020 ········-F·auid!=unset·-F·key=perm_mod9020 ········-F·auid!=unset·-F·key=perm_mod
9021 ······create:·true9021 ······create:·true
9022 ······mode:·o-rwx9022 ······mode:·o-rwx
9023 ······state:·present9023 ······state:·present
9024 ····when:·syscalls_found·|·length·==·09024 ····when:·syscalls_found·|·length·==·0
9025 ··when:9025 ··when:
9026 ··-·'"audit"·in·ansible_facts.packages' 
9027 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]9026 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 9027 ··-·'"audit"·in·ansible_facts.packages'
9028 ··-·audit_arch·==·"b64"9028 ··-·audit_arch·==·"b64"
9029 ··tags:9029 ··tags:
9030 ··-·CCE-85693-09030 ··-·CCE-85693-0
9031 ··-·CJIS-5.4.1.19031 ··-·CJIS-5.4.1.1
9032 ··-·DISA-STIG-SLES-15-0302909032 ··-·DISA-STIG-SLES-15-030290
9033 ··-·NIST-800-171-3.1.79033 ··-·NIST-800-171-3.1.7
9034 ··-·NIST-800-53-AU-12(a)9034 ··-·NIST-800-53-AU-12(a)
Offset 9079, 15 lines modifiedOffset 9079, 15 lines modified
9079 ············AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,9079 ············AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,
9080 ············PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,9080 ············PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,
9081 ············SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,9081 ············SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,·SRG-OS-000471-GPOS-00215,
9082 ············SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,9082 ············SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,
9083 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030250,·4.1.9,·SV-234924r622137_rule9083 ············SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030250,·4.1.9,·SV-234924r622137_rule
9084 Remediation_Shell_script_⇲9084 Remediation_Shell_script_⇲
9085 #·Remediation·is·applicable·only·in·certain·platforms9085 #·Remediation·is·applicable·only·in·certain·platforms
9086 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9086 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
9087 #·First·perform·the·remediation·of·the·syscall·rule9087 #·First·perform·the·remediation·of·the·syscall·rule
9088 #·Retrieve·hardware·architecture·of·the·underlying·system9088 #·Retrieve·hardware·architecture·of·the·underlying·system
9089 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")9089 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
9090 for·ARCH·in·"${RULE_ARCHS[@]}"9090 for·ARCH·in·"${RULE_ARCHS[@]}"
9091 do9091 do
Offset 9446, 16 lines modifiedOffset 9446, 16 lines modified
9446 ··-·reboot_required9446 ··-·reboot_required
9447 ··-·restrict_strategy9447 ··-·restrict_strategy
  
9448 -·name:·Set·architecture·for·audit·chown·tasks9448 -·name:·Set·architecture·for·audit·chown·tasks
9449 ··set_fact:9449 ··set_fact:
9450 ····audit_arch:·b649450 ····audit_arch:·b64
9451 ··when:9451 ··when:
9452 ··-·'"audit"·in·ansible_facts.packages' 
9453 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]9452 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 9453 ··-·'"audit"·in·ansible_facts.packages'
9454 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture9454 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
9455 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"9455 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
9456 ··tags:9456 ··tags:
9457 ··-·CCE-85690-69457 ··-·CCE-85690-6
9458 ··-·CJIS-5.4.1.19458 ··-·CJIS-5.4.1.1
9459 ··-·DISA-STIG-SLES-15-0302509459 ··-·DISA-STIG-SLES-15-030250
9460 ··-·NIST-800-171-3.1.79460 ··-·NIST-800-171-3.1.7
Offset 9599, 16 lines modifiedOffset 9599, 16 lines modified
9599 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009599 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9600 ········-F·auid!=unset·-F·key=perm_mod9600 ········-F·auid!=unset·-F·key=perm_mod
9601 ······create:·true9601 ······create:·true
9602 ······mode:·o-rwx9602 ······mode:·o-rwx
9603 ······state:·present9603 ······state:·present
9604 ····when:·syscalls_found·|·length·==·09604 ····when:·syscalls_found·|·length·==·0
9605 ··when:9605 ··when:
9606 ··-·'"audit"·in·ansible_facts.packages' 
9607 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]9606 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 9607 ··-·'"audit"·in·ansible_facts.packages'
9608 ··tags:9608 ··tags:
9609 ··-·CCE-85690-69609 ··-·CCE-85690-6
9610 ··-·CJIS-5.4.1.19610 ··-·CJIS-5.4.1.1
9611 ··-·DISA-STIG-SLES-15-0302509611 ··-·DISA-STIG-SLES-15-030250
9612 ··-·NIST-800-171-3.1.79612 ··-·NIST-800-171-3.1.7
9613 ··-·NIST-800-53-AU-12(a)9613 ··-·NIST-800-53-AU-12(a)
9614 ··-·NIST-800-53-AU-12(c)9614 ··-·NIST-800-53-AU-12(c)
Offset 9750, 16 lines modifiedOffset 9750, 16 lines modified
9750 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009750 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9751 ········-F·auid!=unset·-F·key=perm_mod9751 ········-F·auid!=unset·-F·key=perm_mod
9752 ······create:·true9752 ······create:·true
9753 ······mode:·o-rwx9753 ······mode:·o-rwx
9754 ······state:·present9754 ······state:·present
Max diff block lines reached; 235860/241259 bytes (97.76%) of diff not shown.
1.21 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pcs-hardening-sap.html
    
Offset 42748, 21 lines modifiedOffset 42748, 21 lines modified
000a6fb0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=000a6fb0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
000a6fc0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·000a6fc0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
000a6fd0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id000a6fd0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
000a6fe0:·6d31·3936·3738·223e·3c70·7265·3e3c·636f··m19678"><pre><co000a6fe0:·6d31·3936·3738·223e·3c70·7265·3e3c·636f··m19678"><pre><co
000a6ff0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation000a6ff0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
000a7000:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o000a7000:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
000a7010:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p000a7010:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
000a7020:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·000a7020:·6c61·7466·6f72·6d73·0a69·6620·5b20·2120··latforms.if·[·!·
000a7030:·2d2d·7175·6965·7420·2d71·2061·7564·6974··--quiet·-q·audit000a7030:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·]
000a7040:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·000a7040:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!·
000a7050:·2d66·202f·2e64·6f63·6b65·7265·6e76·205d··-f·/.dockerenv·] 
000a7060:·2026·616d·703b·2661·6d70·3b20·5b20·2120···&amp;&amp;·[·!· 
000a7070:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain000a7050:·2d66·202f·7275·6e2f·2e63·6f6e·7461·696e··-f·/run/.contain
000a7080:·6572·656e·7620·5d3b·2074·6865·6e0a·0a23··erenv·];·then..#000a7060:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
 000a7070:·703b·2072·706d·202d·2d71·7569·6574·202d··p;·rpm·--quiet·-
 000a7080:·7120·6175·6469·743b·2074·6865·6e0a·0a23··q·audit;·then..#
000a7090:·2046·6972·7374·2070·6572·666f·726d·2074···First·perform·t000a7090:·2046·6972·7374·2070·6572·666f·726d·2074···First·perform·t
000a70a0:·6865·2072·656d·6564·6961·7469·6f6e·206f··he·remediation·o000a70a0:·6865·2072·656d·6564·6961·7469·6f6e·206f··he·remediation·o
000a70b0:·6620·7468·6520·7379·7363·616c·6c20·7275··f·the·syscall·ru000a70b0:·6620·7468·6520·7379·7363·616c·6c20·7275··f·the·syscall·ru
000a70c0:·6c65·0a23·2052·6574·7269·6576·6520·6861··le.#·Retrieve·ha000a70c0:·6c65·0a23·2052·6574·7269·6576·6520·6861··le.#·Retrieve·ha
000a70d0:·7264·7761·7265·2061·7263·6869·7465·6374··rdware·architect000a70d0:·7264·7761·7265·2061·7263·6869·7465·6374··rdware·architect
000a70e0:·7572·6520·6f66·2074·6865·2075·6e64·6572··ure·of·the·under000a70e0:·7572·6520·6f66·2074·6865·2075·6e64·6572··ure·of·the·under
000a70f0:·6c79·696e·6720·7379·7374·656d·0a5b·2022··lying·system.[·"000a70f0:·6c79·696e·6720·7379·7374·656d·0a5b·2022··lying·system.[·"
Offset 43649, 23 lines modifiedOffset 43649, 23 lines modified
000aa800:·6f6f·745f·7265·7175·6972·6564·0a20·202d··oot_required.··-000aa800:·6f6f·745f·7265·7175·6972·6564·0a20·202d··oot_required.··-
000aa810:·2072·6573·7472·6963·745f·7374·7261·7465···restrict_strate000aa810:·2072·6573·7472·6963·745f·7374·7261·7465···restrict_strate
000aa820:·6779·0a0a·2d20·6e61·6d65·3a20·5365·7420··gy..-·name:·Set·000aa820:·6779·0a0a·2d20·6e61·6d65·3a20·5365·7420··gy..-·name:·Set·
000aa830:·6172·6368·6974·6563·7475·7265·2066·6f72··architecture·for000aa830:·6172·6368·6974·6563·7475·7265·2066·6f72··architecture·for
000aa840:·2061·7564·6974·2063·686d·6f64·2074·6173···audit·chmod·tas000aa840:·2061·7564·6974·2063·686d·6f64·2074·6173···audit·chmod·tas
000aa850:·6b73·0a20·2073·6574·5f66·6163·743a·0a20··ks.··set_fact:.·000aa850:·6b73·0a20·2073·6574·5f66·6163·743a·0a20··ks.··set_fact:.·
000aa860:·2020·2061·7564·6974·5f61·7263·683a·2062·····audit_arch:·b000aa860:·2020·2061·7564·6974·5f61·7263·683a·2062·····audit_arch:·b
000aa870:·3634·0a20·2077·6865·6e3a·0a20·202d·2027··64.··when:.··-·'000aa870:·3634·0a20·2077·6865·6e3a·0a20·202d·2061··64.··when:.··-·a
000aa880:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib 
000aa890:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
000aa8a0:·7327·0a20·202d·2061·6e73·6962·6c65·5f76··s'.··-·ansible_v 
000aa8b0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty 
000aa8c0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock 
000aa8d0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope 
000aa8e0:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",· 
000aa8f0:·2263·6f6e·7461·696e·6572·225d·0a20·202d··"container"].··-000aa880:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
 000aa890:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
 000aa8a0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
 000aa8b0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
 000aa8c0:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
 000aa8d0:·6572·225d·0a20·202d·2027·2261·7564·6974··er"].··-·'"audit
 000aa8e0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 000aa8f0:·7473·2e70·6163·6b61·6765·7327·0a20·202d··ts.packages'.··-
000aa900:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite000aa900:·2061·6e73·6962·6c65·5f61·7263·6869·7465···ansible_archite
000aa910:·6374·7572·6520·3d3d·2022·6161·7263·6836··cture·==·"aarch6000aa910:·6374·7572·6520·3d3d·2022·6161·7263·6836··cture·==·"aarch6
000aa920:·3422·206f·7220·616e·7369·626c·655f·6172··4"·or·ansible_ar000aa920:·3422·206f·7220·616e·7369·626c·655f·6172··4"·or·ansible_ar
000aa930:·6368·6974·6563·7475·7265·203d·3d20·2270··chitecture·==·"p000aa930:·6368·6974·6563·7475·7265·203d·3d20·2270··chitecture·==·"p
000aa940:·7063·3634·2220·6f72·2061·6e73·6962·6c65··pc64"·or·ansible000aa940:·7063·3634·2220·6f72·2061·6e73·6962·6c65··pc64"·or·ansible
000aa950:·5f61·7263·6869·7465·6374·7572·650a·2020··_architecture.··000aa950:·5f61·7263·6869·7465·6374·7572·650a·2020··_architecture.··
000aa960:·2020·3d3d·2022·7070·6336·346c·6522·206f····==·"ppc64le"·o000aa960:·2020·3d3d·2022·7070·6336·346c·6522·206f····==·"ppc64le"·o
Offset 43980, 23 lines modifiedOffset 43980, 23 lines modified
000abcb0:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···000abcb0:·6b65·793d·7065·726d·5f6d·6f64·0a20·2020··key=perm_mod.···
000abcc0:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.000abcc0:·2020·2063·7265·6174·653a·2074·7275·650a·····create:·true.
000abcd0:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw000abcd0:·2020·2020·2020·6d6f·6465·3a20·6f2d·7277········mode:·o-rw
000abce0:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p000abce0:·780a·2020·2020·2020·7374·6174·653a·2070··x.······state:·p
000abcf0:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:000abcf0:·7265·7365·6e74·0a20·2020·2077·6865·6e3a··resent.····when:
000abd00:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·000abd00:·2073·7973·6361·6c6c·735f·666f·756e·6420···syscalls_found·
000abd10:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··000abd10:·7c20·6c65·6e67·7468·203d·3d20·300a·2020··|·length·==·0.··
000abd20:·7768·656e·3a0a·2020·2d20·2722·6175·6469··when:.··-·'"audi000abd20:·7768·656e·3a0a·2020·2d20·616e·7369·626c··when:.··-·ansibl
000abd30:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa 
000abd40:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
000abd50:·2d20·616e·7369·626c·655f·7669·7274·7561··-·ansible_virtua 
000abd60:·6c69·7a61·7469·6f6e·5f74·7970·6520·6e6f··lization_type·no 
000abd70:·7420·696e·205b·2264·6f63·6b65·7222·2c20··t·in·["docker",· 
000abd80:·226c·7863·222c·2022·6f70·656e·767a·222c··"lxc",·"openvz", 
000abd90:·2022·706f·646d·616e·222c·2022·636f·6e74···"podman",·"cont000abd30:·655f·7669·7274·7561·6c69·7a61·7469·6f6e··e_virtualization
 000abd40:·5f74·7970·6520·6e6f·7420·696e·205b·2264··_type·not·in·["d
 000abd50:·6f63·6b65·7222·2c20·226c·7863·222c·2022··ocker",·"lxc",·"
 000abd60:·6f70·656e·767a·222c·2022·706f·646d·616e··openvz",·"podman
 000abd70:·222c·2022·636f·6e74·6169·6e65·7222·5d0a··",·"container"].
 000abd80:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in·
 000abd90:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa
000abda0:·6169·6e65·7222·5d0a·2020·7461·6773·3a0a··ainer"].··tags:.000abda0:·636b·6167·6573·270a·2020·7461·6773·3a0a··ckages'.··tags:.
000abdb0:·2020·2d20·4343·452d·3835·3639·332d·300a····-·CCE-85693-0.000abdb0:·2020·2d20·4343·452d·3835·3639·332d·300a····-·CCE-85693-0.
000abdc0:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1000abdc0:·2020·2d20·434a·4953·2d35·2e34·2e31·2e31····-·CJIS-5.4.1.1
000abdd0:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S000abdd0:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
000abde0:·4c45·532d·3135·2d30·3330·3239·300a·2020··LES-15-030290.··000abde0:·4c45·532d·3135·2d30·3330·3239·300a·2020··LES-15-030290.··
000abdf0:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3000abdf0:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3
000abe00:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80000abe00:·2e31·2e37·0a20·202d·204e·4953·542d·3830··.1.7.··-·NIST-80
000abe10:·302d·3533·2d41·552d·3132·2861·290a·2020··0-53-AU-12(a).··000abe10:·302d·3533·2d41·552d·3132·2861·290a·2020··0-53-AU-12(a).··
Offset 44299, 23 lines modifiedOffset 44299, 23 lines modified
000ad0a0:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·000ad0a0:·4620·6b65·793d·7065·726d·5f6d·6f64·0a20··F·key=perm_mod.·
000ad0b0:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru000ad0b0:·2020·2020·2063·7265·6174·653a·2074·7275·······create:·tru
000ad0c0:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-000ad0c0:·650a·2020·2020·2020·6d6f·6465·3a20·6f2d··e.······mode:·o-
000ad0d0:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:000ad0d0:·7277·780a·2020·2020·2020·7374·6174·653a··rwx.······state:
000ad0e0:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe000ad0e0:·2070·7265·7365·6e74·0a20·2020·2077·6865···present.····whe
000ad0f0:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun000ad0f0:·6e3a·2073·7973·6361·6c6c·735f·666f·756e··n:·syscalls_foun
000ad100:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.000ad100:·6420·7c20·6c65·6e67·7468·203d·3d20·300a··d·|·length·==·0.
000ad110:·2020·7768·656e·3a0a·2020·2d20·2722·6175····when:.··-·'"au000ad110:·2020·7768·656e·3a0a·2020·2d20·616e·7369····when:.··-·ansi
000ad120:·6469·7422·2069·6e20·616e·7369·626c·655f··dit"·in·ansible_ 
000ad130:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
000ad140:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt 
000ad150:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type· 
000ad160:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker" 
000ad170:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz 
000ad180:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co 
000ad190:·6e74·6169·6e65·7222·5d0a·2020·2d20·6175··ntainer"].··-·au000ad120:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati
 000ad130:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[
 000ad140:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc",
 000ad150:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm
 000ad160:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"
 000ad170:·5d0a·2020·2d20·2722·6175·6469·7422·2069··].··-·'"audit"·i
 000ad180:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 000ad190:·7061·636b·6167·6573·270a·2020·2d20·6175··packages'.··-·au
000ad1a0:·6469·745f·6172·6368·203d·3d20·2262·3634··dit_arch·==·"b64000ad1a0:·6469·745f·6172·6368·203d·3d20·2262·3634··dit_arch·==·"b64
000ad1b0:·220a·2020·7461·6773·3a0a·2020·2d20·4343··".··tags:.··-·CC000ad1b0:·220a·2020·7461·6773·3a0a·2020·2d20·4343··".··tags:.··-·CC
000ad1c0:·452d·3835·3639·332d·300a·2020·2d20·434a··E-85693-0.··-·CJ000ad1c0:·452d·3835·3639·332d·300a·2020·2d20·434a··E-85693-0.··-·CJ
000ad1d0:·4953·2d35·2e34·2e31·2e31·0a20·202d·2044··IS-5.4.1.1.··-·D000ad1d0:·4953·2d35·2e34·2e31·2e31·0a20·202d·2044··IS-5.4.1.1.··-·D
000ad1e0:·4953·412d·5354·4947·2d53·4c45·532d·3135··ISA-STIG-SLES-15000ad1e0:·4953·412d·5354·4947·2d53·4c45·532d·3135··ISA-STIG-SLES-15
000ad1f0:·2d30·3330·3239·300a·2020·2d20·4e49·5354··-030290.··-·NIST000ad1f0:·2d30·3330·3239·300a·2020·2d20·4e49·5354··-030290.··-·NIST
000ad200:·2d38·3030·2d31·3731·2d33·2e31·2e37·0a20··-800-171-3.1.7.·000ad200:·2d38·3030·2d31·3731·2d33·2e31·2e37·0a20··-800-171-3.1.7.·
Offset 45335, 20 lines modifiedOffset 45335, 20 lines modified
000b1160:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000b1160:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
000b1170:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"000b1170:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
000b1180:·2069·643d·2269·646d·3139·3834·3222·3e3c···id="idm19842"><000b1180:·2069·643d·2269·646d·3139·3834·3222·3e3c···id="idm19842"><
000b1190:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme000b1190:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
000b11a0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli000b11a0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
000b11b0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce000b11b0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
000b11c0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.000b11c0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
000b11d0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
000b11e0:·7120·6175·6469·7420·2661·6d70·3b26·616d··q·audit·&amp;&am 
000b11f0:·703b·205b·2021·202d·6620·2f2e·646f·636b··p;·[·!·-f·/.dock000b11d0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
000b1200:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am000b11e0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
Max diff block lines reached; 944818/954815 bytes (98.95%) of diff not shown.
303 KB
html2text {}
    
Offset 6251, 15 lines modifiedOffset 6251, 15 lines modified
6251 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-6251 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
6252 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,6252 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
6253 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-6253 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
6254 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-6254 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-
6255 ············234928r622137_rule6255 ············234928r622137_rule
6256 Remediation_Shell_script_⇲6256 Remediation_Shell_script_⇲
6257 #·Remediation·is·applicable·only·in·certain·platforms6257 #·Remediation·is·applicable·only·in·certain·platforms
6258 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then6258 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
6259 #·First·perform·the·remediation·of·the·syscall·rule6259 #·First·perform·the·remediation·of·the·syscall·rule
6260 #·Retrieve·hardware·architecture·of·the·underlying·system6260 #·Retrieve·hardware·architecture·of·the·underlying·system
6261 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6261 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6262 for·ARCH·in·"${RULE_ARCHS[@]}"6262 for·ARCH·in·"${RULE_ARCHS[@]}"
6263 do6263 do
Offset 6620, 16 lines modifiedOffset 6620, 16 lines modified
6620 ··-·reboot_required6620 ··-·reboot_required
6621 ··-·restrict_strategy6621 ··-·restrict_strategy
  
6622 -·name:·Set·architecture·for·audit·chmod·tasks6622 -·name:·Set·architecture·for·audit·chmod·tasks
6623 ··set_fact:6623 ··set_fact:
6624 ····audit_arch:·b646624 ····audit_arch:·b64
6625 ··when:6625 ··when:
6626 ··-·'"audit"·in·ansible_facts.packages' 
6627 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6626 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6627 ··-·'"audit"·in·ansible_facts.packages'
6628 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6628 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6629 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6629 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6630 ··tags:6630 ··tags:
6631 ··-·CCE-85693-06631 ··-·CCE-85693-0
6632 ··-·CJIS-5.4.1.16632 ··-·CJIS-5.4.1.1
6633 ··-·DISA-STIG-SLES-15-0302906633 ··-·DISA-STIG-SLES-15-030290
6634 ··-·NIST-800-171-3.1.76634 ··-·NIST-800-171-3.1.7
Offset 6771, 16 lines modifiedOffset 6771, 16 lines modified
6771 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006771 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6772 ········-F·auid!=unset·-F·key=perm_mod6772 ········-F·auid!=unset·-F·key=perm_mod
6773 ······create:·true6773 ······create:·true
6774 ······mode:·o-rwx6774 ······mode:·o-rwx
6775 ······state:·present6775 ······state:·present
6776 ····when:·syscalls_found·|·length·==·06776 ····when:·syscalls_found·|·length·==·0
6777 ··when:6777 ··when:
6778 ··-·'"audit"·in·ansible_facts.packages' 
6779 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6778 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6779 ··-·'"audit"·in·ansible_facts.packages'
6780 ··tags:6780 ··tags:
6781 ··-·CCE-85693-06781 ··-·CCE-85693-0
6782 ··-·CJIS-5.4.1.16782 ··-·CJIS-5.4.1.1
6783 ··-·DISA-STIG-SLES-15-0302906783 ··-·DISA-STIG-SLES-15-030290
6784 ··-·NIST-800-171-3.1.76784 ··-·NIST-800-171-3.1.7
6785 ··-·NIST-800-53-AU-12(a)6785 ··-·NIST-800-53-AU-12(a)
6786 ··-·NIST-800-53-AU-12(c)6786 ··-·NIST-800-53-AU-12(c)
Offset 6920, 16 lines modifiedOffset 6920, 16 lines modified
6920 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006920 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6921 ········-F·auid!=unset·-F·key=perm_mod6921 ········-F·auid!=unset·-F·key=perm_mod
6922 ······create:·true6922 ······create:·true
6923 ······mode:·o-rwx6923 ······mode:·o-rwx
6924 ······state:·present6924 ······state:·present
6925 ····when:·syscalls_found·|·length·==·06925 ····when:·syscalls_found·|·length·==·0
6926 ··when:6926 ··when:
6927 ··-·'"audit"·in·ansible_facts.packages' 
6928 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6927 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6928 ··-·'"audit"·in·ansible_facts.packages'
6929 ··-·audit_arch·==·"b64"6929 ··-·audit_arch·==·"b64"
6930 ··tags:6930 ··tags:
6931 ··-·CCE-85693-06931 ··-·CCE-85693-0
6932 ··-·CJIS-5.4.1.16932 ··-·CJIS-5.4.1.1
6933 ··-·DISA-STIG-SLES-15-0302906933 ··-·DISA-STIG-SLES-15-030290
6934 ··-·NIST-800-171-3.1.76934 ··-·NIST-800-171-3.1.7
6935 ··-·NIST-800-53-AU-12(a)6935 ··-·NIST-800-53-AU-12(a)
Offset 6982, 15 lines modifiedOffset 6982, 15 lines modified
6982 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-6982 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
6983 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,6983 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
6984 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-6984 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
6985 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-6985 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-
6986 ············030250,·4.1.9,·SV-234924r622137_rule6986 ············030250,·4.1.9,·SV-234924r622137_rule
6987 Remediation_Shell_script_⇲6987 Remediation_Shell_script_⇲
6988 #·Remediation·is·applicable·only·in·certain·platforms6988 #·Remediation·is·applicable·only·in·certain·platforms
6989 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then6989 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
6990 #·First·perform·the·remediation·of·the·syscall·rule6990 #·First·perform·the·remediation·of·the·syscall·rule
6991 #·Retrieve·hardware·architecture·of·the·underlying·system6991 #·Retrieve·hardware·architecture·of·the·underlying·system
6992 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6992 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6993 for·ARCH·in·"${RULE_ARCHS[@]}"6993 for·ARCH·in·"${RULE_ARCHS[@]}"
6994 do6994 do
Offset 7351, 16 lines modifiedOffset 7351, 16 lines modified
7351 ··-·reboot_required7351 ··-·reboot_required
7352 ··-·restrict_strategy7352 ··-·restrict_strategy
  
7353 -·name:·Set·architecture·for·audit·chown·tasks7353 -·name:·Set·architecture·for·audit·chown·tasks
7354 ··set_fact:7354 ··set_fact:
7355 ····audit_arch:·b647355 ····audit_arch:·b64
7356 ··when:7356 ··when:
7357 ··-·'"audit"·in·ansible_facts.packages' 
7358 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7357 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7358 ··-·'"audit"·in·ansible_facts.packages'
7359 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture7359 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
7360 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"7360 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
7361 ··tags:7361 ··tags:
7362 ··-·CCE-85690-67362 ··-·CCE-85690-6
7363 ··-·CJIS-5.4.1.17363 ··-·CJIS-5.4.1.1
7364 ··-·DISA-STIG-SLES-15-0302507364 ··-·DISA-STIG-SLES-15-030250
7365 ··-·NIST-800-171-3.1.77365 ··-·NIST-800-171-3.1.7
Offset 7504, 16 lines modifiedOffset 7504, 16 lines modified
7504 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007504 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7505 ········-F·auid!=unset·-F·key=perm_mod7505 ········-F·auid!=unset·-F·key=perm_mod
7506 ······create:·true7506 ······create:·true
7507 ······mode:·o-rwx7507 ······mode:·o-rwx
7508 ······state:·present7508 ······state:·present
7509 ····when:·syscalls_found·|·length·==·07509 ····when:·syscalls_found·|·length·==·0
7510 ··when:7510 ··when:
7511 ··-·'"audit"·in·ansible_facts.packages' 
7512 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7511 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7512 ··-·'"audit"·in·ansible_facts.packages'
7513 ··tags:7513 ··tags:
7514 ··-·CCE-85690-67514 ··-·CCE-85690-6
7515 ··-·CJIS-5.4.1.17515 ··-·CJIS-5.4.1.1
7516 ··-·DISA-STIG-SLES-15-0302507516 ··-·DISA-STIG-SLES-15-030250
7517 ··-·NIST-800-171-3.1.77517 ··-·NIST-800-171-3.1.7
7518 ··-·NIST-800-53-AU-12(a)7518 ··-·NIST-800-53-AU-12(a)
7519 ··-·NIST-800-53-AU-12(c)7519 ··-·NIST-800-53-AU-12(c)
Offset 7655, 16 lines modifiedOffset 7655, 16 lines modified
7655 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007655 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7656 ········-F·auid!=unset·-F·key=perm_mod7656 ········-F·auid!=unset·-F·key=perm_mod
7657 ······create:·true7657 ······create:·true
7658 ······mode:·o-rwx7658 ······mode:·o-rwx
7659 ······state:·present7659 ······state:·present
Max diff block lines reached; 304890/310099 bytes (98.32%) of diff not shown.
1.21 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pcs-hardening.html
    
Offset 42917, 20 lines modifiedOffset 42917, 20 lines modified
000a7a40:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000a7a40:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
000a7a50:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"000a7a50:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
000a7a60:·2069·643d·2269·646d·3139·3637·3822·3e3c···id="idm19678"><000a7a60:·2069·643d·2269·646d·3139·3637·3822·3e3c···id="idm19678"><
000a7a70:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme000a7a70:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
000a7a80:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli000a7a80:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
000a7a90:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce000a7a90:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
000a7aa0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.000a7aa0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
000a7ab0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
000a7ac0:·7120·6175·6469·7420·2661·6d70·3b26·616d··q·audit·&amp;&am 
000a7ad0:·703b·205b·2021·202d·6620·2f2e·646f·636b··p;·[·!·-f·/.dock000a7ab0:·6966·205b·2021·202d·6620·2f2e·646f·636b··if·[·!·-f·/.dock
000a7ae0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am000a7ac0:·6572·656e·7620·5d20·2661·6d70·3b26·616d··erenv·]·&amp;&am
000a7af0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.000a7ad0:·703b·205b·2021·202d·6620·2f72·756e·2f2e··p;·[·!·-f·/run/.
000a7b00:·636f·6e74·6169·6e65·7265·6e76·205d·3b20··containerenv·];·000a7ae0:·636f·6e74·6169·6e65·7265·6e76·205d·2026··containerenv·]·&
 000a7af0:·616d·703b·2661·6d70·3b20·7270·6d20·2d2d··amp;&amp;·rpm·--
 000a7b00:·7175·6965·7420·2d71·2061·7564·6974·3b20··quiet·-q·audit;·
000a7b10:·7468·656e·0a0a·2320·4669·7273·7420·7065··then..#·First·pe000a7b10:·7468·656e·0a0a·2320·4669·7273·7420·7065··then..#·First·pe
000a7b20:·7266·6f72·6d20·7468·6520·7265·6d65·6469··rform·the·remedi000a7b20:·7266·6f72·6d20·7468·6520·7265·6d65·6469··rform·the·remedi
000a7b30:·6174·696f·6e20·6f66·2074·6865·2073·7973··ation·of·the·sys000a7b30:·6174·696f·6e20·6f66·2074·6865·2073·7973··ation·of·the·sys
000a7b40:·6361·6c6c·2072·756c·650a·2320·5265·7472··call·rule.#·Retr000a7b40:·6361·6c6c·2072·756c·650a·2320·5265·7472··call·rule.#·Retr
000a7b50:·6965·7665·2068·6172·6477·6172·6520·6172··ieve·hardware·ar000a7b50:·6965·7665·2068·6172·6477·6172·6520·6172··ieve·hardware·ar
000a7b60:·6368·6974·6563·7475·7265·206f·6620·7468··chitecture·of·th000a7b60:·6368·6974·6563·7475·7265·206f·6620·7468··chitecture·of·th
000a7b70:·6520·756e·6465·726c·7969·6e67·2073·7973··e·underlying·sys000a7b70:·6520·756e·6465·726c·7969·6e67·2073·7973··e·underlying·sys
Offset 43818, 23 lines modifiedOffset 43818, 23 lines modified
000ab290:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict000ab290:·7265·640a·2020·2d20·7265·7374·7269·6374··red.··-·restrict
000ab2a0:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam000ab2a0:·5f73·7472·6174·6567·790a·0a2d·206e·616d··_strategy..-·nam
000ab2b0:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect000ab2b0:·653a·2053·6574·2061·7263·6869·7465·6374··e:·Set·architect
000ab2c0:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch000ab2c0:·7572·6520·666f·7220·6175·6469·7420·6368··ure·for·audit·ch
000ab2d0:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_000ab2d0:·6d6f·6420·7461·736b·730a·2020·7365·745f··mod·tasks.··set_
000ab2e0:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_000ab2e0:·6661·6374·3a0a·2020·2020·6175·6469·745f··fact:.····audit_
000ab2f0:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when000ab2f0:·6172·6368·3a20·6236·340a·2020·7768·656e··arch:·b64.··when
000ab300:·3a0a·2020·2d20·2722·6175·6469·7422·2069··:.··-·'"audit"·i 
000ab310:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
000ab320:·7061·636b·6167·6573·270a·2020·2d20·616e··packages'.··-·an 
000ab330:·7369·626c·655f·7669·7274·7561·6c69·7a61··sible_virtualiza 
000ab340:·7469·6f6e·5f74·7970·6520·6e6f·7420·696e··tion_type·not·in 
000ab350:·205b·2264·6f63·6b65·7222·2c20·226c·7863···["docker",·"lxc 
000ab360:·222c·2022·6f70·656e·767a·222c·2022·706f··",·"openvz",·"po 
000ab370:·646d·616e·222c·2022·636f·6e74·6169·6e65··dman",·"containe000ab300:·3a0a·2020·2d20·616e·7369·626c·655f·7669··:.··-·ansible_vi
 000ab310:·7274·7561·6c69·7a61·7469·6f6e·5f74·7970··rtualization_typ
 000ab320:·6520·6e6f·7420·696e·205b·2264·6f63·6b65··e·not·in·["docke
 000ab330:·7222·2c20·226c·7863·222c·2022·6f70·656e··r",·"lxc",·"open
 000ab340:·767a·222c·2022·706f·646d·616e·222c·2022··vz",·"podman",·"
 000ab350:·636f·6e74·6169·6e65·7222·5d0a·2020·2d20··container"].··-·
 000ab360:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi
 000ab370:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
000ab380:·7222·5d0a·2020·2d20·616e·7369·626c·655f··r"].··-·ansible_000ab380:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_
000ab390:·6172·6368·6974·6563·7475·7265·203d·3d20··architecture·==·000ab390:·6172·6368·6974·6563·7475·7265·203d·3d20··architecture·==·
000ab3a0:·2261·6172·6368·3634·2220·6f72·2061·6e73··"aarch64"·or·ans000ab3a0:·2261·6172·6368·3634·2220·6f72·2061·6e73··"aarch64"·or·ans
000ab3b0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur000ab3b0:·6962·6c65·5f61·7263·6869·7465·6374·7572··ible_architectur
000ab3c0:·6520·3d3d·2022·7070·6336·3422·206f·7220··e·==·"ppc64"·or·000ab3c0:·6520·3d3d·2022·7070·6336·3422·206f·7220··e·==·"ppc64"·or·
000ab3d0:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec000ab3d0:·616e·7369·626c·655f·6172·6368·6974·6563··ansible_architec
000ab3e0:·7475·7265·0a20·2020·203d·3d20·2270·7063··ture.····==·"ppc000ab3e0:·7475·7265·0a20·2020·203d·3d20·2270·7063··ture.····==·"ppc
000ab3f0:·3634·6c65·2220·6f72·2061·6e73·6962·6c65··64le"·or·ansible000ab3f0:·3634·6c65·2220·6f72·2061·6e73·6962·6c65··64le"·or·ansible
Offset 44149, 22 lines modifiedOffset 44149, 22 lines modified
000ac740:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create000ac740:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create
000ac750:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod000ac750:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod
000ac760:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s000ac760:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s
000ac770:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··000ac770:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
000ac780:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls000ac780:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls
000ac790:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·000ac790:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·
000ac7a0:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-000ac7a0:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-
000ac7b0:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans 
000ac7c0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
000ac7d0:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible 
000ac7e0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
000ac7f0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
000ac800:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
000ac810:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
000ac820:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·000ac7b0:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
 000ac7c0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
 000ac7d0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
 000ac7e0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
 000ac7f0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
 000ac800:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud
 000ac810:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f
 000ac820:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·
000ac830:·2074·6167·733a·0a20·202d·2043·4345·2d38···tags:.··-·CCE-8000ac830:·2074·6167·733a·0a20·202d·2043·4345·2d38···tags:.··-·CCE-8
000ac840:·3536·3933·2d30·0a20·202d·2043·4a49·532d··5693-0.··-·CJIS-000ac840:·3536·3933·2d30·0a20·202d·2043·4a49·532d··5693-0.··-·CJIS-
000ac850:·352e·342e·312e·310a·2020·2d20·4449·5341··5.4.1.1.··-·DISA000ac850:·352e·342e·312e·310a·2020·2d20·4449·5341··5.4.1.1.··-·DISA
000ac860:·2d53·5449·472d·534c·4553·2d31·352d·3033··-STIG-SLES-15-03000ac860:·2d53·5449·472d·534c·4553·2d31·352d·3033··-STIG-SLES-15-03
000ac870:·3032·3930·0a20·202d·204e·4953·542d·3830··0290.··-·NIST-80000ac870:·3032·3930·0a20·202d·204e·4953·542d·3830··0290.··-·NIST-80
000ac880:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·000ac880:·302d·3137·312d·332e·312e·370a·2020·2d20··0-171-3.1.7.··-·
000ac890:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1000ac890:·4e49·5354·2d38·3030·2d35·332d·4155·2d31··NIST-800-53-AU-1
Offset 44468, 22 lines modifiedOffset 44468, 22 lines modified
000adb30:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea000adb30:·6d5f·6d6f·640a·2020·2020·2020·6372·6561··m_mod.······crea
000adb40:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m000adb40:·7465·3a20·7472·7565·0a20·2020·2020·206d··te:·true.······m
000adb50:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····000adb50:·6f64·653a·206f·2d72·7778·0a20·2020·2020··ode:·o-rwx.·····
000adb60:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.000adb60:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
000adb70:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal000adb70:·2020·2020·7768·656e·3a20·7379·7363·616c······when:·syscal
000adb80:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt000adb80:·6c73·5f66·6f75·6e64·207c·206c·656e·6774··ls_found·|·lengt
000adb90:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·000adb90:·6820·3d3d·2030·0a20·2077·6865·6e3a·0a20··h·==·0.··when:.·
000adba0:·202d·2027·2261·7564·6974·2220·696e·2061···-·'"audit"·in·a 
000adbb0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
000adbc0:·6b61·6765·7327·0a20·202d·2061·6e73·6962··kages'.··-·ansib 
000adbd0:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio 
000adbe0:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·[" 
000adbf0:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",· 
000adc00:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma 
000adc10:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]000adba0:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu
 000adbb0:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n
 000adbc0:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker",
 000adbd0:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz"
 000adbe0:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con
 000adbf0:·7461·696e·6572·225d·0a20·202d·2027·2261··tainer"].··-·'"a
 000adc00:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible
 000adc10:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'
000adc20:·0a20·202d·2061·7564·6974·5f61·7263·6820··.··-·audit_arch·000adc20:·0a20·202d·2061·7564·6974·5f61·7263·6820··.··-·audit_arch·
000adc30:·3d3d·2022·6236·3422·0a20·2074·6167·733a··==·"b64".··tags:000adc30:·3d3d·2022·6236·3422·0a20·2074·6167·733a··==·"b64".··tags:
000adc40:·0a20·202d·2043·4345·2d38·3536·3933·2d30··.··-·CCE-85693-0000adc40:·0a20·202d·2043·4345·2d38·3536·3933·2d30··.··-·CCE-85693-0
000adc50:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.000adc50:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.
000adc60:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-000adc60:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-
000adc70:·534c·4553·2d31·352d·3033·3032·3930·0a20··SLES-15-030290.·000adc70:·534c·4553·2d31·352d·3033·3032·3930·0a20··SLES-15-030290.·
000adc80:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-000adc80:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
Offset 45503, 21 lines modifiedOffset 45503, 21 lines modified
000b1be0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p000b1be0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
000b1bf0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co000b1bf0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000b1c00:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1000b1c00:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
000b1c10:·3938·3432·223e·3c70·7265·3e3c·636f·6465··9842"><pre><code000b1c10:·3938·3432·223e·3c70·7265·3e3c·636f·6465··9842"><pre><code
000b1c20:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i000b1c20:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
000b1c30:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl000b1c30:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
000b1c40:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla000b1c40:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
000b1c50:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--000b1c50:·7466·6f72·6d73·0a69·6620·5b20·2120·2d66··tforms.if·[·!·-f
000b1c60:·7175·6965·7420·2d71·2061·7564·6974·2026··quiet·-q·audit·&000b1c60:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·&
000b1c70:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f000b1c70:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f
000b1c80:·202f·2e64·6f63·6b65·7265·6e76·205d·2026···/.dockerenv·]·& 
000b1c90:·616d·703b·2661·6d70·3b20·5b20·2120·2d66··amp;&amp;·[·!·-f 
000b1ca0:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container000b1c80:·202f·7275·6e2f·2e63·6f6e·7461·696e·6572···/run/.container
Max diff block lines reached; 947785/957506 bytes (98.98%) of diff not shown.
303 KB
html2text {}
    
Offset 6328, 15 lines modifiedOffset 6328, 15 lines modified
6328 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-6328 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
6329 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,6329 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
6330 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-6330 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
6331 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-6331 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-
6332 ············234928r622137_rule6332 ············234928r622137_rule
6333 Remediation_Shell_script_⇲6333 Remediation_Shell_script_⇲
6334 #·Remediation·is·applicable·only·in·certain·platforms6334 #·Remediation·is·applicable·only·in·certain·platforms
6335 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then6335 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
6336 #·First·perform·the·remediation·of·the·syscall·rule6336 #·First·perform·the·remediation·of·the·syscall·rule
6337 #·Retrieve·hardware·architecture·of·the·underlying·system6337 #·Retrieve·hardware·architecture·of·the·underlying·system
6338 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6338 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6339 for·ARCH·in·"${RULE_ARCHS[@]}"6339 for·ARCH·in·"${RULE_ARCHS[@]}"
6340 do6340 do
Offset 6697, 16 lines modifiedOffset 6697, 16 lines modified
6697 ··-·reboot_required6697 ··-·reboot_required
6698 ··-·restrict_strategy6698 ··-·restrict_strategy
  
6699 -·name:·Set·architecture·for·audit·chmod·tasks6699 -·name:·Set·architecture·for·audit·chmod·tasks
6700 ··set_fact:6700 ··set_fact:
6701 ····audit_arch:·b646701 ····audit_arch:·b64
6702 ··when:6702 ··when:
6703 ··-·'"audit"·in·ansible_facts.packages' 
6704 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6703 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6704 ··-·'"audit"·in·ansible_facts.packages'
6705 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6705 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6706 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6706 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6707 ··tags:6707 ··tags:
6708 ··-·CCE-85693-06708 ··-·CCE-85693-0
6709 ··-·CJIS-5.4.1.16709 ··-·CJIS-5.4.1.1
6710 ··-·DISA-STIG-SLES-15-0302906710 ··-·DISA-STIG-SLES-15-030290
6711 ··-·NIST-800-171-3.1.76711 ··-·NIST-800-171-3.1.7
Offset 6848, 16 lines modifiedOffset 6848, 16 lines modified
6848 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006848 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6849 ········-F·auid!=unset·-F·key=perm_mod6849 ········-F·auid!=unset·-F·key=perm_mod
6850 ······create:·true6850 ······create:·true
6851 ······mode:·o-rwx6851 ······mode:·o-rwx
6852 ······state:·present6852 ······state:·present
6853 ····when:·syscalls_found·|·length·==·06853 ····when:·syscalls_found·|·length·==·0
6854 ··when:6854 ··when:
6855 ··-·'"audit"·in·ansible_facts.packages' 
6856 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6855 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6856 ··-·'"audit"·in·ansible_facts.packages'
6857 ··tags:6857 ··tags:
6858 ··-·CCE-85693-06858 ··-·CCE-85693-0
6859 ··-·CJIS-5.4.1.16859 ··-·CJIS-5.4.1.1
6860 ··-·DISA-STIG-SLES-15-0302906860 ··-·DISA-STIG-SLES-15-030290
6861 ··-·NIST-800-171-3.1.76861 ··-·NIST-800-171-3.1.7
6862 ··-·NIST-800-53-AU-12(a)6862 ··-·NIST-800-53-AU-12(a)
6863 ··-·NIST-800-53-AU-12(c)6863 ··-·NIST-800-53-AU-12(c)
Offset 6997, 16 lines modifiedOffset 6997, 16 lines modified
6997 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006997 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6998 ········-F·auid!=unset·-F·key=perm_mod6998 ········-F·auid!=unset·-F·key=perm_mod
6999 ······create:·true6999 ······create:·true
7000 ······mode:·o-rwx7000 ······mode:·o-rwx
7001 ······state:·present7001 ······state:·present
7002 ····when:·syscalls_found·|·length·==·07002 ····when:·syscalls_found·|·length·==·0
7003 ··when:7003 ··when:
7004 ··-·'"audit"·in·ansible_facts.packages' 
7005 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7004 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7005 ··-·'"audit"·in·ansible_facts.packages'
7006 ··-·audit_arch·==·"b64"7006 ··-·audit_arch·==·"b64"
7007 ··tags:7007 ··tags:
7008 ··-·CCE-85693-07008 ··-·CCE-85693-0
7009 ··-·CJIS-5.4.1.17009 ··-·CJIS-5.4.1.1
7010 ··-·DISA-STIG-SLES-15-0302907010 ··-·DISA-STIG-SLES-15-030290
7011 ··-·NIST-800-171-3.1.77011 ··-·NIST-800-171-3.1.7
7012 ··-·NIST-800-53-AU-12(a)7012 ··-·NIST-800-53-AU-12(a)
Offset 7059, 15 lines modifiedOffset 7059, 15 lines modified
7059 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-7059 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
7060 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,7060 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
7061 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-7061 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
7062 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-7062 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-
7063 ············030250,·4.1.9,·SV-234924r622137_rule7063 ············030250,·4.1.9,·SV-234924r622137_rule
7064 Remediation_Shell_script_⇲7064 Remediation_Shell_script_⇲
7065 #·Remediation·is·applicable·only·in·certain·platforms7065 #·Remediation·is·applicable·only·in·certain·platforms
7066 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then7066 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
7067 #·First·perform·the·remediation·of·the·syscall·rule7067 #·First·perform·the·remediation·of·the·syscall·rule
7068 #·Retrieve·hardware·architecture·of·the·underlying·system7068 #·Retrieve·hardware·architecture·of·the·underlying·system
7069 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")7069 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
7070 for·ARCH·in·"${RULE_ARCHS[@]}"7070 for·ARCH·in·"${RULE_ARCHS[@]}"
7071 do7071 do
Offset 7428, 16 lines modifiedOffset 7428, 16 lines modified
7428 ··-·reboot_required7428 ··-·reboot_required
7429 ··-·restrict_strategy7429 ··-·restrict_strategy
  
7430 -·name:·Set·architecture·for·audit·chown·tasks7430 -·name:·Set·architecture·for·audit·chown·tasks
7431 ··set_fact:7431 ··set_fact:
7432 ····audit_arch:·b647432 ····audit_arch:·b64
7433 ··when:7433 ··when:
7434 ··-·'"audit"·in·ansible_facts.packages' 
7435 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7434 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7435 ··-·'"audit"·in·ansible_facts.packages'
7436 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture7436 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
7437 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"7437 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
7438 ··tags:7438 ··tags:
7439 ··-·CCE-85690-67439 ··-·CCE-85690-6
7440 ··-·CJIS-5.4.1.17440 ··-·CJIS-5.4.1.1
7441 ··-·DISA-STIG-SLES-15-0302507441 ··-·DISA-STIG-SLES-15-030250
7442 ··-·NIST-800-171-3.1.77442 ··-·NIST-800-171-3.1.7
Offset 7581, 16 lines modifiedOffset 7581, 16 lines modified
7581 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007581 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7582 ········-F·auid!=unset·-F·key=perm_mod7582 ········-F·auid!=unset·-F·key=perm_mod
7583 ······create:·true7583 ······create:·true
7584 ······mode:·o-rwx7584 ······mode:·o-rwx
7585 ······state:·present7585 ······state:·present
7586 ····when:·syscalls_found·|·length·==·07586 ····when:·syscalls_found·|·length·==·0
7587 ··when:7587 ··when:
7588 ··-·'"audit"·in·ansible_facts.packages' 
7589 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7588 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7589 ··-·'"audit"·in·ansible_facts.packages'
7590 ··tags:7590 ··tags:
7591 ··-·CCE-85690-67591 ··-·CCE-85690-6
7592 ··-·CJIS-5.4.1.17592 ··-·CJIS-5.4.1.1
7593 ··-·DISA-STIG-SLES-15-0302507593 ··-·DISA-STIG-SLES-15-030250
7594 ··-·NIST-800-171-3.1.77594 ··-·NIST-800-171-3.1.7
7595 ··-·NIST-800-53-AU-12(a)7595 ··-·NIST-800-53-AU-12(a)
7596 ··-·NIST-800-53-AU-12(c)7596 ··-·NIST-800-53-AU-12(c)
Offset 7732, 16 lines modifiedOffset 7732, 16 lines modified
7732 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10007732 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
7733 ········-F·auid!=unset·-F·key=perm_mod7733 ········-F·auid!=unset·-F·key=perm_mod
7734 ······create:·true7734 ······create:·true
7735 ······mode:·o-rwx7735 ······mode:·o-rwx
7736 ······state:·present7736 ······state:·present
Max diff block lines reached; 304890/310099 bytes (98.32%) of diff not shown.
448 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-standard.html
    
Offset 39108, 20 lines modifiedOffset 39108, 20 lines modified
00098c30:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00098c30:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00098c40:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00098c40:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00098c50:·643d·2269·646d·3139·3637·3822·3e3c·7072··d="idm19678"><pr00098c50:·643d·2269·646d·3139·3637·3822·3e3c·7072··d="idm19678"><pr
00098c60:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi00098c60:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
00098c70:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica00098c70:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
00098c80:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert00098c80:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
00098c90:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if00098c90:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
00098ca0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
00098cb0:·6175·6469·7420·2661·6d70·3b26·616d·703b··audit·&amp;&amp; 
00098cc0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker00098ca0:·205b·2021·202d·6620·2f2e·646f·636b·6572···[·!·-f·/.docker
00098cd0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;00098cb0:·656e·7620·5d20·2661·6d70·3b26·616d·703b··env·]·&amp;&amp;
00098ce0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co00098cc0:·205b·2021·202d·6620·2f72·756e·2f2e·636f···[·!·-f·/run/.co
00098cf0:·6e74·6169·6e65·7265·6e76·205d·3b20·7468··ntainerenv·];·th00098cd0:·6e74·6169·6e65·7265·6e76·205d·2026·616d··ntainerenv·]·&am
 00098ce0:·703b·2661·6d70·3b20·7270·6d20·2d2d·7175··p;&amp;·rpm·--qu
 00098cf0:·6965·7420·2d71·2061·7564·6974·3b20·7468··iet·-q·audit;·th
00098d00:·656e·0a0a·2320·4669·7273·7420·7065·7266··en..#·First·perf00098d00:·656e·0a0a·2320·4669·7273·7420·7065·7266··en..#·First·perf
00098d10:·6f72·6d20·7468·6520·7265·6d65·6469·6174··orm·the·remediat00098d10:·6f72·6d20·7468·6520·7265·6d65·6469·6174··orm·the·remediat
00098d20:·696f·6e20·6f66·2074·6865·2073·7973·6361··ion·of·the·sysca00098d20:·696f·6e20·6f66·2074·6865·2073·7973·6361··ion·of·the·sysca
00098d30:·6c6c·2072·756c·650a·2320·5265·7472·6965··ll·rule.#·Retrie00098d30:·6c6c·2072·756c·650a·2320·5265·7472·6965··ll·rule.#·Retrie
00098d40:·7665·2068·6172·6477·6172·6520·6172·6368··ve·hardware·arch00098d40:·7665·2068·6172·6477·6172·6520·6172·6368··ve·hardware·arch
00098d50:·6974·6563·7475·7265·206f·6620·7468·6520··itecture·of·the·00098d50:·6974·6563·7475·7265·206f·6620·7468·6520··itecture·of·the·
00098d60:·756e·6465·726c·7969·6e67·2073·7973·7465··underlying·syste00098d60:·756e·6465·726c·7969·6e67·2073·7973·7465··underlying·syste
Offset 40009, 23 lines modifiedOffset 40009, 23 lines modified
0009c480:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s0009c480:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s
0009c490:·7472·6174·6567·790a·0a2d·206e·616d·653a··trategy..-·name:0009c490:·7472·6174·6567·790a·0a2d·206e·616d·653a··trategy..-·name:
0009c4a0:·2053·6574·2061·7263·6869·7465·6374·7572···Set·architectur0009c4a0:·2053·6574·2061·7263·6869·7465·6374·7572···Set·architectur
0009c4b0:·6520·666f·7220·6175·6469·7420·6368·6d6f··e·for·audit·chmo0009c4b0:·6520·666f·7220·6175·6469·7420·6368·6d6f··e·for·audit·chmo
0009c4c0:·6420·7461·736b·730a·2020·7365·745f·6661··d·tasks.··set_fa0009c4c0:·6420·7461·736b·730a·2020·7365·745f·6661··d·tasks.··set_fa
0009c4d0:·6374·3a0a·2020·2020·6175·6469·745f·6172··ct:.····audit_ar0009c4d0:·6374·3a0a·2020·2020·6175·6469·745f·6172··ct:.····audit_ar
0009c4e0:·6368·3a20·6236·340a·2020·7768·656e·3a0a··ch:·b64.··when:.0009c4e0:·6368·3a20·6236·340a·2020·7768·656e·3a0a··ch:·b64.··when:.
0009c4f0:·2020·2d20·2722·6175·6469·7422·2069·6e20····-·'"audit"·in· 
0009c500:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
0009c510:·636b·6167·6573·270a·2020·2d20·616e·7369··ckages'.··-·ansi 
0009c520:·626c·655f·7669·7274·7561·6c69·7a61·7469··ble_virtualizati 
0009c530:·6f6e·5f74·7970·6520·6e6f·7420·696e·205b··on_type·not·in·[ 
0009c540:·2264·6f63·6b65·7222·2c20·226c·7863·222c··"docker",·"lxc", 
0009c550:·2022·6f70·656e·767a·222c·2022·706f·646d···"openvz",·"podm 
0009c560:·616e·222c·2022·636f·6e74·6169·6e65·7222··an",·"container"0009c4f0:·2020·2d20·616e·7369·626c·655f·7669·7274····-·ansible_virt
 0009c500:·7561·6c69·7a61·7469·6f6e·5f74·7970·6520··ualization_type·
 0009c510:·6e6f·7420·696e·205b·2264·6f63·6b65·7222··not·in·["docker"
 0009c520:·2c20·226c·7863·222c·2022·6f70·656e·767a··,·"lxc",·"openvz
 0009c530:·222c·2022·706f·646d·616e·222c·2022·636f··",·"podman",·"co
 0009c540:·6e74·6169·6e65·7222·5d0a·2020·2d20·2722··ntainer"].··-·'"
 0009c550:·6175·6469·7422·2069·6e20·616e·7369·626c··audit"·in·ansibl
 0009c560:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
0009c570:·5d0a·2020·2d20·616e·7369·626c·655f·6172··].··-·ansible_ar0009c570:·270a·2020·2d20·616e·7369·626c·655f·6172··'.··-·ansible_ar
0009c580:·6368·6974·6563·7475·7265·203d·3d20·2261··chitecture·==·"a0009c580:·6368·6974·6563·7475·7265·203d·3d20·2261··chitecture·==·"a
0009c590:·6172·6368·3634·2220·6f72·2061·6e73·6962··arch64"·or·ansib0009c590:·6172·6368·3634·2220·6f72·2061·6e73·6962··arch64"·or·ansib
0009c5a0:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·0009c5a0:·6c65·5f61·7263·6869·7465·6374·7572·6520··le_architecture·
0009c5b0:·3d3d·2022·7070·6336·3422·206f·7220·616e··==·"ppc64"·or·an0009c5b0:·3d3d·2022·7070·6336·3422·206f·7220·616e··==·"ppc64"·or·an
0009c5c0:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu0009c5c0:·7369·626c·655f·6172·6368·6974·6563·7475··sible_architectu
0009c5d0:·7265·0a20·2020·203d·3d20·2270·7063·3634··re.····==·"ppc640009c5d0:·7265·0a20·2020·203d·3d20·2270·7063·3634··re.····==·"ppc64
0009c5e0:·6c65·2220·6f72·2061·6e73·6962·6c65·5f61··le"·or·ansible_a0009c5e0:·6c65·2220·6f72·2061·6e73·6962·6c65·5f61··le"·or·ansible_a
Offset 40339, 23 lines modifiedOffset 40339, 23 lines modified
0009d920:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo0009d920:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo
0009d930:·640a·2020·2020·2020·6372·6561·7465·3a20··d.······create:·0009d930:·640a·2020·2020·2020·6372·6561·7465·3a20··d.······create:·
0009d940:·7472·7565·0a20·2020·2020·206d·6f64·653a··true.······mode:0009d940:·7472·7565·0a20·2020·2020·206d·6f64·653a··true.······mode:
0009d950:·206f·2d72·7778·0a20·2020·2020·2073·7461···o-rwx.······sta0009d950:·206f·2d72·7778·0a20·2020·2020·2073·7461···o-rwx.······sta
0009d960:·7465·3a20·7072·6573·656e·740a·2020·2020··te:·present.····0009d960:·7465·3a20·7072·6573·656e·740a·2020·2020··te:·present.····
0009d970:·7768·656e·3a20·7379·7363·616c·6c73·5f66··when:·syscalls_f0009d970:·7768·656e·3a20·7379·7363·616c·6c73·5f66··when:·syscalls_f
0009d980:·6f75·6e64·207c·206c·656e·6774·6820·3d3d··ound·|·length·==0009d980:·6f75·6e64·207c·206c·656e·6774·6820·3d3d··ound·|·length·==
0009d990:·2030·0a20·2077·6865·6e3a·0a20·202d·2027···0.··when:.··-·'0009d990:·2030·0a20·2077·6865·6e3a·0a20·202d·2061···0.··when:.··-·a
0009d9a0:·2261·7564·6974·2220·696e·2061·6e73·6962··"audit"·in·ansib 
0009d9b0:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
0009d9c0:·7327·0a20·202d·2061·6e73·6962·6c65·5f76··s'.··-·ansible_v 
0009d9d0:·6972·7475·616c·697a·6174·696f·6e5f·7479··irtualization_ty 
0009d9e0:·7065·206e·6f74·2069·6e20·5b22·646f·636b··pe·not·in·["dock 
0009d9f0:·6572·222c·2022·6c78·6322·2c20·226f·7065··er",·"lxc",·"ope 
0009da00:·6e76·7a22·2c20·2270·6f64·6d61·6e22·2c20··nvz",·"podman",· 
0009da10:·2263·6f6e·7461·696e·6572·225d·0a20·2074··"container"].··t0009d9a0:·6e73·6962·6c65·5f76·6972·7475·616c·697a··nsible_virtualiz
 0009d9b0:·6174·696f·6e5f·7479·7065·206e·6f74·2069··ation_type·not·i
 0009d9c0:·6e20·5b22·646f·636b·6572·222c·2022·6c78··n·["docker",·"lx
 0009d9d0:·6322·2c20·226f·7065·6e76·7a22·2c20·2270··c",·"openvz",·"p
 0009d9e0:·6f64·6d61·6e22·2c20·2263·6f6e·7461·696e··odman",·"contain
 0009d9f0:·6572·225d·0a20·202d·2027·2261·7564·6974··er"].··-·'"audit
 0009da00:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 0009da10:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t
0009da20:·6167·733a·0a20·202d·2043·4345·2d38·3536··ags:.··-·CCE-8560009da20:·6167·733a·0a20·202d·2043·4345·2d38·3536··ags:.··-·CCE-856
0009da30:·3933·2d30·0a20·202d·2043·4a49·532d·352e··93-0.··-·CJIS-5.0009da30:·3933·2d30·0a20·202d·2043·4a49·532d·352e··93-0.··-·CJIS-5.
0009da40:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S0009da40:·342e·312e·310a·2020·2d20·4449·5341·2d53··4.1.1.··-·DISA-S
0009da50:·5449·472d·534c·4553·2d31·352d·3033·3032··TIG-SLES-15-03020009da50:·5449·472d·534c·4553·2d31·352d·3033·3032··TIG-SLES-15-0302
0009da60:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-0009da60:·3930·0a20·202d·204e·4953·542d·3830·302d··90.··-·NIST-800-
0009da70:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI0009da70:·3137·312d·332e·312e·370a·2020·2d20·4e49··171-3.1.7.··-·NI
0009da80:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(0009da80:·5354·2d38·3030·2d35·332d·4155·2d31·3228··ST-800-53-AU-12(
Offset 40659, 22 lines modifiedOffset 40659, 22 lines modified
0009ed20:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create0009ed20:·6d6f·640a·2020·2020·2020·6372·6561·7465··mod.······create
0009ed30:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod0009ed30:·3a20·7472·7565·0a20·2020·2020·206d·6f64··:·true.······mod
0009ed40:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s0009ed40:·653a·206f·2d72·7778·0a20·2020·2020·2073··e:·o-rwx.······s
0009ed50:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··0009ed50:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
0009ed60:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls0009ed60:·2020·7768·656e·3a20·7379·7363·616c·6c73····when:·syscalls
0009ed70:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·0009ed70:·5f66·6f75·6e64·207c·206c·656e·6774·6820··_found·|·length·
0009ed80:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-0009ed80:·3d3d·2030·0a20·2077·6865·6e3a·0a20·202d··==·0.··when:.··-
0009ed90:·2027·2261·7564·6974·2220·696e·2061·6e73···'"audit"·in·ans 
0009eda0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
0009edb0:·6765·7327·0a20·202d·2061·6e73·6962·6c65··ges'.··-·ansible 
0009edc0:·5f76·6972·7475·616c·697a·6174·696f·6e5f··_virtualization_ 
0009edd0:·7479·7065·206e·6f74·2069·6e20·5b22·646f··type·not·in·["do 
0009ede0:·636b·6572·222c·2022·6c78·6322·2c20·226f··cker",·"lxc",·"o 
0009edf0:·7065·6e76·7a22·2c20·2270·6f64·6d61·6e22··penvz",·"podman" 
0009ee00:·2c20·2263·6f6e·7461·696e·6572·225d·0a20··,·"container"].·0009ed90:·2061·6e73·6962·6c65·5f76·6972·7475·616c···ansible_virtual
 0009eda0:·697a·6174·696f·6e5f·7479·7065·206e·6f74··ization_type·not
 0009edb0:·2069·6e20·5b22·646f·636b·6572·222c·2022···in·["docker",·"
 0009edc0:·6c78·6322·2c20·226f·7065·6e76·7a22·2c20··lxc",·"openvz",·
 0009edd0:·2270·6f64·6d61·6e22·2c20·2263·6f6e·7461··"podman",·"conta
 0009ede0:·696e·6572·225d·0a20·202d·2027·2261·7564··iner"].··-·'"aud
 0009edf0:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f
 0009ee00:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.·
0009ee10:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==0009ee10:·202d·2061·7564·6974·5f61·7263·6820·3d3d···-·audit_arch·==
0009ee20:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·0009ee20:·2022·6236·3422·0a20·2074·6167·733a·0a20···"b64".··tags:.·
0009ee30:·202d·2043·4345·2d38·3536·3933·2d30·0a20···-·CCE-85693-0.·0009ee30:·202d·2043·4345·2d38·3536·3933·2d30·0a20···-·CCE-85693-0.·
0009ee40:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.0009ee40:·202d·2043·4a49·532d·352e·342e·312e·310a···-·CJIS-5.4.1.1.
0009ee50:·2020·2d20·4449·5341·2d53·5449·472d·534c····-·DISA-STIG-SL0009ee50:·2020·2d20·4449·5341·2d53·5449·472d·534c····-·DISA-STIG-SL
0009ee60:·4553·2d31·352d·3033·3032·3930·0a20·202d··ES-15-030290.··-0009ee60:·4553·2d31·352d·3033·3032·3930·0a20·202d··ES-15-030290.··-
0009ee70:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.0009ee70:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
Offset 41694, 21 lines modifiedOffset 41694, 21 lines modified
000a2dd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan000a2dd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
000a2de0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll000a2de0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
000a2df0:·6170·7365·2220·6964·3d22·6964·6d31·3938··apse"·id="idm198000a2df0:·6170·7365·2220·6964·3d22·6964·6d31·3938··apse"·id="idm198
000a2e00:·3432·223e·3c70·7265·3e3c·636f·6465·3e23··42"><pre><code>#000a2e00:·3432·223e·3c70·7265·3e3c·636f·6465·3e23··42"><pre><code>#
000a2e10:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·000a2e10:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
000a2e20:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·000a2e20:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
000a2e30:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf000a2e30:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
000a2e40:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu000a2e40:·6f72·6d73·0a69·6620·5b20·2120·2d66·202f··orms.if·[·!·-f·/
000a2e50:·6965·7420·2d71·2061·7564·6974·2026·616d··iet·-q·audit·&am000a2e50:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am
000a2e60:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/000a2e60:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/
000a2e70:·2e64·6f63·6b65·7265·6e76·205d·2026·616d··.dockerenv·]·&am 
000a2e80:·703b·2661·6d70·3b20·5b20·2120·2d66·202f··p;&amp;·[·!·-f·/ 
Max diff block lines reached; 336662/346521 bytes (97.15%) of diff not shown.
110 KB
html2text {}
    
Offset 5564, 15 lines modifiedOffset 5564, 15 lines modified
5564 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-5564 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
5565 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,5565 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
5566 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-5566 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
5567 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-5567 ············00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-030290,·4.1.9,·SV-
5568 ············234928r622137_rule5568 ············234928r622137_rule
5569 Remediation_Shell_script_⇲5569 Remediation_Shell_script_⇲
5570 #·Remediation·is·applicable·only·in·certain·platforms5570 #·Remediation·is·applicable·only·in·certain·platforms
5571 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then5571 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
5572 #·First·perform·the·remediation·of·the·syscall·rule5572 #·First·perform·the·remediation·of·the·syscall·rule
5573 #·Retrieve·hardware·architecture·of·the·underlying·system5573 #·Retrieve·hardware·architecture·of·the·underlying·system
5574 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")5574 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
5575 for·ARCH·in·"${RULE_ARCHS[@]}"5575 for·ARCH·in·"${RULE_ARCHS[@]}"
5576 do5576 do
Offset 5933, 16 lines modifiedOffset 5933, 16 lines modified
5933 ··-·reboot_required5933 ··-·reboot_required
5934 ··-·restrict_strategy5934 ··-·restrict_strategy
  
5935 -·name:·Set·architecture·for·audit·chmod·tasks5935 -·name:·Set·architecture·for·audit·chmod·tasks
5936 ··set_fact:5936 ··set_fact:
5937 ····audit_arch:·b645937 ····audit_arch:·b64
5938 ··when:5938 ··when:
5939 ··-·'"audit"·in·ansible_facts.packages' 
5940 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5939 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5940 ··-·'"audit"·in·ansible_facts.packages'
5941 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5941 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5942 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5942 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5943 ··tags:5943 ··tags:
5944 ··-·CCE-85693-05944 ··-·CCE-85693-0
5945 ··-·CJIS-5.4.1.15945 ··-·CJIS-5.4.1.1
5946 ··-·DISA-STIG-SLES-15-0302905946 ··-·DISA-STIG-SLES-15-030290
5947 ··-·NIST-800-171-3.1.75947 ··-·NIST-800-171-3.1.7
Offset 6084, 16 lines modifiedOffset 6084, 16 lines modified
6084 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006084 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6085 ········-F·auid!=unset·-F·key=perm_mod6085 ········-F·auid!=unset·-F·key=perm_mod
6086 ······create:·true6086 ······create:·true
6087 ······mode:·o-rwx6087 ······mode:·o-rwx
6088 ······state:·present6088 ······state:·present
6089 ····when:·syscalls_found·|·length·==·06089 ····when:·syscalls_found·|·length·==·0
6090 ··when:6090 ··when:
6091 ··-·'"audit"·in·ansible_facts.packages' 
6092 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6091 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6092 ··-·'"audit"·in·ansible_facts.packages'
6093 ··tags:6093 ··tags:
6094 ··-·CCE-85693-06094 ··-·CCE-85693-0
6095 ··-·CJIS-5.4.1.16095 ··-·CJIS-5.4.1.1
6096 ··-·DISA-STIG-SLES-15-0302906096 ··-·DISA-STIG-SLES-15-030290
6097 ··-·NIST-800-171-3.1.76097 ··-·NIST-800-171-3.1.7
6098 ··-·NIST-800-53-AU-12(a)6098 ··-·NIST-800-53-AU-12(a)
6099 ··-·NIST-800-53-AU-12(c)6099 ··-·NIST-800-53-AU-12(c)
Offset 6233, 16 lines modifiedOffset 6233, 16 lines modified
6233 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006233 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6234 ········-F·auid!=unset·-F·key=perm_mod6234 ········-F·auid!=unset·-F·key=perm_mod
6235 ······create:·true6235 ······create:·true
6236 ······mode:·o-rwx6236 ······mode:·o-rwx
6237 ······state:·present6237 ······state:·present
6238 ····when:·syscalls_found·|·length·==·06238 ····when:·syscalls_found·|·length·==·0
6239 ··when:6239 ··when:
6240 ··-·'"audit"·in·ansible_facts.packages' 
6241 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6240 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6241 ··-·'"audit"·in·ansible_facts.packages'
6242 ··-·audit_arch·==·"b64"6242 ··-·audit_arch·==·"b64"
6243 ··tags:6243 ··tags:
6244 ··-·CCE-85693-06244 ··-·CCE-85693-0
6245 ··-·CJIS-5.4.1.16245 ··-·CJIS-5.4.1.1
6246 ··-·DISA-STIG-SLES-15-0302906246 ··-·DISA-STIG-SLES-15-030290
6247 ··-·NIST-800-171-3.1.76247 ··-·NIST-800-171-3.1.7
6248 ··-·NIST-800-53-AU-12(a)6248 ··-·NIST-800-53-AU-12(a)
Offset 6295, 15 lines modifiedOffset 6295, 15 lines modified
6295 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-6295 ············PR.PT-1,·PR.PT-4,·RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-
6296 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,6296 ············000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-GPOS-00206,
6297 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-6297 ············SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-
6298 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-6298 ············00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,·SLES-15-
6299 ············030250,·4.1.9,·SV-234924r622137_rule6299 ············030250,·4.1.9,·SV-234924r622137_rule
6300 Remediation_Shell_script_⇲6300 Remediation_Shell_script_⇲
6301 #·Remediation·is·applicable·only·in·certain·platforms6301 #·Remediation·is·applicable·only·in·certain·platforms
6302 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then6302 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
6303 #·First·perform·the·remediation·of·the·syscall·rule6303 #·First·perform·the·remediation·of·the·syscall·rule
6304 #·Retrieve·hardware·architecture·of·the·underlying·system6304 #·Retrieve·hardware·architecture·of·the·underlying·system
6305 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")6305 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
6306 for·ARCH·in·"${RULE_ARCHS[@]}"6306 for·ARCH·in·"${RULE_ARCHS[@]}"
6307 do6307 do
Offset 6664, 16 lines modifiedOffset 6664, 16 lines modified
6664 ··-·reboot_required6664 ··-·reboot_required
6665 ··-·restrict_strategy6665 ··-·restrict_strategy
  
6666 -·name:·Set·architecture·for·audit·chown·tasks6666 -·name:·Set·architecture·for·audit·chown·tasks
6667 ··set_fact:6667 ··set_fact:
6668 ····audit_arch:·b646668 ····audit_arch:·b64
6669 ··when:6669 ··when:
6670 ··-·'"audit"·in·ansible_facts.packages' 
6671 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6670 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6671 ··-·'"audit"·in·ansible_facts.packages'
6672 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6672 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6673 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6673 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6674 ··tags:6674 ··tags:
6675 ··-·CCE-85690-66675 ··-·CCE-85690-6
6676 ··-·CJIS-5.4.1.16676 ··-·CJIS-5.4.1.1
6677 ··-·DISA-STIG-SLES-15-0302506677 ··-·DISA-STIG-SLES-15-030250
6678 ··-·NIST-800-171-3.1.76678 ··-·NIST-800-171-3.1.7
Offset 6817, 16 lines modifiedOffset 6817, 16 lines modified
6817 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006817 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6818 ········-F·auid!=unset·-F·key=perm_mod6818 ········-F·auid!=unset·-F·key=perm_mod
6819 ······create:·true6819 ······create:·true
6820 ······mode:·o-rwx6820 ······mode:·o-rwx
6821 ······state:·present6821 ······state:·present
6822 ····when:·syscalls_found·|·length·==·06822 ····when:·syscalls_found·|·length·==·0
6823 ··when:6823 ··when:
6824 ··-·'"audit"·in·ansible_facts.packages' 
6825 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6824 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6825 ··-·'"audit"·in·ansible_facts.packages'
6826 ··tags:6826 ··tags:
6827 ··-·CCE-85690-66827 ··-·CCE-85690-6
6828 ··-·CJIS-5.4.1.16828 ··-·CJIS-5.4.1.1
6829 ··-·DISA-STIG-SLES-15-0302506829 ··-·DISA-STIG-SLES-15-030250
6830 ··-·NIST-800-171-3.1.76830 ··-·NIST-800-171-3.1.7
6831 ··-·NIST-800-53-AU-12(a)6831 ··-·NIST-800-53-AU-12(a)
6832 ··-·NIST-800-53-AU-12(c)6832 ··-·NIST-800-53-AU-12(c)
Offset 6968, 16 lines modifiedOffset 6968, 16 lines modified
6968 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006968 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6969 ········-F·auid!=unset·-F·key=perm_mod6969 ········-F·auid!=unset·-F·key=perm_mod
6970 ······create:·true6970 ······create:·true
6971 ······mode:·o-rwx6971 ······mode:·o-rwx
6972 ······state:·present6972 ······state:·present
Max diff block lines reached; 106899/112108 bytes (95.35%) of diff not shown.
942 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-stig.html
    
Offset 66377, 21 lines modifiedOffset 66377, 21 lines modified
00103480:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class00103480:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
00103490:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse00103490:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
001034a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i001034a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
001034b0:·646d·3139·3637·3822·3e3c·7072·653e·3c63··dm19678"><pre><c001034b0:·646d·3139·3637·3822·3e3c·7072·653e·3c63··dm19678"><pre><c
001034c0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio001034c0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
001034d0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·001034d0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
001034e0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·001034e0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
001034f0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm001034f0:·706c·6174·666f·726d·730a·6966·205b·2021··platforms.if·[·!
00103500:·202d·2d71·7569·6574·202d·7120·6175·6469···--quiet·-q·audi 
00103510:·7420·2661·6d70·3b26·616d·703b·205b·2021··t·&amp;&amp;·[·! 
00103520:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·00103500:·202d·6620·2f2e·646f·636b·6572·656e·7620···-f·/.dockerenv·
00103530:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!00103510:·5d20·2661·6d70·3b26·616d·703b·205b·2021··]·&amp;&amp;·[·!
00103540:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai00103520:·202d·6620·2f72·756e·2f2e·636f·6e74·6169···-f·/run/.contai
00103550:·6e65·7265·6e76·205d·3b20·7468·656e·0a0a··nerenv·];·then..00103530:·6e65·7265·6e76·205d·2026·616d·703b·2661··nerenv·]·&amp;&a
 00103540:·6d70·3b20·7270·6d20·2d2d·7175·6965·7420··mp;·rpm·--quiet·
 00103550:·2d71·2061·7564·6974·3b20·7468·656e·0a0a··-q·audit;·then..
00103560:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·00103560:·2320·4669·7273·7420·7065·7266·6f72·6d20··#·First·perform·
00103570:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·00103570:·7468·6520·7265·6d65·6469·6174·696f·6e20··the·remediation·
00103580:·6f66·2074·6865·2073·7973·6361·6c6c·2072··of·the·syscall·r00103580:·6f66·2074·6865·2073·7973·6361·6c6c·2072··of·the·syscall·r
00103590:·756c·650a·2320·5265·7472·6965·7665·2068··ule.#·Retrieve·h00103590:·756c·650a·2320·5265·7472·6965·7665·2068··ule.#·Retrieve·h
001035a0:·6172·6477·6172·6520·6172·6368·6974·6563··ardware·architec001035a0:·6172·6477·6172·6520·6172·6368·6974·6563··ardware·architec
001035b0:·7475·7265·206f·6620·7468·6520·756e·6465··ture·of·the·unde001035b0:·7475·7265·206f·6620·7468·6520·756e·6465··ture·of·the·unde
001035c0:·726c·7969·6e67·2073·7973·7465·6d0a·5b20··rlying·system.[·001035c0:·726c·7969·6e67·2073·7973·7465·6d0a·5b20··rlying·system.[·
Offset 67279, 22 lines modifiedOffset 67279, 22 lines modified
00106ce0:·2d20·7265·7374·7269·6374·5f73·7472·6174··-·restrict_strat00106ce0:·2d20·7265·7374·7269·6374·5f73·7472·6174··-·restrict_strat
00106cf0:·6567·790a·0a2d·206e·616d·653a·2053·6574··egy..-·name:·Set00106cf0:·6567·790a·0a2d·206e·616d·653a·2053·6574··egy..-·name:·Set
00106d00:·2061·7263·6869·7465·6374·7572·6520·666f···architecture·fo00106d00:·2061·7263·6869·7465·6374·7572·6520·666f···architecture·fo
00106d10:·7220·6175·6469·7420·6368·6d6f·6420·7461··r·audit·chmod·ta00106d10:·7220·6175·6469·7420·6368·6d6f·6420·7461··r·audit·chmod·ta
00106d20:·736b·730a·2020·7365·745f·6661·6374·3a0a··sks.··set_fact:.00106d20:·736b·730a·2020·7365·745f·6661·6374·3a0a··sks.··set_fact:.
00106d30:·2020·2020·6175·6469·745f·6172·6368·3a20······audit_arch:·00106d30:·2020·2020·6175·6469·745f·6172·6368·3a20······audit_arch:·
00106d40:·6236·340a·2020·7768·656e·3a0a·2020·2d20··b64.··when:.··-·00106d40:·6236·340a·2020·7768·656e·3a0a·2020·2d20··b64.··when:.··-·
00106d50:·2722·6175·6469·7422·2069·6e20·616e·7369··'"audit"·in·ansi 
00106d60:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag 
00106d70:·6573·270a·2020·2d20·616e·7369·626c·655f··es'.··-·ansible_ 
00106d80:·7669·7274·7561·6c69·7a61·7469·6f6e·5f74··virtualization_t 
00106d90:·7970·6520·6e6f·7420·696e·205b·2264·6f63··ype·not·in·["doc 
00106da0:·6b65·7222·2c20·226c·7863·222c·2022·6f70··ker",·"lxc",·"op 
00106db0:·656e·767a·222c·2022·706f·646d·616e·222c··envz",·"podman", 
00106dc0:·2022·636f·6e74·6169·6e65·7222·5d0a·2020···"container"].··00106d50:·616e·7369·626c·655f·7669·7274·7561·6c69··ansible_virtuali
 00106d60:·7a61·7469·6f6e·5f74·7970·6520·6e6f·7420··zation_type·not·
 00106d70:·696e·205b·2264·6f63·6b65·7222·2c20·226c··in·["docker",·"l
 00106d80:·7863·222c·2022·6f70·656e·767a·222c·2022··xc",·"openvz",·"
 00106d90:·706f·646d·616e·222c·2022·636f·6e74·6169··podman",·"contai
 00106da0:·6e65·7222·5d0a·2020·2d20·2722·6175·6469··ner"].··-·'"audi
 00106db0:·7422·2069·6e20·616e·7369·626c·655f·6661··t"·in·ansible_fa
 00106dc0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
00106dd0:·2d20·616e·7369·626c·655f·6172·6368·6974··-·ansible_archit00106dd0:·2d20·616e·7369·626c·655f·6172·6368·6974··-·ansible_archit
00106de0:·6563·7475·7265·203d·3d20·2261·6172·6368··ecture·==·"aarch00106de0:·6563·7475·7265·203d·3d20·2261·6172·6368··ecture·==·"aarch
00106df0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a00106df0:·3634·2220·6f72·2061·6e73·6962·6c65·5f61··64"·or·ansible_a
00106e00:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"00106e00:·7263·6869·7465·6374·7572·6520·3d3d·2022··rchitecture·==·"
00106e10:·7070·6336·3422·206f·7220·616e·7369·626c··ppc64"·or·ansibl00106e10:·7070·6336·3422·206f·7220·616e·7369·626c··ppc64"·or·ansibl
00106e20:·655f·6172·6368·6974·6563·7475·7265·0a20··e_architecture.·00106e20:·655f·6172·6368·6974·6563·7475·7265·0a20··e_architecture.·
00106e30:·2020·203d·3d20·2270·7063·3634·6c65·2220·····==·"ppc64le"·00106e30:·2020·203d·3d20·2270·7063·3634·6c65·2220·····==·"ppc64le"·
Offset 67609, 23 lines modifiedOffset 67609, 23 lines modified
00108180:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··00108180:·206b·6579·3d70·6572·6d5f·6d6f·640a·2020···key=perm_mod.··
00108190:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true00108190:·2020·2020·6372·6561·7465·3a20·7472·7565······create:·true
001081a0:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r001081a0:·0a20·2020·2020·206d·6f64·653a·206f·2d72··.······mode:·o-r
001081b0:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·001081b0:·7778·0a20·2020·2020·2073·7461·7465·3a20··wx.······state:·
001081c0:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when001081c0:·7072·6573·656e·740a·2020·2020·7768·656e··present.····when
001081d0:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found001081d0:·3a20·7379·7363·616c·6c73·5f66·6f75·6e64··:·syscalls_found
001081e0:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·001081e0:·207c·206c·656e·6774·6820·3d3d·2030·0a20···|·length·==·0.·
001081f0:·2077·6865·6e3a·0a20·202d·2027·2261·7564···when:.··-·'"aud001081f0:·2077·6865·6e3a·0a20·202d·2061·6e73·6962···when:.··-·ansib
00108200:·6974·2220·696e·2061·6e73·6962·6c65·5f66··it"·in·ansible_f 
00108210:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
00108220:·202d·2061·6e73·6962·6c65·5f76·6972·7475···-·ansible_virtu 
00108230:·616c·697a·6174·696f·6e5f·7479·7065·206e··alization_type·n 
00108240:·6f74·2069·6e20·5b22·646f·636b·6572·222c··ot·in·["docker", 
00108250:·2022·6c78·6322·2c20·226f·7065·6e76·7a22···"lxc",·"openvz" 
00108260:·2c20·2270·6f64·6d61·6e22·2c20·2263·6f6e··,·"podman",·"con 
00108270:·7461·696e·6572·225d·0a20·2074·6167·733a··tainer"].··tags:00108200:·6c65·5f76·6972·7475·616c·697a·6174·696f··le_virtualizatio
 00108210:·6e5f·7479·7065·206e·6f74·2069·6e20·5b22··n_type·not·in·["
 00108220:·646f·636b·6572·222c·2022·6c78·6322·2c20··docker",·"lxc",·
 00108230:·226f·7065·6e76·7a22·2c20·2270·6f64·6d61··"openvz",·"podma
 00108240:·6e22·2c20·2263·6f6e·7461·696e·6572·225d··n",·"container"]
 00108250:·0a20·202d·2027·2261·7564·6974·2220·696e··.··-·'"audit"·in
 00108260:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 00108270:·6163·6b61·6765·7327·0a20·2074·6167·733a··ackages'.··tags:
00108280:·0a20·202d·2043·4345·2d38·3536·3933·2d30··.··-·CCE-85693-000108280:·0a20·202d·2043·4345·2d38·3536·3933·2d30··.··-·CCE-85693-0
00108290:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.00108290:·0a20·202d·2043·4a49·532d·352e·342e·312e··.··-·CJIS-5.4.1.
001082a0:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-001082a0:·310a·2020·2d20·4449·5341·2d53·5449·472d··1.··-·DISA-STIG-
001082b0:·534c·4553·2d31·352d·3033·3032·3930·0a20··SLES-15-030290.·001082b0:·534c·4553·2d31·352d·3033·3032·3930·0a20··SLES-15-030290.·
001082c0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-001082c0:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171-
001082d0:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8001082d0:·332e·312e·370a·2020·2d20·4e49·5354·2d38··3.1.7.··-·NIST-8
001082e0:·3030·2d35·332d·4155·2d31·3228·6129·0a20··00-53-AU-12(a).·001082e0:·3030·2d35·332d·4155·2d31·3228·6129·0a20··00-53-AU-12(a).·
Offset 67928, 23 lines modifiedOffset 67928, 23 lines modified
00109570:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.00109570:·2d46·206b·6579·3d70·6572·6d5f·6d6f·640a··-F·key=perm_mod.
00109580:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr00109580:·2020·2020·2020·6372·6561·7465·3a20·7472········create:·tr
00109590:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o00109590:·7565·0a20·2020·2020·206d·6f64·653a·206f··ue.······mode:·o
001095a0:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state001095a0:·2d72·7778·0a20·2020·2020·2073·7461·7465··-rwx.······state
001095b0:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh001095b0:·3a20·7072·6573·656e·740a·2020·2020·7768··:·present.····wh
001095c0:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou001095c0:·656e·3a20·7379·7363·616c·6c73·5f66·6f75··en:·syscalls_fou
001095d0:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0001095d0:·6e64·207c·206c·656e·6774·6820·3d3d·2030··nd·|·length·==·0
001095e0:·0a20·2077·6865·6e3a·0a20·202d·2027·2261··.··when:.··-·'"a001095e0:·0a20·2077·6865·6e3a·0a20·202d·2061·6e73··.··when:.··-·ans
001095f0:·7564·6974·2220·696e·2061·6e73·6962·6c65··udit"·in·ansible 
00109600:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
00109610:·0a20·202d·2061·6e73·6962·6c65·5f76·6972··.··-·ansible_vir 
00109620:·7475·616c·697a·6174·696f·6e5f·7479·7065··tualization_type 
00109630:·206e·6f74·2069·6e20·5b22·646f·636b·6572···not·in·["docker 
00109640:·222c·2022·6c78·6322·2c20·226f·7065·6e76··",·"lxc",·"openv 
00109650:·7a22·2c20·2270·6f64·6d61·6e22·2c20·2263··z",·"podman",·"c 
00109660:·6f6e·7461·696e·6572·225d·0a20·202d·2061··ontainer"].··-·a001095f0:·6962·6c65·5f76·6972·7475·616c·697a·6174··ible_virtualizat
 00109600:·696f·6e5f·7479·7065·206e·6f74·2069·6e20··ion_type·not·in·
 00109610:·5b22·646f·636b·6572·222c·2022·6c78·6322··["docker",·"lxc"
 00109620:·2c20·226f·7065·6e76·7a22·2c20·2270·6f64··,·"openvz",·"pod
 00109630:·6d61·6e22·2c20·2263·6f6e·7461·696e·6572··man",·"container
 00109640:·225d·0a20·202d·2027·2261·7564·6974·2220··"].··-·'"audit"·
 00109650:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 00109660:·2e70·6163·6b61·6765·7327·0a20·202d·2061··.packages'.··-·a
00109670:·7564·6974·5f61·7263·6820·3d3d·2022·6236··udit_arch·==·"b600109670:·7564·6974·5f61·7263·6820·3d3d·2022·6236··udit_arch·==·"b6
00109680:·3422·0a20·2074·6167·733a·0a20·202d·2043··4".··tags:.··-·C00109680:·3422·0a20·2074·6167·733a·0a20·202d·2043··4".··tags:.··-·C
00109690:·4345·2d38·3536·3933·2d30·0a20·202d·2043··CE-85693-0.··-·C00109690:·4345·2d38·3536·3933·2d30·0a20·202d·2043··CE-85693-0.··-·C
001096a0:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·001096a0:·4a49·532d·352e·342e·312e·310a·2020·2d20··JIS-5.4.1.1.··-·
001096b0:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1001096b0:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1
001096c0:·352d·3033·3032·3930·0a20·202d·204e·4953··5-030290.··-·NIS001096c0:·352d·3033·3032·3930·0a20·202d·204e·4953··5-030290.··-·NIS
001096d0:·542d·3830·302d·3137·312d·332e·312e·370a··T-800-171-3.1.7.001096d0:·542d·3830·302d·3137·312d·332e·312e·370a··T-800-171-3.1.7.
Offset 68964, 20 lines modifiedOffset 68964, 20 lines modified
0010d630:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0010d630:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0010d640:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0010d640:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0010d650:·2220·6964·3d22·6964·6d31·3938·3432·223e··"·id="idm19842">0010d650:·2220·6964·3d22·6964·6d31·3938·3432·223e··"·id="idm19842">
0010d660:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem0010d660:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
0010d670:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl0010d670:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
0010d680:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c0010d680:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
0010d690:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms0010d690:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
0010d6a0:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet· 
0010d6b0:·2d71·2061·7564·6974·2026·616d·703b·2661··-q·audit·&amp;&a 
0010d6c0:·6d70·3b20·5b20·2120·2d66·202f·2e64·6f63··mp;·[·!·-f·/.doc0010d6a0:·0a69·6620·5b20·2120·2d66·202f·2e64·6f63··.if·[·!·-f·/.doc
0010d6d0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a0010d6b0:·6b65·7265·6e76·205d·2026·616d·703b·2661··kerenv·]·&amp;&a
Max diff block lines reached; 703698/713626 bytes (98.61%) of diff not shown.
245 KB
html2text {}
    
Offset 9901, 15 lines modifiedOffset 9901, 15 lines modified
9901 References··SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,9901 References··SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,
9902 ············A.6.2.2,·AU-3,·AU-3.1,·AU-12(c),·AU-12.1(iv),·AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,9902 ············A.6.2.2,·AU-3,·AU-3.1,·AU-12(c),·AU-12.1(iv),·AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,
9903 ············RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-9903 ············RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-
9904 ············GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,9904 ············GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000458-VMM-001810,·SRG-OS-000474-VMM-001940,
9905 ············SLES-15-030290,·4.1.9,·SV-234928r622137_rule9905 ············SLES-15-030290,·4.1.9,·SV-234928r622137_rule
9906 Remediation_Shell_script_⇲9906 Remediation_Shell_script_⇲
9907 #·Remediation·is·applicable·only·in·certain·platforms9907 #·Remediation·is·applicable·only·in·certain·platforms
9908 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9908 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
9909 #·First·perform·the·remediation·of·the·syscall·rule9909 #·First·perform·the·remediation·of·the·syscall·rule
9910 #·Retrieve·hardware·architecture·of·the·underlying·system9910 #·Retrieve·hardware·architecture·of·the·underlying·system
9911 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")9911 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
9912 for·ARCH·in·"${RULE_ARCHS[@]}"9912 for·ARCH·in·"${RULE_ARCHS[@]}"
9913 do9913 do
Offset 10263, 16 lines modifiedOffset 10263, 16 lines modified
10263 ··-·reboot_required10263 ··-·reboot_required
10264 ··-·restrict_strategy10264 ··-·restrict_strategy
  
10265 -·name:·Set·architecture·for·audit·chmod·tasks10265 -·name:·Set·architecture·for·audit·chmod·tasks
10266 ··set_fact:10266 ··set_fact:
10267 ····audit_arch:·b6410267 ····audit_arch:·b64
10268 ··when:10268 ··when:
10269 ··-·'"audit"·in·ansible_facts.packages' 
10270 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]10269 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 10270 ··-·'"audit"·in·ansible_facts.packages'
10271 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture10271 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
10272 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"10272 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
10273 ··tags:10273 ··tags:
10274 ··-·CCE-85693-010274 ··-·CCE-85693-0
10275 ··-·CJIS-5.4.1.110275 ··-·CJIS-5.4.1.1
10276 ··-·DISA-STIG-SLES-15-03029010276 ··-·DISA-STIG-SLES-15-030290
10277 ··-·NIST-800-171-3.1.710277 ··-·NIST-800-171-3.1.7
Offset 10414, 16 lines modifiedOffset 10414, 16 lines modified
10414 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100010414 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
10415 ········-F·auid!=unset·-F·key=perm_mod10415 ········-F·auid!=unset·-F·key=perm_mod
10416 ······create:·true10416 ······create:·true
10417 ······mode:·o-rwx10417 ······mode:·o-rwx
10418 ······state:·present10418 ······state:·present
10419 ····when:·syscalls_found·|·length·==·010419 ····when:·syscalls_found·|·length·==·0
10420 ··when:10420 ··when:
10421 ··-·'"audit"·in·ansible_facts.packages' 
10422 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]10421 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 10422 ··-·'"audit"·in·ansible_facts.packages'
10423 ··tags:10423 ··tags:
10424 ··-·CCE-85693-010424 ··-·CCE-85693-0
10425 ··-·CJIS-5.4.1.110425 ··-·CJIS-5.4.1.1
10426 ··-·DISA-STIG-SLES-15-03029010426 ··-·DISA-STIG-SLES-15-030290
10427 ··-·NIST-800-171-3.1.710427 ··-·NIST-800-171-3.1.7
10428 ··-·NIST-800-53-AU-12(a)10428 ··-·NIST-800-53-AU-12(a)
10429 ··-·NIST-800-53-AU-12(c)10429 ··-·NIST-800-53-AU-12(c)
Offset 10563, 16 lines modifiedOffset 10563, 16 lines modified
10563 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100010563 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
10564 ········-F·auid!=unset·-F·key=perm_mod10564 ········-F·auid!=unset·-F·key=perm_mod
10565 ······create:·true10565 ······create:·true
10566 ······mode:·o-rwx10566 ······mode:·o-rwx
10567 ······state:·present10567 ······state:·present
10568 ····when:·syscalls_found·|·length·==·010568 ····when:·syscalls_found·|·length·==·0
10569 ··when:10569 ··when:
10570 ··-·'"audit"·in·ansible_facts.packages' 
10571 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]10570 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 10571 ··-·'"audit"·in·ansible_facts.packages'
10572 ··-·audit_arch·==·"b64"10572 ··-·audit_arch·==·"b64"
10573 ··tags:10573 ··tags:
10574 ··-·CCE-85693-010574 ··-·CCE-85693-0
10575 ··-·CJIS-5.4.1.110575 ··-·CJIS-5.4.1.1
10576 ··-·DISA-STIG-SLES-15-03029010576 ··-·DISA-STIG-SLES-15-030290
10577 ··-·NIST-800-171-3.1.710577 ··-·NIST-800-171-3.1.7
10578 ··-·NIST-800-53-AU-12(a)10578 ··-·NIST-800-53-AU-12(a)
Offset 10614, 15 lines modifiedOffset 10614, 15 lines modified
10614 References··SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,10614 References··SR_7.6,·A.11.2.6,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.16.1.4,·A.16.1.5,·A.16.1.7,·A.6.2.1,
10615 ············A.6.2.2,·AU-3,·AU-3.1,·AU-12(c),·AU-12.1(iv),·AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,10615 ············A.6.2.2,·AU-3,·AU-3.1,·AU-12(c),·AU-12.1(iv),·AU-12(a),·AU-12.1(ii),·MA-4(1)(a),·DE.AE-3,·DE.AE-5,·DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.AC-3,·PR.PT-1,·PR.PT-4,
10616 ············RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-10616 ············RS.AN-1,·RS.AN-4,·FAU_GEN.1.1.c,·Req-10.5.5,·SRG-OS-000037-GPOS-00015,·SRG-OS-000042-GPOS-00020,·SRG-OS-000062-GPOS-00031,·SRG-OS-000392-GPOS-00172,·SRG-OS-000462-
10617 ············GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,10617 ············GPOS-00206,·SRG-OS-000471-GPOS-00215,·SRG-OS-000064-GPOS-00033,·SRG-OS-000466-GPOS-00210,·SRG-OS-000458-GPOS-00203,·SRG-OS-000474-GPOS-00219,·SRG-OS-000458-VMM-001810,
10618 ············SRG-OS-000474-VMM-001940,·SLES-15-030250,·4.1.9,·SV-234924r622137_rule10618 ············SRG-OS-000474-VMM-001940,·SLES-15-030250,·4.1.9,·SV-234924r622137_rule
10619 Remediation_Shell_script_⇲10619 Remediation_Shell_script_⇲
10620 #·Remediation·is·applicable·only·in·certain·platforms10620 #·Remediation·is·applicable·only·in·certain·platforms
10621 if·rpm·--quiet·-q·audit·&&·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then10621 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·]·&&·rpm·--quiet·-q·audit;·then
  
10622 #·First·perform·the·remediation·of·the·syscall·rule10622 #·First·perform·the·remediation·of·the·syscall·rule
10623 #·Retrieve·hardware·architecture·of·the·underlying·system10623 #·Retrieve·hardware·architecture·of·the·underlying·system
10624 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")10624 [·"$(getconf·LONG_BIT)"·=·"32"·]·&&·RULE_ARCHS=("b32")·||·RULE_ARCHS=("b32"·"b64")
  
10625 for·ARCH·in·"${RULE_ARCHS[@]}"10625 for·ARCH·in·"${RULE_ARCHS[@]}"
10626 do10626 do
Offset 10976, 16 lines modifiedOffset 10976, 16 lines modified
10976 ··-·reboot_required10976 ··-·reboot_required
10977 ··-·restrict_strategy10977 ··-·restrict_strategy
  
10978 -·name:·Set·architecture·for·audit·chown·tasks10978 -·name:·Set·architecture·for·audit·chown·tasks
10979 ··set_fact:10979 ··set_fact:
10980 ····audit_arch:·b6410980 ····audit_arch:·b64
10981 ··when:10981 ··when:
10982 ··-·'"audit"·in·ansible_facts.packages' 
10983 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]10982 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 10983 ··-·'"audit"·in·ansible_facts.packages'
10984 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture10984 ··-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
10985 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"10985 ····==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
10986 ··tags:10986 ··tags:
10987 ··-·CCE-85690-610987 ··-·CCE-85690-6
10988 ··-·CJIS-5.4.1.110988 ··-·CJIS-5.4.1.1
10989 ··-·DISA-STIG-SLES-15-03025010989 ··-·DISA-STIG-SLES-15-030250
10990 ··-·NIST-800-171-3.1.710990 ··-·NIST-800-171-3.1.7
Offset 11129, 16 lines modifiedOffset 11129, 16 lines modified
11129 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011129 ······line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11130 ········-F·auid!=unset·-F·key=perm_mod11130 ········-F·auid!=unset·-F·key=perm_mod
11131 ······create:·true11131 ······create:·true
11132 ······mode:·o-rwx11132 ······mode:·o-rwx
11133 ······state:·present11133 ······state:·present
11134 ····when:·syscalls_found·|·length·==·011134 ····when:·syscalls_found·|·length·==·0
11135 ··when:11135 ··when:
11136 ··-·'"audit"·in·ansible_facts.packages' 
11137 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11136 ··-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11137 ··-·'"audit"·in·ansible_facts.packages'
11138 ··tags:11138 ··tags:
11139 ··-·CCE-85690-611139 ··-·CCE-85690-6
11140 ··-·CJIS-5.4.1.111140 ··-·CJIS-5.4.1.1
11141 ··-·DISA-STIG-SLES-15-03025011141 ··-·DISA-STIG-SLES-15-030250
11142 ··-·NIST-800-171-3.1.711142 ··-·NIST-800-171-3.1.7
11143 ··-·NIST-800-53-AU-12(a)11143 ··-·NIST-800-53-AU-12(a)
11144 ··-·NIST-800-53-AU-12(c)11144 ··-·NIST-800-53-AU-12(c)
Offset 11280, 16 lines modifiedOffset 11280, 16 lines modified
11280 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011280 ······line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11281 ········-F·auid!=unset·-F·key=perm_mod11281 ········-F·auid!=unset·-F·key=perm_mod
11282 ······create:·true11282 ······create:·true
11283 ······mode:·o-rwx11283 ······mode:·o-rwx
11284 ······state:·present11284 ······state:·present
Max diff block lines reached; 245254/251095 bytes (97.67%) of diff not shown.
1.36 MB
./usr/share/doc/ssg-nondebian/table-ol7-anssirefs.html
    
Offset 63, 568 lines modifiedOffset 63, 568 lines modified
000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····
000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<
00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat
00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</
00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>
00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t
Diff chunk too large, falling back to line-by-line diff (554 lines added, 554 lines removed)
00000440:·643e·4250·3238·2852·3129·3c2f·7464·3e0a··d>BP28(R1)</td>.00000440:·643e·4250·3238·2852·3129·3c2f·7464·3e0a··d>BP28(R1)</td>.
00000450:·2020·2020·2020·3c74·643e·5265·6d6f·7665········<td>Remove00000450:·2020·2020·2020·3c74·643e·556e·696e·7374········<td>Uninst
00000460:·2074·6674·7020·4461·656d·6f6e·3c2f·7464···tftp·Daemon</td00000460:·616c·6c20·5365·6e64·6d61·696c·2050·6163··all·Sendmail·Pac
00000470:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:00000470:·6b61·6765·3c2f·7464·3e0a·2020·2020·2020··kage</td>.······
00000480:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··00000480:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
00000490:·2020·2020·2020·5472·6976·6961·6c20·4669········Trivial·Fi00000490:·2d55·5322·3e0a·2020·2020·2020·2020·5365··-US">.········Se
000004a0:·6c65·2054·7261·6e73·6665·7220·5072·6f74··le·Transfer·Prot000004a0:·6e64·6d61·696c·2069·7320·6e6f·7420·7468··ndmail·is·not·th
000004b0:·6f63·6f6c·2028·5446·5450·2920·6973·2061··ocol·(TFTP)·is·a000004b0:·6520·6465·6661·756c·7420·6d61·696c·2074··e·default·mail·t
000004c0:·2073·696d·706c·6520·6669·6c65·2074·7261···simple·file·tra000004c0:·7261·6e73·6665·7220·6167·656e·7420·616e··ransfer·agent·an
000004d0:·6e73·6665·7220·7072·6f74·6f63·6f6c·2c0a··nsfer·protocol,.000004d0:·6420·6973·0a6e·6f74·2069·6e73·7461·6c6c··d·is.not·install
000004e0:·7479·7069·6361·6c6c·7920·7573·6564·2074··typically·used·t000004e0:·6564·2062·7920·6465·6661·756c·742e·0a54··ed·by·default..T
000004f0:·6f20·6175·746f·6d61·7469·6361·6c6c·7920··o·automatically·000004f0:·6865·203c·636f·6465·3e73·656e·646d·6169··he·<code>sendmai
00000500:·7472·616e·7366·6572·2063·6f6e·6669·6775··transfer·configu00000500:·6c3c·2f63·6f64·653e·2070·6163·6b61·6765··l</code>·package
00000510:·7261·7469·6f6e·206f·7220·626f·6f74·2066··ration·or·boot·f00000510:·2063·616e·2062·6520·7265·6d6f·7665·6420···can·be·removed·
00000520:·696c·6573·2062·6574·7765·656e·2073·7973··iles·between·sys00000520:·7769·7468·2074·6865·2066·6f6c·6c6f·7769··with·the·followi
00000530:·7465·6d73·2e0a·5446·5450·2064·6f65·7320··tems..TFTP·does·00000530:·6e67·2063·6f6d·6d61·6e64·3a0a·3c70·7265··ng·command:.<pre
00000540:·6e6f·7420·7375·7070·6f72·7420·6175·7468··not·support·auth00000540:·3e0a·2420·7375·646f·2079·756d·2065·7261··>.$·sudo·yum·era
00000550:·656e·7469·6361·7469·6f6e·2061·6e64·2063··entication·and·c00000550:·7365·2073·656e·646d·6169·6c3c·2f70·7265··se·sendmail</pre
00000560:·616e·2062·6520·6561·7369·6c79·2068·6163··an·be·easily·hac00000560:·3e0a·2020·2020·2020·3c2f·7464·3e0a·2020··>.······</td>.··
00000570:·6b65·642e·2054·6865·2070·6163·6b61·6765··ked.·The·package00000570:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
00000580:·0a3c·7474·3e74·6674·703c·2f74·743e·2069··.<tt>tftp</tt>·i00000580:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
00000590:·7320·6120·636c·6965·6e74·2070·726f·6772··s·a·client·progr00000590:·2020·5468·6520·7365·6e64·6d61·696c·2073····The·sendmail·s
000005a0:·616d·2074·6861·7420·616c·6c6f·7773·2066··am·that·allows·f000005a0:·6f66·7477·6172·6520·7761·7320·6e6f·7420··oftware·was·not·
000005b0:·6f72·2063·6f6e·6e65·6374·696f·6e73·2074··or·connections·t000005b0:·6465·7665·6c6f·7065·6420·7769·7468·2073··developed·with·s
000005c0:·6f20·6120·3c74·743e·7466·7470·3c2f·7474··o·a·<tt>tftp</tt000005c0:·6563·7572·6974·7920·696e·206d·696e·6420··ecurity·in·mind·
000005d0:·3e20·7365·7276·6572·2e0a·2020·2020·2020··>·server..······000005d0:·616e·640a·6974·7320·6465·7369·676e·2070··and.its·design·p
000005e0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·000005e0:·7265·7665·6e74·7320·6974·2066·726f·6d20··revents·it·from·
000005f0:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"000005f0:·6265·696e·6720·6566·6665·6374·6976·656c··being·effectivel
00000600:·3e0a·2020·2020·2020·2020·4974·2069·7320··>.········It·is·00000600:·7920·636f·6e74·6169·6e65·6420·6279·2053··y·contained·by·S
00000610:·7265·636f·6d6d·656e·6465·6420·7468·6174··recommended·that00000610:·454c·696e·7578·2e20·2050·6f73·7466·6978··ELinux.··Postfix
00000620:·2054·4654·5020·6265·2072·656d·6f76·6564···TFTP·be·removed00000620:·0a73·686f·756c·6420·6265·2075·7365·6420··.should·be·used·
00000630:·2c20·756e·6c65·7373·2074·6865·7265·2069··,·unless·there·i00000630:·696e·7374·6561·642e·0a20·2020·2020·203c··instead..······<
00000640:·7320·6120·7370·6563·6966·6963·206e·6565··s·a·specific·nee00000640:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·
00000650:·640a·666f·7220·5446·5450·2028·7375·6368··d.for·TFTP·(such00000650:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t
00000660:·2061·7320·6120·626f·6f74·2073·6572·7665···as·a·boot·serve00000660:·643e·4250·3238·2852·3129·3c62·722f·3e4e··d>BP28(R1)<br/>N
00000670:·7229·2e20·496e·2074·6861·7420·6361·7365··r).·In·that·case00000670:·5430·3037·2852·3033·293c·2f74·643e·0a20··T007(R03)</td>.·
00000680:·2c20·7573·6520·6578·7472·656d·6520·6361··,·use·extreme·ca00000680:·2020·2020·203c·7464·3e55·6e69·6e73·7461·······<td>Uninsta
00000690:·7574·696f·6e20·7768·656e·2063·6f6e·6669··ution·when·confi00000690:·6c6c·2074·6865·2074·656c·6e65·7420·7365··ll·the·telnet·se
000006a0:·6775·7269·6e67·0a74·6865·2073·6572·7669··guring.the·servi000006a0:·7276·6572·3c2f·7464·3e0a·2020·2020·2020··rver</td>.······
000006b0:·6365·732e·0a20·2020·2020·203c·2f74·643e··ces..······</td>000006b0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
000006c0:·0a20·2020·203c·2f74·723e·0a20·2020·203c··.····</tr>.····<000006c0:·2d55·5322·3e0a·2020·2020·2020·2020·5468··-US">.········Th
000006d0:·7472·3e0a·2020·2020·2020·3c74·643e·4250··tr>.······<td>BP000006d0:·6520·7465·6c6e·6574·2064·6165·6d6f·6e20··e·telnet·daemon·
000006e0:·3238·2852·3129·3c2f·7464·3e0a·2020·2020··28(R1)</td>.····000006e0:·7368·6f75·6c64·2062·6520·756e·696e·7374··should·be·uninst
000006f0:·2020·3c74·643e·556e·696e·7374·616c·6c20····<td>Uninstall·000006f0:·616c·6c65·642e·0a20·2020·2020·203c·2f74··alled..······</t
00000700:·7869·6e65·7464·2050·6163·6b61·6765·3c2f··xinetd·Package</00000700:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
00000710:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm00000710:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
00000720:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.00000720:·2020·2020·2020·203c·7474·3e74·656c·6e65·········<tt>telne
00000730:·2020·2020·2020·2020·5468·6520·3c63·6f64··········The·<cod00000730:·743c·2f74·743e·2061·6c6c·6f77·7320·636c··t</tt>·allows·cl
00000740:·653e·7869·6e65·7464·3c2f·636f·6465·3e20··e>xinetd</code>·00000740:·6561·7220·7465·7874·2063·6f6d·6d75·6e69··ear·text·communi
00000750:·7061·636b·6167·6520·6361·6e20·6265·2072··package·can·be·r00000750:·6361·7469·6f6e·732c·2061·6e64·2064·6f65··cations,·and·doe
00000760:·656d·6f76·6564·2077·6974·6820·7468·6520··emoved·with·the·00000760:·7320·6e6f·7420·7072·6f74·6563·740a·616e··s·not·protect.an
00000770:·666f·6c6c·6f77·696e·6720·636f·6d6d·616e··following·comman00000770:·7920·6461·7461·2074·7261·6e73·6d69·7373··y·data·transmiss
00000780:·643a·0a3c·7072·653e·0a24·2073·7564·6f20··d:.<pre>.$·sudo·00000780:·696f·6e20·6265·7477·6565·6e20·636c·6965··ion·between·clie
00000790:·7975·6d20·6572·6173·6520·7869·6e65·7464··yum·erase·xinetd00000790:·6e74·2061·6e64·2073·6572·7665·722e·2041··nt·and·server.·A
000007a0:·3c2f·7072·653e·0a20·2020·2020·203c·2f74··</pre>.······</t000007a0:·6e79·2063·6f6e·6669·6465·6e74·6961·6c20··ny·confidential·
000007b0:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml000007b0:·6461·7461·0a63·616e·2062·6520·6c69·7374··data.can·be·list
000007c0:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·000007c0:·656e·6564·2061·6e64·206e·6f20·696e·7465··ened·and·no·inte
000007d0:·2020·2020·2020·2052·656d·6f76·696e·6720·········Removing·000007d0:·6772·6974·7920·6368·6563·6b69·6e67·2069··grity·checking·i
000007e0:·7468·6520·3c74·743e·7869·6e65·7464·3c2f··the·<tt>xinetd</000007e0:·7320·6d61·6465·2e27·0a20·2020·2020·203c··s·made.'.······<
000007f0:·7474·3e20·7061·636b·6167·6520·6465·6372··tt>·package·decr000007f0:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·
00000800:·6561·7365·7320·7468·6520·7269·736b·206f··eases·the·risk·o00000800:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t
00000810:·6620·7468·650a·7869·6e65·7464·2073·6572··f·the.xinetd·ser00000810:·643e·4250·3238·2852·3129·3c2f·7464·3e0a··d>BP28(R1)</td>.
00000820:·7669·6365·2773·2061·6363·6964·656e·7461··vice's·accidenta00000820:·2020·2020·2020·3c74·643e·556e·696e·7374········<td>Uninst
00000830:·6c20·286f·7220·696e·7465·6e74·696f·6e61··l·(or·intentiona00000830:·616c·6c20·7461·6c6b·2d73·6572·7665·7220··all·talk-server·
00000840:·6c29·2061·6374·6976·6174·696f·6e2e·0a20··l)·activation..·00000840:·5061·636b·6167·653c·2f74·643e·0a20·2020··Package</td>.···
00000850:·2020·2020·203c·2f74·643e·0a20·2020·203c·······</td>.····<00000850:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=
00000860:·2f74·723e·0a20·2020·203c·7472·3e0a·2020··/tr>.····<tr>.··00000860:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······
00000870:·2020·2020·3c74·643e·4250·3238·2852·3129······<td>BP28(R1)00000870:·2054·6865·203c·636f·6465·3e74·616c·6b2d···The·<code>talk-
00000880:·3c2f·7464·3e0a·2020·2020·2020·3c74·643e··</td>.······<td>00000880:·7365·7276·6572·3c2f·636f·6465·3e20·7061··server</code>·pa
00000890:·556e·696e·7374·616c·6c20·7465·6c6e·6574··Uninstall·telnet00000890:·636b·6167·6520·6361·6e20·6265·2072·656d··ckage·can·be·rem
000008a0:·2d73·6572·7665·7220·5061·636b·6167·653c··-server·Package<000008a0:·6f76·6564·2077·6974·6820·7468·6520·666f··oved·with·the·fo
000008b0:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x000008b0:·6c6c·6f77·696e·6720·636f·6d6d·616e·643a··llowing·command:
000008c0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">000008c0:·203c·7072·653e·2024·2073·7564·6f20·7975···<pre>·$·sudo·yu
000008d0:·0a20·2020·2020·2020·2054·6865·203c·636f··.········The·<co000008d0:·6d20·6572·6173·6520·7461·6c6b·2d73·6572··m·erase·talk-ser
000008e0:·6465·3e74·656c·6e65·742d·7365·7276·6572··de>telnet-server000008e0:·7665·723c·2f70·7265·3e0a·2020·2020·2020··ver</pre>.······
000008f0:·3c2f·636f·6465·3e20·7061·636b·6167·6520··</code>·package·000008f0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000900:·6361·6e20·6265·2072·656d·6f76·6564·2077··can·be·removed·w00000900:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
00000910:·6974·6820·7468·6520·666f·6c6c·6f77·696e··ith·the·followin00000910:·3e0a·2020·2020·2020·2020·5468·6520·7461··>.········The·ta
00000920:·6720·636f·6d6d·616e·643a·0a3c·7072·653e··g·command:.<pre>00000920:·6c6b·2073·6f66·7477·6172·6520·7072·6573··lk·software·pres
00000930:·0a24·2073·7564·6f20·7975·6d20·6572·6173··.$·sudo·yum·eras00000930:·656e·7473·2061·2073·6563·7572·6974·7920··ents·a·security·
00000940:·6520·7465·6c6e·6574·2d73·6572·7665·723c··e·telnet-server<00000940:·7269·736b·2061·7320·6974·2075·7365·7320··risk·as·it·uses·
00000950:·2f70·7265·3e0a·2020·2020·2020·3c2f·7464··/pre>.······</td00000950:·756e·656e·6372·7970·7465·6420·7072·6f74··unencrypted·prot
00000960:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:00000960:·6f63·6f6c·730a·666f·7220·636f·6d6d·756e··ocols.for·commun
00000970:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··00000970:·6963·6174·696f·6e73·2e20·5265·6d6f·7669··ications.·Removi
00000980:·2020·2020·2020·4974·2069·7320·6465·7472········It·is·detr00000980:·6e67·2074·6865·203c·7474·3e74·616c·6b2d··ng·the·<tt>talk-
00000990:·696d·656e·7461·6c20·666f·7220·6f70·6572··imental·for·oper00000990:·7365·7276·6572·3c2f·7474·3e20·7061·636b··server</tt>·pack
000009a0:·6174·696e·6720·7379·7374·656d·7320·746f··ating·systems·to000009a0:·6167·6520·6465·6372·6561·7365·7320·7468··age·decreases·th
000009b0:·2070·726f·7669·6465·2c20·6f72·2069·6e73···provide,·or·ins000009b0:·650a·7269·736b·206f·6620·7468·6520·6163··e.risk·of·the·ac
000009c0:·7461·6c6c·2062·7920·6465·6661·756c·742c··tall·by·default,000009c0:·6369·6465·6e74·616c·2028·6f72·2069·6e74··cidental·(or·int
000009d0:·0a66·756e·6374·696f·6e61·6c69·7479·2065··.functionality·e000009d0:·656e·7469·6f6e·616c·2920·6163·7469·7661··entional)·activa
000009e0:·7863·6565·6469·6e67·2072·6571·7569·7265··xceeding·require000009e0:·7469·6f6e·206f·6620·7461·6c6b·2073·6572··tion·of·talk·ser
000009f0:·6d65·6e74·7320·6f72·206d·6973·7369·6f6e··ments·or·mission000009f0:·7669·6365·732e·0a20·2020·2020·203c·2f74··vices..······</t
00000a00:·206f·626a·6563·7469·7665·732e·2054·6865···objectives.·The00000a00:·643e·0a20·2020·203c·2f74·723e·0a20·2020··d>.····</tr>.···
00000a10:·7365·0a75·6e6e·6563·6573·7361·7279·2063··se.unnecessary·c00000a10:·203c·7472·3e0a·2020·2020·2020·3c74·643e···<tr>.······<td>
00000a20:·6170·6162·696c·6974·6965·7320·6172·6520··apabilities·are·00000a20:·4250·3238·2852·3129·3c2f·7464·3e0a·2020··BP28(R1)</td>.··
00000a30:·6f66·7465·6e20·6f76·6572·6c6f·6f6b·6564··often·overlooked00000a30:·2020·2020·3c74·643e·556e·696e·7374·616c······<td>Uninstal
00000a40:·2061·6e64·2074·6865·7265·666f·7265·206d···and·therefore·m00000a40:·6c20·7869·6e65·7464·2050·6163·6b61·6765··l·xinetd·Package
00000a50:·6179·2072·656d·6169·6e0a·756e·7365·6375··ay·remain.unsecu00000a50:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000a60:·7265·2e20·5468·6579·2069·6e63·7265·6173··re.·They·increas00000a60:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
00000a70:·6520·7468·6520·7269·736b·2074·6f20·7468··e·the·risk·to·th00000a70:·3e0a·2020·2020·2020·2020·5468·6520·3c63··>.········The·<c
00000a80:·6520·706c·6174·666f·726d·2062·7920·7072··e·platform·by·pr00000a80:·6f64·653e·7869·6e65·7464·3c2f·636f·6465··ode>xinetd</code
00000a90:·6f76·6964·696e·6720·6164·6469·7469·6f6e··oviding·addition00000a90:·3e20·7061·636b·6167·6520·6361·6e20·6265··>·package·can·be
00000aa0:·616c·0a61·7474·6163·6b20·7665·6374·6f72··al.attack·vector00000aa0:·2072·656d·6f76·6564·2077·6974·6820·7468···removed·with·th
00000ab0:·732e·0a3c·6272·202f·3e0a·5468·6520·7465··s..<br·/>.The·te00000ab0:·6520·666f·6c6c·6f77·696e·6720·636f·6d6d··e·following·comm
00000ac0:·6c6e·6574·2073·6572·7669·6365·2070·726f··lnet·service·pro00000ac0:·616e·643a·0a3c·7072·653e·0a24·2073·7564··and:.<pre>.$·sud
00000ad0:·7669·6465·7320·616e·2075·6e65·6e63·7279··vides·an·unencry00000ad0:·6f20·7975·6d20·6572·6173·6520·7869·6e65··o·yum·erase·xine
00000ae0:·7074·6564·2072·656d·6f74·6520·6163·6365··pted·remote·acce00000ae0:·7464·3c2f·7072·653e·0a20·2020·2020·203c··td</pre>.······<
00000af0:·7373·2073·6572·7669·6365·2077·6869·6368··ss·service·which00000af0:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x
00000b00:·2064·6f65·730a·6e6f·7420·7072·6f76·6964···does.not·provid00000b00:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
00000b10:·6520·666f·7220·7468·6520·636f·6e66·6964··e·for·the·confid00000b10:·0a20·2020·2020·2020·2052·656d·6f76·696e··.········Removin
00000b20:·656e·7469·616c·6974·7920·616e·6420·696e··entiality·and·in00000b20:·6720·7468·6520·3c74·743e·7869·6e65·7464··g·the·<tt>xinetd
00000b30:·7465·6772·6974·7920·6f66·2075·7365·7220··tegrity·of·user·00000b30:·3c2f·7474·3e20·7061·636b·6167·6520·6465··</tt>·package·de
00000b40:·7061·7373·776f·7264·7320·6f72·2074·6865··passwords·or·the00000b40:·6372·6561·7365·7320·7468·6520·7269·736b··creases·the·risk
00000b50:·0a72·656d·6f74·6520·7365·7373·696f·6e2e··.remote·session.00000b50:·206f·6620·7468·650a·7869·6e65·7464·2073···of·the.xinetd·s
00000b60:·2049·6620·6120·7072·6976·696c·6567·6564···If·a·privileged00000b60:·6572·7669·6365·2773·2061·6363·6964·656e··ervice's·acciden
00000b70:·2075·7365·7220·7765·7265·2074·6f20·6c6f···user·were·to·lo00000b70:·7461·6c20·286f·7220·696e·7465·6e74·696f··tal·(or·intentio
00000b80:·6769·6e20·7573·696e·6720·7468·6973·2073··gin·using·this·s00000b80:·6e61·6c29·2061·6374·6976·6174·696f·6e2e··nal)·activation.
00000b90:·6572·7669·6365·2c20·7468·650a·7072·6976··ervice,·the.priv00000b90:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00000ba0:·696c·6567·6564·2075·7365·7220·7061·7373··ileged·user·pass00000ba0:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.
00000bb0:·776f·7264·2063·6f75·6c64·2062·6520·636f··word·could·be·co00000bb0:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R
Max diff block lines reached; 1109922/1186948 bytes (93.51%) of diff not shown.
230 KB
html2text {}
    
Offset 1, 102 lines modifiedOffset 1, 107 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux
2 72 7
  
  
3 ································Trivial·File·Transfer·Protocol·(TFTP)·is·a 
4 ································simple·file·transfer·protocol,·typically 
5 ································used·to·automatically·transfer·configuration·It·is·recommended·that·TFTP·be·removed,·unless·there·is·a·specific·need·for 
6 BP28··Remove·tftp·Daemon········or·boot·files·between·systems.·TFTP·does·not·TFTP·(such·as·a·boot·server).·In·that·case,·use·extreme·caution·when 
7 (R1)····························support·authentication·and·can·be·easily·····configuring·the·services. 
8 ································hacked.·The·package·tftp·is·a·client·program 
9 ································that·allows·for·connections·to·a·tftp 
10 ································server. 
11 BP28····························The·xinetd·package·can·be·removed·with·the···Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's 
12 (R1)··Uninstall·xinetd·Package··following·command:···························accidental·(or·intentional)·activation. 
13 ································$·sudo·yum·erase·xinetd 
14 ·············································································It·is·detrimental·for·operating·systems·to·provide,·or·install·by·default, 
15 ·············································································functionality·exceeding·requirements·or·mission·objectives.·These 
16 ·············································································unnecessary·capabilities·are·often·overlooked·and·therefore·may·remain 
17 ·············································································unsecure.·They·increase·the·risk·to·the·platform·by·providing·additional 
18 BP28··Uninstall·telnet-server···The·telnet-server·package·can·be·removed·····attack·vectors. 
19 (R1)··Package···················with·the·following·command:··················The·telnet·service·provides·an·unencrypted·remote·access·service·which·does 
20 ································$·sudo·yum·erase·telnet-server···············not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the 
21 ·············································································remote·session.·If·a·privileged·user·were·to·login·using·this·service,·the 
22 ·············································································privileged·user·password·could·be·compromised. 
23 ·············································································Removing·the·telnet-server·package·decreases·the·risk·of·the·telnet 
24 ·············································································service's·accidental·(or·intentional)·activation. 
25 ································The·Network·Information·Service·(NIS), 
26 ································formerly·known·as·Yellow·Pages,·is·a·client-·The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to 
27 BP28····························server·directory·service·protocol·used·to····DOS·attacks,·buffer·overflows·and·has·poor·authentication·for·querying·NIS 
28 (R1)··Remove·NIS·Client·········distribute·system·configuration·files.·The···maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight 
29 ································NIS·client·(ypbind)·was·used·to·bind·a·······Directory·Access·Protocol·(LDAP).·It·is·recommended·that·the·service·be 
30 ································system·to·an·NIS·server·and·receive·the······removed. 
31 ································distributed·configuration·files. 
32 BP28··Uninstall·talk-server·····The·talk-server·package·can·be·removed·with··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols 
33 (R1)··Package···················the·following·command:·······················for·communications.·Removing·the·talk-server·package·decreases·the·risk·of 
34 ·································$·sudo·yum·erase·talk-server················the·accidental·(or·intentional)·activation·of·talk·services. 
35 ································Sendmail·is·not·the·default·mail·transfer3 ································Sendmail·is·not·the·default·mail·transfer
36 BP28··Uninstall·Sendmail········agent·and·is·not·installed·by·default.·The···The·sendmail·software·was·not·developed·with·security·in·mind·and·its·design4 BP28··Uninstall·Sendmail········agent·and·is·not·installed·by·default.·The···The·sendmail·software·was·not·developed·with·security·in·mind·and·its·design
37 (R1)··Package···················sendmail·package·can·be·removed·with·the·····prevents·it·from·being·effectively·contained·by·SELinux.·Postfix·should·be5 (R1)··Package···················sendmail·package·can·be·removed·with·the·····prevents·it·from·being·effectively·contained·by·SELinux.·Postfix·should·be
38 ································following·command:···························used·instead.6 ································following·command:···························used·instead.
39 ································$·sudo·yum·erase·sendmail7 ································$·sudo·yum·erase·sendmail
40 BP28·········································································telnet·allows·clear·text·communications,·and·does·not·protect·any·data8 BP28·········································································telnet·allows·clear·text·communications,·and·does·not·protect·any·data
41 (R1)··Uninstall·the·telnet······The·telnet·daemon·should·be·uninstalled.·····transmission·between·client·and·server.·Any·confidential·data·can·be9 (R1)··Uninstall·the·telnet······The·telnet·daemon·should·be·uninstalled.·····transmission·between·client·and·server.·Any·confidential·data·can·be
42 NT007·server·································································listened·and·no·integrity·checking·is·made.'10 NT007·server·································································listened·and·no·integrity·checking·is·made.'
43 (R03)11 (R03)
44 ································The·ypserv·package·can·be·removed·with·the···The·NIS·service·provides·an·unencrypted·authentication·service·which·does 
45 BP28··Uninstall·ypserv·Package··following·command:···························not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the 
46 (R1)····························$·sudo·yum·erase·ypserv······················remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the 
47 ·············································································accidental·(or·intentional)·activation·of·NIS·or·NIS+·services. 
48 ·············································································Removing·the·tftp-server·package·decreases·the·risk·of·the·accidental·(or 
49 ·············································································intentional)·activation·of·tftp·services. 
50 BP28··Uninstall·tftp-server·····The·tftp-server·package·can·be·removed·with 
51 (R1)··Package···················the·following·command:·······················If·TFTP·is·required·for·operational·support·(such·as·transmission·of·router 
52 ·································$·sudo·yum·erase·tftp-server················configurations),·its·use·must·be·documented·with·the·Information·Systems 
53 ·············································································Securty·Manager·(ISSM),·restricted·to·only·authorized·personnel,·and·have 
54 ·············································································access·control·rules·established.12 BP28··Uninstall·talk-server·····The·talk-server·package·can·be·removed·with··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols
 13 (R1)··Package···················the·following·command:·······················for·communications.·Removing·the·talk-server·package·decreases·the·risk·of
 14 ·································$·sudo·yum·erase·talk-server················the·accidental·(or·intentional)·activation·of·talk·services.
 15 BP28····························The·xinetd·package·can·be·removed·with·the···Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's
 16 (R1)··Uninstall·xinetd·Package··following·command:···························accidental·(or·intentional)·activation.
 17 ································$·sudo·yum·erase·xinetd
 18 ································Trivial·File·Transfer·Protocol·(TFTP)·is·a
 19 ································simple·file·transfer·protocol,·typically
 20 ································used·to·automatically·transfer·configuration·It·is·recommended·that·TFTP·be·removed,·unless·there·is·a·specific·need·for
 21 BP28··Remove·tftp·Daemon········or·boot·files·between·systems.·TFTP·does·not·TFTP·(such·as·a·boot·server).·In·that·case,·use·extreme·caution·when
 22 (R1)····························support·authentication·and·can·be·easily·····configuring·the·services.
 23 ································hacked.·The·package·tftp·is·a·client·program
 24 ································that·allows·for·connections·to·a·tftp
 25 ································server.
55 ································The·talk·package·contains·the·client·program26 ································The·talk·package·contains·the·client·program
56 ································for·the·Internet·talk·protocol,·which·allows27 ································for·the·Internet·talk·protocol,·which·allows
57 ································the·user·to·chat·with·other·users·on28 ································the·user·to·chat·with·other·users·on
58 BP28····························different·systems.·Talk·is·a·communication···The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols29 BP28····························different·systems.·Talk·is·a·communication···The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols
59 (R1)··Uninstall·talk·Package····program·which·copies·lines·from·one·terminal·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the30 (R1)··Uninstall·talk·Package····program·which·copies·lines·from·one·terminal·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the
60 ································to·the·terminal·of·another·user.·The·talk····accidental·(or·intentional)·activation·of·talk·client·program.31 ································to·the·terminal·of·another·user.·The·talk····accidental·(or·intentional)·activation·of·talk·client·program.
61 ································package·can·be·removed·with·the·following32 ································package·can·be·removed·with·the·following
62 ································command:33 ································command:
63 ································$·sudo·yum·erase·talk34 ································$·sudo·yum·erase·talk
64 ·············································································These·legacy·clients·contain·numerous·security·exposures·and·have·been 
65 ·············································································replaced·with·the·more·secure·SSH·package.·Even·if·the·server·is·removed,·it 
66 BP28··Uninstall·rsh·Package·····The·rsh·package·contains·the·client·commands·is·best·to·ensure·the·clients·are·also·removed·to·prevent·users·from 
67 (R1)····························for·the·rsh·services·························inadvertently·attempting·to·use·these·commands·and·therefore·exposing·their 
68 ·············································································credentials.·Note·that·removing·the·rsh·package·removes·the·clients·for35 ································The·Network·Information·Service·(NIS),
 36 ································formerly·known·as·Yellow·Pages,·is·a·client-·The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to
 37 BP28····························server·directory·service·protocol·used·to····DOS·attacks,·buffer·overflows·and·has·poor·authentication·for·querying·NIS
 38 (R1)··Remove·NIS·Client·········distribute·system·configuration·files.·The···maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight
 39 ································NIS·client·(ypbind)·was·used·to·bind·a·······Directory·Access·Protocol·(LDAP).·It·is·recommended·that·the·service·be
 40 ································system·to·an·NIS·server·and·receive·the······removed.
 41 ································distributed·configuration·files.
 42 ································The·telnet·client·allows·users·to·start······The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted
 43 BP28··Remove·telnet·Clients·····connections·to·other·systems·via·the·telnet··transmission·medium·could·allow·an·unauthorized·user·to·steal·credentials.
 44 (R1)····························protocol.····································The·ssh·package·provides·an·encrypted·session·and·stronger·security·and·is
69 ·············································································rsh,rcp,·and·rlogin.45 ·············································································included·in·Oracle·Linux·7.
70 ································If·the·system·does·not·need·to·act·as·a·DHCP46 ································If·the·system·does·not·need·to·act·as·a·DHCP
71 BP28··Uninstall·DHCP·Server·····server,·the·dhcp·package·can·be·uninstalled.·Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally47 BP28··Uninstall·DHCP·Server·····server,·the·dhcp·package·can·be·uninstalled.·Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally
72 (R1)··Package···················The·dhcp·package·can·be·removed·with·the·····reactivated·and·disrupt·network·operation.48 (R1)··Package···················The·dhcp·package·can·be·removed·with·the·····reactivated·and·disrupt·network·operation.
73 ································following·command:49 ································following·command:
74 ································$·sudo·yum·erase·dhcp50 ································$·sudo·yum·erase·dhcp
 51 ·············································································Removing·the·tftp-server·package·decreases·the·risk·of·the·accidental·(or
75 ································The·telnet·client·allows·users·to·start······The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted 
76 BP28··Remove·telnet·Clients·····connections·to·other·systems·via·the·telnet··transmission·medium·could·allow·an·unauthorized·user·to·steal·credentials. 
77 (R1)····························protocol.····································The·ssh·package·provides·an·encrypted·session·and·stronger·security·and·is 
78 ·············································································included·in·Oracle·Linux·7.52 ·············································································intentional)·activation·of·tftp·services.
 53 BP28··Uninstall·tftp-server·····The·tftp-server·package·can·be·removed·with
 54 (R1)··Package···················the·following·command:·······················If·TFTP·is·required·for·operational·support·(such·as·transmission·of·router
 55 ·································$·sudo·yum·erase·tftp-server················configurations),·its·use·must·be·documented·with·the·Information·Systems
 56 ·············································································Securty·Manager·(ISSM),·restricted·to·only·authorized·personnel,·and·have
 57 ·············································································access·control·rules·established.
79 ·············································································The·rsh-server·service·provides·unencrypted·remote·access·service·which·does58 ·············································································The·rsh-server·service·provides·unencrypted·remote·access·service·which·does
80 ·············································································not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the59 ·············································································not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the
81 BP28··Uninstall·rsh-server······The·rsh-server·package·can·be·removed·with···remote·session·and·has·very·weak·authentication.·If·a·privileged·user·were60 BP28··Uninstall·rsh-server······The·rsh-server·package·can·be·removed·with···remote·session·and·has·very·weak·authentication.·If·a·privileged·user·were
82 (R1)··Package···················the·following·command:·······················to·login·using·this·service,·the·privileged·user·password·could·be61 (R1)··Package···················the·following·command:·······················to·login·using·this·service,·the·privileged·user·password·could·be
83 ································$·sudo·yum·erase·rsh-server··················compromised.·The·rsh-server·package·provides·several·obsolete·and·insecure62 ································$·sudo·yum·erase·rsh-server··················compromised.·The·rsh-server·package·provides·several·obsolete·and·insecure
84 ·············································································network·services.·Removing·it·decreases·the·risk·of·those·services'63 ·············································································network·services.·Removing·it·decreases·the·risk·of·those·services'
85 ·············································································accidental·(or·intentional)·activation.64 ·············································································accidental·(or·intentional)·activation.
 65 ································The·ypserv·package·can·be·removed·with·the···The·NIS·service·provides·an·unencrypted·authentication·service·which·does
 66 BP28··Uninstall·ypserv·Package··following·command:···························not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the
 67 (R1)····························$·sudo·yum·erase·ypserv······················remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the
 68 ·············································································accidental·(or·intentional)·activation·of·NIS·or·NIS+·services.
 69 ·············································································These·legacy·clients·contain·numerous·security·exposures·and·have·been
 70 ·············································································replaced·with·the·more·secure·SSH·package.·Even·if·the·server·is·removed,·it
 71 BP28··Uninstall·rsh·Package·····The·rsh·package·contains·the·client·commands·is·best·to·ensure·the·clients·are·also·removed·to·prevent·users·from
 72 (R1)····························for·the·rsh·services·························inadvertently·attempting·to·use·these·commands·and·therefore·exposing·their
 73 ·············································································credentials.·Note·that·removing·the·rsh·package·removes·the·clients·for
 74 ·············································································rsh,rcp,·and·rlogin.
Max diff block lines reached; 218488/235620 bytes (92.73%) of diff not shown.
1.12 MB
./usr/share/doc/ssg-nondebian/table-ol7-cuirefs.html
Ordering differences only
    
Offset 41, 104 lines modifiedOffset 41, 14 lines modified
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td>47 ······<td>3.1.1<br/>3.1.5</td>
48 ······<td>Disable·SSH·Root·Login</td> 
49 ······<td·xml:lang="en-US"> 
50 ········The·root·user·should·never·be·allowed·to·login·to·a 
51 system·directly·over·a·network. 
52 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
53 <tt>/etc/ssh/sshd_config</tt>: 
  
54 <pre>PermitRootLogin·no</pre> 
55 ······</td> 
56 ······<td·xml:lang="en-US"> 
57 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
58 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
59 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
60 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
61 direct·attack·attempts·on·root's·password. 
62 ······</td> 
63 ····</tr> 
64 ····<tr> 
65 ······<td>3.1.1</td> 
66 ······<td>Disable·GDM·Guest·Login</td> 
67 ······<td·xml:lang="en-US"> 
68 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials 
69 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials 
70 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable 
71 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in 
72 the·<tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
73 <pre>[daemon] 
74 TimedLoginEnable=false</pre> 
75 ······</td> 
76 ······<td·xml:lang="en-US"> 
77 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
78 system·security. 
79 ······</td> 
80 ····</tr> 
81 ····<tr> 
82 ······<td>3.1.1<br/>3.4.5</td> 
83 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td> 
84 ······<td·xml:lang="en-US"> 
85 ········Emergency·mode·is·intended·as·a·system·recovery 
86 method,·providing·a·single·user·root·access·to·the·system 
87 during·a·failed·boot·sequence. 
88 <br·/><br·/> 
89 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set 
90 in·<tt>/usr/lib/systemd/system/emergency.service</tt>. 
91 ······</td> 
92 ······<td·xml:lang="en-US"> 
93 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security 
94 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented 
95 by·configuring·the·bootloader·password. 
96 ······</td> 
97 ····</tr> 
98 ····<tr> 
99 ······<td>3.1.1<br/>3.1.5</td> 
100 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td> 
101 ······<td·xml:lang="en-US"> 
102 ········If·an·account·is·configured·for·password·authentication 
103 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log 
104 into·the·account·without·authentication.·Remove·any·instances·of·the 
105 <tt>nullok</tt>·in 
  
106 <tt>/etc/pam.d/system-auth</tt>·and 
107 <tt>/etc/pam.d/password-auth</tt> 
  
108 to·prevent·logins·with·empty·passwords. 
109 ······</td> 
110 ······<td·xml:lang="en-US"> 
111 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and 
112 run·commands·with·the·privileges·of·that·account.·Accounts·with 
113 empty·passwords·should·never·be·used·in·operational·environments. 
114 ······</td> 
115 ····</tr> 
116 ····<tr> 
117 ······<td>3.1.1<br/>3.1.5</td> 
118 ······<td>Restrict·Serial·Port·Root·Logins</td> 
119 ······<td·xml:lang="en-US"> 
120 ········To·restrict·root·logins·on·serial·ports, 
121 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
122 <pre>ttyS0 
123 ttyS1</pre> 
124 ······</td> 
125 ······<td·xml:lang="en-US"> 
126 ········Preventing·direct·root·login·to·serial·port·interfaces 
127 helps·ensure·accountability·for·actions·taken·on·the·systems 
128 using·the·root·account. 
129 ······</td> 
130 ····</tr> 
131 ····<tr> 
132 ······<td>3.1.1<br/>3.1.5</td> 
133 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>48 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>
134 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
135 ········Disallow·SSH·login·with·empty·passwords.50 ········Disallow·SSH·login·with·empty·passwords.
136 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate51 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate
137 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.52 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.
138 <br·/>53 <br·/>
139 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,54 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,
Offset 189, 14 lines modifiedOffset 99, 40 lines modified
189 ······</td>99 ······</td>
190 ······<td·xml:lang="en-US">100 ······<td·xml:lang="en-US">
191 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating101 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
192 system·security.102 system·security.
193 ······</td>103 ······</td>
194 ····</tr>104 ····</tr>
195 ····<tr>105 ····<tr>
 106 ······<td>3.1.1<br/>3.1.6</td>
 107 ······<td>Direct·root·Logins·Not·Allowed</td>
 108 ······<td·xml:lang="en-US">
 109 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators
 110 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file.
 111 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does
 112 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the
 113 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous
 114 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in
 115 plain·text·over·the·network.·By·default,·Oracle·Linux·7's
 116 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console
 117 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the
 118 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this
 119 file·by·typing·the·following·command:
 120 <pre>
Max diff block lines reached; 427537/433113 bytes (98.71%) of diff not shown.
725 KB
html2text {}
    
Offset 1, 74 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of
2 Oracle·Linux·72 Oracle·Linux·7
  
  
3 ····························································································Even·though·the 
4 ····························································································communications 
5 ····························································································channel·may·be 
6 ····························································································encrypted,·an 
7 ····························································································additional·layer·of 
8 ····························································································security·is·gained 
9 ····························································································by·extending·the 
10 ····························································································policy·of·not 
11 ·····································The·root·user·should·never·be·allowed·to·login·to·a····logging·directly·on 
12 3.1.1································system·directly·over·a·network.·To·disable·root·login··as·root.·In 
13 3.1.5···Disable·SSH·Root·Login·······via·SSH,·add·or·correct·the·following·line·in·/etc/····addition,·logging·in 
14 ·····································ssh/sshd_config:·······································with·a·user-specific 
15 ·····································PermitRootLogin·no·····································account·provides 
16 ····························································································individual 
17 ····························································································accountability·of 
18 ····························································································actions·performed·on 
19 ····························································································the·system·and·also 
20 ····························································································helps·to·minimize 
21 ····························································································direct·attack 
22 ····························································································attempts·on·root's 
23 ····························································································password. 
24 ·····································The·GNOME·Display·Manager·(GDM)·can·allow·users·to 
25 ·····································login·without·credentials·which·can·be·useful·for 
26 ·····································public·kiosk·scenarios.·Allowing·users·to·login········Failure·to·restrict 
27 ·····································without·credentials·or·"guest"·account·access·has······system·access·to 
28 3.1.1···Disable·GDM·Guest·Login······inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users 
29 ·····································disable·timed·logins·or·guest·account·access,·set·the··negatively·impacts 
30 ·····································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/·operating·system 
31 ·····································etc/gdm/custom.conf.·For·example:······················security. 
32 ·····································[daemon] 
33 ·····································TimedLoginEnable=false 
34 ····························································································This·prevents 
35 ····························································································attackers·with 
36 ·····································Emergency·mode·is·intended·as·a·system·recovery········physical·access·from 
37 ·····································method,·providing·a·single·user·root·access·to·the·····trivially·bypassing 
38 3.1.1···Require·Authentication·for···system·during·a·failed·boot·sequence.··················security·on·the 
39 3.4.5···Emergency·Systemd·Target····························································machine·and·gaining 
40 ·····································By·default,·Emergency·mode·is·protected·by·requiring·a·root·access.·Such 
41 ·····································password·and·is·set·in·/usr/lib/systemd/system/········accesses·are·further 
42 ·····································emergency.service.·····································prevented·by 
43 ····························································································configuring·the 
44 ····························································································bootloader·password. 
45 ····························································································If·an·account·has·an 
46 ····························································································empty·password, 
47 ·····································If·an·account·is·configured·for·password···············anyone·could·log·in 
48 ·····································authentication·but·does·not·have·an·assigned·password,·and·run·commands 
49 3.1.1···Prevent·Login·to·Accounts····it·may·be·possible·to·log·into·the·account·without·····with·the·privileges 
50 3.1.5···With·Empty·Password··········authentication.·Remove·any·instances·of·the·nullok·in··of·that·account. 
51 ·····································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·Accounts·with·empty 
52 ·····································prevent·logins·with·empty·passwords.···················passwords·should 
53 ····························································································never·be·used·in 
54 ····························································································operational 
55 ····························································································environments. 
56 ····························································································Preventing·direct 
57 ····························································································root·login·to·serial 
58 ·····································To·restrict·root·logins·on·serial·ports,·ensure·lines··port·interfaces 
59 3.1.1···Restrict·Serial·Port·Root····of·this·form·do·not·appear·in·/etc/securetty:··········helps·ensure 
60 3.1.5···Logins·······················ttyS0··················································accountability·for 
61 ·····································ttyS1··················································actions·taken·on·the 
62 ····························································································systems·using·the 
63 ····························································································root·account. 
64 ·····································Disallow·SSH·login·with·empty·passwords.·The·default3 ·····································Disallow·SSH·login·with·empty·passwords.·The·default
65 ·····································SSH·configuration·disables·logins·with·empty···········Configuring·this4 ·····································SSH·configuration·disables·logins·with·empty···········Configuring·this
66 ·····································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH5 ·····································passwords.·The·appropriate·configuration·is·used·if·no·setting·for·the·SSH
67 ·····································value·is·set·for·PermitEmptyPasswords.·················daemon·provides6 ·····································value·is·set·for·PermitEmptyPasswords.·················daemon·provides
68 ·····································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance7 ·····································To·explicitly·disallow·SSH·login·from·accounts·with····additional·assurance
69 3.1.1···Disable·SSH·Access·via·Empty·empty·passwords,·add·or·correct·the·following·line·in··that·remote·login8 3.1.1···Disable·SSH·Access·via·Empty·empty·passwords,·add·or·correct·the·following·line·in··that·remote·login
70 3.1.5···Passwords····················/etc/ssh/sshd_config:··································via·SSH·will·require9 3.1.5···Passwords····················/etc/ssh/sshd_config:··································via·SSH·will·require
Offset 94, 14 lines modifiedOffset 33, 31 lines modified
94 ·····································authenticate·themselves·to·the·system·that·they·are····system·access·to33 ·····································authenticate·themselves·to·the·system·that·they·are····system·access·to
95 3.1.1···Disable·GDM·Automatic·Login··authorized·to·use.·To·disable·user·ability·to··········authenticated·users34 3.1.1···Disable·GDM·Automatic·Login··authorized·to·use.·To·disable·user·ability·to··········authenticated·users
96 ·····································automatically·login·to·the·system,·set·the·············negatively·impacts35 ·····································automatically·login·to·the·system,·set·the·············negatively·impacts
97 ·····································AutomaticLoginEnable·to·false·in·the·[daemon]·section··operating·system36 ·····································AutomaticLoginEnable·to·false·in·the·[daemon]·section··operating·system
98 ·····································in·/etc/gdm/custom.conf.·For·example:··················security.37 ·····································in·/etc/gdm/custom.conf.·For·example:··················security.
99 ·····································[daemon]38 ·····································[daemon]
100 ·····································AutomaticLoginEnable=false39 ·····································AutomaticLoginEnable=false
 40 ·····································To·further·limit·access·to·the·root·account,
 41 ·····································administrators·can·disable·root·logins·at·the·console··Disabling·direct
 42 ·····································by·editing·the·/etc/securetty·file.·This·file·lists····root·logins·ensures
 43 ·····································all·devices·the·root·user·is·allowed·to·login·to.·If···proper
 44 ·····································the·file·does·not·exist·at·all,·the·root·user·can······accountability·and
 45 ·····································login·through·any·communication·device·on·the·system,··multifactor
 46 ·····································whether·via·the·console·or·via·a·raw·network···········authentication·to
 47 3.1.1···Direct·root·Logins·Not·······interface.·This·is·dangerous·as·user·can·login·to·the··privileged·accounts.
 48 3.1.6···Allowed······················system·as·root·via·Telnet,·which·sends·the·password·in·Users·will·first
 49 ·····································plain·text·over·the·network.·By·default,·Oracle·Linux··login,·then·escalate
 50 ·····································7's·/etc/securetty·file·only·allows·the·root·user·to···to·privileged·(root)
 51 ·····································login·at·the·console·physically·attached·to·the········access·via·su·/
 52 ·····································system.·To·prevent·root·from·logging·in,·remove·the····sudo.·This·is
 53 ·····································contents·of·this·file.·To·prevent·direct·root·logins,··required·for·FISMA
 54 ·····································remove·the·contents·of·this·file·by·typing·the·········Low·and·FISMA
 55 ·····································following·command:·····································Moderate·systems.
 56 ·····································$·sudo·echo·>·/etc/securetty
101 ····························································································An·account·has·root57 ····························································································An·account·has·root
102 ····························································································authority·if·it·has58 ····························································································authority·if·it·has
103 ····························································································a·UID·of·0.·Multiple59 ····························································································a·UID·of·0.·Multiple
104 ····························································································accounts·with·a·UID60 ····························································································accounts·with·a·UID
105 ·····································If·any·account·other·than·root·has·a·UID·of·0,·this····of·0·afford·more61 ·····································If·any·account·other·than·root·has·a·UID·of·0,·this····of·0·afford·more
106 ·····································misconfiguration·should·be·investigated·and·the········opportunity·for62 ·····································misconfiguration·should·be·investigated·and·the········opportunity·for
107 ·····································accounts·other·than·root·should·be·removed·or·have·····potential·intruders63 ·····································accounts·other·than·root·should·be·removed·or·have·····potential·intruders
Offset 120, 88 lines modifiedOffset 76, 87 lines modified
120 ·····································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to76 ·····································virtual·console·devices,·ensure·lines·of·this·form·do··root·login·to
121 ·····································not·appear·in·/etc/securetty:··························virtual·console77 ·····································not·appear·in·/etc/securetty:··························virtual·console
122 3.1.1···Restrict·Virtual·Console·····vc/1···················································devices·helps·ensure78 3.1.1···Restrict·Virtual·Console·····vc/1···················································devices·helps·ensure
123 3.1.5···Root·Logins··················vc/2···················································accountability·for79 3.1.5···Root·Logins··················vc/2···················································accountability·for
124 ·····································vc/3···················································actions·taken·on·the80 ·····································vc/3···················································actions·taken·on·the
125 ·····································vc/4···················································system·using·the81 ·····································vc/4···················································system·using·the
126 ····························································································root·account.82 ····························································································root·account.
127 ·····································To·further·limit·access·to·the·root·account, 
128 ·····································administrators·can·disable·root·logins·at·the·console··Disabling·direct 
129 ·····································by·editing·the·/etc/securetty·file.·This·file·lists····root·logins·ensures 
130 ·····································all·devices·the·root·user·is·allowed·to·login·to.·If···proper 
131 ·····································the·file·does·not·exist·at·all,·the·root·user·can······accountability·and 
132 ·····································login·through·any·communication·device·on·the·system,··multifactor 
133 ·····································whether·via·the·console·or·via·a·raw·network···········authentication·to 
134 3.1.1···Direct·root·Logins·Not·······interface.·This·is·dangerous·as·user·can·login·to·the··privileged·accounts. 
135 3.1.6···Allowed······················system·as·root·via·Telnet,·which·sends·the·password·in·Users·will·first 
136 ·····································plain·text·over·the·network.·By·default,·Oracle·Linux··login,·then·escalate 
137 ·····································7's·/etc/securetty·file·only·allows·the·root·user·to···to·privileged·(root) 
138 ·····································login·at·the·console·physically·attached·to·the········access·via·su·/ 
139 ·····································system.·To·prevent·root·from·logging·in,·remove·the····sudo.·This·is 
Max diff block lines reached; 722641/742622 bytes (97.31%) of diff not shown.
6.34 KB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs-stig_gui.html
    
Offset 7648, 18 lines modifiedOffset 7648, 18 lines modified
0001ddf0:·7320·7061·7373·776f·7264·7320·6865·6c70··s·passwords·help0001ddf0:·7320·7061·7373·776f·7264·7320·6865·6c70··s·passwords·help
0001de00:·7320·656e·7375·7265·2074·6861·7420·6120··s·ensure·that·a·0001de00:·7320·656e·7375·7265·2074·6861·7420·6120··s·ensure·that·a·
0001de10:·636f·6d70·726f·6d69·7365·6420·7061·7373··compromised·pass0001de10:·636f·6d70·726f·6d69·7365·6420·7061·7373··compromised·pass
0001de20:·776f·7264·2069·7320·6e6f·7420·7265·2d75··word·is·not·re-u0001de20:·776f·7264·2069·7320·6e6f·7420·7265·2d75··word·is·not·re-u
0001de30:·7365·6420·6279·2061·2075·7365·722e·0a20··sed·by·a·user..·0001de30:·7365·6420·6279·2061·2075·7365·722e·0a20··sed·by·a·user..·
0001de40:·203c·2f74·643e·0a20·203c·7464·3e76·6172···</td>.··<td>var0001de40:·203c·2f74·643e·0a20·203c·7464·3e76·6172···</td>.··<td>var
0001de50:·5f70·6173·7377·6f72·645f·7061·6d5f·7265··_password_pam_re0001de50:·5f70·6173·7377·6f72·645f·7061·6d5f·7265··_password_pam_re
 0001de60:·6d65·6d62·6572·3d35·3c62·722f·3e76·6172··member=5<br/>var
 0001de70:·5f70·6173·7377·6f72·645f·7061·6d5f·7265··_password_pam_re
0001de60:·6d65·6d62·6572·5f63·6f6e·7472·6f6c·5f66··member_control_f0001de80:·6d65·6d62·6572·5f63·6f6e·7472·6f6c·5f66··member_control_f
0001de70:·6c61·673d·7265·7175·6972·6564·3c62·722f··lag=required<br/0001de90:·6c61·673d·7265·7175·6972·6564·3c2f·7464··lag=required</td
0001de80:·3e76·6172·5f70·6173·7377·6f72·645f·7061··>var_password_pa 
0001de90:·6d5f·7265·6d65·6d62·6572·3d35·3c2f·7464··m_remember=5</td 
0001dea0:·3e0a·3c2f·7472·3e0a·3c74·723e·0a20·203c··>.</tr>.<tr>.··<0001dea0:·3e0a·3c2f·7472·3e0a·3c74·723e·0a20·203c··>.</tr>.<tr>.··<
0001deb0:·7464·3e49·412d·3528·6629·3c62·722f·3e49··td>IA-5(f)<br/>I0001deb0:·7464·3e49·412d·3528·6629·3c62·722f·3e49··td>IA-5(f)<br/>I
0001dec0:·412d·3528·3129·2865·293c·2f74·643e·0a20··A-5(1)(e)</td>.·0001dec0:·412d·3528·3129·2865·293c·2f74·643e·0a20··A-5(1)(e)</td>.·
0001ded0:·203c·7464·3e4e·2f41·3c2f·7464·3e0a·2020···<td>N/A</td>.··0001ded0:·203c·7464·3e4e·2f41·3c2f·7464·3e0a·2020···<td>N/A</td>.··
0001dee0:·3c74·643e·4c69·6d69·7420·5061·7373·776f··<td>Limit·Passwo0001dee0:·3c74·643e·4c69·6d69·7420·5061·7373·776f··<td>Limit·Passwo
0001def0:·7264·2052·6575·7365·3a20·7379·7374·656d··rd·Reuse:·system0001def0:·7264·2052·6575·7365·3a20·7379·7374·656d··rd·Reuse:·system
0001df00:·2d61·7574·683c·2f74·643e·0a20·203c·7464··-auth</td>.··<td0001df00:·2d61·7574·683c·2f74·643e·0a20·203c·7464··-auth</td>.··<td
Offset 7704, 19 lines modifiedOffset 7704, 19 lines modified
0001e170:·2070·7265·7669·6f75·7320·7061·7373·776f···previous·passwo0001e170:·2070·7265·7669·6f75·7320·7061·7373·776f···previous·passwo
0001e180:·7264·7320·6865·6c70·7320·656e·7375·7265··rds·helps·ensure0001e180:·7264·7320·6865·6c70·7320·656e·7375·7265··rds·helps·ensure
0001e190:·2074·6861·7420·6120·636f·6d70·726f·6d69···that·a·compromi0001e190:·2074·6861·7420·6120·636f·6d70·726f·6d69···that·a·compromi
0001e1a0:·7365·6420·7061·7373·776f·7264·2069·7320··sed·password·is·0001e1a0:·7365·6420·7061·7373·776f·7264·2069·7320··sed·password·is·
0001e1b0:·6e6f·7420·7265·2d75·7365·6420·6279·2061··not·re-used·by·a0001e1b0:·6e6f·7420·7265·2d75·7365·6420·6279·2061··not·re-used·by·a
0001e1c0:·2075·7365·722e·0a20·203c·2f74·643e·0a20···user..··</td>.·0001e1c0:·2075·7365·722e·0a20·203c·2f74·643e·0a20···user..··</td>.·
0001e1d0:·203c·7464·3e76·6172·5f70·6173·7377·6f72···<td>var_passwor0001e1d0:·203c·7464·3e76·6172·5f70·6173·7377·6f72···<td>var_passwor
 0001e1e0:·645f·7061·6d5f·7265·6d65·6d62·6572·3d35··d_pam_remember=5
 0001e1f0:·3c62·722f·3e76·6172·5f70·6173·7377·6f72··<br/>var_passwor
0001e1e0:·645f·7061·6d5f·7265·6d65·6d62·6572·5f63··d_pam_remember_c0001e200:·645f·7061·6d5f·7265·6d65·6d62·6572·5f63··d_pam_remember_c
0001e1f0:·6f6e·7472·6f6c·5f66·6c61·673d·7265·7175··ontrol_flag=requ0001e210:·6f6e·7472·6f6c·5f66·6c61·673d·7265·7175··ontrol_flag=requ
0001e200:·6972·6564·3c62·722f·3e76·6172·5f70·6173··ired<br/>var_pas 
0001e210:·7377·6f72·645f·7061·6d5f·7265·6d65·6d62··sword_pam_rememb 
0001e220:·6572·3d35·3c2f·7464·3e0a·3c2f·7472·3e0a··er=5</td>.</tr>.0001e220:·6972·6564·3c2f·7464·3e0a·3c2f·7472·3e0a··ired</td>.</tr>.
0001e230:·3c74·723e·0a20·203c·7464·3e49·412d·3528··<tr>.··<td>IA-5(0001e230:·3c74·723e·0a20·203c·7464·3e49·412d·3528··<tr>.··<td>IA-5(
0001e240:·6329·3c62·722f·3e49·412d·3528·3129·2861··c)<br/>IA-5(1)(a0001e240:·6329·3c62·722f·3e49·412d·3528·3129·2861··c)<br/>IA-5(1)(a
0001e250:·293c·6272·2f3e·434d·2d36·2861·293c·6272··)<br/>CM-6(a)<br0001e250:·293c·6272·2f3e·434d·2d36·2861·293c·6272··)<br/>CM-6(a)<br
0001e260:·2f3e·4941·2d35·2834·293c·2f74·643e·0a20··/>IA-5(4)</td>.·0001e260:·2f3e·4941·2d35·2834·293c·2f74·643e·0a20··/>IA-5(4)</td>.·
0001e270:·203c·7464·3e4e·2f41·3c2f·7464·3e0a·2020···<td>N/A</td>.··0001e270:·203c·7464·3e4e·2f41·3c2f·7464·3e0a·2020···<td>N/A</td>.··
0001e280:·3c74·643e·456e·7375·7265·2050·414d·2045··<td>Ensure·PAM·E0001e280:·3c74·643e·456e·7375·7265·2050·414d·2045··<td>Ensure·PAM·E
0001e290:·6e66·6f72·6365·7320·5061·7373·776f·7264··nforces·Password0001e290:·6e66·6f72·6365·7320·5061·7373·776f·7264··nforces·Password
3.08 KB
html2text {}
    
Offset 1666, 30 lines modifiedOffset 1666, 30 lines modified
1666 ··············································································search·space.1666 ··············································································search·space.
1667 ··································Do·not·allow·users·to·reuse·recent1667 ··································Do·not·allow·users·to·reuse·recent
1668 ··································passwords.·This·can·be·accomplished·by1668 ··································passwords.·This·can·be·accomplished·by
1669 ··································using·the·remember·option·for·the1669 ··································using·the·remember·option·for·the
1670 ··································pam_pwhistory·PAM·module.1670 ··································pam_pwhistory·PAM·module.
  
1671 IA-5(f)···························In·the·file·/etc/pam.d/password-auth,·make1671 IA-5(f)···························In·the·file·/etc/pam.d/password-auth,·make
1672 IA-5(1)·N/·Limit·Password·Reuse:··sure·the·parameter·remember·is·present·and··Preventing·re-use·of·previous·passwords·helps·ensure·that·a····var_password_pam_remember_control_flag=required1672 IA-5(1)·N/·Limit·Password·Reuse:··sure·the·parameter·remember·is·present·and··Preventing·re-use·of·previous·passwords·helps·ensure·that·a····var_password_pam_remember=5
1673 (e)·····A··password-auth··········it·has·a·value·equal·to·or·greater·than·5.··compromised·password·is·not·re-used·by·a·user.·················var_password_pam_remember=51673 (e)·····A··password-auth··········it·has·a·value·equal·to·or·greater·than·5.··compromised·password·is·not·re-used·by·a·user.·················var_password_pam_remember_control_flag=required
1674 ··································For·example:1674 ··································For·example:
1675 ··································password·control_flag·pam_pwhistory.so1675 ··································password·control_flag·pam_pwhistory.so
1676 ··································...existing_options...·remember=51676 ··································...existing_options...·remember=5
1677 ··································use_authtok1677 ··································use_authtok
1678 ··································control_flag·should·be·one·of·the·next1678 ··································control_flag·should·be·one·of·the·next
1679 ··································values:·required1679 ··································values:·required
1680 ··································Do·not·allow·users·to·reuse·recent1680 ··································Do·not·allow·users·to·reuse·recent
1681 ··································passwords.·This·can·be·accomplished·by1681 ··································passwords.·This·can·be·accomplished·by
1682 ··································using·the·remember·option·for·the1682 ··································using·the·remember·option·for·the
1683 ··································pam_pwhistory·PAM·module.1683 ··································pam_pwhistory·PAM·module.
  
1684 IA-5(f)···························In·the·file·/etc/pam.d/system-auth,·make1684 IA-5(f)···························In·the·file·/etc/pam.d/system-auth,·make
1685 IA-5(1)·N/·Limit·Password·Reuse:··sure·the·parameter·remember·is·present·and··Preventing·re-use·of·previous·passwords·helps·ensure·that·a····var_password_pam_remember_control_flag=required1685 IA-5(1)·N/·Limit·Password·Reuse:··sure·the·parameter·remember·is·present·and··Preventing·re-use·of·previous·passwords·helps·ensure·that·a····var_password_pam_remember=5
1686 (e)·····A··system-auth············it·has·a·value·equal·to·or·greater·than·5···compromised·password·is·not·re-used·by·a·user.·················var_password_pam_remember=51686 (e)·····A··system-auth············it·has·a·value·equal·to·or·greater·than·5···compromised·password·is·not·re-used·by·a·user.·················var_password_pam_remember_control_flag=required
1687 ··································For·example:1687 ··································For·example:
1688 ··································password·control_flag·pam_pwhistory.so1688 ··································password·control_flag·pam_pwhistory.so
1689 ··································...existing_options...·remember=51689 ··································...existing_options...·remember=5
1690 ··································use_authtok1690 ··································use_authtok
1691 ··································control_flag·should·be·one·of·the·next1691 ··································control_flag·should·be·one·of·the·next
1692 ··································values:·required1692 ··································values:·required
1693 ··································The·pam_pwquality·module's·ucredit=·········Use·of·a·complex·password·helps·to·increase·the·time·and1693 ··································The·pam_pwquality·module's·ucredit=·········Use·of·a·complex·password·helps·to·increase·the·time·and
5.65 MB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs.html
    
Offset 66, 9837 lines modifiedOffset 66, 9837 lines modified
00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa
00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea
00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<
00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU
00000450:·2d32·2864·293c·6272·2f3e·4155·2d31·3228··-2(d)<br/>AU-12(00000450:·2d32·2864·293c·6272·2f3e·4155·2d31·3228··-2(d)<br/>AU-12(
00000460:·6329·3c62·722f·3e43·4d2d·3628·6129·3c2f··c)<br/>CM-6(a)</00000460:·6329·3c62·722f·3e43·4d2d·3628·6129·3c2f··c)<br/>CM-6(a)</
Diff chunk too large, falling back to line-by-line diff (1193 lines added, 1193 lines removed)
00000470:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re00000470:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re
00000480:·636f·7264·2055·6e73·7563·6365·7373·6675··cord·Unsuccessfu00000480:·636f·7264·2045·7665·6e74·7320·7468·6174··cord·Events·that
00000490:·6c20·5065·726d·6973·7369·6f6e·2043·6861··l·Permission·Cha00000490:·204d·6f64·6966·7920·7468·6520·5379·7374···Modify·the·Syst
000004a0:·6e67·6573·2074·6f20·4669·6c65·7320·2d20··nges·to·Files·-·000004a0:·656d·2773·2044·6973·6372·6574·696f·6e61··em's·Discretiona
000004b0:·6663·686d·6f64·3c2f·7464·3e0a·2020·2020··fchmod</td>.····000004b0:·7279·2041·6363·6573·7320·436f·6e74·726f··ry·Access·Contro
000004c0:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="000004c0:·6c73·202d·2073·6574·7861·7474·723c·2f74··ls·-·setxattr</t
000004d0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········000004d0:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
000004e0:·5468·6520·6175·6469·7420·7379·7374·656d··The·audit·system000004e0:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
000004f0:·2073·686f·756c·6420·636f·6c6c·6563·7420···should·collect·000004f0:·2020·2020·2020·2041·7420·6120·6d69·6e69·········At·a·mini
00000500:·756e·7375·6363·6573·7366·756c·2066·696c··unsuccessful·fil00000500:·6d75·6d2c·2074·6865·2061·7564·6974·2073··mum,·the·audit·s
00000510:·6520·7065·726d·6973·7369·6f6e·2063·6861··e·permission·cha00000510:·7973·7465·6d20·7368·6f75·6c64·2063·6f6c··ystem·should·col
00000520:·6e67·650a·6174·7465·6d70·7473·2066·6f72··nge.attempts·for00000520:·6c65·6374·2066·696c·6520·7065·726d·6973··lect·file·permis
00000530:·2061·6c6c·2075·7365·7273·2061·6e64·2072···all·users·and·r00000530:·7369·6f6e·0a63·6861·6e67·6573·2066·6f72··sion.changes·for
00000540:·6f6f·742e·0a49·6620·7468·6520·3c74·743e··oot..If·the·<tt>00000540:·2061·6c6c·2075·7365·7273·2061·6e64·2072···all·users·and·r
00000550:·6175·6469·7464·3c2f·7474·3e20·6461·656d··auditd</tt>·daem00000550:·6f6f·742e·2049·6620·7468·6520·3c74·743e··oot.·If·the·<tt>
00000560:·6f6e·2069·7320·636f·6e66·6967·7572·6564··on·is·configured00000560:·6175·6469·7464·3c2f·7474·3e20·6461·656d··auditd</tt>·daem
00000570:·0a74·6f20·7573·6520·7468·6520·3c74·743e··.to·use·the·<tt>00000570:·6f6e·2069·7320·636f·6e66·6967·7572·6564··on·is·configured
00000580:·6175·6765·6e72·756c·6573·3c2f·7474·3e20··augenrules</tt>·00000580:·0a74·6f20·7573·6520·7468·6520·3c74·743e··.to·use·the·<tt>
00000590:·7072·6f67·7261·6d20·746f·2072·6561·6420··program·to·read·00000590:·6175·6765·6e72·756c·6573·3c2f·7474·3e20··augenrules</tt>·
000005a0:·6175·6469·7420·7275·6c65·7320·6475·7269··audit·rules·duri000005a0:·7072·6f67·7261·6d20·746f·2072·6561·6420··program·to·read·
000005b0:·6e67·2064·6165·6d6f·6e0a·7374·6172·7475··ng·daemon.startu000005b0:·6175·6469·7420·7275·6c65·7320·6475·7269··audit·rules·duri
000005c0:·7020·2874·6865·2064·6566·6175·6c74·292c··p·(the·default),000005c0:·6e67·2064·6165·6d6f·6e0a·7374·6172·7475··ng·daemon.startu
000005d0:·2061·6464·2074·6865·2066·6f6c·6c6f·7769···add·the·followi000005d0:·7020·2874·6865·2064·6566·6175·6c74·292c··p·(the·default),
000005e0:·6e67·206c·696e·6573·2074·6f20·6120·6669··ng·lines·to·a·fi000005e0:·2061·6464·2074·6865·2066·6f6c·6c6f·7769···add·the·followi
000005f0:·6c65·2077·6974·6820·7375·6666·6978·0a3c··le·with·suffix.<000005f0:·6e67·206c·696e·6520·746f·2061·2066·696c··ng·line·to·a·fil
00000600:·7474·3e2e·7275·6c65·733c·2f74·743e·2069··tt>.rules</tt>·i00000600:·6520·7769·7468·2073·7566·6669·780a·3c74··e·with·suffix.<t
00000610:·6e20·7468·6520·6469·7265·6374·6f72·7920··n·the·directory·00000610:·743e·2e72·756c·6573·3c2f·7474·3e20·696e··t>.rules</tt>·in
00000620:·3c74·743e·2f65·7463·2f61·7564·6974·2f72··<tt>/etc/audit/r00000620:·2074·6865·2064·6972·6563·746f·7279·203c···the·directory·<
00000630:·756c·6573·2e64·3c2f·7474·3e2e·0a49·6620··ules.d</tt>..If·00000630:·7474·3e2f·6574·632f·6175·6469·742f·7275··tt>/etc/audit/ru
00000640:·7468·6520·3c74·743e·6175·6469·7464·3c2f··the·<tt>auditd</00000640:·6c65·732e·643c·2f74·743e·3a0a·3c70·7265··les.d</tt>:.<pre
00000650:·7474·3e20·6461·656d·6f6e·2069·7320·636f··tt>·daemon·is·co00000650:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·
00000660:·6e66·6967·7572·6564·2074·6f20·7573·6520··nfigured·to·use·00000660:·2d46·2061·7263·683d·6233·3220·2d53·2073··-F·arch=b32·-S·s
00000670:·7468·6520·3c74·743e·6175·6469·7463·746c··the·<tt>auditctl00000670:·6574·7861·7474·7220·2d46·2061·7569·6426··etxattr·-F·auid&
00000680:·3c2f·7474·3e0a·7574·696c·6974·7920·746f··</tt>.utility·to00000680:·6774·3b3d·3130·3030·202d·4620·6175·6964··gt;=1000·-F·auid
00000690:·2072·6561·6420·6175·6469·7420·7275·6c65···read·audit·rule00000690:·213d·756e·7365·7420·2d46·206b·6579·3d70··!=unset·-F·key=p
000006a0:·7320·6475·7269·6e67·2064·6165·6d6f·6e20··s·during·daemon·000006a0:·6572·6d5f·6d6f·643c·2f70·7265·3e0a·4966··erm_mod</pre>.If
000006b0:·7374·6172·7475·702c·2061·6464·2074·6865··startup,·add·the000006b0:·2074·6865·2073·7973·7465·6d20·6973·2036···the·system·is·6
000006c0:·2066·6f6c·6c6f·7769·6e67·206c·696e·6573···following·lines000006c0:·3420·6269·7420·7468·656e·2061·6c73·6f20··4·bit·then·also·
000006d0:·2074·6f0a·3c74·743e·2f65·7463·2f61·7564···to.<tt>/etc/aud000006d0:·6164·6420·7468·6520·666f·6c6c·6f77·696e··add·the·followin
000006e0:·6974·2f61·7564·6974·2e72·756c·6573·3c2f··it/audit.rules</000006e0:·6720·6c69·6e65·3a0a·3c70·7265·3e2d·6120··g·line:.<pre>-a·
000006f0:·7474·3e20·6669·6c65·2e0a·3c70·7265·3e2d··tt>·file..<pre>-000006f0:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a
00000700:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F00000700:·7263·683d·6236·3420·2d53·2073·6574·7861··rch=b64·-S·setxa
00000710:·2061·7263·683d·6233·3220·2d53·2066·6368···arch=b32·-S·fch00000710:·7474·7220·2d46·2061·7569·6426·6774·3b3d··ttr·-F·auid&gt;=
00000720:·6d6f·6420·2d46·2065·7869·743d·2d45·4143··mod·-F·exit=-EAC00000720:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un
00000730:·4345·5320·2d46·2061·7569·643e·3d31·3030··CES·-F·auid>=10000000730:·7365·7420·2d46·206b·6579·3d70·6572·6d5f··set·-F·key=perm_
00000740:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset00000740:·6d6f·643c·2f70·7265·3e0a·4966·2074·6865··mod</pre>.If·the
00000750:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces00000750:·203c·7474·3e61·7564·6974·643c·2f74·743e···<tt>auditd</tt>
00000760:·6675·6c2d·7065·726d·2d63·6861·6e67·650a··ful-perm-change.00000760:·2064·6165·6d6f·6e20·6973·2063·6f6e·6669···daemon·is·confi
00000770:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-00000770:·6775·7265·6420·746f·2075·7365·2074·6865··gured·to·use·the
00000780:·4620·6172·6368·3d62·3332·202d·5320·6663··F·arch=b32·-S·fc00000780:·203c·7474·3e61·7564·6974·6374·6c3c·2f74···<tt>auditctl</t
00000790:·686d·6f64·202d·4620·6578·6974·3d2d·4550··hmod·-F·exit=-EP00000790:·743e·0a75·7469·6c69·7479·2074·6f20·7265··t>.utility·to·re
000007a0:·4552·4d20·2d46·2061·7569·643e·3d31·3030··ERM·-F·auid>=100000007a0:·6164·2061·7564·6974·2072·756c·6573·2064··ad·audit·rules·d
000007b0:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset000007b0:·7572·696e·6720·6461·656d·6f6e·2073·7461··uring·daemon·sta
000007c0:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces000007c0:·7274·7570·2c20·6164·6420·7468·6520·666f··rtup,·add·the·fo
000007d0:·6675·6c2d·7065·726d·2d63·6861·6e67·653c··ful-perm-change<000007d0:·6c6c·6f77·696e·6720·6c69·6e65·2074·6f0a··llowing·line·to.
000007e0:·2f70·7265·3e0a·4966·2074·6865·2073·7973··/pre>.If·the·sys000007e0:·3c74·743e·2f65·7463·2f61·7564·6974·2f61··<tt>/etc/audit/a
000007f0:·7465·6d20·6973·2036·3420·6269·7420·7468··tem·is·64·bit·th000007f0:·7564·6974·2e72·756c·6573·3c2f·7474·3e20··udit.rules</tt>·
00000800:·656e·2061·6c73·6f20·6164·6420·7468·6520··en·also·add·the·00000800:·6669·6c65·3a0a·3c70·7265·3e2d·6120·616c··file:.<pre>-a·al
00000810:·666f·6c6c·6f77·696e·6720·6c69·6e65·733a··following·lines:00000810:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc
00000820:·0a3c·7072·653e·2d61·2061·6c77·6179·732c··.<pre>-a·always,00000820:·683d·6233·3220·2d53·2073·6574·7861·7474··h=b32·-S·setxatt
00000830:·6578·6974·202d·4620·6172·6368·3d62·3634··exit·-F·arch=b6400000830:·7220·2d46·2061·7569·6426·6774·3b3d·3130··r·-F·auid&gt;=10
00000840:·202d·5320·6663·686d·6f64·202d·4620·6578···-S·fchmod·-F·ex00000840:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
00000850:·6974·3d2d·4541·4343·4553·202d·4620·6175··it=-EACCES·-F·au00000850:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo
00000860:·6964·3e3d·3130·3030·202d·4620·6175·6964··id>=1000·-F·auid00000860:·643c·2f70·7265·3e0a·4966·2074·6865·2073··d</pre>.If·the·s
00000870:·213d·756e·7365·7420·2d46·206b·6579·3d75··!=unset·-F·key=u00000870:·7973·7465·6d20·6973·2036·3420·6269·7420··ystem·is·64·bit·
00000880:·6e73·7563·6365·7366·756c·2d70·6572·6d2d··nsuccesful-perm-00000880:·7468·656e·2061·6c73·6f20·6164·6420·7468··then·also·add·th
00000890:·6368·616e·6765·0a2d·6120·616c·7761·7973··change.-a·always00000890:·6520·666f·6c6c·6f77·696e·6720·6c69·6e65··e·following·line
000008a0:·2c65·7869·7420·2d46·2061·7263·683d·6236··,exit·-F·arch=b6000008a0:·3a0a·3c70·7265·3e2d·6120·616c·7761·7973··:.<pre>-a·always
000008b0:·3420·2d53·2066·6368·6d6f·6420·2d46·2065··4·-S·fchmod·-F·e000008b0:·2c65·7869·7420·2d46·2061·7263·683d·6236··,exit·-F·arch=b6
000008c0:·7869·743d·2d45·5045·524d·202d·4620·6175··xit=-EPERM·-F·au000008c0:·3420·2d53·2073·6574·7861·7474·7220·2d46··4·-S·setxattr·-F
000008d0:·6964·3e3d·3130·3030·202d·4620·6175·6964··id>=1000·-F·auid000008d0:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-
000008e0:·213d·756e·7365·7420·2d46·206b·6579·3d75··!=unset·-F·key=u000008e0:·4620·6175·6964·213d·756e·7365·7420·2d46··F·auid!=unset·-F
000008f0:·6e73·7563·6365·7366·756c·2d70·6572·6d2d··nsuccesful-perm-000008f0:·206b·6579·3d70·6572·6d5f·6d6f·643c·2f70···key=perm_mod</p
00000900:·6368·616e·6765·3c2f·7072·653e·0a20·2020··change</pre>.···00000900:·7265·3e0a·2020·2020·2020·3c2f·7464·3e0a··re>.······</td>.
00000910:·2020·203c·2f74·643e·0a20·2020·2020·203c·····</td>.······<00000910:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la
00000920:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-00000920:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····
00000930:·5553·223e·0a20·2020·2020·2020·2055·6e73··US">.········Uns00000930:·2020·2020·5468·6520·6368·616e·6769·6e67······The·changing
00000940:·7563·6365·7373·6675·6c20·6174·7465·6d70··uccessful·attemp00000940:·206f·6620·6669·6c65·2070·6572·6d69·7373···of·file·permiss
00000950:·7473·2074·6f20·6368·616e·6765·2070·6572··ts·to·change·per00000950:·696f·6e73·2063·6f75·6c64·2069·6e64·6963··ions·could·indic
00000960:·6d69·7373·696f·6e73·206f·6620·6669·6c65··missions·of·file00000960:·6174·6520·7468·6174·2061·2075·7365·7220··ate·that·a·user·
00000970:·7320·636f·756c·6420·6265·2061·6e20·696e··s·could·be·an·in00000970:·6973·2061·7474·656d·7074·696e·6720·746f··is·attempting·to
00000980:·6469·6361·746f·7220·6f66·206d·616c·6963··dicator·of·malic00000980:·0a67·6169·6e20·6163·6365·7373·2074·6f20··.gain·access·to·
00000990:·696f·7573·2061·6374·6976·6974·7920·6f6e··ious·activity·on00000990:·696e·666f·726d·6174·696f·6e20·7468·6174··information·that
000009a0:·2061·2073·7973·7465·6d2e·2041·7564·6974···a·system.·Audit000009a0:·2077·6f75·6c64·206f·7468·6572·7769·7365···would·otherwise
000009b0:·696e·670a·7468·6573·6520·6576·656e·7473··ing.these·events000009b0:·2062·6520·6469·7361·6c6c·6f77·6564·2e20···be·disallowed.·
000009c0:·2063·6f75·6c64·2073·6572·7665·2061·7320···could·serve·as·000009c0:·4175·6469·7469·6e67·2044·4143·206d·6f64··Auditing·DAC·mod
000009d0:·6576·6964·656e·6365·206f·6620·706f·7465··evidence·of·pote000009d0:·6966·6963·6174·696f·6e73·0a63·616e·2066··ifications.can·f
000009e0:·6e74·6961·6c20·7379·7374·656d·2063·6f6d··ntial·system·com000009e0:·6163·696c·6974·6174·6520·7468·6520·6964··acilitate·the·id
000009f0:·7072·6f6d·6973·652e·0a20·2020·2020·203c··promise..······<000009f0:·656e·7469·6669·6361·7469·6f6e·206f·6620··entification·of·
00000a00:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·00000a00:·7061·7474·6572·6e73·206f·6620·6162·7573··patterns·of·abus
00000a10:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t00000a10:·6520·616d·6f6e·6720·626f·7468·2061·7574··e·among·both·aut
00000a20:·643e·4155·2d32·2864·293c·6272·2f3e·4155··d>AU-2(d)<br/>AU00000a20:·686f·7269·7a65·6420·616e·640a·756e·6175··horized·and.unau
00000a30:·2d31·3228·6329·3c62·722f·3e41·432d·3628··-12(c)<br/>AC-6(00000a30:·7468·6f72·697a·6564·2075·7365·7273·2e0a··thorized·users..
00000a40:·3929·3c62·722f·3e43·4d2d·3628·6129·3c2f··9)<br/>CM-6(a)</00000a40:·2020·2020·2020·3c2f·7464·3e0a·2020·2020········</td>.····
00000a50:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re00000a50:·3c2f·7472·3e0a·2020·2020·3c74·723e·0a20··</tr>.····<tr>.·
00000a60:·636f·7264·2041·7474·656d·7074·7320·746f··cord·Attempts·to00000a60:·2020·2020·203c·7464·3e41·552d·3228·6429·······<td>AU-2(d)
00000a70:·2041·6c74·6572·204c·6f67·6f6e·2061·6e64···Alter·Logon·and00000a70:·3c62·722f·3e41·552d·3132·2863·293c·6272··<br/>AU-12(c)<br
00000a80:·204c·6f67·6f75·7420·4576·656e·7473·202d···Logout·Events·-00000a80:·2f3e·434d·2d36·2861·293c·2f74·643e·0a20··/>CM-6(a)</td>.·
00000a90:·2074·616c·6c79·6c6f·673c·2f74·643e·0a20···tallylog</td>.·00000a90:·2020·2020·203c·7464·3e45·6e73·7572·6520·······<td>Ensure·
00000aa0:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan00000aa0:·6175·6469·7464·2043·6f6c·6c65·6374·7320··auditd·Collects·
00000ab0:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····00000ab0:·4669·6c65·2044·656c·6574·696f·6e20·4576··File·Deletion·Ev
00000ac0:·2020·2054·6865·2061·7564·6974·2073·7973·····The·audit·sys00000ac0:·656e·7473·2062·7920·5573·6572·202d·2075··ents·by·User·-·u
00000ad0:·7465·6d20·616c·7265·6164·7920·636f·6c6c··tem·already·coll00000ad0:·6e6c·696e·6b3c·2f74·643e·0a20·2020·2020··nlink</td>.·····
00000ae0:·6563·7473·206c·6f67·696e·2069·6e66·6f72··ects·login·infor00000ae0:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
00000af0:·6d61·7469·6f6e·2066·6f72·2061·6c6c·2075··mation·for·all·u00000af0:·6e2d·5553·223e·0a20·2020·2020·2020·2041··n-US">.········A
00000b00:·7365·7273·0a61·6e64·2072·6f6f·742e·2049··sers.and·root.·I00000b00:·7420·6120·6d69·6e69·6d75·6d2c·2074·6865··t·a·minimum,·the
00000b10:·6620·7468·6520·3c74·743e·6175·6469·7464··f·the·<tt>auditd00000b10:·2061·7564·6974·2073·7973·7465·6d20·7368···audit·system·sh
00000b20:·3c2f·7474·3e20·6461·656d·6f6e·2069·7320··</tt>·daemon·is·00000b20:·6f75·6c64·2063·6f6c·6c65·6374·2066·696c··ould·collect·fil
00000b30:·636f·6e66·6967·7572·6564·2074·6f20·7573··configured·to·us00000b30:·6520·6465·6c65·7469·6f6e·2065·7665·6e74··e·deletion·event
00000b40:·6520·7468·650a·3c74·743e·6175·6765·6e72··e·the.<tt>augenr00000b40:·730a·666f·7220·616c·6c20·7573·6572·7320··s.for·all·users·
00000b50:·756c·6573·3c2f·7474·3e20·7072·6f67·7261··ules</tt>·progra00000b50:·616e·6420·726f·6f74·2e20·4966·2074·6865··and·root.·If·the
00000b60:·6d20·746f·2072·6561·6420·6175·6469·7420··m·to·read·audit·00000b60:·203c·7474·3e61·7564·6974·643c·2f74·743e···<tt>auditd</tt>
00000b70:·7275·6c65·7320·6475·7269·6e67·2064·6165··rules·during·dae00000b70:·2064·6165·6d6f·6e20·6973·2063·6f6e·6669···daemon·is·confi
00000b80:·6d6f·6e20·7374·6172·7475·7020·2874·6865··mon·startup·(the00000b80:·6775·7265·6420·746f·2075·7365·2074·6865··gured·to·use·the
00000b90:·0a64·6566·6175·6c74·292c·2061·6464·2074··.default),·add·t00000b90:·0a3c·7474·3e61·7567·656e·7275·6c65·733c··.<tt>augenrules<
00000ba0:·6865·2066·6f6c·6c6f·7769·6e67·206c·696e··he·following·lin00000ba0:·2f74·743e·2070·726f·6772·616d·2074·6f20··/tt>·program·to·
00000bb0:·6573·2074·6f20·6120·6669·6c65·2077·6974··es·to·a·file·wit00000bb0:·7265·6164·2061·7564·6974·2072·756c·6573··read·audit·rules
00000bc0:·6820·7375·6666·6978·203c·7474·3e2e·7275··h·suffix·<tt>.ru00000bc0:·2064·7572·696e·6720·6461·656d·6f6e·2073···during·daemon·s
00000bd0:·6c65·733c·2f74·743e·2069·6e20·7468·650a··les</tt>·in·the.00000bd0:·7461·7274·7570·2028·7468·650a·6465·6661··tartup·(the.defa
00000be0:·6469·7265·6374·6f72·7920·3c74·743e·2f65··directory·<tt>/e00000be0:·756c·7429·2c20·6164·6420·7468·6520·666f··ult),·add·the·fo
Max diff block lines reached; 4706489/4871699 bytes (96.61%) of diff not shown.
1.01 MB
html2text {}
Max HTML report size reached
817 KB
./usr/share/doc/ssg-nondebian/table-ol7-ospprefs.html
Ordering differences only
    
Offset 75, 31 lines modifiedOffset 75, 33 lines modified
75 package,·or·the·SCAP·Workbench·GUI·tool·from·the·<tt>scap-workbench</tt>·package,·to·verify75 package,·or·the·SCAP·Workbench·GUI·tool·from·the·<tt>scap-workbench</tt>·package,·to·verify
76 that·the·system·conforms·to·provided·guidelines.·Refer·to·the·scap-security-guide(8)·manual76 that·the·system·conforms·to·provided·guidelines.·Refer·to·the·scap-security-guide(8)·manual
77 page·for·futher·information.77 page·for·futher·information.
78 ······</td>78 ······</td>
79 ····</tr>79 ····</tr>
80 ····<tr>80 ····<tr>
81 ······<td>FAU_GEN.1</td>81 ······<td>FAU_GEN.1</td>
82 ······<td>Disable·SSH·Root·Login</td>82 ······<td>Ensure·the·audit·Subsystem·is·Installed</td>
83 ······<td·xml:lang="en-US">83 ······<td·xml:lang="en-US">
 84 ········The·audit·package·should·be·installed.
84 ········The·root·user·should·never·be·allowed·to·login·to·a 
85 system·directly·over·a·network. 
86 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
87 <tt>/etc/ssh/sshd_config</tt>: 
  
88 <pre>PermitRootLogin·no</pre> 
89 ······</td>85 ······</td>
90 ······<td·xml:lang="en-US">86 ······<td·xml:lang="en-US">
91 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
92 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
93 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
94 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
95 direct·attack·attempts·on·root's·password.87 ········The·auditd·service·is·an·access·monitoring·and·accounting·daemon,·watching·system·calls·to·audit·any·access,·in·comparison·with·potential·local·access·control·policy·such·as·SELinux·policy.
 88 ······</td>
 89 ····</tr>
 90 ····<tr>
 91 ······<td>FAU_GEN.1</td>
 92 ······<td>Include·Local·Events·in·Audit·Logs</td>
 93 ······<td·xml:lang="en-US">
 94 ········To·configure·Audit·daemon·to·include·local·events·in·Audit·logs,·set
 95 <tt>local_events</tt>·to·<tt>yes</tt>·in·<tt>/etc/audit/auditd.conf</tt>.
 96 This·is·the·default·setting.
 97 ······</td>
 98 ······<td·xml:lang="en-US">
 99 ········If·option·<tt>local_events</tt>·isn't·set·to·<tt>yes</tt>·only·events·from
 100 network·will·be·aggregated.
96 ······</td>101 ······</td>
97 ····</tr>102 ····</tr>
98 ····<tr>103 ····<tr>
99 ······<td>FAU_GEN.1</td>104 ······<td>FAU_GEN.1</td>
100 ······<td>Enable·Auditing·for·Processes·Which·Start·Prior·to·the·Audit·Daemon</td>105 ······<td>Enable·Auditing·for·Processes·Which·Start·Prior·to·the·Audit·Daemon</td>
101 ······<td·xml:lang="en-US">106 ······<td·xml:lang="en-US">
102 ········To·ensure·all·processes·can·be·audited,·even·those·which·start107 ········To·ensure·all·processes·can·be·audited,·even·those·which·start
Offset 117, 51 lines modifiedOffset 119, 28 lines modified
117 its·activities·can·be·audited.·Although·<tt>auditd</tt>·takes·care·of·enabling119 its·activities·can·be·audited.·Although·<tt>auditd</tt>·takes·care·of·enabling
118 this·for·all·processes·which·launch·after·it·does,·adding·the·kernel·argument120 this·for·all·processes·which·launch·after·it·does,·adding·the·kernel·argument
119 ensures·it·is·set·for·every·process·during·boot.121 ensures·it·is·set·for·every·process·during·boot.
120 ······</td>122 ······</td>
121 ····</tr>123 ····</tr>
122 ····<tr>124 ····<tr>
123 ······<td>FAU_GEN.1</td>125 ······<td>FAU_GEN.1</td>
124 ······<td>Include·Local·Events·in·Audit·Logs</td> 
125 ······<td·xml:lang="en-US"> 
126 ········To·configure·Audit·daemon·to·include·local·events·in·Audit·logs,·set 
127 <tt>local_events</tt>·to·<tt>yes</tt>·in·<tt>/etc/audit/auditd.conf</tt>. 
128 This·is·the·default·setting. 
129 ······</td> 
130 ······<td·xml:lang="en-US"> 
131 ········If·option·<tt>local_events</tt>·isn't·set·to·<tt>yes</tt>·only·events·from 
132 network·will·be·aggregated. 
133 ······</td> 
134 ····</tr> 
135 ····<tr> 
136 ······<td>FAU_GEN.1</td> 
137 ······<td>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</td>126 ······<td>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</td>
138 ······<td·xml:lang="en-US">127 ······<td·xml:lang="en-US">
139 ········To·configure·Audit·daemon·to·issue·an·explicit·flush·to·disk·command128 ········To·configure·Audit·daemon·to·issue·an·explicit·flush·to·disk·command
140 after·writing·<abbr·title="$var_auditd_freq"><tt>50</tt></abbr>·records,·set·<tt>freq</tt>·to·<tt><abbr·title="$var_auditd_freq"><tt>50</tt></abbr></tt>129 after·writing·<abbr·title="$var_auditd_freq"><tt>50</tt></abbr>·records,·set·<tt>freq</tt>·to·<tt><abbr·title="$var_auditd_freq"><tt>50</tt></abbr></tt>
141 in·<tt>/etc/audit/auditd.conf</tt>.130 in·<tt>/etc/audit/auditd.conf</tt>.
142 ······</td>131 ······</td>
143 ······<td·xml:lang="en-US">132 ······<td·xml:lang="en-US">
144 ········If·option·<tt>freq</tt>·isn't·set·to·<tt><sub·idref="var_auditd_freq"·/></tt>,·the·flush·to·disk133 ········If·option·<tt>freq</tt>·isn't·set·to·<tt><sub·idref="var_auditd_freq"·/></tt>,·the·flush·to·disk
145 may·happen·after·higher·number·of·records,·increasing·the·danger134 may·happen·after·higher·number·of·records,·increasing·the·danger
146 of·audit·loss.135 of·audit·loss.
147 ······</td>136 ······</td>
148 ····</tr>137 ····</tr>
149 ····<tr>138 ····<tr>
150 ······<td>FAU_GEN.1</td>139 ······<td>FAU_GEN.1</td>
151 ······<td>Ensure·the·audit·Subsystem·is·Installed</td> 
152 ······<td·xml:lang="en-US"> 
153 ········The·audit·package·should·be·installed. 
154 ······</td> 
155 ······<td·xml:lang="en-US"> 
156 ········The·auditd·service·is·an·access·monitoring·and·accounting·daemon,·watching·system·calls·to·audit·any·access,·in·comparison·with·potential·local·access·control·policy·such·as·SELinux·policy. 
157 ······</td> 
158 ····</tr> 
159 ····<tr> 
160 ······<td>FAU_GEN.1</td> 
161 ······<td>Enable·auditd·Service</td>140 ······<td>Enable·auditd·Service</td>
162 ······<td·xml:lang="en-US">141 ······<td·xml:lang="en-US">
163 ········The·<tt>auditd</tt>·service·is·an·essential·userspace·component·of142 ········The·<tt>auditd</tt>·service·is·an·essential·userspace·component·of
164 the·Linux·Auditing·System,·as·it·is·responsible·for·writing·audit·records·to143 the·Linux·Auditing·System,·as·it·is·responsible·for·writing·audit·records·to
165 disk.144 disk.
  
166 The·<code>auditd</code>·service·can·be·enabled·with·the·following·command:145 The·<code>auditd</code>·service·can·be·enabled·with·the·following·command:
Offset 175, 177 lines modifiedOffset 154, 126 lines modified
175 <br·/><br·/>154 <br·/><br·/>
176 Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of155 Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of
177 individual·system·users·can·be·uniquely·traced·to·those·users·so·they156 individual·system·users·can·be·uniquely·traced·to·those·users·so·they
178 can·be·held·accountable·for·their·actions.157 can·be·held·accountable·for·their·actions.
179 ······</td>158 ······</td>
180 ····</tr>159 ····</tr>
181 ····<tr>160 ····<tr>
182 ······<td>FAU_GEN.1.1.c</td>161 ······<td>FAU_GEN.1</td>
 162 ······<td>Disable·SSH·Root·Login</td>
183 ······<td>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</td> 
184 ······<td·xml:lang="en-US"> 
185 ········The·audit·system·already·collects·login·information·for·all·users 
186 and·root.·If·the·<tt>auditd</tt>·daemon·is·configured·to·use·the 
187 <tt>augenrules</tt>·program·to·read·audit·rules·during·daemon·startup·(the 
188 default),·add·the·following·lines·to·a·file·with·suffix·<tt>.rules</tt>·in·the 
189 directory·<tt>/etc/audit/rules.d</tt>·in·order·to·watch·for·attempted·manual 
190 edits·of·files·involved·in·storing·logon·events: 
191 <pre>-w·/var/log/tallylog·-p·wa·-k·logins</pre> 
192 If·the·<tt>auditd</tt>·daemon·is·configured·to·use·the·<tt>auditctl</tt> 
193 utility·to·read·audit·rules·during·daemon·startup,·add·the·following·lines·to 
194 <tt>/etc/audit/audit.rules</tt>·file·in·order·to·watch·for·unattempted·manual 
195 edits·of·files·involved·in·storing·logon·events: 
196 <pre>-w·/var/log/tallylog·-p·wa·-k·logins</pre> 
197 ······</td> 
198 ······<td·xml:lang="en-US"> 
199 ········Manual·editing·of·these·files·may·indicate·nefarious·activity,·such 
200 as·an·attacker·attempting·to·remove·evidence·of·an·intrusion. 
201 ······</td> 
202 ····</tr> 
Max diff block lines reached; 316614/322443 bytes (98.19%) of diff not shown.
502 KB
html2text {}
    
Offset 43, 31 lines modifiedOffset 43, 28 lines modified
43 ········································································package,·to·verify·that43 ········································································package,·to·verify·that
44 ········································································the·system·conforms·to44 ········································································the·system·conforms·to
45 ········································································provided·guidelines.45 ········································································provided·guidelines.
46 ········································································Refer·to·the·scap-46 ········································································Refer·to·the·scap-
47 ········································································security-guide(8)47 ········································································security-guide(8)
48 ········································································manual·page·for·futher48 ········································································manual·page·for·futher
49 ········································································information.49 ········································································information.
50 ········································································Even·though·the 
51 ········································································communications·channel 
52 ········································································may·be·encrypted,·an 
53 ········································································additional·layer·of50 ········································································The·auditd·service·is
54 ········································································security·is·gained·by51 ········································································an·access·monitoring
55 ··································The·root·user·should·never·be·allowed·extending·the·policy·of 
56 ··································to·login·to·a·system·directly·over·a··not·logging·directly·on 
57 ················Disable·SSH·Root··network.·To·disable·root·login·via····as·root.·In·addition, 
58 FAU_GEN.1·······Login·············SSH,·add·or·correct·the·following·····logging·in·with·a·user- 
59 ··································line·in·/etc/ssh/sshd_config:·········specific·account 
60 ··································PermitRootLogin·no····················provides·individual 
61 ········································································accountability·of52 ········································································and·accounting·daemon,
 53 ················Ensure·the·audit··The·audit·package·should·be···········watching·system·calls
 54 FAU_GEN.1·······Subsystem·is······installed.····························to·audit·any·access,·in
 55 ················Installed···············································comparison·with
 56 ········································································potential·local·access
62 ········································································actions·performed·on57 ········································································control·policy·such·as
63 ········································································the·system·and·also 
64 ········································································helps·to·minimize 
65 ········································································direct·attack·attempts 
66 ········································································on·root's·password.58 ········································································SELinux·policy.
 59 ··································To·configure·Audit·daemon·to·include··If·option·local_events
 60 ················Include·Local·····local·events·in·Audit·logs,·set·······isn't·set·to·yes·only
 61 FAU_GEN.1·······Events·in·Audit···local_events·to·yes·in·/etc/audit/····events·from·network
 62 ················Logs··············auditd.conf.·This·is·the·default······will·be·aggregated.
 63 ··································setting.
67 ··································To·ensure·all·processes·can·be64 ··································To·ensure·all·processes·can·be
68 ··································audited,·even·those·which·start·prior65 ··································audited,·even·those·which·start·prior
69 ··································to·the·audit·daemon,·add·the·argument·Each·process·on·the66 ··································to·the·audit·daemon,·add·the·argument·Each·process·on·the
70 ··································audit=1·to·the·default·GRUB·2·command·system·carries·an67 ··································audit=1·to·the·default·GRUB·2·command·system·carries·an
71 ··································line·for·the·Linux·operating·system.··"auditable"·flag·which68 ··································line·for·the·Linux·operating·system.··"auditable"·flag·which
72 ··································To·ensure·that·audit=1·is·added·as·a··indicates·whether·its69 ··································To·ensure·that·audit=1·is·added·as·a··indicates·whether·its
73 ················Enable·Auditing···kernel·command·line·argument·to·newly·activities·can·be70 ················Enable·Auditing···kernel·command·line·argument·to·newly·activities·can·be
Offset 78, 34 lines modifiedOffset 75, 20 lines modified
78 ··································below:································after·it·does,·adding75 ··································below:································after·it·does,·adding
79 ··································GRUB_CMDLINE_LINUX="...·audit=1·..."··the·kernel·argument76 ··································GRUB_CMDLINE_LINUX="...·audit=1·..."··the·kernel·argument
80 ··································Run·the·following·command·to·update···ensures·it·is·set·for77 ··································Run·the·following·command·to·update···ensures·it·is·set·for
81 ··································command·line·for·already·installed····every·process·during78 ··································command·line·for·already·installed····every·process·during
82 ··································kernels:······························boot.79 ··································kernels:······························boot.
83 ··································#·grubby·--update-kernel=ALL·--80 ··································#·grubby·--update-kernel=ALL·--
84 ··································args="audit=1"81 ··································args="audit=1"
85 ··································To·configure·Audit·daemon·to·include··If·option·local_events 
86 ················Include·Local·····local·events·in·Audit·logs,·set·······isn't·set·to·yes·only 
87 FAU_GEN.1·······Events·in·Audit···local_events·to·yes·in·/etc/audit/····events·from·network 
88 ················Logs··············auditd.conf.·This·is·the·default······will·be·aggregated. 
89 ··································setting. 
90 ········································································If·option·freq·isn't82 ········································································If·option·freq·isn't
91 ················Set·number·of·····To·configure·Audit·daemon·to·issue·an·set·to·,·the·flush·to83 ················Set·number·of·····To·configure·Audit·daemon·to·issue·an·set·to·,·the·flush·to
92 FAU_GEN.1·······records·to·cause··explicit·flush·to·disk·command·after··disk·may·happen·after84 FAU_GEN.1·······records·to·cause··explicit·flush·to·disk·command·after··disk·may·happen·after
93 ················an·explicit·flush·writing·50·records,·set·freq·to·50·in·higher·number·of85 ················an·explicit·flush·writing·50·records,·set·freq·to·50·in·higher·number·of
94 ················to·audit·logs·····/etc/audit/auditd.conf.···············records,·increasing·the86 ················to·audit·logs·····/etc/audit/auditd.conf.···············records,·increasing·the
95 ········································································danger·of·audit·loss.87 ········································································danger·of·audit·loss.
96 ········································································The·auditd·service·is 
97 ········································································an·access·monitoring 
98 ········································································and·accounting·daemon, 
99 ················Ensure·the·audit··The·audit·package·should·be···········watching·system·calls 
100 FAU_GEN.1·······Subsystem·is······installed.····························to·audit·any·access,·in 
101 ················Installed···············································comparison·with 
102 ········································································potential·local·access 
103 ········································································control·policy·such·as 
104 ········································································SELinux·policy. 
105 ········································································Without·establishing88 ········································································Without·establishing
106 ········································································what·type·of·events89 ········································································what·type·of·events
107 ········································································occurred,·it·would·be90 ········································································occurred,·it·would·be
108 ········································································difficult·to·establish,91 ········································································difficult·to·establish,
109 ········································································correlate,·and92 ········································································correlate,·and
110 ········································································investigate·the·events93 ········································································investigate·the·events
111 ········································································leading·up·to·an·outage94 ········································································leading·up·to·an·outage
Offset 122, 200 lines modifiedOffset 105, 140 lines modified
122 ········································································audit·subsystem·ensures105 ········································································audit·subsystem·ensures
123 ········································································that·actions·of106 ········································································that·actions·of
124 ········································································individual·system·users107 ········································································individual·system·users
125 ········································································can·be·uniquely·traced108 ········································································can·be·uniquely·traced
126 ········································································to·those·users·so·they109 ········································································to·those·users·so·they
127 ········································································can·be·held·accountable110 ········································································can·be·held·accountable
128 ········································································for·their·actions.111 ········································································for·their·actions.
 112 ········································································Even·though·the
 113 ········································································communications·channel
 114 ········································································may·be·encrypted,·an
 115 ········································································additional·layer·of
 116 ········································································security·is·gained·by
 117 ··································The·root·user·should·never·be·allowed·extending·the·policy·of
 118 ··································to·login·to·a·system·directly·over·a··not·logging·directly·on
 119 ················Disable·SSH·Root··network.·To·disable·root·login·via····as·root.·In·addition,
 120 FAU_GEN.1·······Login·············SSH,·add·or·correct·the·following·····logging·in·with·a·user-
 121 ··································line·in·/etc/ssh/sshd_config:·········specific·account
 122 ··································PermitRootLogin·no····················provides·individual
129 ··································The·audit·system·already·collects 
130 ··································login·information·for·all·users·and 
131 ··································root.·If·the·auditd·daemon·is 
132 ··································configured·to·use·the·augenrules 
133 ··································program·to·read·audit·rules·during 
134 ··································daemon·startup·(the·default),·add·the 
135 ··································following·lines·to·a·file·with·suffix 
136 ··································.rules·in·the·directory·/etc/audit/···Manual·editing·of·these 
137 ················Record·Attempts···rules.d·in·order·to·watch·for·········files·may·indicate 
138 ················to·Alter·Logon····attempted·manual·edits·of·files·······nefarious·activity, 
139 FAU_GEN.1.1.c···and·Logout·Events·involved·in·storing·logon·events:·····such·as·an·attacker 
140 ················-·tallylog········-w·/var/log/tallylog·-p·wa·-k·logins··attempting·to·remove 
141 ··································If·the·auditd·daemon·is·configured·to·evidence·of·an 
142 ··································use·the·auditctl·utility·to·read······intrusion. 
143 ··································audit·rules·during·daemon·startup, 
144 ··································add·the·following·lines·to·/etc/ 
145 ··································audit/audit.rules·file·in·order·to 
146 ··································watch·for·unattempted·manual·edits·of 
147 ··································files·involved·in·storing·logon 
148 ··································events: 
149 ··································-w·/var/log/tallylog·-p·wa·-k·logins 
150 ··································If·the·auditd·daemon·is·configured·to 
151 ··································use·the·augenrules·program·to·read 
152 ··································audit·rules·during·daemon·startup 
153 ··································(the·default),·add·the·following 
154 ··································lines·to·a·file·with·suffix·.rules·in 
155 ··································the·directory·/etc/audit/rules.d,·in 
156 ··································order·to·capture·events·that·modify···In·addition·to·auditing 
157 ··································account·changes:······················new·user·and·group 
158 ········································································accounts,·these·watches123 ········································································accountability·of
 124 ········································································actions·performed·on
 125 ········································································the·system·and·also
 126 ········································································helps·to·minimize
Max diff block lines reached; 501356/514290 bytes (97.49%) of diff not shown.
684 KB
./usr/share/doc/ssg-nondebian/table-ol7-pcidssrefs.html
Ordering differences only
    
Offset 95, 14 lines modifiedOffset 95, 50 lines modified
95 attacker·to·monitor·and·record·network·traffic.·These·malicious·APs·can·also95 attacker·to·monitor·and·record·network·traffic.·These·malicious·APs·can·also
96 serve·to·create·a·man-in-the-middle·attack·or·be·used·to·create·a·denial·of96 serve·to·create·a·man-in-the-middle·attack·or·be·used·to·create·a·denial·of
97 service·to·valid·network·resources.97 service·to·valid·network·resources.
98 ······</td>98 ······</td>
99 ····</tr>99 ····</tr>
100 ····<tr>100 ····<tr>
101 ······<td>Req-1.4.1</td>101 ······<td>Req-1.4.1</td>
 102 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
 103 ······<td·xml:lang="en-US">
 104 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
 105 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
 106 ······</td>
 107 ······<td·xml:lang="en-US">
 108 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
 109 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state.
 110 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received,
 111 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
 112 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
 113 enables·the·system·to·continue·servicing·valid·connection·requests.
 114 ······</td>
 115 ····</tr>
 116 ····<tr>
 117 ······<td>Req-1.4.1</td>
 118 ······<td>Set·Default·ip6tables·Policy·for·Incoming·Packets</td>
 119 ······<td·xml:lang="en-US">
 120 ········To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)·for
 121 the·built-in·INPUT·chain·which·processes·incoming·packets,
 122 add·or·correct·the·following·line·in
 123 <tt>/etc/sysconfig/ip6tables</tt>:
 124 <pre>:INPUT·DROP·[0:0]</pre>
 125 If·changes·were·required,·reload·the·ip6tables·rules:
 126 <pre>$·sudo·service·ip6tables·reload</pre>
 127 ······</td>
 128 ······<td·xml:lang="en-US">
 129 ········In·<tt>ip6tables</tt>,·the·default·policy·is·applied·only·after·all
 130 the·applicable·rules·in·the·table·are·examined·for·a·match.·Setting·the
 131 default·policy·to·<tt>DROP</tt>·implements·proper·design·for·a·firewall,·i.e.
 132 any·packets·which·are·not·explicitly·permitted·should·not·be
 133 accepted.
 134 ······</td>
 135 ····</tr>
 136 ····<tr>
 137 ······<td>Req-1.4.1</td>
102 ······<td>Set·configuration·for·loopback·traffic</td>138 ······<td>Set·configuration·for·loopback·traffic</td>
103 ······<td·xml:lang="en-US">139 ······<td·xml:lang="en-US">
104 ········Configure·the·loopback·interface·to·accept·traffic.·140 ········Configure·the·loopback·interface·to·accept·traffic.·
105 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback·141 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback·
106 network.142 network.
107 ······</td>143 ······</td>
108 ······<td·xml:lang="en-US">144 ······<td·xml:lang="en-US">
Offset 140, 47 lines modifiedOffset 176, 33 lines modified
140 ······<td·xml:lang="en-US">176 ······<td·xml:lang="en-US">
141 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering177 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
142 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP178 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
143 masquerading,·etc.179 masquerading,·etc.
144 ······</td>180 ······</td>
145 ····</tr>181 ····</tr>
146 ····<tr>182 ····<tr>
147 ······<td>Req-1.4.1</td>183 ······<td>Req-1.4.2</td>
 184 ······<td>Disable·SCTP·Support</td>
148 ······<td>Set·Default·ip6tables·Policy·for·Incoming·Packets</td> 
149 ······<td·xml:lang="en-US"> 
150 ········To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)·for 
151 the·built-in·INPUT·chain·which·processes·incoming·packets, 
152 add·or·correct·the·following·line·in 
153 <tt>/etc/sysconfig/ip6tables</tt>: 
154 <pre>:INPUT·DROP·[0:0]</pre> 
155 If·changes·were·required,·reload·the·ip6tables·rules: 
156 <pre>$·sudo·service·ip6tables·reload</pre> 
157 ······</td> 
158 ······<td·xml:lang="en-US"> 
159 ········In·<tt>ip6tables</tt>,·the·default·policy·is·applied·only·after·all 
160 the·applicable·rules·in·the·table·are·examined·for·a·match.·Setting·the 
161 default·policy·to·<tt>DROP</tt>·implements·proper·design·for·a·firewall,·i.e. 
162 any·packets·which·are·not·explicitly·permitted·should·not·be 
163 accepted. 
164 ······</td> 
165 ····</tr> 
166 ····<tr> 
167 ······<td>Req-1.4.1</td> 
168 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td> 
169 ······<td·xml:lang="en-US">185 ······<td·xml:lang="en-US">
170 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre> 
171 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>186 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
 187 transport·layer·protocol,·designed·to·support·the·idea·of
 188 message-oriented·communication,·with·several·streams·of·messages
 189 within·one·connection.
  
 190 To·configure·the·system·to·prevent·the·<code>sctp</code>
 191 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/sctp.conf</code>:
 192 <pre>install·sctp·/bin/true</pre>
  
 193 To·configure·the·system·to·prevent·the·<code>sctp</code>·from·being·used,
 194 add·the·following·line·to·file·<code>/etc/modprobe.d/sctp.conf</code>:
 195 <pre>blacklist·sctp</pre>
172 ······</td>196 ······</td>
173 ······<td·xml:lang="en-US">197 ······<td·xml:lang="en-US">
 198 ········Disabling·SCTP·protects
 199 the·system·against·exploitation·of·any·flaws·in·its·implementation.
174 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a 
175 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state. 
176 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received, 
177 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood 
178 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and 
179 enables·the·system·to·continue·servicing·valid·connection·requests. 
180 ······</td>200 ······</td>
181 ····</tr>201 ····</tr>
182 ····<tr>202 ····<tr>
183 ······<td>Req-1.4.2</td>203 ······<td>Req-1.4.2</td>
184 ······<td>Disable·DCCP·Support</td>204 ······<td>Disable·DCCP·Support</td>
185 ······<td·xml:lang="en-US">205 ······<td·xml:lang="en-US">
186 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a206 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
Offset 197, 33 lines modifiedOffset 219, 44 lines modified
197 ······</td>219 ······</td>
198 ······<td·xml:lang="en-US">220 ······<td·xml:lang="en-US">
199 ········Disabling·DCCP·protects221 ········Disabling·DCCP·protects
200 the·system·against·exploitation·of·any·flaws·in·its·implementation.222 the·system·against·exploitation·of·any·flaws·in·its·implementation.
201 ······</td>223 ······</td>
202 ····</tr>224 ····</tr>
203 ····<tr>225 ····<tr>
204 ······<td>Req-1.4.2</td>226 ······<td>Req-1.4.3</td>
205 ······<td>Disable·SCTP·Support</td>227 ······<td>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</td>
206 ······<td·xml:lang="en-US">228 ······<td·xml:lang="en-US">
 229 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_echo_ignore_broadcasts</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_echo_ignore_broadcasts=1</pre>
 230 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_echo_ignore_broadcasts·=·1</pre>
207 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a 
208 transport·layer·protocol,·designed·to·support·the·idea·of 
Max diff block lines reached; 260728/267486 bytes (97.47%) of diff not shown.
422 KB
html2text {}
    
Offset 56, 14 lines modifiedOffset 56, 55 lines modified
56 ····················································································also·serve·to56 ····················································································also·serve·to
57 ····················································································create·a·man-in-57 ····················································································create·a·man-in-
58 ····················································································the-middle·attack58 ····················································································the-middle·attack
59 ····················································································or·be·used·to59 ····················································································or·be·used·to
60 ····················································································create·a·denial·of60 ····················································································create·a·denial·of
61 ····················································································service·to·valid61 ····················································································service·to·valid
62 ····················································································network·resources.62 ····················································································network·resources.
 63 ····················································································A·TCP·SYN·flood
 64 ····················································································attack·can·cause·a
 65 ····················································································denial·of·service
 66 ····················································································by·filling·a
 67 ····················································································system's·TCP
 68 ····················································································connection·table
 69 ····················································································with·connections·in
 70 ····················································································the·SYN_RCVD·state.
 71 ····················································································Syncookies·can·be
 72 ·····························To·set·the·runtime·status·of·the·······················used·to·track·a
 73 ·····························net.ipv4.tcp_syncookies·kernel·parameter,·run·the······connection·when·a
 74 ·········Enable·Kernel·······following·command:·····································subsequent·ACK·is
 75 Req-·····Parameter·to·Use····$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1·············received,·verifying
 76 1.4.1····TCP·Syncookies·on···To·make·sure·that·the·setting·is·persistent,·add·the···the·initiator·is
 77 ·········Network·Interfaces··following·line·to·a·file·in·the·directory·/etc/········attempting·a·valid
 78 ·····························sysctl.d:··············································connection·and·is
 79 ·····························net.ipv4.tcp_syncookies·=·1····························not·a·flood·source.
 80 ····················································································This·feature·is
 81 ····················································································activated·when·a
 82 ····················································································flood·condition·is
 83 ····················································································detected,·and
 84 ····················································································enables·the·system
 85 ····················································································to·continue
 86 ····················································································servicing·valid
 87 ····················································································connection
 88 ····················································································requests.
 89 ····················································································In·ip6tables,·the
 90 ····················································································default·policy·is
 91 ····················································································applied·only·after
 92 ····················································································all·the·applicable
 93 ·····························To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)··rules·in·the·table
 94 ·········Set·Default·········for·the·built-in·INPUT·chain·which·processes·incoming··are·examined·for·a
 95 Req-·····ip6tables·Policy····packets,·add·or·correct·the·following·line·in·/etc/····match.·Setting·the
 96 1.4.1····for·Incoming········sysconfig/ip6tables:···································default·policy·to
 97 ·········Packets·············:INPUT·DROP·[0:0]······································DROP·implements
 98 ·····························If·changes·were·required,·reload·the·ip6tables·rules:··proper·design·for·a
 99 ·····························$·sudo·service·ip6tables·reload························firewall,·i.e.·any
 100 ····················································································packets·which·are
 101 ····················································································not·explicitly
 102 ····················································································permitted·should
 103 ····················································································not·be·accepted.
63 ····················································································Loopback·traffic·is104 ····················································································Loopback·traffic·is
64 ····················································································generated·between105 ····················································································generated·between
65 ····················································································processes·on106 ····················································································processes·on
66 ····················································································machine·and·is107 ····················································································machine·and·is
67 ····················································································typically·critical108 ····················································································typically·critical
68 ····················································································to·operation·of·the109 ····················································································to·operation·of·the
69 ····················································································system.·The110 ····················································································system.·The
Offset 99, 78 lines modifiedOffset 140, 84 lines modified
99 ····················································································network·packet140 ····················································································network·packet
100 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.141 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.
101 1.4.1····Package·············following·command:·····································iptables·allows142 1.4.1····Package·············following·command:·····································iptables·allows
102 ·····························$·sudo·yum·install·iptables····························system·operators·to143 ·····························$·sudo·yum·install·iptables····························system·operators·to
103 ····················································································set·up·firewalls144 ····················································································set·up·firewalls
104 ····················································································and·IP145 ····················································································and·IP
105 ····················································································masquerading,·etc.146 ····················································································masquerading,·etc.
106 ····················································································In·ip6tables,·the 
107 ····················································································default·policy·is 
108 ····················································································applied·only·after 
109 ····················································································all·the·applicable 
110 ·····························To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)··rules·in·the·table 
111 ·········Set·Default·········for·the·built-in·INPUT·chain·which·processes·incoming··are·examined·for·a 
112 Req-·····ip6tables·Policy····packets,·add·or·correct·the·following·line·in·/etc/····match.·Setting·the 
113 1.4.1····for·Incoming········sysconfig/ip6tables:···································default·policy·to 
114 ·········Packets·············:INPUT·DROP·[0:0]······································DROP·implements 
115 ·····························If·changes·were·required,·reload·the·ip6tables·rules:··proper·design·for·a 
116 ·····························$·sudo·service·ip6tables·reload························firewall,·i.e.·any 
117 ····················································································packets·which·are 
118 ····················································································not·explicitly 
119 ····················································································permitted·should 
120 ····················································································not·be·accepted. 
121 ····················································································A·TCP·SYN·flood 
122 ····················································································attack·can·cause·a 
123 ····················································································denial·of·service 
124 ····················································································by·filling·a 
125 ····················································································system's·TCP 
126 ····················································································connection·table 
127 ····················································································with·connections·in 
128 ····················································································the·SYN_RCVD·state. 
129 ····················································································Syncookies·can·be 
130 ·····························To·set·the·runtime·status·of·the·······················used·to·track·a 
131 ·····························net.ipv4.tcp_syncookies·kernel·parameter,·run·the······connection·when·a 
132 ·········Enable·Kernel·······following·command:·····································subsequent·ACK·is 
133 Req-·····Parameter·to·Use····$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1·············received,·verifying 
134 1.4.1····TCP·Syncookies·on···To·make·sure·that·the·setting·is·persistent,·add·the···the·initiator·is 
135 ·········Network·Interfaces··following·line·to·a·file·in·the·directory·/etc/········attempting·a·valid 
136 ·····························sysctl.d:··············································connection·and·is 
137 ·····························net.ipv4.tcp_syncookies·=·1····························not·a·flood·source. 
138 ····················································································This·feature·is 
139 ····················································································activated·when·a 
140 ····················································································flood·condition·is 
141 ····················································································detected,·and 
142 ····················································································enables·the·system 
143 ····················································································to·continue 
144 ····················································································servicing·valid 
145 ····················································································connection 
146 ····················································································requests. 
147 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
148 ·····························relatively·new·transport·layer·protocol,·designed·to 
149 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP 
150 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system 
151 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against 
152 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any 
153 ·····························install·dccp·/bin/true·································flaws·in·its 
154 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation. 
155 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/ 
156 ·····························dccp.conf: 
157 ·····························blacklist·dccp 
158 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a147 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
159 ·····························transport·layer·protocol,·designed·to·support·the·idea148 ·····························transport·layer·protocol,·designed·to·support·the·idea
160 ·····························of·message-oriented·communication,·with·several149 ·····························of·message-oriented·communication,·with·several
161 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP150 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP
162 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system151 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system
163 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against152 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against
164 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any153 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any
165 ·····························install·sctp·/bin/true·································flaws·in·its154 ·····························install·sctp·/bin/true·································flaws·in·its
166 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.155 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.
167 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/156 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
168 ·····························sctp.conf:157 ·····························sctp.conf:
169 ·····························blacklist·sctp158 ·····························blacklist·sctp
Max diff block lines reached; 414147/432440 bytes (95.77%) of diff not shown.
1.43 MB
./usr/share/doc/ssg-nondebian/table-ol8-anssirefs.html
    
Offset 63, 569 lines modifiedOffset 63, 569 lines modified
000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····
000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<
00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat
00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</
00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>
00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t
Diff chunk too large, falling back to line-by-line diff (553 lines added, 553 lines removed)
00000440:·643e·4250·3238·2852·3129·3c2f·7464·3e0a··d>BP28(R1)</td>.00000440:·643e·4250·3238·2852·3129·3c2f·7464·3e0a··d>BP28(R1)</td>.
00000450:·2020·2020·2020·3c74·643e·5265·6d6f·7665········<td>Remove00000450:·2020·2020·2020·3c74·643e·556e·696e·7374········<td>Uninst
00000460:·2074·6674·7020·4461·656d·6f6e·3c2f·7464···tftp·Daemon</td00000460:·616c·6c20·5365·6e64·6d61·696c·2050·6163··all·Sendmail·Pac
00000470:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:00000470:·6b61·6765·3c2f·7464·3e0a·2020·2020·2020··kage</td>.······
00000480:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··00000480:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
00000490:·2020·2020·2020·5472·6976·6961·6c20·4669········Trivial·Fi00000490:·2d55·5322·3e0a·2020·2020·2020·2020·5365··-US">.········Se
000004a0:·6c65·2054·7261·6e73·6665·7220·5072·6f74··le·Transfer·Prot000004a0:·6e64·6d61·696c·2069·7320·6e6f·7420·7468··ndmail·is·not·th
000004b0:·6f63·6f6c·2028·5446·5450·2920·6973·2061··ocol·(TFTP)·is·a000004b0:·6520·6465·6661·756c·7420·6d61·696c·2074··e·default·mail·t
000004c0:·2073·696d·706c·6520·6669·6c65·2074·7261···simple·file·tra000004c0:·7261·6e73·6665·7220·6167·656e·7420·616e··ransfer·agent·an
000004d0:·6e73·6665·7220·7072·6f74·6f63·6f6c·2c0a··nsfer·protocol,.000004d0:·6420·6973·0a6e·6f74·2069·6e73·7461·6c6c··d·is.not·install
000004e0:·7479·7069·6361·6c6c·7920·7573·6564·2074··typically·used·t000004e0:·6564·2062·7920·6465·6661·756c·742e·0a54··ed·by·default..T
000004f0:·6f20·6175·746f·6d61·7469·6361·6c6c·7920··o·automatically·000004f0:·6865·203c·636f·6465·3e73·656e·646d·6169··he·<code>sendmai
00000500:·7472·616e·7366·6572·2063·6f6e·6669·6775··transfer·configu00000500:·6c3c·2f63·6f64·653e·2070·6163·6b61·6765··l</code>·package
00000510:·7261·7469·6f6e·206f·7220·626f·6f74·2066··ration·or·boot·f00000510:·2063·616e·2062·6520·7265·6d6f·7665·6420···can·be·removed·
00000520:·696c·6573·2062·6574·7765·656e·2073·7973··iles·between·sys00000520:·7769·7468·2074·6865·2066·6f6c·6c6f·7769··with·the·followi
00000530:·7465·6d73·2e0a·5446·5450·2064·6f65·7320··tems..TFTP·does·00000530:·6e67·2063·6f6d·6d61·6e64·3a0a·3c70·7265··ng·command:.<pre
00000540:·6e6f·7420·7375·7070·6f72·7420·6175·7468··not·support·auth00000540:·3e0a·2420·7375·646f·2079·756d·2065·7261··>.$·sudo·yum·era
00000550:·656e·7469·6361·7469·6f6e·2061·6e64·2063··entication·and·c00000550:·7365·2073·656e·646d·6169·6c3c·2f70·7265··se·sendmail</pre
00000560:·616e·2062·6520·6561·7369·6c79·2068·6163··an·be·easily·hac00000560:·3e0a·2020·2020·2020·3c2f·7464·3e0a·2020··>.······</td>.··
00000570:·6b65·642e·2054·6865·2070·6163·6b61·6765··ked.·The·package00000570:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
00000580:·0a3c·7474·3e74·6674·703c·2f74·743e·2069··.<tt>tftp</tt>·i00000580:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
00000590:·7320·6120·636c·6965·6e74·2070·726f·6772··s·a·client·progr00000590:·2020·5468·6520·7365·6e64·6d61·696c·2073····The·sendmail·s
000005a0:·616d·2074·6861·7420·616c·6c6f·7773·2066··am·that·allows·f000005a0:·6f66·7477·6172·6520·7761·7320·6e6f·7420··oftware·was·not·
000005b0:·6f72·2063·6f6e·6e65·6374·696f·6e73·2074··or·connections·t000005b0:·6465·7665·6c6f·7065·6420·7769·7468·2073··developed·with·s
000005c0:·6f20·6120·3c74·743e·7466·7470·3c2f·7474··o·a·<tt>tftp</tt000005c0:·6563·7572·6974·7920·696e·206d·696e·6420··ecurity·in·mind·
000005d0:·3e20·7365·7276·6572·2e0a·2020·2020·2020··>·server..······000005d0:·616e·640a·6974·7320·6465·7369·676e·2070··and.its·design·p
000005e0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·000005e0:·7265·7665·6e74·7320·6974·2066·726f·6d20··revents·it·from·
000005f0:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"000005f0:·6265·696e·6720·6566·6665·6374·6976·656c··being·effectivel
00000600:·3e0a·2020·2020·2020·2020·4974·2069·7320··>.········It·is·00000600:·7920·636f·6e74·6169·6e65·6420·6279·2053··y·contained·by·S
00000610:·7265·636f·6d6d·656e·6465·6420·7468·6174··recommended·that00000610:·454c·696e·7578·2e20·2050·6f73·7466·6978··ELinux.··Postfix
00000620:·2054·4654·5020·6265·2072·656d·6f76·6564···TFTP·be·removed00000620:·0a73·686f·756c·6420·6265·2075·7365·6420··.should·be·used·
00000630:·2c20·756e·6c65·7373·2074·6865·7265·2069··,·unless·there·i00000630:·696e·7374·6561·642e·0a20·2020·2020·203c··instead..······<
00000640:·7320·6120·7370·6563·6966·6963·206e·6565··s·a·specific·nee00000640:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·
00000650:·640a·666f·7220·5446·5450·2028·7375·6368··d.for·TFTP·(such00000650:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t
00000660:·2061·7320·6120·626f·6f74·2073·6572·7665···as·a·boot·serve00000660:·643e·4250·3238·2852·3129·3c62·722f·3e4e··d>BP28(R1)<br/>N
00000670:·7229·2e20·496e·2074·6861·7420·6361·7365··r).·In·that·case00000670:·5430·3037·2852·3033·293c·2f74·643e·0a20··T007(R03)</td>.·
00000680:·2c20·7573·6520·6578·7472·656d·6520·6361··,·use·extreme·ca00000680:·2020·2020·203c·7464·3e55·6e69·6e73·7461·······<td>Uninsta
00000690:·7574·696f·6e20·7768·656e·2063·6f6e·6669··ution·when·confi00000690:·6c6c·2074·6865·2074·656c·6e65·7420·7365··ll·the·telnet·se
000006a0:·6775·7269·6e67·0a74·6865·2073·6572·7669··guring.the·servi000006a0:·7276·6572·3c2f·7464·3e0a·2020·2020·2020··rver</td>.······
000006b0:·6365·732e·0a20·2020·2020·203c·2f74·643e··ces..······</td>000006b0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
000006c0:·0a20·2020·203c·2f74·723e·0a20·2020·203c··.····</tr>.····<000006c0:·2d55·5322·3e0a·2020·2020·2020·2020·5468··-US">.········Th
000006d0:·7472·3e0a·2020·2020·2020·3c74·643e·4250··tr>.······<td>BP000006d0:·6520·7465·6c6e·6574·2064·6165·6d6f·6e20··e·telnet·daemon·
000006e0:·3238·2852·3129·3c2f·7464·3e0a·2020·2020··28(R1)</td>.····000006e0:·7368·6f75·6c64·2062·6520·756e·696e·7374··should·be·uninst
000006f0:·2020·3c74·643e·556e·696e·7374·616c·6c20····<td>Uninstall·000006f0:·616c·6c65·642e·0a20·2020·2020·203c·2f74··alled..······</t
00000700:·7869·6e65·7464·2050·6163·6b61·6765·3c2f··xinetd·Package</00000700:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
00000710:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm00000710:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
00000720:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.00000720:·2020·2020·2020·203c·7474·3e74·656c·6e65·········<tt>telne
00000730:·2020·2020·2020·2020·5468·6520·3c63·6f64··········The·<cod00000730:·743c·2f74·743e·2061·6c6c·6f77·7320·636c··t</tt>·allows·cl
00000740:·653e·7869·6e65·7464·3c2f·636f·6465·3e20··e>xinetd</code>·00000740:·6561·7220·7465·7874·2063·6f6d·6d75·6e69··ear·text·communi
00000750:·7061·636b·6167·6520·6361·6e20·6265·2072··package·can·be·r00000750:·6361·7469·6f6e·732c·2061·6e64·2064·6f65··cations,·and·doe
00000760:·656d·6f76·6564·2077·6974·6820·7468·6520··emoved·with·the·00000760:·7320·6e6f·7420·7072·6f74·6563·740a·616e··s·not·protect.an
00000770:·666f·6c6c·6f77·696e·6720·636f·6d6d·616e··following·comman00000770:·7920·6461·7461·2074·7261·6e73·6d69·7373··y·data·transmiss
00000780:·643a·0a3c·7072·653e·0a24·2073·7564·6f20··d:.<pre>.$·sudo·00000780:·696f·6e20·6265·7477·6565·6e20·636c·6965··ion·between·clie
00000790:·7975·6d20·6572·6173·6520·7869·6e65·7464··yum·erase·xinetd00000790:·6e74·2061·6e64·2073·6572·7665·722e·2041··nt·and·server.·A
000007a0:·3c2f·7072·653e·0a20·2020·2020·203c·2f74··</pre>.······</t000007a0:·6e79·2063·6f6e·6669·6465·6e74·6961·6c20··ny·confidential·
000007b0:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml000007b0:·6461·7461·0a63·616e·2062·6520·6c69·7374··data.can·be·list
000007c0:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·000007c0:·656e·6564·2061·6e64·206e·6f20·696e·7465··ened·and·no·inte
000007d0:·2020·2020·2020·2052·656d·6f76·696e·6720·········Removing·000007d0:·6772·6974·7920·6368·6563·6b69·6e67·2069··grity·checking·i
000007e0:·7468·6520·3c74·743e·7869·6e65·7464·3c2f··the·<tt>xinetd</000007e0:·7320·6d61·6465·2e27·0a20·2020·2020·203c··s·made.'.······<
000007f0:·7474·3e20·7061·636b·6167·6520·6465·6372··tt>·package·decr000007f0:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·
00000800:·6561·7365·7320·7468·6520·7269·736b·206f··eases·the·risk·o00000800:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t
00000810:·6620·7468·650a·7869·6e65·7464·2073·6572··f·the.xinetd·ser00000810:·643e·4250·3238·2852·3129·3c2f·7464·3e0a··d>BP28(R1)</td>.
00000820:·7669·6365·2773·2061·6363·6964·656e·7461··vice's·accidenta00000820:·2020·2020·2020·3c74·643e·556e·696e·7374········<td>Uninst
00000830:·6c20·286f·7220·696e·7465·6e74·696f·6e61··l·(or·intentiona00000830:·616c·6c20·7461·6c6b·2d73·6572·7665·7220··all·talk-server·
00000840:·6c29·2061·6374·6976·6174·696f·6e2e·0a20··l)·activation..·00000840:·5061·636b·6167·653c·2f74·643e·0a20·2020··Package</td>.···
00000850:·2020·2020·203c·2f74·643e·0a20·2020·203c·······</td>.····<00000850:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=
00000860:·2f74·723e·0a20·2020·203c·7472·3e0a·2020··/tr>.····<tr>.··00000860:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······
00000870:·2020·2020·3c74·643e·4250·3238·2852·3129······<td>BP28(R1)00000870:·2054·6865·203c·636f·6465·3e74·616c·6b2d···The·<code>talk-
00000880:·3c2f·7464·3e0a·2020·2020·2020·3c74·643e··</td>.······<td>00000880:·7365·7276·6572·3c2f·636f·6465·3e20·7061··server</code>·pa
00000890:·556e·696e·7374·616c·6c20·7465·6c6e·6574··Uninstall·telnet00000890:·636b·6167·6520·6361·6e20·6265·2072·656d··ckage·can·be·rem
000008a0:·2d73·6572·7665·7220·5061·636b·6167·653c··-server·Package<000008a0:·6f76·6564·2077·6974·6820·7468·6520·666f··oved·with·the·fo
000008b0:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x000008b0:·6c6c·6f77·696e·6720·636f·6d6d·616e·643a··llowing·command:
000008c0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">000008c0:·203c·7072·653e·2024·2073·7564·6f20·7975···<pre>·$·sudo·yu
000008d0:·0a20·2020·2020·2020·2054·6865·203c·636f··.········The·<co000008d0:·6d20·6572·6173·6520·7461·6c6b·2d73·6572··m·erase·talk-ser
000008e0:·6465·3e74·656c·6e65·742d·7365·7276·6572··de>telnet-server000008e0:·7665·723c·2f70·7265·3e0a·2020·2020·2020··ver</pre>.······
000008f0:·3c2f·636f·6465·3e20·7061·636b·6167·6520··</code>·package·000008f0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000900:·6361·6e20·6265·2072·656d·6f76·6564·2077··can·be·removed·w00000900:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
00000910:·6974·6820·7468·6520·666f·6c6c·6f77·696e··ith·the·followin00000910:·3e0a·2020·2020·2020·2020·5468·6520·7461··>.········The·ta
00000920:·6720·636f·6d6d·616e·643a·0a3c·7072·653e··g·command:.<pre>00000920:·6c6b·2073·6f66·7477·6172·6520·7072·6573··lk·software·pres
00000930:·0a24·2073·7564·6f20·7975·6d20·6572·6173··.$·sudo·yum·eras00000930:·656e·7473·2061·2073·6563·7572·6974·7920··ents·a·security·
00000940:·6520·7465·6c6e·6574·2d73·6572·7665·723c··e·telnet-server<00000940:·7269·736b·2061·7320·6974·2075·7365·7320··risk·as·it·uses·
00000950:·2f70·7265·3e0a·2020·2020·2020·3c2f·7464··/pre>.······</td00000950:·756e·656e·6372·7970·7465·6420·7072·6f74··unencrypted·prot
00000960:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:00000960:·6f63·6f6c·730a·666f·7220·636f·6d6d·756e··ocols.for·commun
00000970:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··00000970:·6963·6174·696f·6e73·2e20·5265·6d6f·7669··ications.·Removi
00000980:·2020·2020·2020·4974·2069·7320·6465·7472········It·is·detr00000980:·6e67·2074·6865·203c·7474·3e74·616c·6b2d··ng·the·<tt>talk-
00000990:·696d·656e·7461·6c20·666f·7220·6f70·6572··imental·for·oper00000990:·7365·7276·6572·3c2f·7474·3e20·7061·636b··server</tt>·pack
000009a0:·6174·696e·6720·7379·7374·656d·7320·746f··ating·systems·to000009a0:·6167·6520·6465·6372·6561·7365·7320·7468··age·decreases·th
000009b0:·2070·726f·7669·6465·2c20·6f72·2069·6e73···provide,·or·ins000009b0:·650a·7269·736b·206f·6620·7468·6520·6163··e.risk·of·the·ac
000009c0:·7461·6c6c·2062·7920·6465·6661·756c·742c··tall·by·default,000009c0:·6369·6465·6e74·616c·2028·6f72·2069·6e74··cidental·(or·int
000009d0:·0a66·756e·6374·696f·6e61·6c69·7479·2065··.functionality·e000009d0:·656e·7469·6f6e·616c·2920·6163·7469·7661··entional)·activa
000009e0:·7863·6565·6469·6e67·2072·6571·7569·7265··xceeding·require000009e0:·7469·6f6e·206f·6620·7461·6c6b·2073·6572··tion·of·talk·ser
000009f0:·6d65·6e74·7320·6f72·206d·6973·7369·6f6e··ments·or·mission000009f0:·7669·6365·732e·0a20·2020·2020·203c·2f74··vices..······</t
00000a00:·206f·626a·6563·7469·7665·732e·2054·6865···objectives.·The00000a00:·643e·0a20·2020·203c·2f74·723e·0a20·2020··d>.····</tr>.···
00000a10:·7365·0a75·6e6e·6563·6573·7361·7279·2063··se.unnecessary·c00000a10:·203c·7472·3e0a·2020·2020·2020·3c74·643e···<tr>.······<td>
00000a20:·6170·6162·696c·6974·6965·7320·6172·6520··apabilities·are·00000a20:·4250·3238·2852·3129·3c2f·7464·3e0a·2020··BP28(R1)</td>.··
00000a30:·6f66·7465·6e20·6f76·6572·6c6f·6f6b·6564··often·overlooked00000a30:·2020·2020·3c74·643e·556e·696e·7374·616c······<td>Uninstal
00000a40:·2061·6e64·2074·6865·7265·666f·7265·206d···and·therefore·m00000a40:·6c20·7869·6e65·7464·2050·6163·6b61·6765··l·xinetd·Package
00000a50:·6179·2072·656d·6169·6e0a·756e·7365·6375··ay·remain.unsecu00000a50:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000a60:·7265·2e20·5468·6579·2069·6e63·7265·6173··re.·They·increas00000a60:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
00000a70:·6520·7468·6520·7269·736b·2074·6f20·7468··e·the·risk·to·th00000a70:·3e0a·2020·2020·2020·2020·5468·6520·3c63··>.········The·<c
00000a80:·6520·706c·6174·666f·726d·2062·7920·7072··e·platform·by·pr00000a80:·6f64·653e·7869·6e65·7464·3c2f·636f·6465··ode>xinetd</code
00000a90:·6f76·6964·696e·6720·6164·6469·7469·6f6e··oviding·addition00000a90:·3e20·7061·636b·6167·6520·6361·6e20·6265··>·package·can·be
00000aa0:·616c·0a61·7474·6163·6b20·7665·6374·6f72··al.attack·vector00000aa0:·2072·656d·6f76·6564·2077·6974·6820·7468···removed·with·th
00000ab0:·732e·0a3c·6272·202f·3e0a·5468·6520·7465··s..<br·/>.The·te00000ab0:·6520·666f·6c6c·6f77·696e·6720·636f·6d6d··e·following·comm
00000ac0:·6c6e·6574·2073·6572·7669·6365·2070·726f··lnet·service·pro00000ac0:·616e·643a·0a3c·7072·653e·0a24·2073·7564··and:.<pre>.$·sud
00000ad0:·7669·6465·7320·616e·2075·6e65·6e63·7279··vides·an·unencry00000ad0:·6f20·7975·6d20·6572·6173·6520·7869·6e65··o·yum·erase·xine
00000ae0:·7074·6564·2072·656d·6f74·6520·6163·6365··pted·remote·acce00000ae0:·7464·3c2f·7072·653e·0a20·2020·2020·203c··td</pre>.······<
00000af0:·7373·2073·6572·7669·6365·2077·6869·6368··ss·service·which00000af0:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x
00000b00:·2064·6f65·730a·6e6f·7420·7072·6f76·6964···does.not·provid00000b00:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
00000b10:·6520·666f·7220·7468·6520·636f·6e66·6964··e·for·the·confid00000b10:·0a20·2020·2020·2020·2052·656d·6f76·696e··.········Removin
00000b20:·656e·7469·616c·6974·7920·616e·6420·696e··entiality·and·in00000b20:·6720·7468·6520·3c74·743e·7869·6e65·7464··g·the·<tt>xinetd
00000b30:·7465·6772·6974·7920·6f66·2075·7365·7220··tegrity·of·user·00000b30:·3c2f·7474·3e20·7061·636b·6167·6520·6465··</tt>·package·de
00000b40:·7061·7373·776f·7264·7320·6f72·2074·6865··passwords·or·the00000b40:·6372·6561·7365·7320·7468·6520·7269·736b··creases·the·risk
00000b50:·0a72·656d·6f74·6520·7365·7373·696f·6e2e··.remote·session.00000b50:·206f·6620·7468·650a·7869·6e65·7464·2073···of·the.xinetd·s
00000b60:·2049·6620·6120·7072·6976·696c·6567·6564···If·a·privileged00000b60:·6572·7669·6365·2773·2061·6363·6964·656e··ervice's·acciden
00000b70:·2075·7365·7220·7765·7265·2074·6f20·6c6f···user·were·to·lo00000b70:·7461·6c20·286f·7220·696e·7465·6e74·696f··tal·(or·intentio
00000b80:·6769·6e20·7573·696e·6720·7468·6973·2073··gin·using·this·s00000b80:·6e61·6c29·2061·6374·6976·6174·696f·6e2e··nal)·activation.
00000b90:·6572·7669·6365·2c20·7468·650a·7072·6976··ervice,·the.priv00000b90:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00000ba0:·696c·6567·6564·2075·7365·7220·7061·7373··ileged·user·pass00000ba0:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.
00000bb0:·776f·7264·2063·6f75·6c64·2062·6520·636f··word·could·be·co00000bb0:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R
Max diff block lines reached; 1179855/1256743 bytes (93.88%) of diff not shown.
238 KB
html2text {}
    
Offset 1, 102 lines modifiedOffset 1, 107 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux
2 82 8
  
  
3 ································Trivial·File·Transfer·Protocol·(TFTP)·is·a 
4 ································simple·file·transfer·protocol,·typically 
5 ································used·to·automatically·transfer·configuration·It·is·recommended·that·TFTP·be·removed,·unless·there·is·a·specific·need·for 
6 BP28··Remove·tftp·Daemon········or·boot·files·between·systems.·TFTP·does·not·TFTP·(such·as·a·boot·server).·In·that·case,·use·extreme·caution·when 
7 (R1)····························support·authentication·and·can·be·easily·····configuring·the·services. 
8 ································hacked.·The·package·tftp·is·a·client·program 
9 ································that·allows·for·connections·to·a·tftp 
10 ································server. 
11 BP28····························The·xinetd·package·can·be·removed·with·the···Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's 
12 (R1)··Uninstall·xinetd·Package··following·command:···························accidental·(or·intentional)·activation. 
13 ································$·sudo·yum·erase·xinetd 
14 ·············································································It·is·detrimental·for·operating·systems·to·provide,·or·install·by·default, 
15 ·············································································functionality·exceeding·requirements·or·mission·objectives.·These 
16 ·············································································unnecessary·capabilities·are·often·overlooked·and·therefore·may·remain 
17 ·············································································unsecure.·They·increase·the·risk·to·the·platform·by·providing·additional 
18 BP28··Uninstall·telnet-server···The·telnet-server·package·can·be·removed·····attack·vectors. 
19 (R1)··Package···················with·the·following·command:··················The·telnet·service·provides·an·unencrypted·remote·access·service·which·does 
20 ································$·sudo·yum·erase·telnet-server···············not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the 
21 ·············································································remote·session.·If·a·privileged·user·were·to·login·using·this·service,·the 
22 ·············································································privileged·user·password·could·be·compromised. 
23 ·············································································Removing·the·telnet-server·package·decreases·the·risk·of·the·telnet 
24 ·············································································service's·accidental·(or·intentional)·activation. 
25 ································The·Network·Information·Service·(NIS), 
26 ································formerly·known·as·Yellow·Pages,·is·a·client-·The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to 
27 BP28····························server·directory·service·protocol·used·to····DOS·attacks,·buffer·overflows·and·has·poor·authentication·for·querying·NIS 
28 (R1)··Remove·NIS·Client·········distribute·system·configuration·files.·The···maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight 
29 ································NIS·client·(ypbind)·was·used·to·bind·a·······Directory·Access·Protocol·(LDAP).·It·is·recommended·that·the·service·be 
30 ································system·to·an·NIS·server·and·receive·the······removed. 
31 ································distributed·configuration·files. 
32 BP28··Uninstall·talk-server·····The·talk-server·package·can·be·removed·with··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols 
33 (R1)··Package···················the·following·command:·······················for·communications.·Removing·the·talk-server·package·decreases·the·risk·of 
34 ·································$·sudo·yum·erase·talk-server················the·accidental·(or·intentional)·activation·of·talk·services. 
35 ································Sendmail·is·not·the·default·mail·transfer3 ································Sendmail·is·not·the·default·mail·transfer
36 BP28··Uninstall·Sendmail········agent·and·is·not·installed·by·default.·The···The·sendmail·software·was·not·developed·with·security·in·mind·and·its·design4 BP28··Uninstall·Sendmail········agent·and·is·not·installed·by·default.·The···The·sendmail·software·was·not·developed·with·security·in·mind·and·its·design
37 (R1)··Package···················sendmail·package·can·be·removed·with·the·····prevents·it·from·being·effectively·contained·by·SELinux.·Postfix·should·be5 (R1)··Package···················sendmail·package·can·be·removed·with·the·····prevents·it·from·being·effectively·contained·by·SELinux.·Postfix·should·be
38 ································following·command:···························used·instead.6 ································following·command:···························used·instead.
39 ································$·sudo·yum·erase·sendmail7 ································$·sudo·yum·erase·sendmail
40 BP28·········································································telnet·allows·clear·text·communications,·and·does·not·protect·any·data8 BP28·········································································telnet·allows·clear·text·communications,·and·does·not·protect·any·data
41 (R1)··Uninstall·the·telnet······The·telnet·daemon·should·be·uninstalled.·····transmission·between·client·and·server.·Any·confidential·data·can·be9 (R1)··Uninstall·the·telnet······The·telnet·daemon·should·be·uninstalled.·····transmission·between·client·and·server.·Any·confidential·data·can·be
42 NT007·server·································································listened·and·no·integrity·checking·is·made.'10 NT007·server·································································listened·and·no·integrity·checking·is·made.'
43 (R03)11 (R03)
44 ································The·ypserv·package·can·be·removed·with·the···The·NIS·service·provides·an·unencrypted·authentication·service·which·does 
45 BP28··Uninstall·ypserv·Package··following·command:···························not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the 
46 (R1)····························$·sudo·yum·erase·ypserv······················remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the 
47 ·············································································accidental·(or·intentional)·activation·of·NIS·or·NIS+·services. 
48 ·············································································Removing·the·tftp-server·package·decreases·the·risk·of·the·accidental·(or 
49 ·············································································intentional)·activation·of·tftp·services. 
50 BP28··Uninstall·tftp-server·····The·tftp-server·package·can·be·removed·with 
51 (R1)··Package···················the·following·command:·······················If·TFTP·is·required·for·operational·support·(such·as·transmission·of·router 
52 ·································$·sudo·yum·erase·tftp-server················configurations),·its·use·must·be·documented·with·the·Information·Systems 
53 ·············································································Securty·Manager·(ISSM),·restricted·to·only·authorized·personnel,·and·have 
54 ·············································································access·control·rules·established.12 BP28··Uninstall·talk-server·····The·talk-server·package·can·be·removed·with··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols
 13 (R1)··Package···················the·following·command:·······················for·communications.·Removing·the·talk-server·package·decreases·the·risk·of
 14 ·································$·sudo·yum·erase·talk-server················the·accidental·(or·intentional)·activation·of·talk·services.
 15 BP28····························The·xinetd·package·can·be·removed·with·the···Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's
 16 (R1)··Uninstall·xinetd·Package··following·command:···························accidental·(or·intentional)·activation.
 17 ································$·sudo·yum·erase·xinetd
 18 ································Trivial·File·Transfer·Protocol·(TFTP)·is·a
 19 ································simple·file·transfer·protocol,·typically
 20 ································used·to·automatically·transfer·configuration·It·is·recommended·that·TFTP·be·removed,·unless·there·is·a·specific·need·for
 21 BP28··Remove·tftp·Daemon········or·boot·files·between·systems.·TFTP·does·not·TFTP·(such·as·a·boot·server).·In·that·case,·use·extreme·caution·when
 22 (R1)····························support·authentication·and·can·be·easily·····configuring·the·services.
 23 ································hacked.·The·package·tftp·is·a·client·program
 24 ································that·allows·for·connections·to·a·tftp
 25 ································server.
55 ································The·talk·package·contains·the·client·program26 ································The·talk·package·contains·the·client·program
56 ································for·the·Internet·talk·protocol,·which·allows27 ································for·the·Internet·talk·protocol,·which·allows
57 ································the·user·to·chat·with·other·users·on28 ································the·user·to·chat·with·other·users·on
58 BP28····························different·systems.·Talk·is·a·communication···The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols29 BP28····························different·systems.·Talk·is·a·communication···The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols
59 (R1)··Uninstall·talk·Package····program·which·copies·lines·from·one·terminal·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the30 (R1)··Uninstall·talk·Package····program·which·copies·lines·from·one·terminal·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the
60 ································to·the·terminal·of·another·user.·The·talk····accidental·(or·intentional)·activation·of·talk·client·program.31 ································to·the·terminal·of·another·user.·The·talk····accidental·(or·intentional)·activation·of·talk·client·program.
61 ································package·can·be·removed·with·the·following32 ································package·can·be·removed·with·the·following
62 ································command:33 ································command:
63 ································$·sudo·yum·erase·talk34 ································$·sudo·yum·erase·talk
64 ·············································································These·legacy·clients·contain·numerous·security·exposures·and·have·been 
65 ·············································································replaced·with·the·more·secure·SSH·package.·Even·if·the·server·is·removed,·it 
66 BP28··Uninstall·rsh·Package·····The·rsh·package·contains·the·client·commands·is·best·to·ensure·the·clients·are·also·removed·to·prevent·users·from 
67 (R1)····························for·the·rsh·services·························inadvertently·attempting·to·use·these·commands·and·therefore·exposing·their 
68 ·············································································credentials.·Note·that·removing·the·rsh·package·removes·the·clients·for35 ································The·Network·Information·Service·(NIS),
 36 ································formerly·known·as·Yellow·Pages,·is·a·client-·The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to
 37 BP28····························server·directory·service·protocol·used·to····DOS·attacks,·buffer·overflows·and·has·poor·authentication·for·querying·NIS
 38 (R1)··Remove·NIS·Client·········distribute·system·configuration·files.·The···maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight
 39 ································NIS·client·(ypbind)·was·used·to·bind·a·······Directory·Access·Protocol·(LDAP).·It·is·recommended·that·the·service·be
 40 ································system·to·an·NIS·server·and·receive·the······removed.
 41 ································distributed·configuration·files.
 42 ································The·telnet·client·allows·users·to·start······The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted
 43 BP28··Remove·telnet·Clients·····connections·to·other·systems·via·the·telnet··transmission·medium·could·allow·an·unauthorized·user·to·steal·credentials.
 44 (R1)····························protocol.····································The·ssh·package·provides·an·encrypted·session·and·stronger·security·and·is
69 ·············································································rsh,rcp,·and·rlogin.45 ·············································································included·in·Oracle·Linux·8.
70 ································If·the·system·does·not·need·to·act·as·a·DHCP46 ································If·the·system·does·not·need·to·act·as·a·DHCP
71 BP28··Uninstall·DHCP·Server·····server,·the·dhcp·package·can·be·uninstalled.·Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally47 BP28··Uninstall·DHCP·Server·····server,·the·dhcp·package·can·be·uninstalled.·Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally
72 (R1)··Package···················The·dhcp-server·package·can·be·removed·with··reactivated·and·disrupt·network·operation.48 (R1)··Package···················The·dhcp-server·package·can·be·removed·with··reactivated·and·disrupt·network·operation.
73 ································the·following·command:49 ································the·following·command:
74 ································$·sudo·yum·erase·dhcp-server50 ································$·sudo·yum·erase·dhcp-server
 51 ·············································································Removing·the·tftp-server·package·decreases·the·risk·of·the·accidental·(or
75 ································The·telnet·client·allows·users·to·start······The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted 
76 BP28··Remove·telnet·Clients·····connections·to·other·systems·via·the·telnet··transmission·medium·could·allow·an·unauthorized·user·to·steal·credentials. 
77 (R1)····························protocol.····································The·ssh·package·provides·an·encrypted·session·and·stronger·security·and·is 
78 ·············································································included·in·Oracle·Linux·8.52 ·············································································intentional)·activation·of·tftp·services.
 53 BP28··Uninstall·tftp-server·····The·tftp-server·package·can·be·removed·with
 54 (R1)··Package···················the·following·command:·······················If·TFTP·is·required·for·operational·support·(such·as·transmission·of·router
 55 ·································$·sudo·yum·erase·tftp-server················configurations),·its·use·must·be·documented·with·the·Information·Systems
 56 ·············································································Securty·Manager·(ISSM),·restricted·to·only·authorized·personnel,·and·have
 57 ·············································································access·control·rules·established.
79 ·············································································The·rsh-server·service·provides·unencrypted·remote·access·service·which·does58 ·············································································The·rsh-server·service·provides·unencrypted·remote·access·service·which·does
80 ·············································································not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the59 ·············································································not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the
81 BP28··Uninstall·rsh-server······The·rsh-server·package·can·be·removed·with···remote·session·and·has·very·weak·authentication.·If·a·privileged·user·were60 BP28··Uninstall·rsh-server······The·rsh-server·package·can·be·removed·with···remote·session·and·has·very·weak·authentication.·If·a·privileged·user·were
82 (R1)··Package···················the·following·command:·······················to·login·using·this·service,·the·privileged·user·password·could·be61 (R1)··Package···················the·following·command:·······················to·login·using·this·service,·the·privileged·user·password·could·be
83 ································$·sudo·yum·erase·rsh-server··················compromised.·The·rsh-server·package·provides·several·obsolete·and·insecure62 ································$·sudo·yum·erase·rsh-server··················compromised.·The·rsh-server·package·provides·several·obsolete·and·insecure
84 ·············································································network·services.·Removing·it·decreases·the·risk·of·those·services'63 ·············································································network·services.·Removing·it·decreases·the·risk·of·those·services'
85 ·············································································accidental·(or·intentional)·activation.64 ·············································································accidental·(or·intentional)·activation.
 65 ································The·ypserv·package·can·be·removed·with·the···The·NIS·service·provides·an·unencrypted·authentication·service·which·does
 66 BP28··Uninstall·ypserv·Package··following·command:···························not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the
 67 (R1)····························$·sudo·yum·erase·ypserv······················remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the
 68 ·············································································accidental·(or·intentional)·activation·of·NIS·or·NIS+·services.
 69 ·············································································These·legacy·clients·contain·numerous·security·exposures·and·have·been
 70 ·············································································replaced·with·the·more·secure·SSH·package.·Even·if·the·server·is·removed,·it
 71 BP28··Uninstall·rsh·Package·····The·rsh·package·contains·the·client·commands·is·best·to·ensure·the·clients·are·also·removed·to·prevent·users·from
 72 (R1)····························for·the·rsh·services·························inadvertently·attempting·to·use·these·commands·and·therefore·exposing·their
 73 ·············································································credentials.·Note·that·removing·the·rsh·package·removes·the·clients·for
 74 ·············································································rsh,rcp,·and·rlogin.
Max diff block lines reached; 226397/243540 bytes (92.96%) of diff not shown.
1.13 MB
./usr/share/doc/ssg-nondebian/table-ol8-cuirefs.html
Ordering differences only
    
Offset 41, 104 lines modifiedOffset 41, 14 lines modified
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td>47 ······<td>3.1.1<br/>3.1.5</td>
48 ······<td>Disable·SSH·Root·Login</td> 
49 ······<td·xml:lang="en-US"> 
50 ········The·root·user·should·never·be·allowed·to·login·to·a 
51 system·directly·over·a·network. 
52 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
53 <tt>/etc/ssh/sshd_config</tt>: 
  
54 <pre>PermitRootLogin·no</pre> 
55 ······</td> 
56 ······<td·xml:lang="en-US"> 
57 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
58 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
59 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
60 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
61 direct·attack·attempts·on·root's·password. 
62 ······</td> 
63 ····</tr> 
64 ····<tr> 
65 ······<td>3.1.1</td> 
66 ······<td>Disable·GDM·Guest·Login</td> 
67 ······<td·xml:lang="en-US"> 
68 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials 
69 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials 
70 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable 
71 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in 
72 the·<tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
73 <pre>[daemon] 
74 TimedLoginEnable=false</pre> 
75 ······</td> 
76 ······<td·xml:lang="en-US"> 
77 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
78 system·security. 
79 ······</td> 
80 ····</tr> 
81 ····<tr> 
82 ······<td>3.1.1<br/>3.4.5</td> 
83 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td> 
84 ······<td·xml:lang="en-US"> 
85 ········Emergency·mode·is·intended·as·a·system·recovery 
86 method,·providing·a·single·user·root·access·to·the·system 
87 during·a·failed·boot·sequence. 
88 <br·/><br·/> 
89 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set 
90 in·<tt>/usr/lib/systemd/system/emergency.service</tt>. 
91 ······</td> 
92 ······<td·xml:lang="en-US"> 
93 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security 
94 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented 
95 by·configuring·the·bootloader·password. 
96 ······</td> 
97 ····</tr> 
98 ····<tr> 
99 ······<td>3.1.1<br/>3.1.5</td> 
100 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td> 
101 ······<td·xml:lang="en-US"> 
102 ········If·an·account·is·configured·for·password·authentication 
103 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log 
104 into·the·account·without·authentication.·Remove·any·instances·of·the 
105 <tt>nullok</tt>·in 
  
106 <tt>/etc/pam.d/system-auth</tt>·and 
107 <tt>/etc/pam.d/password-auth</tt> 
  
108 to·prevent·logins·with·empty·passwords. 
109 ······</td> 
110 ······<td·xml:lang="en-US"> 
111 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and 
112 run·commands·with·the·privileges·of·that·account.·Accounts·with 
113 empty·passwords·should·never·be·used·in·operational·environments. 
114 ······</td> 
115 ····</tr> 
116 ····<tr> 
117 ······<td>3.1.1<br/>3.1.5</td> 
118 ······<td>Restrict·Serial·Port·Root·Logins</td> 
119 ······<td·xml:lang="en-US"> 
120 ········To·restrict·root·logins·on·serial·ports, 
121 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
122 <pre>ttyS0 
123 ttyS1</pre> 
124 ······</td> 
125 ······<td·xml:lang="en-US"> 
126 ········Preventing·direct·root·login·to·serial·port·interfaces 
127 helps·ensure·accountability·for·actions·taken·on·the·systems 
128 using·the·root·account. 
129 ······</td> 
130 ····</tr> 
131 ····<tr> 
132 ······<td>3.1.1<br/>3.1.5</td> 
133 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>48 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>
134 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
135 ········Disallow·SSH·login·with·empty·passwords.50 ········Disallow·SSH·login·with·empty·passwords.
136 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate51 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate
137 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.52 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.
138 <br·/>53 <br·/>
139 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,54 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,
Offset 189, 14 lines modifiedOffset 99, 40 lines modified
189 ······</td>99 ······</td>
190 ······<td·xml:lang="en-US">100 ······<td·xml:lang="en-US">
191 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating101 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
192 system·security.102 system·security.
193 ······</td>103 ······</td>
194 ····</tr>104 ····</tr>
195 ····<tr>105 ····<tr>
 106 ······<td>3.1.1<br/>3.1.6</td>
 107 ······<td>Direct·root·Logins·Not·Allowed</td>
 108 ······<td·xml:lang="en-US">
 109 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators
 110 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file.
 111 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does
 112 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the
 113 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous
 114 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in
 115 plain·text·over·the·network.·By·default,·Oracle·Linux·8's
 116 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console
 117 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the
 118 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this
 119 file·by·typing·the·following·command:
 120 <pre>
Max diff block lines reached; 428196/433772 bytes (98.71%) of diff not shown.
736 KB
html2text {}
Max HTML report size reached
10.4 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-stig.html
    
Offset 7986, 18 lines modifiedOffset 7986, 18 lines modified
0001f310:·7573·2070·6173·7377·6f72·6473·2068·656c··us·passwords·hel0001f310:·7573·2070·6173·7377·6f72·6473·2068·656c··us·passwords·hel
0001f320:·7073·2065·6e73·7572·6520·7468·6174·2061··ps·ensure·that·a0001f320:·7073·2065·6e73·7572·6520·7468·6174·2061··ps·ensure·that·a
0001f330:·2063·6f6d·7072·6f6d·6973·6564·2070·6173···compromised·pas0001f330:·2063·6f6d·7072·6f6d·6973·6564·2070·6173···compromised·pas
0001f340:·7377·6f72·6420·6973·206e·6f74·2072·652d··sword·is·not·re-0001f340:·7377·6f72·6420·6973·206e·6f74·2072·652d··sword·is·not·re-
0001f350:·7573·6564·2062·7920·6120·7573·6572·2e0a··used·by·a·user..0001f350:·7573·6564·2062·7920·6120·7573·6572·2e0a··used·by·a·user..
0001f360:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va0001f360:·2020·3c2f·7464·3e0a·2020·3c74·643e·7661····</td>.··<td>va
0001f370:·725f·7061·7373·776f·7264·5f70·616d·5f72··r_password_pam_r0001f370:·725f·7061·7373·776f·7264·5f70·616d·5f72··r_password_pam_r
 0001f380:·656d·656d·6265·723d·353c·6272·2f3e·7661··emember=5<br/>va
 0001f390:·725f·7061·7373·776f·7264·5f70·616d·5f72··r_password_pam_r
0001f380:·656d·656d·6265·725f·636f·6e74·726f·6c5f··emember_control_0001f3a0:·656d·656d·6265·725f·636f·6e74·726f·6c5f··emember_control_
0001f390:·666c·6167·3d6f·6c38·3c62·722f·3e76·6172··flag=ol8<br/>var0001f3b0:·666c·6167·3d6f·6c38·3c2f·7464·3e0a·3c2f··flag=ol8</td>.</
0001f3a0:·5f70·6173·7377·6f72·645f·7061·6d5f·7265··_password_pam_re 
0001f3b0:·6d65·6d62·6572·3d35·3c2f·7464·3e0a·3c2f··member=5</td>.</ 
0001f3c0:·7472·3e0a·3c74·723e·0a20·203c·7464·3e49··tr>.<tr>.··<td>I0001f3c0:·7472·3e0a·3c74·723e·0a20·203c·7464·3e49··tr>.<tr>.··<td>I
0001f3d0:·412d·3528·6629·3c62·722f·3e49·412d·3528··A-5(f)<br/>IA-5(0001f3d0:·412d·3528·6629·3c62·722f·3e49·412d·3528··A-5(f)<br/>IA-5(
0001f3e0:·3129·2865·293c·2f74·643e·0a20·203c·7464··1)(e)</td>.··<td0001f3e0:·3129·2865·293c·2f74·643e·0a20·203c·7464··1)(e)</td>.··<td
0001f3f0:·3e4e·2f41·3c2f·7464·3e0a·2020·3c74·643e··>N/A</td>.··<td>0001f3f0:·3e4e·2f41·3c2f·7464·3e0a·2020·3c74·643e··>N/A</td>.··<td>
0001f400:·4c69·6d69·7420·5061·7373·776f·7264·2052··Limit·Password·R0001f400:·4c69·6d69·7420·5061·7373·776f·7264·2052··Limit·Password·R
0001f410:·6575·7365·3a20·7379·7374·656d·2d61·7574··euse:·system-aut0001f410:·6575·7365·3a20·7379·7374·656d·2d61·7574··euse:·system-aut
0001f420:·683c·2f74·643e·0a20·203c·7464·2078·6d6c··h</td>.··<td·xml0001f420:·683c·2f74·643e·0a20·203c·7464·2078·6d6c··h</td>.··<td·xml
Offset 8042, 18 lines modifiedOffset 8042, 18 lines modified
0001f690:·2070·6173·7377·6f72·6473·2068·656c·7073···passwords·helps0001f690:·2070·6173·7377·6f72·6473·2068·656c·7073···passwords·helps
0001f6a0:·2065·6e73·7572·6520·7468·6174·2061·2063···ensure·that·a·c0001f6a0:·2065·6e73·7572·6520·7468·6174·2061·2063···ensure·that·a·c
0001f6b0:·6f6d·7072·6f6d·6973·6564·2070·6173·7377··ompromised·passw0001f6b0:·6f6d·7072·6f6d·6973·6564·2070·6173·7377··ompromised·passw
0001f6c0:·6f72·6420·6973·206e·6f74·2072·652d·7573··ord·is·not·re-us0001f6c0:·6f72·6420·6973·206e·6f74·2072·652d·7573··ord·is·not·re-us
0001f6d0:·6564·2062·7920·6120·7573·6572·2e0a·2020··ed·by·a·user..··0001f6d0:·6564·2062·7920·6120·7573·6572·2e0a·2020··ed·by·a·user..··
0001f6e0:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_0001f6e0:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_
0001f6f0:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem0001f6f0:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem
 0001f700:·656d·6265·723d·353c·6272·2f3e·7661·725f··ember=5<br/>var_
 0001f710:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem
0001f700:·656d·6265·725f·636f·6e74·726f·6c5f·666c··ember_control_fl0001f720:·656d·6265·725f·636f·6e74·726f·6c5f·666c··ember_control_fl
0001f710:·6167·3d6f·6c38·3c62·722f·3e76·6172·5f70··ag=ol8<br/>var_p 
0001f720:·6173·7377·6f72·645f·7061·6d5f·7265·6d65··assword_pam_reme 
0001f730:·6d62·6572·3d35·3c2f·7464·3e0a·3c2f·7472··mber=5</td>.</tr0001f730:·6167·3d6f·6c38·3c2f·7464·3e0a·3c2f·7472··ag=ol8</td>.</tr
0001f740:·3e0a·3c74·723e·0a20·203c·7464·3e49·412d··>.<tr>.··<td>IA-0001f740:·3e0a·3c74·723e·0a20·203c·7464·3e49·412d··>.<tr>.··<td>IA-
0001f750:·3528·6329·3c62·722f·3e49·412d·3528·3129··5(c)<br/>IA-5(1)0001f750:·3528·6329·3c62·722f·3e49·412d·3528·3129··5(c)<br/>IA-5(1)
0001f760:·2861·293c·6272·2f3e·434d·2d36·2861·293c··(a)<br/>CM-6(a)<0001f760:·2861·293c·6272·2f3e·434d·2d36·2861·293c··(a)<br/>CM-6(a)<
0001f770:·6272·2f3e·4941·2d35·2834·293c·2f74·643e··br/>IA-5(4)</td>0001f770:·6272·2f3e·4941·2d35·2834·293c·2f74·643e··br/>IA-5(4)</td>
0001f780:·0a20·203c·7464·3e4e·2f41·3c2f·7464·3e0a··.··<td>N/A</td>.0001f780:·0a20·203c·7464·3e4e·2f41·3c2f·7464·3e0a··.··<td>N/A</td>.
0001f790:·2020·3c74·643e·456e·7375·7265·2050·414d····<td>Ensure·PAM0001f790:·2020·3c74·643e·456e·7375·7265·2050·414d····<td>Ensure·PAM
0001f7a0:·2045·6e66·6f72·6365·7320·5061·7373·776f···Enforces·Passwo0001f7a0:·2045·6e66·6f72·6365·7320·5061·7373·776f···Enforces·Passwo
Offset 24025, 17 lines modifiedOffset 24025, 17 lines modified
0005dd80:·6c69·6e67·0a74·696d·652d·6261·7365·6420··ling.time-based·0005dd80:·6c69·6e67·0a74·696d·652d·6261·7365·6420··ling.time-based·
0005dd90:·6c69·6d69·742c·2065·6666·6563·7473·206f··limit,·effects·o0005dd90:·6c69·6d69·742c·2065·6666·6563·7473·206f··limit,·effects·o
0005dda0:·6620·706f·7465·6e74·6961·6c20·6174·7461··f·potential·atta0005dda0:·6620·706f·7465·6e74·6961·6c20·6174·7461··f·potential·atta
0005ddb0:·636b·7320·6167·6169·6e73·740a·656e·6372··cks·against.encr0005ddb0:·636b·7320·6167·6169·6e73·740a·656e·6372··cks·against.encr
0005ddc0:·7970·7469·6f6e·206b·6579·7320·6172·6520··yption·keys·are·0005ddc0:·7970·7469·6f6e·206b·6579·7320·6172·6520··yption·keys·are·
0005ddd0:·6c69·6d69·7465·642e·0a20·203c·2f74·643e··limited..··</td>0005ddd0:·6c69·6d69·7465·642e·0a20·203c·2f74·643e··limited..··</td>
0005dde0:·0a20·203c·7464·3e76·6172·5f72·656b·6579··.··<td>var_rekey0005dde0:·0a20·203c·7464·3e76·6172·5f72·656b·6579··.··<td>var_rekey
0005ddf0:·5f6c·696d·6974·5f74·696d·653d·3168·6f75··_limit_time=1hou0005ddf0:·5f6c·696d·6974·5f73·697a·653d·3147·3c62··_limit_size=1G<b
0005de00:·723c·6272·2f3e·7661·725f·7265·6b65·795f··r<br/>var_rekey_ 
0005de10:·6c69·6d69·745f·7369·7a65·3d31·473c·2f74··limit_size=1G</t0005de00:·722f·3e76·6172·5f72·656b·6579·5f6c·696d··r/>var_rekey_lim
 0005de10:·6974·5f74·696d·653d·3168·6f75·723c·2f74··it_time=1hour</t
0005de20:·643e·0a3c·2f74·723e·0a3c·7472·3e0a·2020··d>.</tr>.<tr>.··0005de20:·643e·0a3c·2f74·723e·0a3c·7472·3e0a·2020··d>.</tr>.<tr>.··
0005de30:·3c74·643e·3c2f·7464·3e0a·2020·3c74·643e··<td></td>.··<td>0005de30:·3c74·643e·3c2f·7464·3e0a·2020·3c74·643e··<td></td>.··<td>
0005de40:·4e2f·413c·2f74·643e·0a20·203c·7464·3e53··N/A</td>.··<td>S0005de40:·4e2f·413c·2f74·643e·0a20·203c·7464·3e53··N/A</td>.··<td>S
0005de50:·5348·2073·6572·7665·7220·7573·6573·2073··SH·server·uses·s0005de50:·5348·2073·6572·7665·7220·7573·6573·2073··SH·server·uses·s
0005de60:·7472·6f6e·6720·656e·7472·6f70·7920·746f··trong·entropy·to0005de60:·7472·6f6e·6720·656e·7472·6f70·7920·746f··trong·entropy·to
0005de70:·2073·6565·643c·2f74·643e·0a20·203c·7464···seed</td>.··<td0005de70:·2073·6565·643c·2f74·643e·0a20·203c·7464···seed</td>.··<td
0005de80:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US0005de80:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US
5.91 KB
html2text {}
    
Offset 1510, 26 lines modifiedOffset 1510, 26 lines modified
1510 ·································pwquality.conf·to·equal·1·to·require·use·of·a·special·is·compromised.·Requiring·a·minimum·number·of·special·characters·makes1510 ·································pwquality.conf·to·equal·1·to·require·use·of·a·special·is·compromised.·Requiring·a·minimum·number·of·special·characters·makes
1511 ·································character·in·passwords.·······························password·guessing·attacks·more·difficult·by·ensuring·a·larger·search1511 ·································character·in·passwords.·······························password·guessing·attacks·more·difficult·by·ensuring·a·larger·search
1512 ·······················································································space.1512 ·······················································································space.
1513 ·································Do·not·allow·users·to·reuse·recent·passwords.·This1513 ·································Do·not·allow·users·to·reuse·recent·passwords.·This
1514 ·································can·be·accomplished·by·using·the·remember·option·for1514 ·································can·be·accomplished·by·using·the·remember·option·for
1515 ·································the·pam_pwhistory·PAM·module.1515 ·································the·pam_pwhistory·PAM·module.
1516 IA-5(f)1516 IA-5(f)
1517 IA-5(1)·N/·Limit·Password·Reuse:·In·the·file·/etc/pam.d/password-auth,·make·sure·the···Preventing·re-use·of·previous·passwords·helps·ensure·that·a·compromised····var_password_pam_remember_control_flag=ol81517 IA-5(1)·N/·Limit·Password·Reuse:·In·the·file·/etc/pam.d/password-auth,·make·sure·the···Preventing·re-use·of·previous·passwords·helps·ensure·that·a·compromised····var_password_pam_remember=5
1518 (e)·····A··password-auth·········parameter·remember·is·present·and·it·has·a·value······password·is·not·re-used·by·a·user.·········································var_password_pam_remember=51518 (e)·····A··password-auth·········parameter·remember·is·present·and·it·has·a·value······password·is·not·re-used·by·a·user.·········································var_password_pam_remember_control_flag=ol8
1519 ·································equal·to·or·greater·than·5.·For·example:1519 ·································equal·to·or·greater·than·5.·For·example:
1520 ·································password·control_flag·pam_pwhistory.so1520 ·································password·control_flag·pam_pwhistory.so
1521 ·································...existing_options...·remember=5·use_authtok1521 ·································...existing_options...·remember=5·use_authtok
1522 ·································control_flag·should·be·one·of·the·next·values:·ol81522 ·································control_flag·should·be·one·of·the·next·values:·ol8
1523 ·································Do·not·allow·users·to·reuse·recent·passwords.·This1523 ·································Do·not·allow·users·to·reuse·recent·passwords.·This
1524 ·································can·be·accomplished·by·using·the·remember·option·for1524 ·································can·be·accomplished·by·using·the·remember·option·for
1525 ·································the·pam_pwhistory·PAM·module.1525 ·································the·pam_pwhistory·PAM·module.
1526 IA-5(f)1526 IA-5(f)
1527 IA-5(1)·N/·Limit·Password·Reuse:·In·the·file·/etc/pam.d/system-auth,·make·sure·the·····Preventing·re-use·of·previous·passwords·helps·ensure·that·a·compromised····var_password_pam_remember_control_flag=ol81527 IA-5(1)·N/·Limit·Password·Reuse:·In·the·file·/etc/pam.d/system-auth,·make·sure·the·····Preventing·re-use·of·previous·passwords·helps·ensure·that·a·compromised····var_password_pam_remember=5
1528 (e)·····A··system-auth···········parameter·remember·is·present·and·it·has·a·value······password·is·not·re-used·by·a·user.·········································var_password_pam_remember=51528 (e)·····A··system-auth···········parameter·remember·is·present·and·it·has·a·value······password·is·not·re-used·by·a·user.·········································var_password_pam_remember_control_flag=ol8
1529 ·································equal·to·or·greater·than·5·For·example:1529 ·································equal·to·or·greater·than·5·For·example:
1530 ·································password·control_flag·pam_pwhistory.so1530 ·································password·control_flag·pam_pwhistory.so
1531 ·································...existing_options...·remember=5·use_authtok1531 ·································...existing_options...·remember=5·use_authtok
1532 ·································control_flag·should·be·one·of·the·next·values:·ol81532 ·································control_flag·should·be·one·of·the·next·values:·ol8
1533 ·································The·pam_pwquality·module's·ucredit=·parameter·········Use·of·a·complex·password·helps·to·increase·the·time·and·resources1533 ·································The·pam_pwquality·module's·ucredit=·parameter·········Use·of·a·complex·password·helps·to·increase·the·time·and·resources
1534 ·································controls·requirements·for·usage·of·uppercase·letters··required·to·compromise·the·password.·Password·complexity,·or·strength,·is1534 ·································controls·requirements·for·usage·of·uppercase·letters··required·to·compromise·the·password.·Password·complexity,·or·strength,·is
1535 IA-5(c)····Ensure·PAM·Enforces···in·a·password.·When·set·to·a·negative·number,·any·····a·measure·of·the·effectiveness·of·a·password·in·resisting·attempts·at1535 IA-5(c)····Ensure·PAM·Enforces···in·a·password.·When·set·to·a·negative·number,·any·····a·measure·of·the·effectiveness·of·a·password·in·resisting·attempts·at
Offset 4230, 16 lines modifiedOffset 4230, 16 lines modified
4230 ········N/·Rounds·in·/etc/·······SHA_CRYPT_MIN_ROUNDS·5000·····························Passwords·that·are·encrypted·with·a·weak·algorithm·are·no·more·protected4230 ········N/·Rounds·in·/etc/·······SHA_CRYPT_MIN_ROUNDS·5000·····························Passwords·that·are·encrypted·with·a·weak·algorithm·are·no·more·protected
4231 ········A··login.defs············SHA_CRYPT_MAX_ROUNDS·5000·····························than·if·they·are·kept·in·plain·text.4231 ········A··login.defs············SHA_CRYPT_MAX_ROUNDS·5000·····························than·if·they·are·kept·in·plain·text.
4232 ·································Notice·that·if·neither·are·set,·they·already·have·the4232 ·································Notice·that·if·neither·are·set,·they·already·have·the
4233 ·································default·value·of·5000.·If·either·is·set,·they·must····Using·more·hashing·rounds·makes·password·cracking·attacks·more·difficult.4233 ·································default·value·of·5000.·If·either·is·set,·they·must····Using·more·hashing·rounds·makes·password·cracking·attacks·more·difficult.
4234 ·································have·the·minimum·value·of·5000.4234 ·································have·the·minimum·value·of·5000.
4235 ·································The·RekeyLimit·parameter·specifies·how·often·the4235 ·································The·RekeyLimit·parameter·specifies·how·often·the
4236 ·································session·key·of·the·is·renegotiated,·both·in·terms·of4236 ·································session·key·of·the·is·renegotiated,·both·in·terms·of
4237 ········N/·Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling·time-·····var_rekey_limit_time=1hour4237 ········N/·Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling·time-·····var_rekey_limit_size=1G
4238 ········A··session·key···········elapsed.··············································based·limit,·effects·of·potential·attacks·against·encryption·keys·are······var_rekey_limit_size=1G4238 ········A··session·key···········elapsed.··············································based·limit,·effects·of·potential·attacks·against·encryption·keys·are······var_rekey_limit_time=1hour
4239 ···········renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limited.4239 ···········renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limited.
4240 ·································following·line·in·/etc/ssh/sshd_config:4240 ·································following·line·in·/etc/ssh/sshd_config:
4241 ·································RekeyLimit·1G·1hour4241 ·································RekeyLimit·1G·1hour
4242 ·································To·set·up·SSH·server·to·use·entropy·from·a·high-······SSH·implementation·in·Oracle·Linux·8·uses·the·openssl·library,·which4242 ·································To·set·up·SSH·server·to·use·entropy·from·a·high-······SSH·implementation·in·Oracle·Linux·8·uses·the·openssl·library,·which
4243 ···········SSH·server·uses·······quality·source,·edit·the·/etc/sysconfig/sshd·file.····doesn't·use·high-entropy·sources·by·default.·Randomness·is·needed·to4243 ···········SSH·server·uses·······quality·source,·edit·the·/etc/sysconfig/sshd·file.····doesn't·use·high-entropy·sources·by·default.·Randomness·is·needed·to
4244 ········N/·strong·entropy·to·····The·SSH_USE_STRONG_RNG·configuration·value·determines·generate·data-encryption·keys,·and·as·plaintext·padding·and·initialization4244 ········N/·strong·entropy·to·····The·SSH_USE_STRONG_RNG·configuration·value·determines·generate·data-encryption·keys,·and·as·plaintext·padding·and·initialization
4245 ········A··seed··················how·many·bytes·of·entropy·to·use,·so·make·sure·that···vectors·in·encryption·algorithms,·and·high-quality·entropy·elliminates·the4245 ········A··seed··················how·many·bytes·of·entropy·to·use,·so·make·sure·that···vectors·in·encryption·algorithms,·and·high-quality·entropy·elliminates·the
6.5 MB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs.html
    
Offset 66, 11804 lines modifiedOffset 66, 11804 lines modified
00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa
00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea
00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<
00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU
00000450:·2d32·2864·293c·6272·2f3e·4155·2d31·3228··-2(d)<br/>AU-12(00000450:·2d32·2864·293c·6272·2f3e·4155·2d31·3228··-2(d)<br/>AU-12(
00000460:·6329·3c62·722f·3e43·4d2d·3628·6129·3c2f··c)<br/>CM-6(a)</00000460:·6329·3c62·722f·3e43·4d2d·3628·6129·3c2f··c)<br/>CM-6(a)</
Diff chunk too large, falling back to line-by-line diff (4906 lines added, 4906 lines removed)
00000470:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re00000470:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re
00000480:·636f·7264·2055·6e73·7563·6365·7373·6675··cord·Unsuccessfu00000480:·636f·7264·2045·7665·6e74·7320·7468·6174··cord·Events·that
00000490:·6c20·5065·726d·6973·7369·6f6e·2043·6861··l·Permission·Cha00000490:·204d·6f64·6966·7920·7468·6520·5379·7374···Modify·the·Syst
000004a0:·6e67·6573·2074·6f20·4669·6c65·7320·2d20··nges·to·Files·-·000004a0:·656d·2773·2044·6973·6372·6574·696f·6e61··em's·Discretiona
000004b0:·6663·686d·6f64·3c2f·7464·3e0a·2020·2020··fchmod</td>.····000004b0:·7279·2041·6363·6573·7320·436f·6e74·726f··ry·Access·Contro
000004c0:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="000004c0:·6c73·202d·2073·6574·7861·7474·723c·2f74··ls·-·setxattr</t
000004d0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········000004d0:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
000004e0:·5468·6520·6175·6469·7420·7379·7374·656d··The·audit·system000004e0:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
000004f0:·2073·686f·756c·6420·636f·6c6c·6563·7420···should·collect·000004f0:·2020·2020·2020·2041·7420·6120·6d69·6e69·········At·a·mini
00000500:·756e·7375·6363·6573·7366·756c·2066·696c··unsuccessful·fil00000500:·6d75·6d2c·2074·6865·2061·7564·6974·2073··mum,·the·audit·s
00000510:·6520·7065·726d·6973·7369·6f6e·2063·6861··e·permission·cha00000510:·7973·7465·6d20·7368·6f75·6c64·2063·6f6c··ystem·should·col
00000520:·6e67·650a·6174·7465·6d70·7473·2066·6f72··nge.attempts·for00000520:·6c65·6374·2066·696c·6520·7065·726d·6973··lect·file·permis
00000530:·2061·6c6c·2075·7365·7273·2061·6e64·2072···all·users·and·r00000530:·7369·6f6e·0a63·6861·6e67·6573·2066·6f72··sion.changes·for
00000540:·6f6f·742e·0a49·6620·7468·6520·3c74·743e··oot..If·the·<tt>00000540:·2061·6c6c·2075·7365·7273·2061·6e64·2072···all·users·and·r
00000550:·6175·6469·7464·3c2f·7474·3e20·6461·656d··auditd</tt>·daem00000550:·6f6f·742e·2049·6620·7468·6520·3c74·743e··oot.·If·the·<tt>
00000560:·6f6e·2069·7320·636f·6e66·6967·7572·6564··on·is·configured00000560:·6175·6469·7464·3c2f·7474·3e20·6461·656d··auditd</tt>·daem
00000570:·0a74·6f20·7573·6520·7468·6520·3c74·743e··.to·use·the·<tt>00000570:·6f6e·2069·7320·636f·6e66·6967·7572·6564··on·is·configured
00000580:·6175·6765·6e72·756c·6573·3c2f·7474·3e20··augenrules</tt>·00000580:·0a74·6f20·7573·6520·7468·6520·3c74·743e··.to·use·the·<tt>
00000590:·7072·6f67·7261·6d20·746f·2072·6561·6420··program·to·read·00000590:·6175·6765·6e72·756c·6573·3c2f·7474·3e20··augenrules</tt>·
000005a0:·6175·6469·7420·7275·6c65·7320·6475·7269··audit·rules·duri000005a0:·7072·6f67·7261·6d20·746f·2072·6561·6420··program·to·read·
000005b0:·6e67·2064·6165·6d6f·6e0a·7374·6172·7475··ng·daemon.startu000005b0:·6175·6469·7420·7275·6c65·7320·6475·7269··audit·rules·duri
000005c0:·7020·2874·6865·2064·6566·6175·6c74·292c··p·(the·default),000005c0:·6e67·2064·6165·6d6f·6e0a·7374·6172·7475··ng·daemon.startu
000005d0:·2061·6464·2074·6865·2066·6f6c·6c6f·7769···add·the·followi000005d0:·7020·2874·6865·2064·6566·6175·6c74·292c··p·(the·default),
000005e0:·6e67·206c·696e·6573·2074·6f20·6120·6669··ng·lines·to·a·fi000005e0:·2061·6464·2074·6865·2066·6f6c·6c6f·7769···add·the·followi
000005f0:·6c65·2077·6974·6820·7375·6666·6978·0a3c··le·with·suffix.<000005f0:·6e67·206c·696e·6520·746f·2061·2066·696c··ng·line·to·a·fil
00000600:·7474·3e2e·7275·6c65·733c·2f74·743e·2069··tt>.rules</tt>·i00000600:·6520·7769·7468·2073·7566·6669·780a·3c74··e·with·suffix.<t
00000610:·6e20·7468·6520·6469·7265·6374·6f72·7920··n·the·directory·00000610:·743e·2e72·756c·6573·3c2f·7474·3e20·696e··t>.rules</tt>·in
00000620:·3c74·743e·2f65·7463·2f61·7564·6974·2f72··<tt>/etc/audit/r00000620:·2074·6865·2064·6972·6563·746f·7279·203c···the·directory·<
00000630:·756c·6573·2e64·3c2f·7474·3e2e·0a49·6620··ules.d</tt>..If·00000630:·7474·3e2f·6574·632f·6175·6469·742f·7275··tt>/etc/audit/ru
00000640:·7468·6520·3c74·743e·6175·6469·7464·3c2f··the·<tt>auditd</00000640:·6c65·732e·643c·2f74·743e·3a0a·3c70·7265··les.d</tt>:.<pre
00000650:·7474·3e20·6461·656d·6f6e·2069·7320·636f··tt>·daemon·is·co00000650:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·
00000660:·6e66·6967·7572·6564·2074·6f20·7573·6520··nfigured·to·use·00000660:·2d46·2061·7263·683d·6233·3220·2d53·2073··-F·arch=b32·-S·s
00000670:·7468·6520·3c74·743e·6175·6469·7463·746c··the·<tt>auditctl00000670:·6574·7861·7474·7220·2d46·2061·7569·6426··etxattr·-F·auid&
00000680:·3c2f·7474·3e0a·7574·696c·6974·7920·746f··</tt>.utility·to00000680:·6774·3b3d·3130·3030·202d·4620·6175·6964··gt;=1000·-F·auid
00000690:·2072·6561·6420·6175·6469·7420·7275·6c65···read·audit·rule00000690:·213d·756e·7365·7420·2d46·206b·6579·3d70··!=unset·-F·key=p
000006a0:·7320·6475·7269·6e67·2064·6165·6d6f·6e20··s·during·daemon·000006a0:·6572·6d5f·6d6f·643c·2f70·7265·3e0a·3c70··erm_mod</pre>.<p
000006b0:·7374·6172·7475·702c·2061·6464·2074·6865··startup,·add·the000006b0:·7265·3e2d·6120·616c·7761·7973·2c65·7869··re>-a·always,exi
000006c0:·2066·6f6c·6c6f·7769·6e67·206c·696e·6573···following·lines000006c0:·7420·2d46·2061·7263·683d·6233·3220·2d53··t·-F·arch=b32·-S
000006d0:·2074·6f0a·3c74·743e·2f65·7463·2f61·7564···to.<tt>/etc/aud000006d0:·2073·6574·7861·7474·7220·2d46·2061·7569···setxattr·-F·aui
000006e0:·6974·2f61·7564·6974·2e72·756c·6573·3c2f··it/audit.rules</000006e0:·643d·3020·2d46·206b·6579·3d70·6572·6d5f··d=0·-F·key=perm_
000006f0:·7474·3e20·6669·6c65·2e0a·3c70·7265·3e2d··tt>·file..<pre>-000006f0:·6d6f·643c·2f70·7265·3e0a·4966·2074·6865··mod</pre>.If·the
00000700:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F00000700:·2073·7973·7465·6d20·6973·2036·3420·6269···system·is·64·bi
00000710:·2061·7263·683d·6233·3220·2d53·2066·6368···arch=b32·-S·fch00000710:·7420·7468·656e·2061·6c73·6f20·6164·6420··t·then·also·add·
00000720:·6d6f·6420·2d46·2065·7869·743d·2d45·4143··mod·-F·exit=-EAC00000720:·7468·6520·666f·6c6c·6f77·696e·6720·6c69··the·following·li
00000730:·4345·5320·2d46·2061·7569·643e·3d31·3030··CES·-F·auid>=10000000730:·6e65·3a0a·3c70·7265·3e2d·6120·616c·7761··ne:.<pre>-a·alwa
00000740:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset00000740:·7973·2c65·7869·7420·2d46·2061·7263·683d··ys,exit·-F·arch=
00000750:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces00000750:·6236·3420·2d53·2073·6574·7861·7474·7220··b64·-S·setxattr·
00000760:·6675·6c2d·7065·726d·2d63·6861·6e67·650a··ful-perm-change.00000760:·2d46·2061·7569·6426·6774·3b3d·3130·3030··-F·auid&gt;=1000
00000770:·2d61·2061·6c77·6179·732c·6578·6974·202d··-a·always,exit·-00000770:·202d·4620·6175·6964·213d·756e·7365·7420···-F·auid!=unset·
00000780:·4620·6172·6368·3d62·3332·202d·5320·6663··F·arch=b32·-S·fc00000780:·2d46·206b·6579·3d70·6572·6d5f·6d6f·643c··-F·key=perm_mod<
00000790:·686d·6f64·202d·4620·6578·6974·3d2d·4550··hmod·-F·exit=-EP00000790:·2f70·7265·3e0a·3c70·7265·3e2d·6120·616c··/pre>.<pre>-a·al
000007a0:·4552·4d20·2d46·2061·7569·643e·3d31·3030··ERM·-F·auid>=100000007a0:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc
000007b0:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset000007b0:·683d·6236·3420·2d53·2073·6574·7861·7474··h=b64·-S·setxatt
000007c0:·202d·4620·6b65·793d·756e·7375·6363·6573···-F·key=unsucces000007c0:·7220·2d46·2061·7569·643d·3020·2d46·206b··r·-F·auid=0·-F·k
000007d0:·6675·6c2d·7065·726d·2d63·6861·6e67·653c··ful-perm-change<000007d0:·6579·3d70·6572·6d5f·6d6f·643c·2f70·7265··ey=perm_mod</pre
000007e0:·2f70·7265·3e0a·4966·2074·6865·2073·7973··/pre>.If·the·sys000007e0:·3e0a·4966·2074·6865·203c·7474·3e61·7564··>.If·the·<tt>aud
000007f0:·7465·6d20·6973·2036·3420·6269·7420·7468··tem·is·64·bit·th000007f0:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·
00000800:·656e·2061·6c73·6f20·6164·6420·7468·6520··en·also·add·the·00000800:·6973·2063·6f6e·6669·6775·7265·6420·746f··is·configured·to
00000810:·666f·6c6c·6f77·696e·6720·6c69·6e65·733a··following·lines:00000810:·2075·7365·2074·6865·203c·7474·3e61·7564···use·the·<tt>aud
00000820:·0a3c·7072·653e·2d61·2061·6c77·6179·732c··.<pre>-a·always,00000820:·6974·6374·6c3c·2f74·743e·0a75·7469·6c69··itctl</tt>.utili
00000830:·6578·6974·202d·4620·6172·6368·3d62·3634··exit·-F·arch=b6400000830:·7479·2074·6f20·7265·6164·2061·7564·6974··ty·to·read·audit
00000840:·202d·5320·6663·686d·6f64·202d·4620·6578···-S·fchmod·-F·ex00000840:·2072·756c·6573·2064·7572·696e·6720·6461···rules·during·da
00000850:·6974·3d2d·4541·4343·4553·202d·4620·6175··it=-EACCES·-F·au00000850:·656d·6f6e·2073·7461·7274·7570·2c20·6164··emon·startup,·ad
00000860:·6964·3e3d·3130·3030·202d·4620·6175·6964··id>=1000·-F·auid00000860:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·
00000870:·213d·756e·7365·7420·2d46·206b·6579·3d75··!=unset·-F·key=u00000870:·6c69·6e65·2074·6f0a·3c74·743e·2f65·7463··line·to.<tt>/etc
00000880:·6e73·7563·6365·7366·756c·2d70·6572·6d2d··nsuccesful-perm-00000880:·2f61·7564·6974·2f61·7564·6974·2e72·756c··/audit/audit.rul
00000890:·6368·616e·6765·0a2d·6120·616c·7761·7973··change.-a·always00000890:·6573·3c2f·7474·3e20·6669·6c65·3a0a·3c70··es</tt>·file:.<p
000008a0:·2c65·7869·7420·2d46·2061·7263·683d·6236··,exit·-F·arch=b6000008a0:·7265·3e2d·6120·616c·7761·7973·2c65·7869··re>-a·always,exi
000008b0:·3420·2d53·2066·6368·6d6f·6420·2d46·2065··4·-S·fchmod·-F·e000008b0:·7420·2d46·2061·7263·683d·6233·3220·2d53··t·-F·arch=b32·-S
000008c0:·7869·743d·2d45·5045·524d·202d·4620·6175··xit=-EPERM·-F·au000008c0:·2073·6574·7861·7474·7220·2d46·2061·7569···setxattr·-F·aui
000008d0:·6964·3e3d·3130·3030·202d·4620·6175·6964··id>=1000·-F·auid000008d0:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au
000008e0:·213d·756e·7365·7420·2d46·206b·6579·3d75··!=unset·-F·key=u000008e0:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
000008f0:·6e73·7563·6365·7366·756c·2d70·6572·6d2d··nsuccesful-perm-000008f0:·3d70·6572·6d5f·6d6f·643c·2f70·7265·3e0a··=perm_mod</pre>.
00000900:·6368·616e·6765·3c2f·7072·653e·0a20·2020··change</pre>.···00000900:·3c70·7265·3e2d·6120·616c·7761·7973·2c65··<pre>-a·always,e
00000910:·2020·203c·2f74·643e·0a20·2020·2020·203c·····</td>.······<00000910:·7869·7420·2d46·2061·7263·683d·6233·3220··xit·-F·arch=b32·
00000920:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-00000920:·2d53·2073·6574·7861·7474·7220·2d46·2061··-S·setxattr·-F·a
00000930:·5553·223e·0a20·2020·2020·2020·2055·6e73··US">.········Uns00000930:·7569·643d·3020·2d46·206b·6579·3d70·6572··uid=0·-F·key=per
00000940:·7563·6365·7373·6675·6c20·6174·7465·6d70··uccessful·attemp00000940:·6d5f·6d6f·643c·2f70·7265·3e0a·4966·2074··m_mod</pre>.If·t
00000950:·7473·2074·6f20·6368·616e·6765·2070·6572··ts·to·change·per00000950:·6865·2073·7973·7465·6d20·6973·2036·3420··he·system·is·64·
00000960:·6d69·7373·696f·6e73·206f·6620·6669·6c65··missions·of·file00000960:·6269·7420·7468·656e·2061·6c73·6f20·6164··bit·then·also·ad
00000970:·7320·636f·756c·6420·6265·2061·6e20·696e··s·could·be·an·in00000970:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·
00000980:·6469·6361·746f·7220·6f66·206d·616c·6963··dicator·of·malic00000980:·6c69·6e65·3a0a·3c70·7265·3e2d·6120·616c··line:.<pre>-a·al
00000990:·696f·7573·2061·6374·6976·6974·7920·6f6e··ious·activity·on00000990:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc
000009a0:·2061·2073·7973·7465·6d2e·2041·7564·6974···a·system.·Audit000009a0:·683d·6236·3420·2d53·2073·6574·7861·7474··h=b64·-S·setxatt
000009b0:·696e·670a·7468·6573·6520·6576·656e·7473··ing.these·events000009b0:·7220·2d46·2061·7569·6426·6774·3b3d·3130··r·-F·auid&gt;=10
000009c0:·2063·6f75·6c64·2073·6572·7665·2061·7320···could·serve·as·000009c0:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
000009d0:·6576·6964·656e·6365·206f·6620·706f·7465··evidence·of·pote000009d0:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo
000009e0:·6e74·6961·6c20·7379·7374·656d·2063·6f6d··ntial·system·com000009e0:·643c·2f70·7265·3e0a·3c70·7265·3e2d·6120··d</pre>.<pre>-a·
000009f0:·7072·6f6d·6973·652e·0a20·2020·2020·203c··promise..······<000009f0:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a
00000a00:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·00000a00:·7263·683d·6236·3420·2d53·2073·6574·7861··rch=b64·-S·setxa
00000a10:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t00000a10:·7474·7220·2d46·2061·7569·643d·3020·2d46··ttr·-F·auid=0·-F
00000a20:·643e·4155·2d32·2864·293c·6272·2f3e·4155··d>AU-2(d)<br/>AU00000a20:·206b·6579·3d70·6572·6d5f·6d6f·643c·2f70···key=perm_mod</p
00000a30:·2d31·3228·6329·3c62·722f·3e41·432d·3628··-12(c)<br/>AC-6(00000a30:·7265·3e0a·2020·2020·2020·3c2f·7464·3e0a··re>.······</td>.
00000a40:·3929·3c62·722f·3e43·4d2d·3628·6129·3c2f··9)<br/>CM-6(a)</00000a40:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la
00000a50:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re00000a50:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····
00000a60:·636f·7264·2041·7474·656d·7074·7320·746f··cord·Attempts·to00000a60:·2020·2020·5468·6520·6368·616e·6769·6e67······The·changing
00000a70:·2041·6c74·6572·204c·6f67·6f6e·2061·6e64···Alter·Logon·and00000a70:·206f·6620·6669·6c65·2070·6572·6d69·7373···of·file·permiss
00000a80:·204c·6f67·6f75·7420·4576·656e·7473·202d···Logout·Events·-00000a80:·696f·6e73·2063·6f75·6c64·2069·6e64·6963··ions·could·indic
00000a90:·2074·616c·6c79·6c6f·673c·2f74·643e·0a20···tallylog</td>.·00000a90:·6174·6520·7468·6174·2061·2075·7365·7220··ate·that·a·user·
00000aa0:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan00000aa0:·6973·2061·7474·656d·7074·696e·6720·746f··is·attempting·to
00000ab0:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····00000ab0:·0a67·6169·6e20·6163·6365·7373·2074·6f20··.gain·access·to·
00000ac0:·2020·2054·6865·2061·7564·6974·2073·7973·····The·audit·sys00000ac0:·696e·666f·726d·6174·696f·6e20·7468·6174··information·that
00000ad0:·7465·6d20·616c·7265·6164·7920·636f·6c6c··tem·already·coll00000ad0:·2077·6f75·6c64·206f·7468·6572·7769·7365···would·otherwise
00000ae0:·6563·7473·206c·6f67·696e·2069·6e66·6f72··ects·login·infor00000ae0:·2062·6520·6469·7361·6c6c·6f77·6564·2e20···be·disallowed.·
00000af0:·6d61·7469·6f6e·2066·6f72·2061·6c6c·2075··mation·for·all·u00000af0:·4175·6469·7469·6e67·2044·4143·206d·6f64··Auditing·DAC·mod
00000b00:·7365·7273·0a61·6e64·2072·6f6f·742e·2049··sers.and·root.·I00000b00:·6966·6963·6174·696f·6e73·0a63·616e·2066··ifications.can·f
00000b10:·6620·7468·6520·3c74·743e·6175·6469·7464··f·the·<tt>auditd00000b10:·6163·696c·6974·6174·6520·7468·6520·6964··acilitate·the·id
00000b20:·3c2f·7474·3e20·6461·656d·6f6e·2069·7320··</tt>·daemon·is·00000b20:·656e·7469·6669·6361·7469·6f6e·206f·6620··entification·of·
00000b30:·636f·6e66·6967·7572·6564·2074·6f20·7573··configured·to·us00000b30:·7061·7474·6572·6e73·206f·6620·6162·7573··patterns·of·abus
00000b40:·6520·7468·650a·3c74·743e·6175·6765·6e72··e·the.<tt>augenr00000b40:·6520·616d·6f6e·6720·626f·7468·2061·7574··e·among·both·aut
00000b50:·756c·6573·3c2f·7474·3e20·7072·6f67·7261··ules</tt>·progra00000b50:·686f·7269·7a65·6420·616e·640a·756e·6175··horized·and.unau
00000b60:·6d20·746f·2072·6561·6420·6175·6469·7420··m·to·read·audit·00000b60:·7468·6f72·697a·6564·2075·7365·7273·2e0a··thorized·users..
00000b70:·7275·6c65·7320·6475·7269·6e67·2064·6165··rules·during·dae00000b70:·2020·2020·2020·3c2f·7464·3e0a·2020·2020········</td>.····
00000b80:·6d6f·6e20·7374·6172·7475·7020·2874·6865··mon·startup·(the00000b80:·3c2f·7472·3e0a·2020·2020·3c74·723e·0a20··</tr>.····<tr>.·
00000b90:·0a64·6566·6175·6c74·292c·2061·6464·2074··.default),·add·t00000b90:·2020·2020·203c·7464·3e41·552d·3228·6429·······<td>AU-2(d)
00000ba0:·6865·2066·6f6c·6c6f·7769·6e67·206c·696e··he·following·lin00000ba0:·3c62·722f·3e41·552d·3132·2863·293c·6272··<br/>AU-12(c)<br
00000bb0:·6573·2074·6f20·6120·6669·6c65·2077·6974··es·to·a·file·wit00000bb0:·2f3e·434d·2d36·2861·293c·2f74·643e·0a20··/>CM-6(a)</td>.·
00000bc0:·6820·7375·6666·6978·203c·7474·3e2e·7275··h·suffix·<tt>.ru00000bc0:·2020·2020·203c·7464·3e45·6e73·7572·6520·······<td>Ensure·
00000bd0:·6c65·733c·2f74·743e·2069·6e20·7468·650a··les</tt>·in·the.00000bd0:·6175·6469·7464·2043·6f6c·6c65·6374·7320··auditd·Collects·
00000be0:·6469·7265·6374·6f72·7920·3c74·743e·2f65··directory·<tt>/e00000be0:·4669·6c65·2044·656c·6574·696f·6e20·4576··File·Deletion·Ev
Max diff block lines reached; 4906651/5584257 bytes (87.87%) of diff not shown.
1.18 MB
html2text {}
Max HTML report size reached
704 KB
./usr/share/doc/ssg-nondebian/table-ol8-pcidssrefs.html
Ordering differences only
    
Offset 95, 14 lines modifiedOffset 95, 50 lines modified
95 attacker·to·monitor·and·record·network·traffic.·These·malicious·APs·can·also95 attacker·to·monitor·and·record·network·traffic.·These·malicious·APs·can·also
96 serve·to·create·a·man-in-the-middle·attack·or·be·used·to·create·a·denial·of96 serve·to·create·a·man-in-the-middle·attack·or·be·used·to·create·a·denial·of
97 service·to·valid·network·resources.97 service·to·valid·network·resources.
98 ······</td>98 ······</td>
99 ····</tr>99 ····</tr>
100 ····<tr>100 ····<tr>
101 ······<td>Req-1.4.1</td>101 ······<td>Req-1.4.1</td>
 102 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
 103 ······<td·xml:lang="en-US">
 104 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
 105 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
 106 ······</td>
 107 ······<td·xml:lang="en-US">
 108 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
 109 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state.
 110 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received,
 111 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
 112 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
 113 enables·the·system·to·continue·servicing·valid·connection·requests.
 114 ······</td>
 115 ····</tr>
 116 ····<tr>
 117 ······<td>Req-1.4.1</td>
 118 ······<td>Set·Default·ip6tables·Policy·for·Incoming·Packets</td>
 119 ······<td·xml:lang="en-US">
 120 ········To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)·for
 121 the·built-in·INPUT·chain·which·processes·incoming·packets,
 122 add·or·correct·the·following·line·in
 123 <tt>/etc/sysconfig/ip6tables</tt>:
 124 <pre>:INPUT·DROP·[0:0]</pre>
 125 If·changes·were·required,·reload·the·ip6tables·rules:
 126 <pre>$·sudo·service·ip6tables·reload</pre>
 127 ······</td>
 128 ······<td·xml:lang="en-US">
 129 ········In·<tt>ip6tables</tt>,·the·default·policy·is·applied·only·after·all
 130 the·applicable·rules·in·the·table·are·examined·for·a·match.·Setting·the
 131 default·policy·to·<tt>DROP</tt>·implements·proper·design·for·a·firewall,·i.e.
 132 any·packets·which·are·not·explicitly·permitted·should·not·be
 133 accepted.
 134 ······</td>
 135 ····</tr>
 136 ····<tr>
 137 ······<td>Req-1.4.1</td>
102 ······<td>Set·configuration·for·loopback·traffic</td>138 ······<td>Set·configuration·for·loopback·traffic</td>
103 ······<td·xml:lang="en-US">139 ······<td·xml:lang="en-US">
104 ········Configure·the·loopback·interface·to·accept·traffic.·140 ········Configure·the·loopback·interface·to·accept·traffic.·
105 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback·141 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback·
106 network.142 network.
107 ······</td>143 ······</td>
108 ······<td·xml:lang="en-US">144 ······<td·xml:lang="en-US">
Offset 140, 47 lines modifiedOffset 176, 33 lines modified
140 ······<td·xml:lang="en-US">176 ······<td·xml:lang="en-US">
141 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering177 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
142 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP178 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
143 masquerading,·etc.179 masquerading,·etc.
144 ······</td>180 ······</td>
145 ····</tr>181 ····</tr>
146 ····<tr>182 ····<tr>
147 ······<td>Req-1.4.1</td>183 ······<td>Req-1.4.2</td>
 184 ······<td>Disable·SCTP·Support</td>
148 ······<td>Set·Default·ip6tables·Policy·for·Incoming·Packets</td> 
149 ······<td·xml:lang="en-US"> 
150 ········To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)·for 
151 the·built-in·INPUT·chain·which·processes·incoming·packets, 
152 add·or·correct·the·following·line·in 
153 <tt>/etc/sysconfig/ip6tables</tt>: 
154 <pre>:INPUT·DROP·[0:0]</pre> 
155 If·changes·were·required,·reload·the·ip6tables·rules: 
156 <pre>$·sudo·service·ip6tables·reload</pre> 
157 ······</td> 
158 ······<td·xml:lang="en-US"> 
159 ········In·<tt>ip6tables</tt>,·the·default·policy·is·applied·only·after·all 
160 the·applicable·rules·in·the·table·are·examined·for·a·match.·Setting·the 
161 default·policy·to·<tt>DROP</tt>·implements·proper·design·for·a·firewall,·i.e. 
162 any·packets·which·are·not·explicitly·permitted·should·not·be 
163 accepted. 
164 ······</td> 
165 ····</tr> 
166 ····<tr> 
167 ······<td>Req-1.4.1</td> 
168 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td> 
169 ······<td·xml:lang="en-US">185 ······<td·xml:lang="en-US">
170 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre> 
171 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>186 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
 187 transport·layer·protocol,·designed·to·support·the·idea·of
 188 message-oriented·communication,·with·several·streams·of·messages
 189 within·one·connection.
  
 190 To·configure·the·system·to·prevent·the·<code>sctp</code>
 191 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/sctp.conf</code>:
 192 <pre>install·sctp·/bin/true</pre>
  
 193 To·configure·the·system·to·prevent·the·<code>sctp</code>·from·being·used,
 194 add·the·following·line·to·file·<code>/etc/modprobe.d/sctp.conf</code>:
 195 <pre>blacklist·sctp</pre>
172 ······</td>196 ······</td>
173 ······<td·xml:lang="en-US">197 ······<td·xml:lang="en-US">
 198 ········Disabling·SCTP·protects
 199 the·system·against·exploitation·of·any·flaws·in·its·implementation.
174 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a 
175 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state. 
176 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received, 
177 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood 
178 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and 
179 enables·the·system·to·continue·servicing·valid·connection·requests. 
180 ······</td>200 ······</td>
181 ····</tr>201 ····</tr>
182 ····<tr>202 ····<tr>
183 ······<td>Req-1.4.2</td>203 ······<td>Req-1.4.2</td>
184 ······<td>Disable·DCCP·Support</td>204 ······<td>Disable·DCCP·Support</td>
185 ······<td·xml:lang="en-US">205 ······<td·xml:lang="en-US">
186 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a206 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
Offset 197, 33 lines modifiedOffset 219, 44 lines modified
197 ······</td>219 ······</td>
198 ······<td·xml:lang="en-US">220 ······<td·xml:lang="en-US">
199 ········Disabling·DCCP·protects221 ········Disabling·DCCP·protects
200 the·system·against·exploitation·of·any·flaws·in·its·implementation.222 the·system·against·exploitation·of·any·flaws·in·its·implementation.
201 ······</td>223 ······</td>
202 ····</tr>224 ····</tr>
203 ····<tr>225 ····<tr>
204 ······<td>Req-1.4.2</td>226 ······<td>Req-1.4.3</td>
205 ······<td>Disable·SCTP·Support</td>227 ······<td>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</td>
206 ······<td·xml:lang="en-US">228 ······<td·xml:lang="en-US">
 229 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_echo_ignore_broadcasts</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_echo_ignore_broadcasts=1</pre>
 230 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_echo_ignore_broadcasts·=·1</pre>
207 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a 
208 transport·layer·protocol,·designed·to·support·the·idea·of 
Max diff block lines reached; 272696/279454 bytes (97.58%) of diff not shown.
431 KB
html2text {}
    
Offset 56, 14 lines modifiedOffset 56, 55 lines modified
56 ····················································································also·serve·to56 ····················································································also·serve·to
57 ····················································································create·a·man-in-57 ····················································································create·a·man-in-
58 ····················································································the-middle·attack58 ····················································································the-middle·attack
59 ····················································································or·be·used·to59 ····················································································or·be·used·to
60 ····················································································create·a·denial·of60 ····················································································create·a·denial·of
61 ····················································································service·to·valid61 ····················································································service·to·valid
62 ····················································································network·resources.62 ····················································································network·resources.
 63 ····················································································A·TCP·SYN·flood
 64 ····················································································attack·can·cause·a
 65 ····················································································denial·of·service
 66 ····················································································by·filling·a
 67 ····················································································system's·TCP
 68 ····················································································connection·table
 69 ····················································································with·connections·in
 70 ····················································································the·SYN_RCVD·state.
 71 ····················································································Syncookies·can·be
 72 ·····························To·set·the·runtime·status·of·the·······················used·to·track·a
 73 ·····························net.ipv4.tcp_syncookies·kernel·parameter,·run·the······connection·when·a
 74 ·········Enable·Kernel·······following·command:·····································subsequent·ACK·is
 75 Req-·····Parameter·to·Use····$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1·············received,·verifying
 76 1.4.1····TCP·Syncookies·on···To·make·sure·that·the·setting·is·persistent,·add·the···the·initiator·is
 77 ·········Network·Interfaces··following·line·to·a·file·in·the·directory·/etc/········attempting·a·valid
 78 ·····························sysctl.d:··············································connection·and·is
 79 ·····························net.ipv4.tcp_syncookies·=·1····························not·a·flood·source.
 80 ····················································································This·feature·is
 81 ····················································································activated·when·a
 82 ····················································································flood·condition·is
 83 ····················································································detected,·and
 84 ····················································································enables·the·system
 85 ····················································································to·continue
 86 ····················································································servicing·valid
 87 ····················································································connection
 88 ····················································································requests.
 89 ····················································································In·ip6tables,·the
 90 ····················································································default·policy·is
 91 ····················································································applied·only·after
 92 ····················································································all·the·applicable
 93 ·····························To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)··rules·in·the·table
 94 ·········Set·Default·········for·the·built-in·INPUT·chain·which·processes·incoming··are·examined·for·a
 95 Req-·····ip6tables·Policy····packets,·add·or·correct·the·following·line·in·/etc/····match.·Setting·the
 96 1.4.1····for·Incoming········sysconfig/ip6tables:···································default·policy·to
 97 ·········Packets·············:INPUT·DROP·[0:0]······································DROP·implements
 98 ·····························If·changes·were·required,·reload·the·ip6tables·rules:··proper·design·for·a
 99 ·····························$·sudo·service·ip6tables·reload························firewall,·i.e.·any
 100 ····················································································packets·which·are
 101 ····················································································not·explicitly
 102 ····················································································permitted·should
 103 ····················································································not·be·accepted.
63 ····················································································Loopback·traffic·is104 ····················································································Loopback·traffic·is
64 ····················································································generated·between105 ····················································································generated·between
65 ····················································································processes·on106 ····················································································processes·on
66 ····················································································machine·and·is107 ····················································································machine·and·is
67 ····················································································typically·critical108 ····················································································typically·critical
68 ····················································································to·operation·of·the109 ····················································································to·operation·of·the
69 ····················································································system.·The110 ····················································································system.·The
Offset 99, 78 lines modifiedOffset 140, 84 lines modified
99 ····················································································network·packet140 ····················································································network·packet
100 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.141 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.
101 1.4.1····Package·············following·command:·····································iptables·allows142 1.4.1····Package·············following·command:·····································iptables·allows
102 ·····························$·sudo·yum·install·iptables····························system·operators·to143 ·····························$·sudo·yum·install·iptables····························system·operators·to
103 ····················································································set·up·firewalls144 ····················································································set·up·firewalls
104 ····················································································and·IP145 ····················································································and·IP
105 ····················································································masquerading,·etc.146 ····················································································masquerading,·etc.
106 ····················································································In·ip6tables,·the 
107 ····················································································default·policy·is 
108 ····················································································applied·only·after 
109 ····················································································all·the·applicable 
110 ·····························To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)··rules·in·the·table 
111 ·········Set·Default·········for·the·built-in·INPUT·chain·which·processes·incoming··are·examined·for·a 
112 Req-·····ip6tables·Policy····packets,·add·or·correct·the·following·line·in·/etc/····match.·Setting·the 
113 1.4.1····for·Incoming········sysconfig/ip6tables:···································default·policy·to 
114 ·········Packets·············:INPUT·DROP·[0:0]······································DROP·implements 
115 ·····························If·changes·were·required,·reload·the·ip6tables·rules:··proper·design·for·a 
116 ·····························$·sudo·service·ip6tables·reload························firewall,·i.e.·any 
117 ····················································································packets·which·are 
118 ····················································································not·explicitly 
119 ····················································································permitted·should 
120 ····················································································not·be·accepted. 
121 ····················································································A·TCP·SYN·flood 
122 ····················································································attack·can·cause·a 
123 ····················································································denial·of·service 
124 ····················································································by·filling·a 
125 ····················································································system's·TCP 
126 ····················································································connection·table 
127 ····················································································with·connections·in 
128 ····················································································the·SYN_RCVD·state. 
129 ····················································································Syncookies·can·be 
130 ·····························To·set·the·runtime·status·of·the·······················used·to·track·a 
131 ·····························net.ipv4.tcp_syncookies·kernel·parameter,·run·the······connection·when·a 
132 ·········Enable·Kernel·······following·command:·····································subsequent·ACK·is 
133 Req-·····Parameter·to·Use····$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1·············received,·verifying 
134 1.4.1····TCP·Syncookies·on···To·make·sure·that·the·setting·is·persistent,·add·the···the·initiator·is 
135 ·········Network·Interfaces··following·line·to·a·file·in·the·directory·/etc/········attempting·a·valid 
136 ·····························sysctl.d:··············································connection·and·is 
137 ·····························net.ipv4.tcp_syncookies·=·1····························not·a·flood·source. 
138 ····················································································This·feature·is 
139 ····················································································activated·when·a 
140 ····················································································flood·condition·is 
141 ····················································································detected,·and 
142 ····················································································enables·the·system 
143 ····················································································to·continue 
144 ····················································································servicing·valid 
145 ····················································································connection 
146 ····················································································requests. 
147 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
148 ·····························relatively·new·transport·layer·protocol,·designed·to 
149 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP 
150 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system 
151 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against 
152 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any 
153 ·····························install·dccp·/bin/true·································flaws·in·its 
154 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation. 
155 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/ 
156 ·····························dccp.conf: 
157 ·····························blacklist·dccp 
158 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a147 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
159 ·····························transport·layer·protocol,·designed·to·support·the·idea148 ·····························transport·layer·protocol,·designed·to·support·the·idea
160 ·····························of·message-oriented·communication,·with·several149 ·····························of·message-oriented·communication,·with·several
161 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP150 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP
162 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system151 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system
163 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against152 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against
164 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any153 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any
165 ·····························install·sctp·/bin/true·································flaws·in·its154 ·····························install·sctp·/bin/true·································flaws·in·its
166 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.155 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.
167 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/156 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
168 ·····························sctp.conf:157 ·····························sctp.conf:
169 ·····························blacklist·sctp158 ·····························blacklist·sctp
Max diff block lines reached; 422921/441214 bytes (95.85%) of diff not shown.
6.01 MB
./usr/share/doc/ssg-nondebian/table-rhcos4-nistrefs.html
    
Offset 68, 11108 lines modifiedOffset 68, 11108 lines modified
00000430:·6e3c·2f74·683e·0a20·2020·203c·7468·3e52··n</th>.····<th>R00000430:·6e3c·2f74·683e·0a20·2020·203c·7468·3e52··n</th>.····<th>R
00000440:·6174·696f·6e61·6c65·3c2f·7468·3e0a·2020··ationale</th>.··00000440:·6174·696f·6e61·6c65·3c2f·7468·3e0a·2020··ationale</th>.··
00000450:·3c2f·7468·6561·643e·0a20·203c·7462·6f64··</thead>.··<tbod00000450:·3c2f·7468·6561·643e·0a20·203c·7462·6f64··</thead>.··<tbod
00000460:·793e·0a20·203c·7472·3e0a·2020·2020·2020··y>.··<tr>.······00000460:·793e·0a20·203c·7472·3e0a·2020·2020·2020··y>.··<tr>.······
00000470:·3c74·643e·4155·2d32·2864·293c·6272·2f3e··<td>AU-2(d)<br/>00000470:·3c74·643e·4155·2d32·2864·293c·6272·2f3e··<td>AU-2(d)<br/>
00000480:·4155·2d31·3228·6329·3c62·722f·3e43·4d2d··AU-12(c)<br/>CM-00000480:·4155·2d31·3228·6329·3c62·722f·3e43·4d2d··AU-12(c)<br/>CM-
Diff chunk too large, falling back to line-by-line diff (1601 lines added, 1601 lines removed)
00000490:·3628·6129·3c2f·7464·3e0a·2020·2020·2020··6(a)</td>.······00000490:·3628·6129·3c2f·7464·3e0a·2020·2020·2020··6(a)</td>.······
000004a0:·3c74·643e·5265·636f·7264·2055·6e73·7563··<td>Record·Unsuc000004a0:·3c74·643e·5265·636f·7264·2045·7665·6e74··<td>Record·Event
000004b0:·6365·7373·6675·6c20·5065·726d·6973·7369··cessful·Permissi000004b0:·7320·7468·6174·204d·6f64·6966·7920·7468··s·that·Modify·th
000004c0:·6f6e·2043·6861·6e67·6573·2074·6f20·4669··on·Changes·to·Fi000004c0:·6520·5379·7374·656d·2773·2044·6973·6372··e·System's·Discr
000004d0:·6c65·7320·2d20·6663·686d·6f64·3c2f·7464··les·-·fchmod</td000004d0:·6574·696f·6e61·7279·2041·6363·6573·7320··etionary·Access·
000004e0:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:000004e0:·436f·6e74·726f·6c73·202d·2073·6574·7861··Controls·-·setxa
000004f0:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··000004f0:·7474·723c·2f74·643e·0a20·2020·2020·203c··ttr</td>.······<
00000500:·2020·2020·2020·5468·6520·6175·6469·7420········The·audit·00000500:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-
00000510:·7379·7374·656d·2073·686f·756c·6420·636f··system·should·co00000510:·5553·223e·0a20·2020·2020·2020·2041·7420··US">.········At·
00000520:·6c6c·6563·7420·756e·7375·6363·6573·7366··llect·unsuccessf00000520:·6120·6d69·6e69·6d75·6d2c·2074·6865·2061··a·minimum,·the·a
00000530:·756c·2066·696c·6520·7065·726d·6973·7369··ul·file·permissi00000530:·7564·6974·2073·7973·7465·6d20·7368·6f75··udit·system·shou
00000540:·6f6e·2063·6861·6e67·650a·6174·7465·6d70··on·change.attemp00000540:·6c64·2063·6f6c·6c65·6374·2066·696c·6520··ld·collect·file·
00000550:·7473·2066·6f72·2061·6c6c·2075·7365·7273··ts·for·all·users00000550:·7065·726d·6973·7369·6f6e·0a63·6861·6e67··permission.chang
00000560:·2061·6e64·2072·6f6f·742e·0a49·6620·7468···and·root..If·th00000560:·6573·2066·6f72·2061·6c6c·2075·7365·7273··es·for·all·users
00000570:·6520·3c74·743e·6175·6469·7464·3c2f·7474··e·<tt>auditd</tt00000570:·2061·6e64·2072·6f6f·742e·2049·6620·7468···and·root.·If·th
00000580:·3e20·6461·656d·6f6e·2069·7320·636f·6e66··>·daemon·is·conf00000580:·6520·3c74·743e·6175·6469·7464·3c2f·7474··e·<tt>auditd</tt
00000590:·6967·7572·6564·0a74·6f20·7573·6520·7468··igured.to·use·th00000590:·3e20·6461·656d·6f6e·2069·7320·636f·6e66··>·daemon·is·conf
000005a0:·6520·3c74·743e·6175·6765·6e72·756c·6573··e·<tt>augenrules000005a0:·6967·7572·6564·0a74·6f20·7573·6520·7468··igured.to·use·th
000005b0:·3c2f·7474·3e20·7072·6f67·7261·6d20·746f··</tt>·program·to000005b0:·6520·3c74·743e·6175·6765·6e72·756c·6573··e·<tt>augenrules
000005c0:·2072·6561·6420·6175·6469·7420·7275·6c65···read·audit·rule000005c0:·3c2f·7474·3e20·7072·6f67·7261·6d20·746f··</tt>·program·to
000005d0:·7320·6475·7269·6e67·2064·6165·6d6f·6e0a··s·during·daemon.000005d0:·2072·6561·6420·6175·6469·7420·7275·6c65···read·audit·rule
000005e0:·7374·6172·7475·7020·2874·6865·2064·6566··startup·(the·def000005e0:·7320·6475·7269·6e67·2064·6165·6d6f·6e0a··s·during·daemon.
000005f0:·6175·6c74·292c·2061·6464·2074·6865·2066··ault),·add·the·f000005f0:·7374·6172·7475·7020·2874·6865·2064·6566··startup·(the·def
00000600:·6f6c·6c6f·7769·6e67·206c·696e·6573·2074··ollowing·lines·t00000600:·6175·6c74·292c·2061·6464·2074·6865·2066··ault),·add·the·f
00000610:·6f20·6120·6669·6c65·2077·6974·6820·7375··o·a·file·with·su00000610:·6f6c·6c6f·7769·6e67·206c·696e·6520·746f··ollowing·line·to
00000620:·6666·6978·0a3c·7474·3e2e·7275·6c65·733c··ffix.<tt>.rules<00000620:·2061·2066·696c·6520·7769·7468·2073·7566···a·file·with·suf
00000630:·2f74·743e·2069·6e20·7468·6520·6469·7265··/tt>·in·the·dire00000630:·6669·780a·3c74·743e·2e72·756c·6573·3c2f··fix.<tt>.rules</
00000640:·6374·6f72·7920·3c74·743e·2f65·7463·2f61··ctory·<tt>/etc/a00000640:·7474·3e20·696e·2074·6865·2064·6972·6563··tt>·in·the·direc
00000650:·7564·6974·2f72·756c·6573·2e64·3c2f·7474··udit/rules.d</tt00000650:·746f·7279·203c·7474·3e2f·6574·632f·6175··tory·<tt>/etc/au
00000660:·3e2e·0a49·6620·7468·6520·3c74·743e·6175··>..If·the·<tt>au00000660:·6469·742f·7275·6c65·732e·643c·2f74·743e··dit/rules.d</tt>
00000670:·6469·7464·3c2f·7474·3e20·6461·656d·6f6e··ditd</tt>·daemon00000670:·3a0a·3c70·7265·3e2d·6120·616c·7761·7973··:.<pre>-a·always
00000680:·2069·7320·636f·6e66·6967·7572·6564·2074···is·configured·t00000680:·2c65·7869·7420·2d46·2061·7263·683d·6233··,exit·-F·arch=b3
00000690:·6f20·7573·6520·7468·6520·3c74·743e·6175··o·use·the·<tt>au00000690:·3220·2d53·2073·6574·7861·7474·7220·2d46··2·-S·setxattr·-F
000006a0:·6469·7463·746c·3c2f·7474·3e0a·7574·696c··ditctl</tt>.util000006a0:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-
000006b0:·6974·7920·746f·2072·6561·6420·6175·6469··ity·to·read·audi000006b0:·4620·6175·6964·213d·756e·7365·7420·2d46··F·auid!=unset·-F
000006c0:·7420·7275·6c65·7320·6475·7269·6e67·2064··t·rules·during·d000006c0:·206b·6579·3d70·6572·6d5f·6d6f·643c·2f70···key=perm_mod</p
000006d0:·6165·6d6f·6e20·7374·6172·7475·702c·2061··aemon·startup,·a000006d0:·7265·3e0a·4966·2074·6865·2073·7973·7465··re>.If·the·syste
000006e0:·6464·2074·6865·2066·6f6c·6c6f·7769·6e67··dd·the·following000006e0:·6d20·6973·2036·3420·6269·7420·7468·656e··m·is·64·bit·then
000006f0:·206c·696e·6573·2074·6f0a·3c74·743e·2f65···lines·to.<tt>/e000006f0:·2061·6c73·6f20·6164·6420·7468·6520·666f···also·add·the·fo
00000700:·7463·2f61·7564·6974·2f61·7564·6974·2e72··tc/audit/audit.r00000700:·6c6c·6f77·696e·6720·6c69·6e65·3a0a·3c70··llowing·line:.<p
00000710:·756c·6573·3c2f·7474·3e20·6669·6c65·2e0a··ules</tt>·file..00000710:·7265·3e2d·6120·616c·7761·7973·2c65·7869··re>-a·always,exi
00000720:·3c70·7265·3e2d·6120·616c·7761·7973·2c65··<pre>-a·always,e00000720:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S
00000730:·7869·7420·2d46·2061·7263·683d·6233·3220··xit·-F·arch=b32·00000730:·2073·6574·7861·7474·7220·2d46·2061·7569···setxattr·-F·aui
00000740:·2d53·2066·6368·6d6f·6420·2d46·2065·7869··-S·fchmod·-F·exi00000740:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au
00000750:·743d·2d45·4143·4345·5320·2d46·2061·7569··t=-EACCES·-F·aui00000750:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
00000760:·643e·3d31·3030·3020·2d46·2061·7569·6421··d>=1000·-F·auid!00000760:·3d70·6572·6d5f·6d6f·643c·2f70·7265·3e0a··=perm_mod</pre>.
00000770:·3d75·6e73·6574·202d·4620·6b65·793d·756e··=unset·-F·key=un00000770:·4966·2074·6865·203c·7474·3e61·7564·6974··If·the·<tt>audit
00000780:·7375·6363·6573·6675·6c2d·7065·726d·2d63··succesful-perm-c00000780:·643c·2f74·743e·2064·6165·6d6f·6e20·6973··d</tt>·daemon·is
00000790:·6861·6e67·650a·2d61·2061·6c77·6179·732c··hange.-a·always,00000790:·2063·6f6e·6669·6775·7265·6420·746f·2075···configured·to·u
000007a0:·6578·6974·202d·4620·6172·6368·3d62·3332··exit·-F·arch=b32000007a0:·7365·2074·6865·203c·7474·3e61·7564·6974··se·the·<tt>audit
000007b0:·202d·5320·6663·686d·6f64·202d·4620·6578···-S·fchmod·-F·ex000007b0:·6374·6c3c·2f74·743e·0a75·7469·6c69·7479··ctl</tt>.utility
000007c0:·6974·3d2d·4550·4552·4d20·2d46·2061·7569··it=-EPERM·-F·aui000007c0:·2074·6f20·7265·6164·2061·7564·6974·2072···to·read·audit·r
000007d0:·643e·3d31·3030·3020·2d46·2061·7569·6421··d>=1000·-F·auid!000007d0:·756c·6573·2064·7572·696e·6720·6461·656d··ules·during·daem
000007e0:·3d75·6e73·6574·202d·4620·6b65·793d·756e··=unset·-F·key=un000007e0:·6f6e·2073·7461·7274·7570·2c20·6164·6420··on·startup,·add·
000007f0:·7375·6363·6573·6675·6c2d·7065·726d·2d63··succesful-perm-c000007f0:·7468·6520·666f·6c6c·6f77·696e·6720·6c69··the·following·li
00000800:·6861·6e67·653c·2f70·7265·3e0a·4966·2074··hange</pre>.If·t00000800:·6e65·2074·6f0a·3c74·743e·2f65·7463·2f61··ne·to.<tt>/etc/a
00000810:·6865·2073·7973·7465·6d20·6973·2036·3420··he·system·is·64·00000810:·7564·6974·2f61·7564·6974·2e72·756c·6573··udit/audit.rules
00000820:·6269·7420·7468·656e·2061·6c73·6f20·6164··bit·then·also·ad00000820:·3c2f·7474·3e20·6669·6c65·3a0a·3c70·7265··</tt>·file:.<pre
00000830:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·00000830:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·
00000840:·6c69·6e65·733a·0a3c·7072·653e·2d61·2061··lines:.<pre>-a·a00000840:·2d46·2061·7263·683d·6233·3220·2d53·2073··-F·arch=b32·-S·s
00000850:·6c77·6179·732c·6578·6974·202d·4620·6172··lways,exit·-F·ar00000850:·6574·7861·7474·7220·2d46·2061·7569·6426··etxattr·-F·auid&
00000860:·6368·3d62·3634·202d·5320·6663·686d·6f64··ch=b64·-S·fchmod00000860:·6774·3b3d·3130·3030·202d·4620·6175·6964··gt;=1000·-F·auid
00000870:·202d·4620·6578·6974·3d2d·4541·4343·4553···-F·exit=-EACCES00000870:·213d·756e·7365·7420·2d46·206b·6579·3d70··!=unset·-F·key=p
00000880:·202d·4620·6175·6964·3e3d·3130·3030·202d···-F·auid>=1000·-00000880:·6572·6d5f·6d6f·643c·2f70·7265·3e0a·4966··erm_mod</pre>.If
00000890:·4620·6175·6964·213d·756e·7365·7420·2d46··F·auid!=unset·-F00000890:·2074·6865·2073·7973·7465·6d20·6973·2036···the·system·is·6
000008a0:·206b·6579·3d75·6e73·7563·6365·7366·756c···key=unsuccesful000008a0:·3420·6269·7420·7468·656e·2061·6c73·6f20··4·bit·then·also·
000008b0:·2d70·6572·6d2d·6368·616e·6765·0a2d·6120··-perm-change.-a·000008b0:·6164·6420·7468·6520·666f·6c6c·6f77·696e··add·the·followin
000008c0:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a000008c0:·6720·6c69·6e65·3a0a·3c70·7265·3e2d·6120··g·line:.<pre>-a·
000008d0:·7263·683d·6236·3420·2d53·2066·6368·6d6f··rch=b64·-S·fchmo000008d0:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a
000008e0:·6420·2d46·2065·7869·743d·2d45·5045·524d··d·-F·exit=-EPERM000008e0:·7263·683d·6236·3420·2d53·2073·6574·7861··rch=b64·-S·setxa
000008f0:·202d·4620·6175·6964·3e3d·3130·3030·202d···-F·auid>=1000·-000008f0:·7474·7220·2d46·2061·7569·6426·6774·3b3d··ttr·-F·auid&gt;=
00000900:·4620·6175·6964·213d·756e·7365·7420·2d46··F·auid!=unset·-F00000900:·3130·3030·202d·4620·6175·6964·213d·756e··1000·-F·auid!=un
00000910:·206b·6579·3d75·6e73·7563·6365·7366·756c···key=unsuccesful00000910:·7365·7420·2d46·206b·6579·3d70·6572·6d5f··set·-F·key=perm_
00000920:·2d70·6572·6d2d·6368·616e·6765·3c2f·7072··-perm-change</pr00000920:·6d6f·643c·2f70·7265·3e0a·2020·2020·2020··mod</pre>.······
00000930:·653e·0a20·2020·2020·203c·2f74·643e·0a20··e>.······</td>.·00000930:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000940:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan00000940:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
00000950:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····00000950:·3e0a·2020·2020·2020·2020·5468·6520·6368··>.········The·ch
00000960:·2020·2055·6e73·7563·6365·7373·6675·6c20·····Unsuccessful·00000960:·616e·6769·6e67·206f·6620·6669·6c65·2070··anging·of·file·p
00000970:·6174·7465·6d70·7473·2074·6f20·6368·616e··attempts·to·chan00000970:·6572·6d69·7373·696f·6e73·2063·6f75·6c64··ermissions·could
00000980:·6765·2070·6572·6d69·7373·696f·6e73·206f··ge·permissions·o00000980:·2069·6e64·6963·6174·6520·7468·6174·2061···indicate·that·a
00000990:·6620·6669·6c65·7320·636f·756c·6420·6265··f·files·could·be00000990:·2075·7365·7220·6973·2061·7474·656d·7074···user·is·attempt
000009a0:·2061·6e20·696e·6469·6361·746f·7220·6f66···an·indicator·of000009a0:·696e·6720·746f·0a67·6169·6e20·6163·6365··ing·to.gain·acce
000009b0:·206d·616c·6963·696f·7573·2061·6374·6976···malicious·activ000009b0:·7373·2074·6f20·696e·666f·726d·6174·696f··ss·to·informatio
000009c0:·6974·7920·6f6e·2061·2073·7973·7465·6d2e··ity·on·a·system.000009c0:·6e20·7468·6174·2077·6f75·6c64·206f·7468··n·that·would·oth
000009d0:·2041·7564·6974·696e·670a·7468·6573·6520···Auditing.these·000009d0:·6572·7769·7365·2062·6520·6469·7361·6c6c··erwise·be·disall
000009e0:·6576·656e·7473·2063·6f75·6c64·2073·6572··events·could·ser000009e0:·6f77·6564·2e20·4175·6469·7469·6e67·2044··owed.·Auditing·D
000009f0:·7665·2061·7320·6576·6964·656e·6365·206f··ve·as·evidence·o000009f0:·4143·206d·6f64·6966·6963·6174·696f·6e73··AC·modifications
00000a00:·6620·706f·7465·6e74·6961·6c20·7379·7374··f·potential·syst00000a00:·0a63·616e·2066·6163·696c·6974·6174·6520··.can·facilitate·
00000a10:·656d·2063·6f6d·7072·6f6d·6973·652e·0a20··em·compromise..·00000a10:·7468·6520·6964·656e·7469·6669·6361·7469··the·identificati
00000a20:·2020·2020·203c·2f74·643e·0a20·2020·203c·······</td>.····<00000a20:·6f6e·206f·6620·7061·7474·6572·6e73·206f··on·of·patterns·o
00000a30:·2f74·723e·0a20·2020·203c·7472·3e0a·2020··/tr>.····<tr>.··00000a30:·6620·6162·7573·6520·616d·6f6e·6720·626f··f·abuse·among·bo
00000a40:·2020·2020·3c74·643e·4155·2d32·2864·293c······<td>AU-2(d)<00000a40:·7468·2061·7574·686f·7269·7a65·6420·616e··th·authorized·an
00000a50:·6272·2f3e·4155·2d31·3228·6329·3c62·722f··br/>AU-12(c)<br/00000a50:·640a·756e·6175·7468·6f72·697a·6564·2075··d.unauthorized·u
00000a60:·3e41·432d·3628·3929·3c62·722f·3e43·4d2d··>AC-6(9)<br/>CM-00000a60:·7365·7273·2e0a·2020·2020·2020·3c2f·7464··sers..······</td
00000a70:·3628·6129·3c2f·7464·3e0a·2020·2020·2020··6(a)</td>.······00000a70:·3e0a·2020·2020·3c2f·7472·3e0a·2020·2020··>.····</tr>.····
00000a80:·3c74·643e·5265·636f·7264·2041·7474·656d··<td>Record·Attem00000a80:·3c74·723e·0a20·2020·2020·203c·7464·3e41··<tr>.······<td>A
00000a90:·7074·7320·746f·2041·6c74·6572·204c·6f67··pts·to·Alter·Log00000a90:·552d·3228·6429·3c62·722f·3e41·552d·3132··U-2(d)<br/>AU-12
00000aa0:·6f6e·2061·6e64·204c·6f67·6f75·7420·4576··on·and·Logout·Ev00000aa0:·2863·293c·6272·2f3e·434d·2d36·2861·293c··(c)<br/>CM-6(a)<
00000ab0:·656e·7473·202d·2074·616c·6c79·6c6f·673c··ents·-·tallylog<00000ab0:·2f74·643e·0a20·2020·2020·203c·7464·3e45··/td>.······<td>E
00000ac0:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x00000ac0:·6e73·7572·6520·6175·6469·7464·2043·6f6c··nsure·auditd·Col
00000ad0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">00000ad0:·6c65·6374·7320·4669·6c65·2044·656c·6574··lects·File·Delet
00000ae0:·0a20·2020·2020·2020·2054·6865·2061·7564··.········The·aud00000ae0:·696f·6e20·4576·656e·7473·2062·7920·5573··ion·Events·by·Us
00000af0:·6974·2073·7973·7465·6d20·616c·7265·6164··it·system·alread00000af0:·6572·202d·2075·6e6c·696e·6b3c·2f74·643e··er·-·unlink</td>
00000b00:·7920·636f·6c6c·6563·7473·206c·6f67·696e··y·collects·login00000b00:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l
00000b10:·2069·6e66·6f72·6d61·7469·6f6e·2066·6f72···information·for00000b10:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···
00000b20:·2061·6c6c·2075·7365·7273·0a61·6e64·2072···all·users.and·r00000b20:·2020·2020·2041·7420·6120·6d69·6e69·6d75·······At·a·minimu
00000b30:·6f6f·742e·2049·6620·7468·6520·3c74·743e··oot.·If·the·<tt>00000b30:·6d2c·2074·6865·2061·7564·6974·2073·7973··m,·the·audit·sys
00000b40:·6175·6469·7464·3c2f·7474·3e20·6461·656d··auditd</tt>·daem00000b40:·7465·6d20·7368·6f75·6c64·2063·6f6c·6c65··tem·should·colle
00000b50:·6f6e·2069·7320·636f·6e66·6967·7572·6564··on·is·configured00000b50:·6374·2066·696c·6520·6465·6c65·7469·6f6e··ct·file·deletion
00000b60:·2074·6f20·7573·6520·7468·650a·3c74·743e···to·use·the.<tt>00000b60:·2065·7665·6e74·730a·666f·7220·616c·6c20···events.for·all·
00000b70:·6175·6765·6e72·756c·6573·3c2f·7474·3e20··augenrules</tt>·00000b70:·7573·6572·7320·616e·6420·726f·6f74·2e20··users·and·root.·
00000b80:·7072·6f67·7261·6d20·746f·2072·6561·6420··program·to·read·00000b80:·4966·2074·6865·203c·7474·3e61·7564·6974··If·the·<tt>audit
00000b90:·6175·6469·7420·7275·6c65·7320·6475·7269··audit·rules·duri00000b90:·643c·2f74·743e·2064·6165·6d6f·6e20·6973··d</tt>·daemon·is
00000ba0:·6e67·2064·6165·6d6f·6e20·7374·6172·7475··ng·daemon·startu00000ba0:·2063·6f6e·6669·6775·7265·6420·746f·2075···configured·to·u
00000bb0:·7020·2874·6865·0a64·6566·6175·6c74·292c··p·(the.default),00000bb0:·7365·2074·6865·0a3c·7474·3e61·7567·656e··se·the.<tt>augen
00000bc0:·2061·6464·2074·6865·2066·6f6c·6c6f·7769···add·the·followi00000bc0:·7275·6c65·733c·2f74·743e·2070·726f·6772··rules</tt>·progr
00000bd0:·6e67·206c·696e·6573·2074·6f20·6120·6669··ng·lines·to·a·fi00000bd0:·616d·2074·6f20·7265·6164·2061·7564·6974··am·to·read·audit
00000be0:·6c65·2077·6974·6820·7375·6666·6978·203c··le·with·suffix·<00000be0:·2072·756c·6573·2064·7572·696e·6720·6461···rules·during·da
00000bf0:·7474·3e2e·7275·6c65·733c·2f74·743e·2069··tt>.rules</tt>·i00000bf0:·656d·6f6e·2073·7461·7274·7570·2028·7468··emon·startup·(th
00000c00:·6e20·7468·650a·6469·7265·6374·6f72·7920··n·the.directory·00000c00:·650a·6465·6661·756c·7429·2c20·6164·6420··e.default),·add·
Max diff block lines reached; 4016273/4237789 bytes (94.77%) of diff not shown.
1.97 MB
html2text {}
Max HTML report size reached
1.45 MB
./usr/share/doc/ssg-nondebian/table-rhel7-anssirefs.html
    
Offset 65, 569 lines modifiedOffset 65, 569 lines modified
00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc
00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···
00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</
00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·
00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.
00000450:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R00000450:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R
Diff chunk too large, falling back to line-by-line diff (553 lines added, 553 lines removed)
00000460:·3129·3c2f·7464·3e0a·2020·2020·2020·3c74··1)</td>.······<t00000460:·3129·3c2f·7464·3e0a·2020·2020·2020·3c74··1)</td>.······<t
00000470:·643e·5265·6d6f·7665·2074·6674·7020·4461··d>Remove·tftp·Da00000470:·643e·556e·696e·7374·616c·6c20·5365·6e64··d>Uninstall·Send
00000480:·656d·6f6e·3c2f·7464·3e0a·2020·2020·2020··emon</td>.······00000480:·6d61·696c·2050·6163·6b61·6765·3c2f·7464··mail·Package</td
00000490:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en00000490:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:
000004a0:·2d55·5322·3e0a·2020·2020·2020·2020·5472··-US">.········Tr000004a0:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··
000004b0:·6976·6961·6c20·4669·6c65·2054·7261·6e73··ivial·File·Trans000004b0:·2020·2020·2020·5365·6e64·6d61·696c·2069········Sendmail·i
000004c0:·6665·7220·5072·6f74·6f63·6f6c·2028·5446··fer·Protocol·(TF000004c0:·7320·6e6f·7420·7468·6520·6465·6661·756c··s·not·the·defaul
000004d0:·5450·2920·6973·2061·2073·696d·706c·6520··TP)·is·a·simple·000004d0:·7420·6d61·696c·2074·7261·6e73·6665·7220··t·mail·transfer·
000004e0:·6669·6c65·2074·7261·6e73·6665·7220·7072··file·transfer·pr000004e0:·6167·656e·7420·616e·6420·6973·0a6e·6f74··agent·and·is.not
000004f0:·6f74·6f63·6f6c·2c0a·7479·7069·6361·6c6c··otocol,.typicall000004f0:·2069·6e73·7461·6c6c·6564·2062·7920·6465···installed·by·de
00000500:·7920·7573·6564·2074·6f20·6175·746f·6d61··y·used·to·automa00000500:·6661·756c·742e·0a54·6865·203c·636f·6465··fault..The·<code
00000510:·7469·6361·6c6c·7920·7472·616e·7366·6572··tically·transfer00000510:·3e73·656e·646d·6169·6c3c·2f63·6f64·653e··>sendmail</code>
00000520:·2063·6f6e·6669·6775·7261·7469·6f6e·206f···configuration·o00000520:·2070·6163·6b61·6765·2063·616e·2062·6520···package·can·be·
00000530:·7220·626f·6f74·2066·696c·6573·2062·6574··r·boot·files·bet00000530:·7265·6d6f·7665·6420·7769·7468·2074·6865··removed·with·the
00000540:·7765·656e·2073·7973·7465·6d73·2e0a·5446··ween·systems..TF00000540:·2066·6f6c·6c6f·7769·6e67·2063·6f6d·6d61···following·comma
00000550:·5450·2064·6f65·7320·6e6f·7420·7375·7070··TP·does·not·supp00000550:·6e64·3a0a·3c70·7265·3e0a·2420·7375·646f··nd:.<pre>.$·sudo
00000560:·6f72·7420·6175·7468·656e·7469·6361·7469··ort·authenticati00000560:·2079·756d·2065·7261·7365·2073·656e·646d···yum·erase·sendm
00000570:·6f6e·2061·6e64·2063·616e·2062·6520·6561··on·and·can·be·ea00000570:·6169·6c3c·2f70·7265·3e0a·2020·2020·2020··ail</pre>.······
00000580:·7369·6c79·2068·6163·6b65·642e·2054·6865··sily·hacked.·The00000580:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000590:·2070·6163·6b61·6765·0a3c·7474·3e74·6674···package.<tt>tft00000590:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
000005a0:·703c·2f74·743e·2069·7320·6120·636c·6965··p</tt>·is·a·clie000005a0:·3e0a·2020·2020·2020·2020·5468·6520·7365··>.········The·se
000005b0:·6e74·2070·726f·6772·616d·2074·6861·7420··nt·program·that·000005b0:·6e64·6d61·696c·2073·6f66·7477·6172·6520··ndmail·software·
000005c0:·616c·6c6f·7773·2066·6f72·2063·6f6e·6e65··allows·for·conne000005c0:·7761·7320·6e6f·7420·6465·7665·6c6f·7065··was·not·develope
000005d0:·6374·696f·6e73·2074·6f20·6120·3c74·743e··ctions·to·a·<tt>000005d0:·6420·7769·7468·2073·6563·7572·6974·7920··d·with·security·
000005e0:·7466·7470·3c2f·7474·3e20·7365·7276·6572··tftp</tt>·server000005e0:·696e·206d·696e·6420·616e·640a·6974·7320··in·mind·and.its·
000005f0:·2e0a·2020·2020·2020·3c2f·7464·3e0a·2020··..······</td>.··000005f0:·6465·7369·676e·2070·7265·7665·6e74·7320··design·prevents·
00000600:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang00000600:·6974·2066·726f·6d20·6265·696e·6720·6566··it·from·being·ef
00000610:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······00000610:·6665·6374·6976·656c·7920·636f·6e74·6169··fectively·contai
00000620:·2020·4974·2069·7320·7265·636f·6d6d·656e····It·is·recommen00000620:·6e65·6420·6279·2053·454c·696e·7578·2e20··ned·by·SELinux.·
00000630:·6465·6420·7468·6174·2054·4654·5020·6265··ded·that·TFTP·be00000630:·2050·6f73·7466·6978·0a73·686f·756c·6420···Postfix.should·
00000640:·2072·656d·6f76·6564·2c20·756e·6c65·7373···removed,·unless00000640:·6265·2075·7365·6420·696e·7374·6561·642e··be·used·instead.
00000650:·2074·6865·7265·2069·7320·6120·7370·6563···there·is·a·spec00000650:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00000660:·6966·6963·206e·6565·640a·666f·7220·5446··ific·need.for·TF00000660:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.
00000670:·5450·2028·7375·6368·2061·7320·6120·626f··TP·(such·as·a·bo00000670:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R
00000680:·6f74·2073·6572·7665·7229·2e20·496e·2074··ot·server).·In·t00000680:·3129·3c62·722f·3e4e·5430·3037·2852·3033··1)<br/>NT007(R03
00000690:·6861·7420·6361·7365·2c20·7573·6520·6578··hat·case,·use·ex00000690:·293c·2f74·643e·0a20·2020·2020·203c·7464··)</td>.······<td
000006a0:·7472·656d·6520·6361·7574·696f·6e20·7768··treme·caution·wh000006a0:·3e55·6e69·6e73·7461·6c6c·2074·6865·2074··>Uninstall·the·t
000006b0:·656e·2063·6f6e·6669·6775·7269·6e67·0a74··en·configuring.t000006b0:·656c·6e65·7420·7365·7276·6572·3c2f·7464··elnet·server</td
000006c0:·6865·2073·6572·7669·6365·732e·0a20·2020··he·services..···000006c0:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:
000006d0:·2020·203c·2f74·643e·0a20·2020·203c·2f74·····</td>.····</t000006d0:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··
000006e0:·723e·0a20·2020·203c·7472·3e0a·2020·2020··r>.····<tr>.····000006e0:·2020·2020·2020·5468·6520·7465·6c6e·6574········The·telnet
000006f0:·2020·3c74·643e·4250·3238·2852·3129·3c2f····<td>BP28(R1)</000006f0:·2064·6165·6d6f·6e20·7368·6f75·6c64·2062···daemon·should·b
00000700:·7464·3e0a·2020·2020·2020·3c74·643e·556e··td>.······<td>Un00000700:·6520·756e·696e·7374·616c·6c65·642e·0a20··e·uninstalled..·
00000710:·696e·7374·616c·6c20·7869·6e65·7464·2050··install·xinetd·P00000710:·2020·2020·203c·2f74·643e·0a20·2020·2020·······</td>.·····
00000720:·6163·6b61·6765·3c2f·7464·3e0a·2020·2020··ackage</td>.····00000720:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
00000730:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="00000730:·6e2d·5553·223e·0a20·2020·2020·2020·203c··n-US">.········<
00000740:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········00000740:·7474·3e74·656c·6e65·743c·2f74·743e·2061··tt>telnet</tt>·a
00000750:·5468·6520·3c63·6f64·653e·7869·6e65·7464··The·<code>xinetd00000750:·6c6c·6f77·7320·636c·6561·7220·7465·7874··llows·clear·text
00000760:·3c2f·636f·6465·3e20·7061·636b·6167·6520··</code>·package·00000760:·2063·6f6d·6d75·6e69·6361·7469·6f6e·732c···communications,
00000770:·6361·6e20·6265·2072·656d·6f76·6564·2077··can·be·removed·w00000770:·2061·6e64·2064·6f65·7320·6e6f·7420·7072···and·does·not·pr
00000780:·6974·6820·7468·6520·666f·6c6c·6f77·696e··ith·the·followin00000780:·6f74·6563·740a·616e·7920·6461·7461·2074··otect.any·data·t
00000790:·6720·636f·6d6d·616e·643a·0a3c·7072·653e··g·command:.<pre>00000790:·7261·6e73·6d69·7373·696f·6e20·6265·7477··ransmission·betw
000007a0:·0a24·2073·7564·6f20·7975·6d20·6572·6173··.$·sudo·yum·eras000007a0:·6565·6e20·636c·6965·6e74·2061·6e64·2073··een·client·and·s
000007b0:·6520·7869·6e65·7464·3c2f·7072·653e·0a20··e·xinetd</pre>.·000007b0:·6572·7665·722e·2041·6e79·2063·6f6e·6669··erver.·Any·confi
000007c0:·2020·2020·203c·2f74·643e·0a20·2020·2020·······</td>.·····000007c0:·6465·6e74·6961·6c20·6461·7461·0a63·616e··dential·data.can
000007d0:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e000007d0:·2062·6520·6c69·7374·656e·6564·2061·6e64···be·listened·and
000007e0:·6e2d·5553·223e·0a20·2020·2020·2020·2052··n-US">.········R000007e0:·206e·6f20·696e·7465·6772·6974·7920·6368···no·integrity·ch
000007f0:·656d·6f76·696e·6720·7468·6520·3c74·743e··emoving·the·<tt>000007f0:·6563·6b69·6e67·2069·7320·6d61·6465·2e27··ecking·is·made.'
00000800:·7869·6e65·7464·3c2f·7474·3e20·7061·636b··xinetd</tt>·pack00000800:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00000810:·6167·6520·6465·6372·6561·7365·7320·7468··age·decreases·th00000810:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.
00000820:·6520·7269·736b·206f·6620·7468·650a·7869··e·risk·of·the.xi00000820:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R
00000830:·6e65·7464·2073·6572·7669·6365·2773·2061··netd·service's·a00000830:·3129·3c2f·7464·3e0a·2020·2020·2020·3c74··1)</td>.······<t
00000840:·6363·6964·656e·7461·6c20·286f·7220·696e··ccidental·(or·in00000840:·643e·556e·696e·7374·616c·6c20·7461·6c6b··d>Uninstall·talk
00000850:·7465·6e74·696f·6e61·6c29·2061·6374·6976··tentional)·activ00000850:·2d73·6572·7665·7220·5061·636b·6167·653c··-server·Package<
00000860:·6174·696f·6e2e·0a20·2020·2020·203c·2f74··ation..······</t00000860:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x
00000870:·643e·0a20·2020·203c·2f74·723e·0a20·2020··d>.····</tr>.···00000870:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
00000880:·203c·7472·3e0a·2020·2020·2020·3c74·643e···<tr>.······<td>00000880:·0a20·2020·2020·2020·2054·6865·203c·636f··.········The·<co
00000890:·4250·3238·2852·3129·3c2f·7464·3e0a·2020··BP28(R1)</td>.··00000890:·6465·3e74·616c·6b2d·7365·7276·6572·3c2f··de>talk-server</
000008a0:·2020·2020·3c74·643e·556e·696e·7374·616c······<td>Uninstal000008a0:·636f·6465·3e20·7061·636b·6167·6520·6361··code>·package·ca
000008b0:·6c20·7465·6c6e·6574·2d73·6572·7665·7220··l·telnet-server·000008b0:·6e20·6265·2072·656d·6f76·6564·2077·6974··n·be·removed·wit
000008c0:·5061·636b·6167·653c·2f74·643e·0a20·2020··Package</td>.···000008c0:·6820·7468·6520·666f·6c6c·6f77·696e·6720··h·the·following·
000008d0:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=000008d0:·636f·6d6d·616e·643a·203c·7072·653e·2024··command:·<pre>·$
000008e0:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······000008e0:·2073·7564·6f20·7975·6d20·6572·6173·6520···sudo·yum·erase·
000008f0:·2054·6865·203c·636f·6465·3e74·656c·6e65···The·<code>telne000008f0:·7461·6c6b·2d73·6572·7665·723c·2f70·7265··talk-server</pre
00000900:·742d·7365·7276·6572·3c2f·636f·6465·3e20··t-server</code>·00000900:·3e0a·2020·2020·2020·3c2f·7464·3e0a·2020··>.······</td>.··
00000910:·7061·636b·6167·6520·6361·6e20·6265·2072··package·can·be·r00000910:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
00000920:·656d·6f76·6564·2077·6974·6820·7468·6520··emoved·with·the·00000920:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
00000930:·666f·6c6c·6f77·696e·6720·636f·6d6d·616e··following·comman00000930:·2020·5468·6520·7461·6c6b·2073·6f66·7477····The·talk·softw
00000940:·643a·0a3c·7072·653e·0a24·2073·7564·6f20··d:.<pre>.$·sudo·00000940:·6172·6520·7072·6573·656e·7473·2061·2073··are·presents·a·s
00000950:·7975·6d20·6572·6173·6520·7465·6c6e·6574··yum·erase·telnet00000950:·6563·7572·6974·7920·7269·736b·2061·7320··ecurity·risk·as·
00000960:·2d73·6572·7665·723c·2f70·7265·3e0a·2020··-server</pre>.··00000960:·6974·2075·7365·7320·756e·656e·6372·7970··it·uses·unencryp
00000970:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······00000970:·7465·6420·7072·6f74·6f63·6f6c·730a·666f··ted·protocols.fo
00000980:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en00000980:·7220·636f·6d6d·756e·6963·6174·696f·6e73··r·communications
00000990:·2d55·5322·3e0a·2020·2020·2020·2020·4974··-US">.········It00000990:·2e20·5265·6d6f·7669·6e67·2074·6865·203c··.·Removing·the·<
000009a0:·2069·7320·6465·7472·696d·656e·7461·6c20···is·detrimental·000009a0:·7474·3e74·616c·6b2d·7365·7276·6572·3c2f··tt>talk-server</
000009b0:·666f·7220·6f70·6572·6174·696e·6720·7379··for·operating·sy000009b0:·7474·3e20·7061·636b·6167·6520·6465·6372··tt>·package·decr
000009c0:·7374·656d·7320·746f·2070·726f·7669·6465··stems·to·provide000009c0:·6561·7365·7320·7468·650a·7269·736b·206f··eases·the.risk·o
000009d0:·2c20·6f72·2069·6e73·7461·6c6c·2062·7920··,·or·install·by·000009d0:·6620·7468·6520·6163·6369·6465·6e74·616c··f·the·accidental
000009e0:·6465·6661·756c·742c·0a66·756e·6374·696f··default,.functio000009e0:·2028·6f72·2069·6e74·656e·7469·6f6e·616c···(or·intentional
000009f0:·6e61·6c69·7479·2065·7863·6565·6469·6e67··nality·exceeding000009f0:·2920·6163·7469·7661·7469·6f6e·206f·6620··)·activation·of·
00000a00:·2072·6571·7569·7265·6d65·6e74·7320·6f72···requirements·or00000a00:·7461·6c6b·2073·6572·7669·6365·732e·0a20··talk·services..·
00000a10:·206d·6973·7369·6f6e·206f·626a·6563·7469···mission·objecti00000a10:·2020·2020·203c·2f74·643e·0a20·2020·203c·······</td>.····<
00000a20:·7665·732e·2054·6865·7365·0a75·6e6e·6563··ves.·These.unnec00000a20:·2f74·723e·0a20·2020·203c·7472·3e0a·2020··/tr>.····<tr>.··
00000a30:·6573·7361·7279·2063·6170·6162·696c·6974··essary·capabilit00000a30:·2020·2020·3c74·643e·4250·3238·2852·3129······<td>BP28(R1)
00000a40:·6965·7320·6172·6520·6f66·7465·6e20·6f76··ies·are·often·ov00000a40:·3c2f·7464·3e0a·2020·2020·2020·3c74·643e··</td>.······<td>
00000a50:·6572·6c6f·6f6b·6564·2061·6e64·2074·6865··erlooked·and·the00000a50:·556e·696e·7374·616c·6c20·7869·6e65·7464··Uninstall·xinetd
00000a60:·7265·666f·7265·206d·6179·2072·656d·6169··refore·may·remai00000a60:·2050·6163·6b61·6765·3c2f·7464·3e0a·2020···Package</td>.··
00000a70:·6e0a·756e·7365·6375·7265·2e20·5468·6579··n.unsecure.·They00000a70:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
00000a80:·2069·6e63·7265·6173·6520·7468·6520·7269···increase·the·ri00000a80:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
00000a90:·736b·2074·6f20·7468·6520·706c·6174·666f··sk·to·the·platfo00000a90:·2020·5468·6520·3c63·6f64·653e·7869·6e65····The·<code>xine
00000aa0:·726d·2062·7920·7072·6f76·6964·696e·6720··rm·by·providing·00000aa0:·7464·3c2f·636f·6465·3e20·7061·636b·6167··td</code>·packag
00000ab0:·6164·6469·7469·6f6e·616c·0a61·7474·6163··additional.attac00000ab0:·6520·6361·6e20·6265·2072·656d·6f76·6564··e·can·be·removed
00000ac0:·6b20·7665·6374·6f72·732e·0a3c·6272·202f··k·vectors..<br·/00000ac0:·2077·6974·6820·7468·6520·666f·6c6c·6f77···with·the·follow
00000ad0:·3e0a·5468·6520·7465·6c6e·6574·2073·6572··>.The·telnet·ser00000ad0:·696e·6720·636f·6d6d·616e·643a·0a3c·7072··ing·command:.<pr
00000ae0:·7669·6365·2070·726f·7669·6465·7320·616e··vice·provides·an00000ae0:·653e·0a24·2073·7564·6f20·7975·6d20·6572··e>.$·sudo·yum·er
00000af0:·2075·6e65·6e63·7279·7074·6564·2072·656d···unencrypted·rem00000af0:·6173·6520·7869·6e65·7464·3c2f·7072·653e··ase·xinetd</pre>
00000b00:·6f74·6520·6163·6365·7373·2073·6572·7669··ote·access·servi00000b00:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00000b10:·6365·2077·6869·6368·2064·6f65·730a·6e6f··ce·which·does.no00000b10:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=
00000b20:·7420·7072·6f76·6964·6520·666f·7220·7468··t·provide·for·th00000b20:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······
00000b30:·6520·636f·6e66·6964·656e·7469·616c·6974··e·confidentialit00000b30:·2052·656d·6f76·696e·6720·7468·6520·3c74···Removing·the·<t
00000b40:·7920·616e·6420·696e·7465·6772·6974·7920··y·and·integrity·00000b40:·743e·7869·6e65·7464·3c2f·7474·3e20·7061··t>xinetd</tt>·pa
00000b50:·6f66·2075·7365·7220·7061·7373·776f·7264··of·user·password00000b50:·636b·6167·6520·6465·6372·6561·7365·7320··ckage·decreases·
00000b60:·7320·6f72·2074·6865·0a72·656d·6f74·6520··s·or·the.remote·00000b60:·7468·6520·7269·736b·206f·6620·7468·650a··the·risk·of·the.
00000b70:·7365·7373·696f·6e2e·2049·6620·6120·7072··session.·If·a·pr00000b70:·7869·6e65·7464·2073·6572·7669·6365·2773··xinetd·service's
00000b80:·6976·696c·6567·6564·2075·7365·7220·7765··ivileged·user·we00000b80:·2061·6363·6964·656e·7461·6c20·286f·7220···accidental·(or·
00000b90:·7265·2074·6f20·6c6f·6769·6e20·7573·696e··re·to·login·usin00000b90:·696e·7465·6e74·696f·6e61·6c29·2061·6374··intentional)·act
00000ba0:·6720·7468·6973·2073·6572·7669·6365·2c20··g·this·service,·00000ba0:·6976·6174·696f·6e2e·0a20·2020·2020·203c··ivation..······<
00000bb0:·7468·650a·7072·6976·696c·6567·6564·2075··the.privileged·u00000bb0:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·
00000bc0:·7365·7220·7061·7373·776f·7264·2063·6f75··ser·password·cou00000bc0:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t
00000bd0:·6c64·2062·6520·636f·6d70·726f·6d69·7365··ld·be·compromise00000bd0:·643e·4250·3238·2852·3129·3c2f·7464·3e0a··d>BP28(R1)</td>.
Max diff block lines reached; 1194415/1271303 bytes (93.95%) of diff not shown.
242 KB
html2text {}
    
Offset 1, 102 lines modifiedOffset 1, 107 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Red·Hat1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Red·Hat
2 Enterprise·Linux·72 Enterprise·Linux·7
  
  
3 ································Trivial·File·Transfer·Protocol·(TFTP)·is·a 
4 ································simple·file·transfer·protocol,·typically 
5 ································used·to·automatically·transfer·configuration·It·is·recommended·that·TFTP·be·removed,·unless·there·is·a·specific·need·for 
6 BP28··Remove·tftp·Daemon········or·boot·files·between·systems.·TFTP·does·not·TFTP·(such·as·a·boot·server).·In·that·case,·use·extreme·caution·when 
7 (R1)····························support·authentication·and·can·be·easily·····configuring·the·services. 
8 ································hacked.·The·package·tftp·is·a·client·program 
9 ································that·allows·for·connections·to·a·tftp 
10 ································server. 
11 BP28····························The·xinetd·package·can·be·removed·with·the···Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's 
12 (R1)··Uninstall·xinetd·Package··following·command:···························accidental·(or·intentional)·activation. 
13 ································$·sudo·yum·erase·xinetd 
14 ·············································································It·is·detrimental·for·operating·systems·to·provide,·or·install·by·default, 
15 ·············································································functionality·exceeding·requirements·or·mission·objectives.·These 
16 ·············································································unnecessary·capabilities·are·often·overlooked·and·therefore·may·remain 
17 ·············································································unsecure.·They·increase·the·risk·to·the·platform·by·providing·additional 
18 BP28··Uninstall·telnet-server···The·telnet-server·package·can·be·removed·····attack·vectors. 
19 (R1)··Package···················with·the·following·command:··················The·telnet·service·provides·an·unencrypted·remote·access·service·which·does 
20 ································$·sudo·yum·erase·telnet-server···············not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the 
21 ·············································································remote·session.·If·a·privileged·user·were·to·login·using·this·service,·the 
22 ·············································································privileged·user·password·could·be·compromised. 
23 ·············································································Removing·the·telnet-server·package·decreases·the·risk·of·the·telnet 
24 ·············································································service's·accidental·(or·intentional)·activation. 
25 ································The·Network·Information·Service·(NIS), 
26 ································formerly·known·as·Yellow·Pages,·is·a·client-·The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to 
27 BP28····························server·directory·service·protocol·used·to····DOS·attacks,·buffer·overflows·and·has·poor·authentication·for·querying·NIS 
28 (R1)··Remove·NIS·Client·········distribute·system·configuration·files.·The···maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight 
29 ································NIS·client·(ypbind)·was·used·to·bind·a·······Directory·Access·Protocol·(LDAP).·It·is·recommended·that·the·service·be 
30 ································system·to·an·NIS·server·and·receive·the······removed. 
31 ································distributed·configuration·files. 
32 BP28··Uninstall·talk-server·····The·talk-server·package·can·be·removed·with··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols 
33 (R1)··Package···················the·following·command:·······················for·communications.·Removing·the·talk-server·package·decreases·the·risk·of 
34 ·································$·sudo·yum·erase·talk-server················the·accidental·(or·intentional)·activation·of·talk·services. 
35 ································Sendmail·is·not·the·default·mail·transfer3 ································Sendmail·is·not·the·default·mail·transfer
36 BP28··Uninstall·Sendmail········agent·and·is·not·installed·by·default.·The···The·sendmail·software·was·not·developed·with·security·in·mind·and·its·design4 BP28··Uninstall·Sendmail········agent·and·is·not·installed·by·default.·The···The·sendmail·software·was·not·developed·with·security·in·mind·and·its·design
37 (R1)··Package···················sendmail·package·can·be·removed·with·the·····prevents·it·from·being·effectively·contained·by·SELinux.·Postfix·should·be5 (R1)··Package···················sendmail·package·can·be·removed·with·the·····prevents·it·from·being·effectively·contained·by·SELinux.·Postfix·should·be
38 ································following·command:···························used·instead.6 ································following·command:···························used·instead.
39 ································$·sudo·yum·erase·sendmail7 ································$·sudo·yum·erase·sendmail
40 BP28·········································································telnet·allows·clear·text·communications,·and·does·not·protect·any·data8 BP28·········································································telnet·allows·clear·text·communications,·and·does·not·protect·any·data
41 (R1)··Uninstall·the·telnet······The·telnet·daemon·should·be·uninstalled.·····transmission·between·client·and·server.·Any·confidential·data·can·be9 (R1)··Uninstall·the·telnet······The·telnet·daemon·should·be·uninstalled.·····transmission·between·client·and·server.·Any·confidential·data·can·be
42 NT007·server·································································listened·and·no·integrity·checking·is·made.'10 NT007·server·································································listened·and·no·integrity·checking·is·made.'
43 (R03)11 (R03)
44 ································The·ypserv·package·can·be·removed·with·the···The·NIS·service·provides·an·unencrypted·authentication·service·which·does 
45 BP28··Uninstall·ypserv·Package··following·command:···························not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the 
46 (R1)····························$·sudo·yum·erase·ypserv······················remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the 
47 ·············································································accidental·(or·intentional)·activation·of·NIS·or·NIS+·services. 
48 ·············································································Removing·the·tftp-server·package·decreases·the·risk·of·the·accidental·(or 
49 ·············································································intentional)·activation·of·tftp·services. 
50 BP28··Uninstall·tftp-server·····The·tftp-server·package·can·be·removed·with 
51 (R1)··Package···················the·following·command:·······················If·TFTP·is·required·for·operational·support·(such·as·transmission·of·router 
52 ·································$·sudo·yum·erase·tftp-server················configurations),·its·use·must·be·documented·with·the·Information·Systems 
53 ·············································································Securty·Manager·(ISSM),·restricted·to·only·authorized·personnel,·and·have 
54 ·············································································access·control·rules·established.12 BP28··Uninstall·talk-server·····The·talk-server·package·can·be·removed·with··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols
 13 (R1)··Package···················the·following·command:·······················for·communications.·Removing·the·talk-server·package·decreases·the·risk·of
 14 ·································$·sudo·yum·erase·talk-server················the·accidental·(or·intentional)·activation·of·talk·services.
 15 BP28····························The·xinetd·package·can·be·removed·with·the···Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's
 16 (R1)··Uninstall·xinetd·Package··following·command:···························accidental·(or·intentional)·activation.
 17 ································$·sudo·yum·erase·xinetd
 18 ································Trivial·File·Transfer·Protocol·(TFTP)·is·a
 19 ································simple·file·transfer·protocol,·typically
 20 ································used·to·automatically·transfer·configuration·It·is·recommended·that·TFTP·be·removed,·unless·there·is·a·specific·need·for
 21 BP28··Remove·tftp·Daemon········or·boot·files·between·systems.·TFTP·does·not·TFTP·(such·as·a·boot·server).·In·that·case,·use·extreme·caution·when
 22 (R1)····························support·authentication·and·can·be·easily·····configuring·the·services.
 23 ································hacked.·The·package·tftp·is·a·client·program
 24 ································that·allows·for·connections·to·a·tftp
 25 ································server.
55 ································The·talk·package·contains·the·client·program26 ································The·talk·package·contains·the·client·program
56 ································for·the·Internet·talk·protocol,·which·allows27 ································for·the·Internet·talk·protocol,·which·allows
57 ································the·user·to·chat·with·other·users·on28 ································the·user·to·chat·with·other·users·on
58 BP28····························different·systems.·Talk·is·a·communication···The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols29 BP28····························different·systems.·Talk·is·a·communication···The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols
59 (R1)··Uninstall·talk·Package····program·which·copies·lines·from·one·terminal·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the30 (R1)··Uninstall·talk·Package····program·which·copies·lines·from·one·terminal·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the
60 ································to·the·terminal·of·another·user.·The·talk····accidental·(or·intentional)·activation·of·talk·client·program.31 ································to·the·terminal·of·another·user.·The·talk····accidental·(or·intentional)·activation·of·talk·client·program.
61 ································package·can·be·removed·with·the·following32 ································package·can·be·removed·with·the·following
62 ································command:33 ································command:
63 ································$·sudo·yum·erase·talk34 ································$·sudo·yum·erase·talk
64 ·············································································These·legacy·clients·contain·numerous·security·exposures·and·have·been 
65 ·············································································replaced·with·the·more·secure·SSH·package.·Even·if·the·server·is·removed,·it 
66 BP28··Uninstall·rsh·Package·····The·rsh·package·contains·the·client·commands·is·best·to·ensure·the·clients·are·also·removed·to·prevent·users·from 
67 (R1)····························for·the·rsh·services·························inadvertently·attempting·to·use·these·commands·and·therefore·exposing·their 
68 ·············································································credentials.·Note·that·removing·the·rsh·package·removes·the·clients·for35 ································The·Network·Information·Service·(NIS),
 36 ································formerly·known·as·Yellow·Pages,·is·a·client-·The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to
 37 BP28····························server·directory·service·protocol·used·to····DOS·attacks,·buffer·overflows·and·has·poor·authentication·for·querying·NIS
 38 (R1)··Remove·NIS·Client·········distribute·system·configuration·files.·The···maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight
 39 ································NIS·client·(ypbind)·was·used·to·bind·a·······Directory·Access·Protocol·(LDAP).·It·is·recommended·that·the·service·be
 40 ································system·to·an·NIS·server·and·receive·the······removed.
 41 ································distributed·configuration·files.
 42 ································The·telnet·client·allows·users·to·start······The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted
 43 BP28··Remove·telnet·Clients·····connections·to·other·systems·via·the·telnet··transmission·medium·could·allow·an·unauthorized·user·to·steal·credentials.
 44 (R1)····························protocol.····································The·ssh·package·provides·an·encrypted·session·and·stronger·security·and·is
69 ·············································································rsh,rcp,·and·rlogin.45 ·············································································included·in·Red·Hat·Enterprise·Linux·7.
70 ································If·the·system·does·not·need·to·act·as·a·DHCP46 ································If·the·system·does·not·need·to·act·as·a·DHCP
71 BP28··Uninstall·DHCP·Server·····server,·the·dhcp·package·can·be·uninstalled.·Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally47 BP28··Uninstall·DHCP·Server·····server,·the·dhcp·package·can·be·uninstalled.·Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally
72 (R1)··Package···················The·dhcp·package·can·be·removed·with·the·····reactivated·and·disrupt·network·operation.48 (R1)··Package···················The·dhcp·package·can·be·removed·with·the·····reactivated·and·disrupt·network·operation.
73 ································following·command:49 ································following·command:
74 ································$·sudo·yum·erase·dhcp50 ································$·sudo·yum·erase·dhcp
 51 ·············································································Removing·the·tftp-server·package·decreases·the·risk·of·the·accidental·(or
75 ································The·telnet·client·allows·users·to·start······The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted 
76 BP28··Remove·telnet·Clients·····connections·to·other·systems·via·the·telnet··transmission·medium·could·allow·an·unauthorized·user·to·steal·credentials. 
77 (R1)····························protocol.····································The·ssh·package·provides·an·encrypted·session·and·stronger·security·and·is 
78 ·············································································included·in·Red·Hat·Enterprise·Linux·7.52 ·············································································intentional)·activation·of·tftp·services.
 53 BP28··Uninstall·tftp-server·····The·tftp-server·package·can·be·removed·with
 54 (R1)··Package···················the·following·command:·······················If·TFTP·is·required·for·operational·support·(such·as·transmission·of·router
 55 ·································$·sudo·yum·erase·tftp-server················configurations),·its·use·must·be·documented·with·the·Information·Systems
 56 ·············································································Securty·Manager·(ISSM),·restricted·to·only·authorized·personnel,·and·have
 57 ·············································································access·control·rules·established.
79 ·············································································The·rsh-server·service·provides·unencrypted·remote·access·service·which·does58 ·············································································The·rsh-server·service·provides·unencrypted·remote·access·service·which·does
80 ·············································································not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the59 ·············································································not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the
81 BP28··Uninstall·rsh-server······The·rsh-server·package·can·be·removed·with···remote·session·and·has·very·weak·authentication.·If·a·privileged·user·were60 BP28··Uninstall·rsh-server······The·rsh-server·package·can·be·removed·with···remote·session·and·has·very·weak·authentication.·If·a·privileged·user·were
82 (R1)··Package···················the·following·command:·······················to·login·using·this·service,·the·privileged·user·password·could·be61 (R1)··Package···················the·following·command:·······················to·login·using·this·service,·the·privileged·user·password·could·be
83 ································$·sudo·yum·erase·rsh-server··················compromised.·The·rsh-server·package·provides·several·obsolete·and·insecure62 ································$·sudo·yum·erase·rsh-server··················compromised.·The·rsh-server·package·provides·several·obsolete·and·insecure
84 ·············································································network·services.·Removing·it·decreases·the·risk·of·those·services'63 ·············································································network·services.·Removing·it·decreases·the·risk·of·those·services'
85 ·············································································accidental·(or·intentional)·activation.64 ·············································································accidental·(or·intentional)·activation.
 65 ································The·ypserv·package·can·be·removed·with·the···The·NIS·service·provides·an·unencrypted·authentication·service·which·does
 66 BP28··Uninstall·ypserv·Package··following·command:···························not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the
 67 (R1)····························$·sudo·yum·erase·ypserv······················remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the
 68 ·············································································accidental·(or·intentional)·activation·of·NIS·or·NIS+·services.
 69 ·············································································These·legacy·clients·contain·numerous·security·exposures·and·have·been
 70 ·············································································replaced·with·the·more·secure·SSH·package.·Even·if·the·server·is·removed,·it
 71 BP28··Uninstall·rsh·Package·····The·rsh·package·contains·the·client·commands·is·best·to·ensure·the·clients·are·also·removed·to·prevent·users·from
 72 (R1)····························for·the·rsh·services·························inadvertently·attempting·to·use·these·commands·and·therefore·exposing·their
 73 ·············································································credentials.·Note·that·removing·the·rsh·package·removes·the·clients·for
 74 ·············································································rsh,rcp,·and·rlogin.
Max diff block lines reached; 230750/247918 bytes (93.08%) of diff not shown.
1.62 MB
./usr/share/doc/ssg-nondebian/table-rhel7-cisrefs.html
    
Offset 123, 225 lines modifiedOffset 123, 225 lines modified
000007a0:·206c·6f63·616c·2061·7474·6163·6b20·7375···local·attack·su000007a0:·206c·6f63·616c·2061·7474·6163·6b20·7375···local·attack·su
000007b0:·7266·6163·650a·6f66·2074·6865·2073·6572··rface.of·the·ser000007b0:·7266·6163·650a·6f66·2074·6865·2073·6572··rface.of·the·ser
000007c0:·7665·722e·0a20·2020·2020·203c·2f74·643e··ver..······</td>000007c0:·7665·722e·0a20·2020·2020·203c·2f74·643e··ver..······</td>
000007d0:·0a20·2020·203c·2f74·723e·0a20·2020·203c··.····</tr>.····<000007d0:·0a20·2020·203c·2f74·723e·0a20·2020·203c··.····</tr>.····<
000007e0:·7472·3e0a·2020·2020·2020·3c74·643e·312e··tr>.······<td>1.000007e0:·7472·3e0a·2020·2020·2020·3c74·643e·312e··tr>.······<td>1.
000007f0:·312e·312e·323c·2f74·643e·0a20·2020·2020··1.1.2</td>.·····000007f0:·312e·312e·323c·2f74·643e·0a20·2020·2020··1.1.2</td>.·····
00000800:·203c·7464·3e44·6973·6162·6c65·204d·6f75···<td>Disable·Mou00000800:·203c·7464·3e44·6973·6162·6c65·204d·6f75···<td>Disable·Mou
00000810:·6e74·696e·6720·6f66·2073·7175·6173·6866··nting·of·squashf00000810:·6e74·696e·6720·6f66·2066·7265·6576·7866··nting·of·freevxf
00000820:·733c·2f74·643e·0a20·2020·2020·203c·7464··s</td>.······<td00000820:·733c·2f74·643e·0a20·2020·2020·203c·7464··s</td>.······<td
00000830:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US00000830:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US
00000840:·223e·0a20·2020·2020·2020·200a·546f·2063··">.········.To·c00000840:·223e·0a20·2020·2020·2020·200a·546f·2063··">.········.To·c
00000850:·6f6e·6669·6775·7265·2074·6865·2073·7973··onfigure·the·sys00000850:·6f6e·6669·6775·7265·2074·6865·2073·7973··onfigure·the·sys
00000860:·7465·6d20·746f·2070·7265·7665·6e74·2074··tem·to·prevent·t00000860:·7465·6d20·746f·2070·7265·7665·6e74·2074··tem·to·prevent·t
00000870:·6865·203c·636f·6465·3e73·7175·6173·6866··he·<code>squashf00000870:·6865·203c·636f·6465·3e66·7265·6576·7866··he·<code>freevxf
00000880:·733c·2f63·6f64·653e·0a6b·6572·6e65·6c20··s</code>.kernel·00000880:·733c·2f63·6f64·653e·0a6b·6572·6e65·6c20··s</code>.kernel·
00000890:·6d6f·6475·6c65·2066·726f·6d20·6265·696e··module·from·bein00000890:·6d6f·6475·6c65·2066·726f·6d20·6265·696e··module·from·bein
000008a0:·6720·6c6f·6164·6564·2c20·6164·6420·7468··g·loaded,·add·th000008a0:·6720·6c6f·6164·6564·2c20·6164·6420·7468··g·loaded,·add·th
000008b0:·6520·666f·6c6c·6f77·696e·6720·6c69·6e65··e·following·line000008b0:·6520·666f·6c6c·6f77·696e·6720·6c69·6e65··e·following·line
000008c0:·2074·6f20·7468·6520·6669·6c65·203c·636f···to·the·file·<co000008c0:·2074·6f20·7468·6520·6669·6c65·203c·636f···to·the·file·<co
000008d0:·6465·3e2f·6574·632f·6d6f·6470·726f·6265··de>/etc/modprobe000008d0:·6465·3e2f·6574·632f·6d6f·6470·726f·6265··de>/etc/modprobe
000008e0:·2e64·2f73·7175·6173·6866·732e·636f·6e66··.d/squashfs.conf000008e0:·2e64·2f66·7265·6576·7866·732e·636f·6e66··.d/freevxfs.conf
000008f0:·3c2f·636f·6465·3e3a·0a3c·7072·653e·696e··</code>:.<pre>in000008f0:·3c2f·636f·6465·3e3a·0a3c·7072·653e·696e··</code>:.<pre>in
00000900:·7374·616c·6c20·7371·7561·7368·6673·202f··stall·squashfs·/00000900:·7374·616c·6c20·6672·6565·7678·6673·202f··stall·freevxfs·/
00000910:·6269·6e2f·7472·7565·3c2f·7072·653e·0a0a··bin/true</pre>..00000910:·6269·6e2f·7472·7565·3c2f·7072·653e·0a0a··bin/true</pre>..
00000920:·546f·2063·6f6e·6669·6775·7265·2074·6865··To·configure·the00000920:·546f·2063·6f6e·6669·6775·7265·2074·6865··To·configure·the
00000930:·2073·7973·7465·6d20·746f·2070·7265·7665···system·to·preve00000930:·2073·7973·7465·6d20·746f·2070·7265·7665···system·to·preve
00000940:·6e74·2074·6865·203c·636f·6465·3e73·7175··nt·the·<code>squ00000940:·6e74·2074·6865·203c·636f·6465·3e66·7265··nt·the·<code>fre
00000950:·6173·6866·733c·2f63·6f64·653e·2066·726f··ashfs</code>·fro00000950:·6576·7866·733c·2f63·6f64·653e·2066·726f··evxfs</code>·fro
00000960:·6d20·6265·696e·6720·7573·6564·2c0a·6164··m·being·used,.ad00000960:·6d20·6265·696e·6720·7573·6564·2c0a·6164··m·being·used,.ad
00000970:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·00000970:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·
00000980:·6c69·6e65·2074·6f20·6669·6c65·203c·636f··line·to·file·<co00000980:·6c69·6e65·2074·6f20·6669·6c65·203c·636f··line·to·file·<co
00000990:·6465·3e2f·6574·632f·6d6f·6470·726f·6265··de>/etc/modprobe00000990:·6465·3e2f·6574·632f·6d6f·6470·726f·6265··de>/etc/modprobe
000009a0:·2e64·2f73·7175·6173·6866·732e·636f·6e66··.d/squashfs.conf000009a0:·2e64·2f66·7265·6576·7866·732e·636f·6e66··.d/freevxfs.conf
000009b0:·3c2f·636f·6465·3e3a·0a3c·7072·653e·626c··</code>:.<pre>bl000009b0:·3c2f·636f·6465·3e3a·0a3c·7072·653e·626c··</code>:.<pre>bl
000009c0:·6163·6b6c·6973·7420·7371·7561·7368·6673··acklist·squashfs000009c0:·6163·6b6c·6973·7420·6672·6565·7678·6673··acklist·freevxfs
000009d0:·3c2f·7072·653e·0a0a·5468·6973·2065·6666··</pre>..This·eff000009d0:·3c2f·7072·653e·0a0a·5468·6973·2065·6666··</pre>..This·eff
000009e0:·6563·7469·7665·6c79·2070·7265·7665·6e74··ectively·prevent000009e0:·6563·7469·7665·6c79·2070·7265·7665·6e74··ectively·prevent
000009f0:·7320·7573·6167·6520·6f66·2074·6869·7320··s·usage·of·this·000009f0:·7320·7573·6167·6520·6f66·2074·6869·7320··s·usage·of·this·
00000a00:·756e·636f·6d6d·6f6e·2066·696c·6573·7973··uncommon·filesys00000a00:·756e·636f·6d6d·6f6e·2066·696c·6573·7973··uncommon·filesys
 00000a10:·7465·6d2e·0a20·2020·2020·203c·2f74·643e··tem..······</td>
 00000a20:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l
 00000a30:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···
 00000a40:·2020·2020·204c·696e·7578·206b·6572·6e65·······Linux·kerne
 00000a50:·6c20·6d6f·6475·6c65·7320·7768·6963·6820··l·modules·which·
 00000a60:·696d·706c·656d·656e·7420·6669·6c65·7379··implement·filesy
 00000a70:·7374·656d·7320·7468·6174·2061·7265·206e··stems·that·are·n
 00000a80:·6f74·206e·6565·6465·6420·6279·2074·6865··ot·needed·by·the
 00000a90:·0a6c·6f63·616c·2073·7973·7465·6d20·7368··.local·system·sh
 00000aa0:·6f75·6c64·2062·6520·6469·7361·626c·6564··ould·be·disabled
 00000ab0:·2e0a·2020·2020·2020·3c2f·7464·3e0a·2020··..······</td>.··
00000a10:·7465·6d2e·0a0a·5468·6520·3c74·743e·7371··tem...The·<tt>sq 
00000a20:·7561·7368·6673·3c2f·7474·3e20·6669·6c65··uashfs</tt>·file 
00000a30:·7379·7374·656d·2074·7970·6520·6973·2061··system·type·is·a 
00000a40:·2063·6f6d·7072·6573·7365·6420·7265·6164···compressed·read 
00000a50:·2d6f·6e6c·7920·4c69·6e75·780a·6669·6c65··-only·Linux.file 
00000a60:·7379·7374·656d·2065·6d62·6564·6465·6420··system·embedded· 
00000a70:·696e·2073·6d61·6c6c·2066·6f6f·7470·7269··in·small·footpri 
00000a80:·6e74·2073·7973·7465·6d73·2028·7369·6d69··nt·systems·(simi 
00000a90:·6c61·7220·746f·0a3c·7474·3e63·7261·6d66··lar·to.<tt>cramf 
00000aa0:·733c·2f74·743e·292e·2041·203c·7474·3e73··s</tt>).·A·<tt>s 
00000ab0:·7175·6173·6866·733c·2f74·743e·2069·6d61··quashfs</tt>·ima 
00000ac0:·6765·2063·616e·2062·6520·7573·6564·2077··ge·can·be·used·w 
00000ad0:·6974·686f·7574·2068·6176·696e·670a·746f··ithout·having.to 
00000ae0:·2066·6972·7374·2064·6563·6f6d·7072·6573···first·decompres 
00000af0:·7320·7468·6520·696d·6167·652e·0a20·2020··s·the·image..··· 
00000b00:·2020·203c·2f74·643e·0a20·2020·2020·203c·····</td>.······<00000ac0:·2020·3c2f·7472·3e0a·2020·2020·3c74·723e····</tr>.····<tr>
 00000ad0:·0a20·2020·2020·203c·7464·3e31·2e31·2e31··.······<td>1.1.1
00000b10:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en- 
00000b20:·5553·223e·0a20·2020·2020·2020·2052·656d··US">.········Rem 
00000b30:·6f76·696e·6720·7375·7070·6f72·7420·666f··oving·support·fo 
00000b40:·7220·756e·6e65·6564·6564·2066·696c·6573··r·unneeded·files 
00000b50:·7973·7465·6d20·7479·7065·7320·7265·6475··ystem·types·redu 
00000b60:·6365·7320·7468·6520·6c6f·6361·6c20·6174··ces·the·local·at 
00000b70:·7461·636b·0a73·7572·6661·6365·206f·6620··tack.surface·of· 
00000b80:·7468·6520·7379·7374·656d·2e0a·2020·2020··the·system..···· 
00000b90:·2020·3c2f·7464·3e0a·2020·2020·3c2f·7472····</td>.····</tr 
00000ba0:·3e0a·2020·2020·3c74·723e·0a20·2020·2020··>.····<tr>.····· 
00000bb0:·203c·7464·3e31·2e31·2e31·2e32·3c2f·7464···<td>1.1.1.2</td 
00000bc0:·3e0a·2020·2020·2020·3c74·643e·4469·7361··>.······<td>Disa 
00000bd0:·626c·6520·4d6f·756e·7469·6e67·206f·6620··ble·Mounting·of· 
00000be0:·6672·6565·7678·6673·3c2f·7464·3e0a·2020··freevxfs</td>.·· 
00000bf0:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang 
00000c00:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······ 
00000c10:·2020·0a54·6f20·636f·6e66·6967·7572·6520····.To·configure· 
00000c20:·7468·6520·7379·7374·656d·2074·6f20·7072··the·system·to·pr 
00000c30:·6576·656e·7420·7468·6520·3c63·6f64·653e··event·the·<code> 
00000c40:·6672·6565·7678·6673·3c2f·636f·6465·3e0a··freevxfs</code>. 
00000c50:·6b65·726e·656c·206d·6f64·756c·6520·6672··kernel·module·fr 
00000c60:·6f6d·2062·6569·6e67·206c·6f61·6465·642c··om·being·loaded, 
00000c70:·2061·6464·2074·6865·2066·6f6c·6c6f·7769···add·the·followi 
00000c80:·6e67·206c·696e·6520·746f·2074·6865·2066··ng·line·to·the·f 
00000c90:·696c·6520·3c63·6f64·653e·2f65·7463·2f6d··ile·<code>/etc/m 
00000ca0:·6f64·7072·6f62·652e·642f·6672·6565·7678··odprobe.d/freevx 
00000cb0:·6673·2e63·6f6e·663c·2f63·6f64·653e·3a0a··fs.conf</code>:. 
00000cc0:·3c70·7265·3e69·6e73·7461·6c6c·2066·7265··<pre>install·fre 
00000cd0:·6576·7866·7320·2f62·696e·2f74·7275·653c··evxfs·/bin/true< 
00000ce0:·2f70·7265·3e0a·0a54·6f20·636f·6e66·6967··/pre>..To·config 
00000cf0:·7572·6520·7468·6520·7379·7374·656d·2074··ure·the·system·t 
00000d00:·6f20·7072·6576·656e·7420·7468·6520·3c63··o·prevent·the·<c 
00000d10:·6f64·653e·6672·6565·7678·6673·3c2f·636f··ode>freevxfs</co 
00000d20:·6465·3e20·6672·6f6d·2062·6569·6e67·2075··de>·from·being·u 
00000d30:·7365·642c·0a61·6464·2074·6865·2066·6f6c··sed,.add·the·fol 
00000d40:·6c6f·7769·6e67·206c·696e·6520·746f·2066··lowing·line·to·f 
00000d50:·696c·6520·3c63·6f64·653e·2f65·7463·2f6d··ile·<code>/etc/m 
00000d60:·6f64·7072·6f62·652e·642f·6672·6565·7678··odprobe.d/freevx 
00000d70:·6673·2e63·6f6e·663c·2f63·6f64·653e·3a0a··fs.conf</code>:. 
00000d80:·3c70·7265·3e62·6c61·636b·6c69·7374·2066··<pre>blacklist·f 
00000d90:·7265·6576·7866·733c·2f70·7265·3e0a·0a54··reevxfs</pre>..T 
00000da0:·6869·7320·6566·6665·6374·6976·656c·7920··his·effectively· 
00000db0:·7072·6576·656e·7473·2075·7361·6765·206f··prevents·usage·o 
00000dc0:·6620·7468·6973·2075·6e63·6f6d·6d6f·6e20··f·this·uncommon· 
00000dd0:·6669·6c65·7379·7374·656d·2e0a·2020·2020··filesystem..···· 
00000de0:·2020·3c2f·7464·3e0a·2020·2020·2020·3c74····</td>.······<t00000ae0:·2e32·3c2f·7464·3e0a·2020·2020·2020·3c74··.2</td>.······<t
 00000af0:·643e·4469·7361·626c·6520·4d6f·756e·7469··d>Disable·Mounti
 00000b00:·6e67·206f·6620·7371·7561·7368·6673·3c2f··ng·of·squashfs</
 00000b10:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm
 00000b20:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.
 00000b30:·2020·2020·2020·2020·0a54·6f20·636f·6e66··········.To·conf
 00000b40:·6967·7572·6520·7468·6520·7379·7374·656d··igure·the·system
 00000b50:·2074·6f20·7072·6576·656e·7420·7468·6520···to·prevent·the·
 00000b60:·3c63·6f64·653e·7371·7561·7368·6673·3c2f··<code>squashfs</
 00000b70:·636f·6465·3e0a·6b65·726e·656c·206d·6f64··code>.kernel·mod
 00000b80:·756c·6520·6672·6f6d·2062·6569·6e67·206c··ule·from·being·l
 00000b90:·6f61·6465·642c·2061·6464·2074·6865·2066··oaded,·add·the·f
 00000ba0:·6f6c·6c6f·7769·6e67·206c·696e·6520·746f··ollowing·line·to
 00000bb0:·2074·6865·2066·696c·6520·3c63·6f64·653e···the·file·<code>
 00000bc0:·2f65·7463·2f6d·6f64·7072·6f62·652e·642f··/etc/modprobe.d/
Max diff block lines reached; 1290895/1304029 bytes (98.99%) of diff not shown.
381 KB
html2text {}
    
Offset 13, 36 lines modifiedOffset 13, 46 lines modified
13 1.1.1.1···cramfs··············modprobe.d/cramfs.conf:·····························types·reduces·the13 1.1.1.1···cramfs··············modprobe.d/cramfs.conf:·····························types·reduces·the
14 ······························blacklist·cramfs····································local·attack·surface14 ······························blacklist·cramfs····································local·attack·surface
15 ······························This·effectively·prevents·usage·of·this·uncommon····of·the·server.15 ······························This·effectively·prevents·usage·of·this·uncommon····of·the·server.
16 ······························filesystem.·The·cramfs·filesystem·type·is·a16 ······························filesystem.·The·cramfs·filesystem·type·is·a
17 ······························compressed·read-only·Linux·filesystem·embedded·in17 ······························compressed·read-only·Linux·filesystem·embedded·in
18 ······························small·footprint·systems.·A·cramfs·image·can·be·used18 ······························small·footprint·systems.·A·cramfs·image·can·be·used
19 ······························without·having·to·first·decompress·the·image.19 ······························without·having·to·first·decompress·the·image.
 20 ······························To·configure·the·system·to·prevent·the·freevxfs
 21 ······························kernel·module·from·being·loaded,·add·the·following
 22 ······························line·to·the·file·/etc/modprobe.d/freevxfs.conf:·····Linux·kernel·modules
 23 ······························install·freevxfs·/bin/true··························which·implement
 24 1.1.1.2···Disable·Mounting·of·To·configure·the·system·to·prevent·the·freevxfs·····filesystems·that·are
 25 ··········freevxfs············from·being·used,·add·the·following·line·to·file·/···not·needed·by·the
 26 ······························etc/modprobe.d/freevxfs.conf:·······················local·system·should
 27 ······························blacklist·freevxfs··································be·disabled.
 28 ······························This·effectively·prevents·usage·of·this·uncommon
 29 ······························filesystem.
20 ······························To·configure·the·system·to·prevent·the·squashfs30 ······························To·configure·the·system·to·prevent·the·squashfs
21 ······························kernel·module·from·being·loaded,·add·the·following31 ······························kernel·module·from·being·loaded,·add·the·following
22 ······························line·to·the·file·/etc/modprobe.d/squashfs.conf:32 ······························line·to·the·file·/etc/modprobe.d/squashfs.conf:
23 ······························install·squashfs·/bin/true33 ······························install·squashfs·/bin/true
24 ······························To·configure·the·system·to·prevent·the·squashfs·····Removing·support·for34 ······························To·configure·the·system·to·prevent·the·squashfs·····Removing·support·for
25 ······························from·being·used,·add·the·following·line·to·file·/···unneeded·filesystem35 ······························from·being·used,·add·the·following·line·to·file·/···unneeded·filesystem
26 1.1.1.2···Disable·Mounting·of·etc/modprobe.d/squashfs.conf:·······················types·reduces·the36 1.1.1.2···Disable·Mounting·of·etc/modprobe.d/squashfs.conf:·······················types·reduces·the
27 ··········squashfs············blacklist·squashfs··································local·attack·surface37 ··········squashfs············blacklist·squashfs··································local·attack·surface
28 ······························This·effectively·prevents·usage·of·this·uncommon····of·the·system.38 ······························This·effectively·prevents·usage·of·this·uncommon····of·the·system.
29 ······························filesystem.·The·squashfs·filesystem·type·is·a39 ······························filesystem.·The·squashfs·filesystem·type·is·a
30 ······························compressed·read-only·Linux·filesystem·embedded·in40 ······························compressed·read-only·Linux·filesystem·embedded·in
31 ······························small·footprint·systems·(similar·to·cramfs).·A41 ······························small·footprint·systems·(similar·to·cramfs).·A
32 ······························squashfs·image·can·be·used·without·having·to·first42 ······························squashfs·image·can·be·used·without·having·to·first
33 ······························decompress·the·image.43 ······························decompress·the·image.
34 ······························To·configure·the·system·to·prevent·the·freevxfs44 ······························To·configure·the·system·to·prevent·the·jffs2·kernel
35 ······························kernel·module·from·being·loaded,·add·the·following45 ······························module·from·being·loaded,·add·the·following·line·to
36 ······························line·to·the·file·/etc/modprobe.d/freevxfs.conf:·····Linux·kernel·modules46 ······························the·file·/etc/modprobe.d/jffs2.conf:················Linux·kernel·modules
37 ······························install·freevxfs·/bin/true··························which·implement47 ······························install·jffs2·/bin/true·····························which·implement
38 1.1.1.2···Disable·Mounting·of·To·configure·the·system·to·prevent·the·freevxfs·····filesystems·that·are48 1.1.1.3···Disable·Mounting·of·To·configure·the·system·to·prevent·the·jffs2·from···filesystems·that·are
39 ··········freevxfs············from·being·used,·add·the·following·line·to·file·/···not·needed·by·the49 ··········jffs2···············being·used,·add·the·following·line·to·file·/etc/····not·needed·by·the
40 ······························etc/modprobe.d/freevxfs.conf:·······················local·system·should50 ······························modprobe.d/jffs2.conf:······························local·system·should
41 ······························blacklist·freevxfs··································be·disabled.51 ······························blacklist·jffs2·····································be·disabled.
42 ······························This·effectively·prevents·usage·of·this·uncommon52 ······························This·effectively·prevents·usage·of·this·uncommon
43 ······························filesystem.53 ······························filesystem.
44 ······························To·configure·the·system·to·prevent·the·udf·kernel54 ······························To·configure·the·system·to·prevent·the·udf·kernel
45 ······························module·from·being·loaded,·add·the·following·line·to55 ······························module·from·being·loaded,·add·the·following·line·to
46 ······························the·file·/etc/modprobe.d/udf.conf:56 ······························the·file·/etc/modprobe.d/udf.conf:
47 ······························install·udf·/bin/true57 ······························install·udf·/bin/true
48 ······························To·configure·the·system·to·prevent·the·udf·from58 ······························To·configure·the·system·to·prevent·the·udf·from
Offset 53, 24 lines modifiedOffset 63, 14 lines modified
53 ······························filesystem.·The·udf·filesystem·type·is·the··········of·the·system.63 ······························filesystem.·The·udf·filesystem·type·is·the··········of·the·system.
54 ······························universal·disk·format·used·to·implement·the·ISO/IEC64 ······························universal·disk·format·used·to·implement·the·ISO/IEC
55 ······························13346·and·ECMA-167·specifications.·This·is·an·open65 ······························13346·and·ECMA-167·specifications.·This·is·an·open
56 ······························vendor·filesystem·type·for·data·storage·on·a·broad66 ······························vendor·filesystem·type·for·data·storage·on·a·broad
57 ······························range·of·media.·This·filesystem·type·is·neccessary67 ······························range·of·media.·This·filesystem·type·is·neccessary
58 ······························to·support·writing·DVDs·and·newer·optical·disc68 ······························to·support·writing·DVDs·and·newer·optical·disc
59 ······························formats.69 ······························formats.
60 ······························To·configure·the·system·to·prevent·the·jffs2·kernel 
61 ······························module·from·being·loaded,·add·the·following·line·to 
62 ······························the·file·/etc/modprobe.d/jffs2.conf:················Linux·kernel·modules 
63 ······························install·jffs2·/bin/true·····························which·implement 
64 1.1.1.3···Disable·Mounting·of·To·configure·the·system·to·prevent·the·jffs2·from···filesystems·that·are 
65 ··········jffs2···············being·used,·add·the·following·line·to·file·/etc/····not·needed·by·the 
66 ······························modprobe.d/jffs2.conf:······························local·system·should 
67 ······························blacklist·jffs2·····································be·disabled. 
68 ······························This·effectively·prevents·usage·of·this·uncommon 
69 ······························filesystem. 
70 ······························To·configure·the·system·to·prevent·the·hfs·kernel70 ······························To·configure·the·system·to·prevent·the·hfs·kernel
71 ······························module·from·being·loaded,·add·the·following·line·to71 ······························module·from·being·loaded,·add·the·following·line·to
72 ······························the·file·/etc/modprobe.d/hfs.conf:··················Linux·kernel·modules72 ······························the·file·/etc/modprobe.d/hfs.conf:··················Linux·kernel·modules
73 ······························install·hfs·/bin/true·······························which·implement73 ······························install·hfs·/bin/true·······························which·implement
74 1.1.1.4···Disable·Mounting·of·To·configure·the·system·to·prevent·the·hfs·from·····filesystems·that·are74 1.1.1.4···Disable·Mounting·of·To·configure·the·system·to·prevent·the·hfs·from·····filesystems·that·are
75 ··········hfs·················being·used,·add·the·following·line·to·file·/etc/····not·needed·by·the75 ··········hfs·················being·used,·add·the·following·line·to·file·/etc/····not·needed·by·the
76 ······························modprobe.d/hfs.conf:································local·system·should76 ······························modprobe.d/hfs.conf:································local·system·should
Offset 331, 61 lines modifiedOffset 331, 37 lines modified
331 ······························from·being·used,·add·the·following·line·to·file·/···software.331 ······························from·being·used,·add·the·following·line·to·file·/···software.
332 ······························etc/modprobe.d/usb-storage.conf:332 ······························etc/modprobe.d/usb-storage.conf:
333 ······························blacklist·usb-storage333 ······························blacklist·usb-storage
334 ······························This·will·prevent·the·modprobe·program·from·loading334 ······························This·will·prevent·the·modprobe·program·from·loading
335 ······························the·usb-storage·module,·but·will·not·prevent·an335 ······························the·usb-storage·module,·but·will·not·prevent·an
336 ······························administrator·(or·another·program)·from·using·the336 ······························administrator·(or·another·program)·from·using·the
337 ······························insmod·program·to·load·the·module·manually.337 ······························insmod·program·to·load·the·module·manually.
338 ··················································································Changes·to·any 
339 ··················································································software·components 
340 ··················································································can·have·significant 
341 ··················································································effects·on·the 
342 ··················································································overall·security·of 
343 ··················································································the·operating 
344 ··················································································system.·This 
345 ··················································································requirement·ensures 
346 ··················································································the·software·has·not 
347 ··················································································been·tampered·with 
348 ··················································································and·that·it·has·been 
349 ··················································································provided·by·a 
350 ··················································································trusted·vendor. 
351 ··················································································Accordingly, 
352 ··················································································patches,·service 
353 ··················································································packs,·device 
354 ··················································································drivers,·or 
355 ··················································································operating·system338 ··················································································Verifying·the
356 ··················································································components·must·be 
357 ··················································································signed·with·a339 ··················································································authenticity·of·the
358 ······························The·gpgcheck·option·controls·whether·RPM·packages'··certificate 
359 ······························signatures·are·always·checked·prior·to··············recognized·and 
360 ··········Ensure·gpgcheck·····installation.·To·configure·yum·to·check·package·····approved·by·the 
361 1.2.3·····Enabled·In·Main·yum·signatures·before·installing·them,·ensure·the·······organization. 
362 ··········Configuration·······following·line·appears·in·/etc/yum.conf·in·the······Verifying·the 
363 ······························[main]·section:·····································authenticity·of·the 
364 ······························gpgcheck=1··········································software·prior·to340 ··················································································software·prior·to
365 ··················································································installation341 ··················································································installation
366 ··················································································validates·the342 ··················································································validates·the
367 ··················································································integrity·of·the343 ··················································································integrity·of·the
368 ··················································································patch·or·upgrade344 ··················································································patch·or·upgrade
369 ··················································································received·from·a345 ··················································································received·from·a
370 ··················································································vendor.·This·ensures346 ··················································································vendor.·This·ensures
371 ··················································································the·software·has·not 
372 ··················································································been·tampered·with 
373 ··················································································and·that·it·has·been347 ··········Ensure·gpgcheck·····To·ensure·signature·checking·is·not·disabled·for····the·software·has·not
 348 ··········Enabled·for·All·yum·any·repos,·remove·any·lines·from·files·in·/etc/·····been·tampered·with
 349 1.2.3·····Package·············yum.repos.d·of·the·form:····························and·that·it·has·been
374 ··················································································provided·by·a350 ··········Repositories········gpgcheck=0··········································provided·by·a
375 ··················································································trusted·vendor.351 ··················································································trusted·vendor.
376 ··················································································Self-signed352 ··················································································Self-signed
377 ··················································································certificates·are353 ··················································································certificates·are
378 ··················································································disallowed·by·this354 ··················································································disallowed·by·this
379 ··················································································requirement.355 ··················································································requirement.
380 ··················································································Certificates·used·to356 ··················································································Certificates·used·to
381 ··················································································verify·the·software357 ··················································································verify·the·software
382 ··················································································must·be·from·an358 ··················································································must·be·from·an
383 ··················································································approved·Certificate359 ··················································································approved·Certificate
Max diff block lines reached; 377178/390199 bytes (96.66%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/table-rhel7-cuirefs.html
Ordering differences only
    
Offset 41, 104 lines modifiedOffset 41, 14 lines modified
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td>47 ······<td>3.1.1<br/>3.1.5</td>
48 ······<td>Disable·SSH·Root·Login</td> 
49 ······<td·xml:lang="en-US"> 
50 ········The·root·user·should·never·be·allowed·to·login·to·a 
51 system·directly·over·a·network. 
52 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
53 <tt>/etc/ssh/sshd_config</tt>: 
  
54 <pre>PermitRootLogin·no</pre> 
55 ······</td> 
56 ······<td·xml:lang="en-US"> 
57 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
58 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
59 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
60 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
61 direct·attack·attempts·on·root's·password. 
62 ······</td> 
63 ····</tr> 
64 ····<tr> 
65 ······<td>3.1.1</td> 
66 ······<td>Disable·GDM·Guest·Login</td> 
67 ······<td·xml:lang="en-US"> 
68 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials 
69 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials 
70 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable 
71 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in 
72 the·<tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
73 <pre>[daemon] 
74 TimedLoginEnable=false</pre> 
75 ······</td> 
76 ······<td·xml:lang="en-US"> 
77 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
78 system·security. 
79 ······</td> 
80 ····</tr> 
81 ····<tr> 
82 ······<td>3.1.1<br/>3.4.5</td> 
83 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td> 
84 ······<td·xml:lang="en-US"> 
85 ········Emergency·mode·is·intended·as·a·system·recovery 
86 method,·providing·a·single·user·root·access·to·the·system 
87 during·a·failed·boot·sequence. 
88 <br·/><br·/> 
89 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set 
90 in·<tt>/usr/lib/systemd/system/emergency.service</tt>. 
91 ······</td> 
92 ······<td·xml:lang="en-US"> 
93 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security 
94 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented 
95 by·configuring·the·bootloader·password. 
96 ······</td> 
97 ····</tr> 
98 ····<tr> 
99 ······<td>3.1.1<br/>3.1.5</td> 
100 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td> 
101 ······<td·xml:lang="en-US"> 
102 ········If·an·account·is·configured·for·password·authentication 
103 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log 
104 into·the·account·without·authentication.·Remove·any·instances·of·the 
105 <tt>nullok</tt>·in 
  
106 <tt>/etc/pam.d/system-auth</tt>·and 
107 <tt>/etc/pam.d/password-auth</tt> 
  
108 to·prevent·logins·with·empty·passwords. 
109 ······</td> 
110 ······<td·xml:lang="en-US"> 
111 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and 
112 run·commands·with·the·privileges·of·that·account.·Accounts·with 
113 empty·passwords·should·never·be·used·in·operational·environments. 
114 ······</td> 
115 ····</tr> 
116 ····<tr> 
117 ······<td>3.1.1<br/>3.1.5</td> 
118 ······<td>Restrict·Serial·Port·Root·Logins</td> 
119 ······<td·xml:lang="en-US"> 
120 ········To·restrict·root·logins·on·serial·ports, 
121 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
122 <pre>ttyS0 
123 ttyS1</pre> 
124 ······</td> 
125 ······<td·xml:lang="en-US"> 
126 ········Preventing·direct·root·login·to·serial·port·interfaces 
127 helps·ensure·accountability·for·actions·taken·on·the·systems 
128 using·the·root·account. 
129 ······</td> 
130 ····</tr> 
131 ····<tr> 
132 ······<td>3.1.1<br/>3.1.5</td> 
133 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>48 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>
134 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
135 ········Disallow·SSH·login·with·empty·passwords.50 ········Disallow·SSH·login·with·empty·passwords.
136 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate51 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate
137 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.52 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.
138 <br·/>53 <br·/>
139 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,54 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,
Offset 189, 14 lines modifiedOffset 99, 40 lines modified
189 ······</td>99 ······</td>
190 ······<td·xml:lang="en-US">100 ······<td·xml:lang="en-US">
191 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating101 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
192 system·security.102 system·security.
193 ······</td>103 ······</td>
194 ····</tr>104 ····</tr>
195 ····<tr>105 ····<tr>
 106 ······<td>3.1.1<br/>3.1.6</td>
 107 ······<td>Direct·root·Logins·Not·Allowed</td>
 108 ······<td·xml:lang="en-US">
 109 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators
 110 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file.
 111 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does
 112 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the
 113 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous
 114 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in
 115 plain·text·over·the·network.·By·default,·Red·Hat·Enterprise·Linux·7's
 116 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console
 117 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the
 118 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this
 119 file·by·typing·the·following·command:
 120 <pre>
Max diff block lines reached; 450329/455917 bytes (98.77%) of diff not shown.
620 KB
html2text {}
    
Offset 1, 48 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of·Red1 Rules·with·NIST-800-171·Reference·in·Guide·to·the·Secure·Configuration·of·Red
2 Hat·Enterprise·Linux·72 Hat·Enterprise·Linux·7
  
  
3 ······························································································Even·though·the·communications·channel·may·be 
4 ·······································The·root·user·should·never·be·allowed·to·login·to·a····encrypted,·an·additional·layer·of·security·is 
5 ·······································system·directly·over·a·network.·To·disable·root·login··gained·by·extending·the·policy·of·not·logging 
6 3.1.1···Disable·SSH·Root·Login·········via·SSH,·add·or·correct·the·following·line·in·/etc/····directly·on·as·root.·In·addition,·logging·in 
7 3.1.5··································ssh/sshd_config:·······································with·a·user-specific·account·provides 
8 ·······································PermitRootLogin·no·····································individual·accountability·of·actions·performed 
9 ······························································································on·the·system·and·also·helps·to·minimize 
10 ······························································································direct·attack·attempts·on·root's·password. 
11 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to 
12 ·······································login·without·credentials·which·can·be·useful·for 
13 ·······································public·kiosk·scenarios.·Allowing·users·to·login 
14 ·······································without·credentials·or·"guest"·account·access·has······Failure·to·restrict·system·access·to 
15 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users·negatively·impacts 
16 ·······································disable·timed·logins·or·guest·account·access,·set·the··operating·system·security. 
17 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/ 
18 ·······································etc/gdm/custom.conf.·For·example: 
19 ·······································[daemon] 
20 ·······································TimedLoginEnable=false 
21 ·······································Emergency·mode·is·intended·as·a·system·recovery 
22 ·······································method,·providing·a·single·user·root·access·to·the·····This·prevents·attackers·with·physical·access 
23 3.1.1···Require·Authentication·for·····system·during·a·failed·boot·sequence.··················from·trivially·bypassing·security·on·the 
24 3.4.5···Emergency·Systemd·Target······························································machine·and·gaining·root·access.·Such·accesses 
25 ·······································By·default,·Emergency·mode·is·protected·by·requiring·a·are·further·prevented·by·configuring·the 
26 ·······································password·and·is·set·in·/usr/lib/systemd/system/········bootloader·password. 
27 ·······································emergency.service. 
28 ·······································If·an·account·is·configured·for·password···············If·an·account·has·an·empty·password,·anyone 
29 ·······································authentication·but·does·not·have·an·assigned·password,·could·log·in·and·run·commands·with·the 
30 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····privileges·of·that·account.·Accounts·with 
31 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··empty·passwords·should·never·be·used·in 
32 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·operational·environments. 
33 ·······································prevent·logins·with·empty·passwords. 
34 ·······································To·restrict·root·logins·on·serial·ports,·ensure·lines··Preventing·direct·root·login·to·serial·port 
35 3.1.1···Restrict·Serial·Port·Root······of·this·form·do·not·appear·in·/etc/securetty:··········interfaces·helps·ensure·accountability·for 
36 3.1.5···Logins·························ttyS0··················································actions·taken·on·the·systems·using·the·root 
37 ·······································ttyS1··················································account. 
38 ·······································Disallow·SSH·login·with·empty·passwords.·The·default3 ·······································Disallow·SSH·login·with·empty·passwords.·The·default
39 ·······································SSH·configuration·disables·logins·with·empty4 ·······································SSH·configuration·disables·logins·with·empty
40 ·······································passwords.·The·appropriate·configuration·is·used·if·no5 ·······································passwords.·The·appropriate·configuration·is·used·if·no
41 ·······································value·is·set·for·PermitEmptyPasswords.6 ·······································value·is·set·for·PermitEmptyPasswords.
42 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····Configuring·this·setting·for·the·SSH·daemon7 ·······································To·explicitly·disallow·SSH·login·from·accounts·with····Configuring·this·setting·for·the·SSH·daemon
43 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··provides·additional·assurance·that·remote8 3.1.1···Disable·SSH·Access·via·Empty···empty·passwords,·add·or·correct·the·following·line·in··provides·additional·assurance·that·remote
44 3.1.5···Passwords······················/etc/ssh/sshd_config:··································login·via·SSH·will·require·a·password,·even·in9 3.1.5···Passwords······················/etc/ssh/sshd_config:··································login·via·SSH·will·require·a·password,·even·in
Offset 64, 30 lines modifiedOffset 29, 14 lines modified
64 ·······································authenticate·themselves·to·the·system·that·they·are····Failure·to·restrict·system·access·to29 ·······································authenticate·themselves·to·the·system·that·they·are····Failure·to·restrict·system·access·to
65 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users·negatively·impacts30 3.1.1···Disable·GDM·Automatic·Login····authorized·to·use.·To·disable·user·ability·to··········authenticated·users·negatively·impacts
66 ·······································automatically·login·to·the·system,·set·the·············operating·system·security.31 ·······································automatically·login·to·the·system,·set·the·············operating·system·security.
67 ·······································AutomaticLoginEnable·to·false·in·the·[daemon]·section32 ·······································AutomaticLoginEnable·to·false·in·the·[daemon]·section
68 ·······································in·/etc/gdm/custom.conf.·For·example:33 ·······································in·/etc/gdm/custom.conf.·For·example:
69 ·······································[daemon]34 ·······································[daemon]
70 ·······································AutomaticLoginEnable=false35 ·······································AutomaticLoginEnable=false
71 ·······································If·any·account·other·than·root·has·a·UID·of·0,·this 
72 ·······································misconfiguration·should·be·investigated·and·the········An·account·has·root·authority·if·it·has·a·UID 
73 ·······································accounts·other·than·root·should·be·removed·or·have·····of·0.·Multiple·accounts·with·a·UID·of·0·afford 
74 3.1.1··································their·UID·changed.·····································more·opportunity·for·potential·intruders·to 
75 3.1.5···Verify·Only·Root·Has·UID·0·····If·the·account·is·associated·with·system·commands·or···guess·a·password·for·a·privileged·account. 
76 ·······································applications·the·UID·should·be·changed·to·one·greater··Proper·configuration·of·sudo·is·recommended·to 
77 ·······································than·"0"·but·less·than·"1000."·Otherwise·assign·a·UID··afford·multiple·system·administrators·access 
78 ·······································greater·than·"1000"·that·has·not·already·been··········to·root·privileges·in·an·accountable·manner. 
79 ·······································assigned. 
80 ·······································To·restrict·root·logins·through·the·(deprecated) 
81 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··Preventing·direct·root·login·to·virtual 
82 3.1.1···Restrict·Virtual·Console·Root··not·appear·in·/etc/securetty:··························console·devices·helps·ensure·accountability 
83 3.1.5···Logins·························vc/1···················································for·actions·taken·on·the·system·using·the·root 
84 ·······································vc/2···················································account. 
85 ·······································vc/3 
86 ·······································vc/4 
87 ·······································To·further·limit·access·to·the·root·account,36 ·······································To·further·limit·access·to·the·root·account,
88 ·······································administrators·can·disable·root·logins·at·the·console37 ·······································administrators·can·disable·root·logins·at·the·console
89 ·······································by·editing·the·/etc/securetty·file.·This·file·lists38 ·······································by·editing·the·/etc/securetty·file.·This·file·lists
90 ·······································all·devices·the·root·user·is·allowed·to·login·to.·If39 ·······································all·devices·the·root·user·is·allowed·to·login·to.·If
91 ·······································the·file·does·not·exist·at·all,·the·root·user·can40 ·······································the·file·does·not·exist·at·all,·the·root·user·can
92 ·······································login·through·any·communication·device·on·the·system,··Disabling·direct·root·logins·ensures·proper41 ·······································login·through·any·communication·device·on·the·system,··Disabling·direct·root·logins·ensures·proper
93 ·······································whether·via·the·console·or·via·a·raw·network···········accountability·and·multifactor·authentication42 ·······································whether·via·the·console·or·via·a·raw·network···········accountability·and·multifactor·authentication
Offset 97, 47 lines modifiedOffset 46, 70 lines modified
97 ·······································Enterprise·Linux·7's·/etc/securetty·file·only·allows···FISMA·Low·and·FISMA·Moderate·systems.46 ·······································Enterprise·Linux·7's·/etc/securetty·file·only·allows···FISMA·Low·and·FISMA·Moderate·systems.
98 ·······································the·root·user·to·login·at·the·console·physically47 ·······································the·root·user·to·login·at·the·console·physically
99 ·······································attached·to·the·system.·To·prevent·root·from·logging48 ·······································attached·to·the·system.·To·prevent·root·from·logging
100 ·······································in,·remove·the·contents·of·this·file.·To·prevent49 ·······································in,·remove·the·contents·of·this·file.·To·prevent
101 ·······································direct·root·logins,·remove·the·contents·of·this·file50 ·······································direct·root·logins,·remove·the·contents·of·this·file
102 ·······································by·typing·the·following·command:51 ·······································by·typing·the·following·command:
103 ·······································$·sudo·echo·>·/etc/securetty52 ·······································$·sudo·echo·>·/etc/securetty
 53 ·······································If·any·account·other·than·root·has·a·UID·of·0,·this
 54 ·······································misconfiguration·should·be·investigated·and·the········An·account·has·root·authority·if·it·has·a·UID
 55 ·······································accounts·other·than·root·should·be·removed·or·have·····of·0.·Multiple·accounts·with·a·UID·of·0·afford
 56 3.1.1··································their·UID·changed.·····································more·opportunity·for·potential·intruders·to
 57 3.1.5···Verify·Only·Root·Has·UID·0·····If·the·account·is·associated·with·system·commands·or···guess·a·password·for·a·privileged·account.
 58 ·······································applications·the·UID·should·be·changed·to·one·greater··Proper·configuration·of·sudo·is·recommended·to
 59 ·······································than·"0"·but·less·than·"1000."·Otherwise·assign·a·UID··afford·multiple·system·administrators·access
 60 ·······································greater·than·"1000"·that·has·not·already·been··········to·root·privileges·in·an·accountable·manner.
 61 ·······································assigned.
 62 ·······································To·restrict·root·logins·through·the·(deprecated)
 63 ·······································virtual·console·devices,·ensure·lines·of·this·form·do··Preventing·direct·root·login·to·virtual
 64 3.1.1···Restrict·Virtual·Console·Root··not·appear·in·/etc/securetty:··························console·devices·helps·ensure·accountability
 65 3.1.5···Logins·························vc/1···················································for·actions·taken·on·the·system·using·the·root
 66 ·······································vc/2···················································account.
 67 ·······································vc/3
 68 ·······································vc/4
 69 ·······································The·GNOME·Display·Manager·(GDM)·can·allow·users·to
 70 ·······································login·without·credentials·which·can·be·useful·for
 71 ·······································public·kiosk·scenarios.·Allowing·users·to·login
 72 ·······································without·credentials·or·"guest"·account·access·has······Failure·to·restrict·system·access·to
 73 3.1.1···Disable·GDM·Guest·Login········inherent·security·risks·and·should·be·disabled.·To·do··authenticated·users·negatively·impacts
 74 ·······································disable·timed·logins·or·guest·account·access,·set·the··operating·system·security.
 75 ·······································TimedLoginEnable·to·false·in·the·[daemon]·section·in·/
 76 ·······································etc/gdm/custom.conf.·For·example:
 77 ·······································[daemon]
 78 ·······································TimedLoginEnable=false
 79 ······························································································Even·though·the·communications·channel·may·be
 80 ·······································The·root·user·should·never·be·allowed·to·login·to·a····encrypted,·an·additional·layer·of·security·is
 81 ·······································system·directly·over·a·network.·To·disable·root·login··gained·by·extending·the·policy·of·not·logging
 82 3.1.1···Disable·SSH·Root·Login·········via·SSH,·add·or·correct·the·following·line·in·/etc/····directly·on·as·root.·In·addition,·logging·in
 83 3.1.5··································ssh/sshd_config:·······································with·a·user-specific·account·provides
 84 ·······································PermitRootLogin·no·····································individual·accountability·of·actions·performed
 85 ······························································································on·the·system·and·also·helps·to·minimize
 86 ······························································································direct·attack·attempts·on·root's·password.
 87 ·······································If·an·account·is·configured·for·password···············If·an·account·has·an·empty·password,·anyone
 88 ·······································authentication·but·does·not·have·an·assigned·password,·could·log·in·and·run·commands·with·the
 89 3.1.1···Prevent·Login·to·Accounts·With·it·may·be·possible·to·log·into·the·account·without·····privileges·of·that·account.·Accounts·with
 90 3.1.5···Empty·Password·················authentication.·Remove·any·instances·of·the·nullok·in··empty·passwords·should·never·be·used·in
 91 ·······································/etc/pam.d/system-auth·and·/etc/pam.d/password-auth·to·operational·environments.
 92 ·······································prevent·logins·with·empty·passwords.
Max diff block lines reached; 618451/634590 bytes (97.46%) of diff not shown.
10.1 KB
./usr/share/doc/ssg-nondebian/table-rhel7-nistrefs-stig.html
    
Offset 7676, 19 lines modifiedOffset 7676, 19 lines modified
0001dfb0:·2070·7265·7669·6f75·7320·7061·7373·776f···previous·passwo0001dfb0:·2070·7265·7669·6f75·7320·7061·7373·776f···previous·passwo
0001dfc0:·7264·7320·6865·6c70·7320·656e·7375·7265··rds·helps·ensure0001dfc0:·7264·7320·6865·6c70·7320·656e·7375·7265··rds·helps·ensure
0001dfd0:·2074·6861·7420·6120·636f·6d70·726f·6d69···that·a·compromi0001dfd0:·2074·6861·7420·6120·636f·6d70·726f·6d69···that·a·compromi
0001dfe0:·7365·6420·7061·7373·776f·7264·2069·7320··sed·password·is·0001dfe0:·7365·6420·7061·7373·776f·7264·2069·7320··sed·password·is·
0001dff0:·6e6f·7420·7265·2d75·7365·6420·6279·2061··not·re-used·by·a0001dff0:·6e6f·7420·7265·2d75·7365·6420·6279·2061··not·re-used·by·a
0001e000:·2075·7365·722e·0a20·203c·2f74·643e·0a20···user..··</td>.·0001e000:·2075·7365·722e·0a20·203c·2f74·643e·0a20···user..··</td>.·
0001e010:·203c·7464·3e76·6172·5f70·6173·7377·6f72···<td>var_passwor0001e010:·203c·7464·3e76·6172·5f70·6173·7377·6f72···<td>var_passwor
 0001e020:·645f·7061·6d5f·7265·6d65·6d62·6572·3d35··d_pam_remember=5
 0001e030:·3c62·722f·3e76·6172·5f70·6173·7377·6f72··<br/>var_passwor
0001e020:·645f·7061·6d5f·7265·6d65·6d62·6572·5f63··d_pam_remember_c0001e040:·645f·7061·6d5f·7265·6d65·6d62·6572·5f63··d_pam_remember_c
0001e030:·6f6e·7472·6f6c·5f66·6c61·673d·7265·7175··ontrol_flag=requ0001e050:·6f6e·7472·6f6c·5f66·6c61·673d·7265·7175··ontrol_flag=requ
0001e040:·6973·6974·653c·6272·2f3e·7661·725f·7061··isite<br/>var_pa 
0001e050:·7373·776f·7264·5f70·616d·5f72·656d·656d··ssword_pam_remem 
0001e060:·6265·723d·353c·2f74·643e·0a3c·2f74·723e··ber=5</td>.</tr>0001e060:·6973·6974·653c·2f74·643e·0a3c·2f74·723e··isite</td>.</tr>
0001e070:·0a3c·7472·3e0a·2020·3c74·643e·4941·2d35··.<tr>.··<td>IA-50001e070:·0a3c·7472·3e0a·2020·3c74·643e·4941·2d35··.<tr>.··<td>IA-5
0001e080:·2866·293c·6272·2f3e·4941·2d35·2831·2928··(f)<br/>IA-5(1)(0001e080:·2866·293c·6272·2f3e·4941·2d35·2831·2928··(f)<br/>IA-5(1)(
0001e090:·6529·3c2f·7464·3e0a·2020·3c74·643e·4343··e)</td>.··<td>CC0001e090:·6529·3c2f·7464·3e0a·2020·3c74·643e·4343··e)</td>.··<td>CC
0001e0a0:·452d·3833·3437·392d·363c·2f74·643e·0a20··E-83479-6</td>.·0001e0a0:·452d·3833·3437·392d·363c·2f74·643e·0a20··E-83479-6</td>.·
0001e0b0:·203c·7464·3e4c·696d·6974·2050·6173·7377···<td>Limit·Passw0001e0b0:·203c·7464·3e4c·696d·6974·2050·6173·7377···<td>Limit·Passw
0001e0c0:·6f72·6420·5265·7573·653a·2073·7973·7465··ord·Reuse:·syste0001e0c0:·6f72·6420·5265·7573·653a·2073·7973·7465··ord·Reuse:·syste
0001e0d0:·6d2d·6175·7468·3c2f·7464·3e0a·2020·3c74··m-auth</td>.··<t0001e0d0:·6d2d·6175·7468·3c2f·7464·3e0a·2020·3c74··m-auth</td>.··<t
Offset 7734, 18 lines modifiedOffset 7734, 18 lines modified
0001e350:·776f·7264·7320·6865·6c70·7320·656e·7375··words·helps·ensu0001e350:·776f·7264·7320·6865·6c70·7320·656e·7375··words·helps·ensu
0001e360:·7265·2074·6861·7420·6120·636f·6d70·726f··re·that·a·compro0001e360:·7265·2074·6861·7420·6120·636f·6d70·726f··re·that·a·compro
0001e370:·6d69·7365·6420·7061·7373·776f·7264·2069··mised·password·i0001e370:·6d69·7365·6420·7061·7373·776f·7264·2069··mised·password·i
0001e380:·7320·6e6f·7420·7265·2d75·7365·6420·6279··s·not·re-used·by0001e380:·7320·6e6f·7420·7265·2d75·7365·6420·6279··s·not·re-used·by
0001e390:·2061·2075·7365·722e·0a20·203c·2f74·643e···a·user..··</td>0001e390:·2061·2075·7365·722e·0a20·203c·2f74·643e···a·user..··</td>
0001e3a0:·0a20·203c·7464·3e76·6172·5f70·6173·7377··.··<td>var_passw0001e3a0:·0a20·203c·7464·3e76·6172·5f70·6173·7377··.··<td>var_passw
0001e3b0:·6f72·645f·7061·6d5f·7265·6d65·6d62·6572··ord_pam_remember0001e3b0:·6f72·645f·7061·6d5f·7265·6d65·6d62·6572··ord_pam_remember
 0001e3c0:·3d35·3c62·722f·3e76·6172·5f70·6173·7377··=5<br/>var_passw
 0001e3d0:·6f72·645f·7061·6d5f·7265·6d65·6d62·6572··ord_pam_remember
0001e3c0:·5f63·6f6e·7472·6f6c·5f66·6c61·673d·7265··_control_flag=re0001e3e0:·5f63·6f6e·7472·6f6c·5f66·6c61·673d·7265··_control_flag=re
 0001e3f0:·7175·6973·6974·653c·2f74·643e·0a3c·2f74··quisite</td>.</t
0001e3d0:·7175·6973·6974·653c·6272·2f3e·7661·725f··quisite<br/>var_ 
0001e3e0:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem 
0001e3f0:·656d·6265·723d·353c·2f74·643e·0a3c·2f74··ember=5</td>.</t 
0001e400:·723e·0a3c·7472·3e0a·2020·3c74·643e·4941··r>.<tr>.··<td>IA0001e400:·723e·0a3c·7472·3e0a·2020·3c74·643e·4941··r>.<tr>.··<td>IA
0001e410:·2d35·2863·293c·6272·2f3e·4941·2d35·2831··-5(c)<br/>IA-5(10001e410:·2d35·2863·293c·6272·2f3e·4941·2d35·2831··-5(c)<br/>IA-5(1
0001e420:·2928·6129·3c62·722f·3e43·4d2d·3628·6129··)(a)<br/>CM-6(a)0001e420:·2928·6129·3c62·722f·3e43·4d2d·3628·6129··)(a)<br/>CM-6(a)
0001e430:·3c62·722f·3e49·412d·3528·3429·3c2f·7464··<br/>IA-5(4)</td0001e430:·3c62·722f·3e49·412d·3528·3429·3c2f·7464··<br/>IA-5(4)</td
0001e440:·3e0a·2020·3c74·643e·4343·452d·3237·3230··>.··<td>CCE-27200001e440:·3e0a·2020·3c74·643e·4343·452d·3237·3230··>.··<td>CCE-2720
0001e450:·302d·353c·2f74·643e·0a20·203c·7464·3e45··0-5</td>.··<td>E0001e450:·302d·353c·2f74·643e·0a20·203c·7464·3e45··0-5</td>.··<td>E
0001e460:·6e73·7572·6520·5041·4d20·456e·666f·7263··nsure·PAM·Enforc0001e460:·6e73·7572·6520·5041·4d20·456e·666f·7263··nsure·PAM·Enforc
Offset 8578, 18 lines modifiedOffset 8578, 18 lines modified
00021810:·7573·6520·7468·6520·696e·666f·726d·6174··use·the·informat00021810:·7573·6520·7468·6520·696e·666f·726d·6174··use·the·informat
00021820:·696f·6e20·746f·2070·6f74·656e·7469·616c··ion·to·potential00021820:·696f·6e20·746f·2070·6f74·656e·7469·616c··ion·to·potential
00021830:·6c79·2063·6f6d·7072·6f6d·6973·6520·7468··ly·compromise·th00021830:·6c79·2063·6f6d·7072·6f6d·6973·6520·7468··ly·compromise·th
00021840:·6520·696e·7465·6772·6974·7920·6f66·2074··e·integrity·of·t00021840:·6520·696e·7465·6772·6974·7920·6f66·2074··e·integrity·of·t
00021850:·6865·2073·7973·7465·6d20·616e·640a·6e65··he·system·and.ne00021850:·6865·2073·7973·7465·6d20·616e·640a·6e65··he·system·and.ne
00021860:·7477·6f72·6b28·7329·2e0a·2020·3c2f·7464··twork(s)..··</td00021860:·7477·6f72·6b28·7329·2e0a·2020·3c2f·7464··twork(s)..··</td
00021870:·3e0a·2020·3c74·643e·7661·725f·736e·6d70··>.··<td>var_snmp00021870:·3e0a·2020·3c74·643e·7661·725f·736e·6d70··>.··<td>var_snmp
00021880:·645f·7277·5f73·7472·696e·673d·6368·616e··d_rw_string=chan00021880:·645f·726f·5f73·7472·696e·673d·6368·616e··d_ro_string=chan
00021890:·6765·6d65·7277·3c62·722f·3e76·6172·5f73··gemerw<br/>var_s00021890:·6765·6d65·726f·3c62·722f·3e76·6172·5f73··gemero<br/>var_s
000218a0:·6e6d·7064·5f72·6f5f·7374·7269·6e67·3d63··nmpd_ro_string=c000218a0:·6e6d·7064·5f72·775f·7374·7269·6e67·3d63··nmpd_rw_string=c
000218b0:·6861·6e67·656d·6572·6f3c·2f74·643e·0a3c··hangemero</td>.<000218b0:·6861·6e67·656d·6572·773c·2f74·643e·0a3c··hangemerw</td>.<
000218c0:·2f74·723e·0a3c·7472·3e0a·2020·3c74·643e··/tr>.<tr>.··<td>000218c0:·2f74·723e·0a3c·7472·3e0a·2020·3c74·643e··/tr>.<tr>.··<td>
000218d0:·434d·2d35·2831·293c·6272·2f3e·4155·2d37··CM-5(1)<br/>AU-7000218d0:·434d·2d35·2831·293c·6272·2f3e·4155·2d37··CM-5(1)<br/>AU-7
000218e0:·2861·293c·6272·2f3e·4155·2d37·2862·293c··(a)<br/>AU-7(b)<000218e0:·2861·293c·6272·2f3e·4155·2d37·2862·293c··(a)<br/>AU-7(b)<
000218f0:·6272·2f3e·4155·2d38·2862·293c·6272·2f3e··br/>AU-8(b)<br/>000218f0:·6272·2f3e·4155·2d38·2862·293c·6272·2f3e··br/>AU-8(b)<br/>
00021900:·4155·2d31·3228·3329·3c62·722f·3e41·432d··AU-12(3)<br/>AC-00021900:·4155·2d31·3228·3329·3c62·722f·3e41·432d··AU-12(3)<br/>AC-
00021910:·3628·3929·3c2f·7464·3e0a·2020·3c74·643e··6(9)</td>.··<td>00021910:·3628·3929·3c2f·7464·3e0a·2020·3c74·643e··6(9)</td>.··<td>
00021920:·4343·452d·3833·3535·352d·333c·2f74·643e··CCE-83555-3</td>00021920:·4343·452d·3833·3535·352d·333c·2f74·643e··CCE-83555-3</td>
5.37 KB
html2text {}
    
Offset 1669, 30 lines modifiedOffset 1669, 30 lines modified
1669 ··················································································search·space.1669 ··················································································search·space.
1670 ······································Do·not·allow·users·to·reuse·recent1670 ······································Do·not·allow·users·to·reuse·recent
1671 ······································passwords.·This·can·be·accomplished·by1671 ······································passwords.·This·can·be·accomplished·by
1672 ······································using·the·remember·option·for·the1672 ······································using·the·remember·option·for·the
1673 ······································pam_pwhistory·PAM·module.1673 ······································pam_pwhistory·PAM·module.
  
1674 IA-5(f)·CCE-··························In·the·file·/etc/pam.d/password-auth,·make1674 IA-5(f)·CCE-··························In·the·file·/etc/pam.d/password-auth,·make
1675 IA-5(1)·83476-·Limit·Password·Reuse:··sure·the·parameter·remember·is·present·and··Preventing·re-use·of·previous·passwords·helps·ensure·that·a····var_password_pam_remember_control_flag=requisite1675 IA-5(1)·83476-·Limit·Password·Reuse:··sure·the·parameter·remember·is·present·and··Preventing·re-use·of·previous·passwords·helps·ensure·that·a····var_password_pam_remember=5
1676 (e)·····2······password-auth··········it·has·a·value·equal·to·or·greater·than·5.··compromised·password·is·not·re-used·by·a·user.·················var_password_pam_remember=51676 (e)·····2······password-auth··········it·has·a·value·equal·to·or·greater·than·5.··compromised·password·is·not·re-used·by·a·user.·················var_password_pam_remember_control_flag=requisite
1677 ······································For·example:1677 ······································For·example:
1678 ······································password·control_flag·pam_pwhistory.so1678 ······································password·control_flag·pam_pwhistory.so
1679 ······································...existing_options...·remember=51679 ······································...existing_options...·remember=5
1680 ······································use_authtok1680 ······································use_authtok
1681 ······································control_flag·should·be·one·of·the·next1681 ······································control_flag·should·be·one·of·the·next
1682 ······································values:·requisite1682 ······································values:·requisite
1683 ······································Do·not·allow·users·to·reuse·recent1683 ······································Do·not·allow·users·to·reuse·recent
1684 ······································passwords.·This·can·be·accomplished·by1684 ······································passwords.·This·can·be·accomplished·by
1685 ······································using·the·remember·option·for·the1685 ······································using·the·remember·option·for·the
1686 ······································pam_pwhistory·PAM·module.1686 ······································pam_pwhistory·PAM·module.
  
1687 IA-5(f)·CCE-··························In·the·file·/etc/pam.d/system-auth,·make1687 IA-5(f)·CCE-··························In·the·file·/etc/pam.d/system-auth,·make
1688 IA-5(1)·83479-·Limit·Password·Reuse:··sure·the·parameter·remember·is·present·and··Preventing·re-use·of·previous·passwords·helps·ensure·that·a····var_password_pam_remember_control_flag=requisite1688 IA-5(1)·83479-·Limit·Password·Reuse:··sure·the·parameter·remember·is·present·and··Preventing·re-use·of·previous·passwords·helps·ensure·that·a····var_password_pam_remember=5
1689 (e)·····6······system-auth············it·has·a·value·equal·to·or·greater·than·5···compromised·password·is·not·re-used·by·a·user.·················var_password_pam_remember=51689 (e)·····6······system-auth············it·has·a·value·equal·to·or·greater·than·5···compromised·password·is·not·re-used·by·a·user.·················var_password_pam_remember_control_flag=requisite
1690 ······································For·example:1690 ······································For·example:
1691 ······································password·control_flag·pam_pwhistory.so1691 ······································password·control_flag·pam_pwhistory.so
1692 ······································...existing_options...·remember=51692 ······································...existing_options...·remember=5
1693 ······································use_authtok1693 ······································use_authtok
1694 ······································control_flag·should·be·one·of·the·next1694 ······································control_flag·should·be·one·of·the·next
1695 ······································values:·requisite1695 ······································values:·requisite
1696 ······································The·pam_pwquality·module's·ucredit=·········Use·of·a·complex·password·helps·to·increase·the·time·and1696 ······································The·pam_pwquality·module's·ucredit=·········Use·of·a·complex·password·helps·to·increase·the·time·and
Offset 1839, 16 lines modifiedOffset 1839, 16 lines modified
1839 ······································This·will·help·ensure·when·local·users······configuration·option·ensures·the·use·of·a·strong·hashing1839 ······································This·will·help·ensure·when·local·users······configuration·option·ensures·the·use·of·a·strong·hashing
1840 ······································change·their·passwords,·hashes·for·the·new··algorithm·that·makes·password·cracking·attacks·more·difficult.1840 ······································change·their·passwords,·hashes·for·the·new··algorithm·that·makes·password·cracking·attacks·more·difficult.
1841 ······································passwords·will·be·generated·using·the·SHA-1841 ······································passwords·will·be·generated·using·the·SHA-
1842 ······································512·algorithm.·This·is·the·default.1842 ······································512·algorithm.·This·is·the·default.
1843 ······································Edit·/etc/snmp/snmpd.conf,·remove·or·change1843 ······································Edit·/etc/snmp/snmpd.conf,·remove·or·change
1844 ······································the·default·community·strings·of·public·and·Whether·active·or·not,·default·simple·network·management1844 ······································the·default·community·strings·of·public·and·Whether·active·or·not,·default·simple·network·management
1845 ········CCE-··························private.·This·profile·configures·new·read-··protocol·(SNMP)·community·strings·must·be·changed·to·maintain1845 ········CCE-··························private.·This·profile·configures·new·read-··protocol·(SNMP)·community·strings·must·be·changed·to·maintain
1846 IA-5(e)·27386-·Ensure·Default·SNMP····only·community·string·to·changemero·and·····security.·If·the·service·is·running·with·the·default···········var_snmpd_rw_string=changemerw1846 IA-5(e)·27386-·Ensure·Default·SNMP····only·community·string·to·changemero·and·····security.·If·the·service·is·running·with·the·default···········var_snmpd_ro_string=changemero
1847 ········2······Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·then·anyone·can·gather·data·about·the·system···var_snmpd_ro_string=changemero1847 ········2······Password·Is·Not·Used···read-write·community·string·to·changemerw.··authenticators,·then·anyone·can·gather·data·about·the·system···var_snmpd_rw_string=changemerw
1848 ······································Once·the·default·community·strings·have·····and·the·network·and·use·the·information·to·potentially1848 ······································Once·the·default·community·strings·have·····and·the·network·and·use·the·information·to·potentially
1849 ······································been·changed,·restart·the·SNMP·service:·····compromise·the·integrity·of·the·system·and·network(s).1849 ······································been·changed,·restart·the·SNMP·service:·····compromise·the·integrity·of·the·system·and·network(s).
1850 ······································$·sudo·service·snmpd·restart1850 ······································$·sudo·service·snmpd·restart
1851 ······································Verify·the·system·generates·an·audit·record1851 ······································Verify·the·system·generates·an·audit·record
1852 ······································when·privileged·functions·are·executed.·If1852 ······································when·privileged·functions·are·executed.·If
1853 ······································audit·is·using·the·"auditctl"·tool·to·load1853 ······································audit·is·using·the·"auditctl"·tool·to·load
1854 ······································the·rules,·run·the·following·command:1854 ······································the·rules,·run·the·following·command:
6.4 MB
./usr/share/doc/ssg-nondebian/table-rhel7-nistrefs.html
    
Offset 67, 9969 lines modifiedOffset 67, 9969 lines modified
00000420:·696f·6e3c·2f74·683e·0a20·2020·203c·7468··ion</th>.····<th00000420:·696f·6e3c·2f74·683e·0a20·2020·203c·7468··ion</th>.····<th
00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.
00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb
00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····
00000460:·2020·3c74·643e·4155·2d32·2864·293c·6272····<td>AU-2(d)<br00000460:·2020·3c74·643e·4155·2d32·2864·293c·6272····<td>AU-2(d)<br
00000470:·2f3e·4155·2d31·3228·6329·3c62·722f·3e43··/>AU-12(c)<br/>C00000470:·2f3e·4155·2d31·3228·6329·3c62·722f·3e43··/>AU-12(c)<br/>C
Diff chunk too large, falling back to line-by-line diff (1194 lines added, 1194 lines removed)
00000480:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····00000480:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····
00000490:·2020·3c74·643e·5265·636f·7264·2055·6e73····<td>Record·Uns00000490:·2020·3c74·643e·5265·636f·7264·2045·7665····<td>Record·Eve
000004a0:·7563·6365·7373·6675·6c20·5065·726d·6973··uccessful·Permis000004a0:·6e74·7320·7468·6174·204d·6f64·6966·7920··nts·that·Modify·
000004b0:·7369·6f6e·2043·6861·6e67·6573·2074·6f20··sion·Changes·to·000004b0:·7468·6520·5379·7374·656d·2773·2044·6973··the·System's·Dis
000004c0:·4669·6c65·7320·2d20·6663·686d·6f64·3c2f··Files·-·fchmod</000004c0:·6372·6574·696f·6e61·7279·2041·6363·6573··cretionary·Acces
000004d0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm000004d0:·7320·436f·6e74·726f·6c73·202d·2073·6574··s·Controls·-·set
000004e0:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.000004e0:·7861·7474·723c·2f74·643e·0a20·2020·2020··xattr</td>.·····
000004f0:·2020·2020·2020·2020·5468·6520·6175·6469··········The·audi000004f0:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
00000500:·7420·7379·7374·656d·2073·686f·756c·6420··t·system·should·00000500:·6e2d·5553·223e·0a20·2020·2020·2020·2041··n-US">.········A
00000510:·636f·6c6c·6563·7420·756e·7375·6363·6573··collect·unsucces00000510:·7420·6120·6d69·6e69·6d75·6d2c·2074·6865··t·a·minimum,·the
00000520:·7366·756c·2066·696c·6520·7065·726d·6973··sful·file·permis00000520:·2061·7564·6974·2073·7973·7465·6d20·7368···audit·system·sh
00000530:·7369·6f6e·2063·6861·6e67·650a·6174·7465··sion·change.atte00000530:·6f75·6c64·2063·6f6c·6c65·6374·2066·696c··ould·collect·fil
00000540:·6d70·7473·2066·6f72·2061·6c6c·2075·7365··mpts·for·all·use00000540:·6520·7065·726d·6973·7369·6f6e·0a63·6861··e·permission.cha
00000550:·7273·2061·6e64·2072·6f6f·742e·0a49·6620··rs·and·root..If·00000550:·6e67·6573·2066·6f72·2061·6c6c·2075·7365··nges·for·all·use
00000560:·7468·6520·3c74·743e·6175·6469·7464·3c2f··the·<tt>auditd</00000560:·7273·2061·6e64·2072·6f6f·742e·2049·6620··rs·and·root.·If·
00000570:·7474·3e20·6461·656d·6f6e·2069·7320·636f··tt>·daemon·is·co00000570:·7468·6520·3c74·743e·6175·6469·7464·3c2f··the·<tt>auditd</
00000580:·6e66·6967·7572·6564·0a74·6f20·7573·6520··nfigured.to·use·00000580:·7474·3e20·6461·656d·6f6e·2069·7320·636f··tt>·daemon·is·co
00000590:·7468·6520·3c74·743e·6175·6765·6e72·756c··the·<tt>augenrul00000590:·6e66·6967·7572·6564·0a74·6f20·7573·6520··nfigured.to·use·
000005a0:·6573·3c2f·7474·3e20·7072·6f67·7261·6d20··es</tt>·program·000005a0:·7468·6520·3c74·743e·6175·6765·6e72·756c··the·<tt>augenrul
000005b0:·746f·2072·6561·6420·6175·6469·7420·7275··to·read·audit·ru000005b0:·6573·3c2f·7474·3e20·7072·6f67·7261·6d20··es</tt>·program·
000005c0:·6c65·7320·6475·7269·6e67·2064·6165·6d6f··les·during·daemo000005c0:·746f·2072·6561·6420·6175·6469·7420·7275··to·read·audit·ru
000005d0:·6e0a·7374·6172·7475·7020·2874·6865·2064··n.startup·(the·d000005d0:·6c65·7320·6475·7269·6e67·2064·6165·6d6f··les·during·daemo
000005e0:·6566·6175·6c74·292c·2061·6464·2074·6865··efault),·add·the000005e0:·6e0a·7374·6172·7475·7020·2874·6865·2064··n.startup·(the·d
000005f0:·2066·6f6c·6c6f·7769·6e67·206c·696e·6573···following·lines000005f0:·6566·6175·6c74·292c·2061·6464·2074·6865··efault),·add·the
00000600:·2074·6f20·6120·6669·6c65·2077·6974·6820···to·a·file·with·00000600:·2066·6f6c·6c6f·7769·6e67·206c·696e·6520···following·line·
00000610:·7375·6666·6978·0a3c·7474·3e2e·7275·6c65··suffix.<tt>.rule00000610:·746f·2061·2066·696c·6520·7769·7468·2073··to·a·file·with·s
00000620:·733c·2f74·743e·2069·6e20·7468·6520·6469··s</tt>·in·the·di00000620:·7566·6669·780a·3c74·743e·2e72·756c·6573··uffix.<tt>.rules
00000630:·7265·6374·6f72·7920·3c74·743e·2f65·7463··rectory·<tt>/etc00000630:·3c2f·7474·3e20·696e·2074·6865·2064·6972··</tt>·in·the·dir
00000640:·2f61·7564·6974·2f72·756c·6573·2e64·3c2f··/audit/rules.d</00000640:·6563·746f·7279·203c·7474·3e2f·6574·632f··ectory·<tt>/etc/
00000650:·7474·3e2e·0a49·6620·7468·6520·3c74·743e··tt>..If·the·<tt>00000650:·6175·6469·742f·7275·6c65·732e·643c·2f74··audit/rules.d</t
00000660:·6175·6469·7464·3c2f·7474·3e20·6461·656d··auditd</tt>·daem00000660:·743e·3a0a·3c70·7265·3e2d·6120·616c·7761··t>:.<pre>-a·alwa
00000670:·6f6e·2069·7320·636f·6e66·6967·7572·6564··on·is·configured00000670:·7973·2c65·7869·7420·2d46·2061·7263·683d··ys,exit·-F·arch=
00000680:·2074·6f20·7573·6520·7468·6520·3c74·743e···to·use·the·<tt>00000680:·6233·3220·2d53·2073·6574·7861·7474·7220··b32·-S·setxattr·
00000690:·6175·6469·7463·746c·3c2f·7474·3e0a·7574··auditctl</tt>.ut00000690:·2d46·2061·7569·6426·6774·3b3d·3130·3030··-F·auid&gt;=1000
000006a0:·696c·6974·7920·746f·2072·6561·6420·6175··ility·to·read·au000006a0:·202d·4620·6175·6964·213d·756e·7365·7420···-F·auid!=unset·
000006b0:·6469·7420·7275·6c65·7320·6475·7269·6e67··dit·rules·during000006b0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·643c··-F·key=perm_mod<
000006c0:·2064·6165·6d6f·6e20·7374·6172·7475·702c···daemon·startup,000006c0:·2f70·7265·3e0a·4966·2074·6865·2073·7973··/pre>.If·the·sys
000006d0:·2061·6464·2074·6865·2066·6f6c·6c6f·7769···add·the·followi000006d0:·7465·6d20·6973·2036·3420·6269·7420·7468··tem·is·64·bit·th
000006e0:·6e67·206c·696e·6573·2074·6f0a·3c74·743e··ng·lines·to.<tt>000006e0:·656e·2061·6c73·6f20·6164·6420·7468·6520··en·also·add·the·
000006f0:·2f65·7463·2f61·7564·6974·2f61·7564·6974··/etc/audit/audit000006f0:·666f·6c6c·6f77·696e·6720·6c69·6e65·3a0a··following·line:.
00000700:·2e72·756c·6573·3c2f·7474·3e20·6669·6c65··.rules</tt>·file00000700:·3c70·7265·3e2d·6120·616c·7761·7973·2c65··<pre>-a·always,e
00000710:·2e0a·3c70·7265·3e2d·6120·616c·7761·7973··..<pre>-a·always00000710:·7869·7420·2d46·2061·7263·683d·6236·3420··xit·-F·arch=b64·
00000720:·2c65·7869·7420·2d46·2061·7263·683d·6233··,exit·-F·arch=b300000720:·2d53·2073·6574·7861·7474·7220·2d46·2061··-S·setxattr·-F·a
00000730:·3220·2d53·2066·6368·6d6f·6420·2d46·2065··2·-S·fchmod·-F·e00000730:·7569·6426·6774·3b3d·3130·3030·202d·4620··uid&gt;=1000·-F·
00000740:·7869·743d·2d45·4143·4345·5320·2d46·2061··xit=-EACCES·-F·a00000740:·6175·6964·213d·756e·7365·7420·2d46·206b··auid!=unset·-F·k
00000750:·7569·643e·3d31·3030·3020·2d46·2061·7569··uid>=1000·-F·aui00000750:·6579·3d70·6572·6d5f·6d6f·643c·2f70·7265··ey=perm_mod</pre
00000760:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=00000760:·3e0a·4966·2074·6865·203c·7474·3e61·7564··>.If·the·<tt>aud
00000770:·756e·7375·6363·6573·6675·6c2d·7065·726d··unsuccesful-perm00000770:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·
00000780:·2d63·6861·6e67·650a·2d61·2061·6c77·6179··-change.-a·alway00000780:·6973·2063·6f6e·6669·6775·7265·6420·746f··is·configured·to
00000790:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b00000790:·2075·7365·2074·6865·203c·7474·3e61·7564···use·the·<tt>aud
000007a0:·3332·202d·5320·6663·686d·6f64·202d·4620··32·-S·fchmod·-F·000007a0:·6974·6374·6c3c·2f74·743e·0a75·7469·6c69··itctl</tt>.utili
000007b0:·6578·6974·3d2d·4550·4552·4d20·2d46·2061··exit=-EPERM·-F·a000007b0:·7479·2074·6f20·7265·6164·2061·7564·6974··ty·to·read·audit
000007c0:·7569·643e·3d31·3030·3020·2d46·2061·7569··uid>=1000·-F·aui000007c0:·2072·756c·6573·2064·7572·696e·6720·6461···rules·during·da
000007d0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=000007d0:·656d·6f6e·2073·7461·7274·7570·2c20·6164··emon·startup,·ad
000007e0:·756e·7375·6363·6573·6675·6c2d·7065·726d··unsuccesful-perm000007e0:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·
000007f0:·2d63·6861·6e67·653c·2f70·7265·3e0a·4966··-change</pre>.If000007f0:·6c69·6e65·2074·6f0a·3c74·743e·2f65·7463··line·to.<tt>/etc
00000800:·2074·6865·2073·7973·7465·6d20·6973·2036···the·system·is·600000800:·2f61·7564·6974·2f61·7564·6974·2e72·756c··/audit/audit.rul
00000810:·3420·6269·7420·7468·656e·2061·6c73·6f20··4·bit·then·also·00000810:·6573·3c2f·7474·3e20·6669·6c65·3a0a·3c70··es</tt>·file:.<p
00000820:·6164·6420·7468·6520·666f·6c6c·6f77·696e··add·the·followin00000820:·7265·3e2d·6120·616c·7761·7973·2c65·7869··re>-a·always,exi
00000830:·6720·6c69·6e65·733a·0a3c·7072·653e·2d61··g·lines:.<pre>-a00000830:·7420·2d46·2061·7263·683d·6233·3220·2d53··t·-F·arch=b32·-S
00000840:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·00000840:·2073·6574·7861·7474·7220·2d46·2061·7569···setxattr·-F·aui
00000850:·6172·6368·3d62·3634·202d·5320·6663·686d··arch=b64·-S·fchm00000850:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au
00000860:·6f64·202d·4620·6578·6974·3d2d·4541·4343··od·-F·exit=-EACC00000860:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
00000870:·4553·202d·4620·6175·6964·3e3d·3130·3030··ES·-F·auid>=100000000870:·3d70·6572·6d5f·6d6f·643c·2f70·7265·3e0a··=perm_mod</pre>.
00000880:·202d·4620·6175·6964·213d·756e·7365·7420···-F·auid!=unset·00000880:·4966·2074·6865·2073·7973·7465·6d20·6973··If·the·system·is
00000890:·2d46·206b·6579·3d75·6e73·7563·6365·7366··-F·key=unsuccesf00000890:·2036·3420·6269·7420·7468·656e·2061·6c73···64·bit·then·als
000008a0:·756c·2d70·6572·6d2d·6368·616e·6765·0a2d··ul-perm-change.-000008a0:·6f20·6164·6420·7468·6520·666f·6c6c·6f77··o·add·the·follow
000008b0:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F000008b0:·696e·6720·6c69·6e65·3a0a·3c70·7265·3e2d··ing·line:.<pre>-
000008c0:·2061·7263·683d·6236·3420·2d53·2066·6368···arch=b64·-S·fch000008c0:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F
000008d0:·6d6f·6420·2d46·2065·7869·743d·2d45·5045··mod·-F·exit=-EPE000008d0:·2061·7263·683d·6236·3420·2d53·2073·6574···arch=b64·-S·set
000008e0:·524d·202d·4620·6175·6964·3e3d·3130·3030··RM·-F·auid>=1000000008e0:·7861·7474·7220·2d46·2061·7569·6426·6774··xattr·-F·auid&gt
000008f0:·202d·4620·6175·6964·213d·756e·7365·7420···-F·auid!=unset·000008f0:·3b3d·3130·3030·202d·4620·6175·6964·213d··;=1000·-F·auid!=
00000900:·2d46·206b·6579·3d75·6e73·7563·6365·7366··-F·key=unsuccesf00000900:·756e·7365·7420·2d46·206b·6579·3d70·6572··unset·-F·key=per
00000910:·756c·2d70·6572·6d2d·6368·616e·6765·3c2f··ul-perm-change</00000910:·6d5f·6d6f·643c·2f70·7265·3e0a·2020·2020··m_mod</pre>.····
00000920:·7072·653e·0a20·2020·2020·203c·2f74·643e··pre>.······</td>00000920:·2020·3c2f·7464·3e0a·2020·2020·2020·3c74····</td>.······<t
00000930:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000930:·6420·786d·6c3a·6c61·6e67·3d22·656e·2d55··d·xml:lang="en-U
00000940:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000940:·5322·3e0a·2020·2020·2020·2020·5468·6520··S">.········The·
00000950:·2020·2020·2055·6e73·7563·6365·7373·6675·······Unsuccessfu00000950:·6368·616e·6769·6e67·206f·6620·6669·6c65··changing·of·file
00000960:·6c20·6174·7465·6d70·7473·2074·6f20·6368··l·attempts·to·ch00000960:·2070·6572·6d69·7373·696f·6e73·2063·6f75···permissions·cou
00000970:·616e·6765·2070·6572·6d69·7373·696f·6e73··ange·permissions00000970:·6c64·2069·6e64·6963·6174·6520·7468·6174··ld·indicate·that
00000980:·206f·6620·6669·6c65·7320·636f·756c·6420···of·files·could·00000980:·2061·2075·7365·7220·6973·2061·7474·656d···a·user·is·attem
00000990:·6265·2061·6e20·696e·6469·6361·746f·7220··be·an·indicator·00000990:·7074·696e·6720·746f·0a67·6169·6e20·6163··pting·to.gain·ac
000009a0:·6f66·206d·616c·6963·696f·7573·2061·6374··of·malicious·act000009a0:·6365·7373·2074·6f20·696e·666f·726d·6174··cess·to·informat
000009b0:·6976·6974·7920·6f6e·2061·2073·7973·7465··ivity·on·a·syste000009b0:·696f·6e20·7468·6174·2077·6f75·6c64·206f··ion·that·would·o
000009c0:·6d2e·2041·7564·6974·696e·670a·7468·6573··m.·Auditing.thes000009c0:·7468·6572·7769·7365·2062·6520·6469·7361··therwise·be·disa
000009d0:·6520·6576·656e·7473·2063·6f75·6c64·2073··e·events·could·s000009d0:·6c6c·6f77·6564·2e20·4175·6469·7469·6e67··llowed.·Auditing
000009e0:·6572·7665·2061·7320·6576·6964·656e·6365··erve·as·evidence000009e0:·2044·4143·206d·6f64·6966·6963·6174·696f···DAC·modificatio
000009f0:·206f·6620·706f·7465·6e74·6961·6c20·7379···of·potential·sy000009f0:·6e73·0a63·616e·2066·6163·696c·6974·6174··ns.can·facilitat
00000a00:·7374·656d·2063·6f6d·7072·6f6d·6973·652e··stem·compromise.00000a00:·6520·7468·6520·6964·656e·7469·6669·6361··e·the·identifica
00000a10:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···00000a10:·7469·6f6e·206f·6620·7061·7474·6572·6e73··tion·of·patterns
00000a20:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.00000a20:·206f·6620·6162·7573·6520·616d·6f6e·6720···of·abuse·among·
00000a30:·2020·2020·2020·3c74·643e·4155·2d32·2864········<td>AU-2(d00000a30:·626f·7468·2061·7574·686f·7269·7a65·6420··both·authorized·
00000a40:·293c·6272·2f3e·4155·2d31·3228·6329·3c62··)<br/>AU-12(c)<b00000a40:·616e·640a·756e·6175·7468·6f72·697a·6564··and.unauthorized
00000a50:·722f·3e41·432d·3628·3929·3c62·722f·3e43··r/>AC-6(9)<br/>C00000a50:·2075·7365·7273·2e0a·2020·2020·2020·3c2f···users..······</
00000a60:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····00000a60:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··
00000a70:·2020·3c74·643e·5265·636f·7264·2041·7474····<td>Record·Att00000a70:·2020·3c74·723e·0a20·2020·2020·203c·7464····<tr>.······<td
00000a80:·656d·7074·7320·746f·2041·6c74·6572·204c··empts·to·Alter·L00000a80:·3e41·552d·3228·6429·3c62·722f·3e41·552d··>AU-2(d)<br/>AU-
00000a90:·6f67·6f6e·2061·6e64·204c·6f67·6f75·7420··ogon·and·Logout·00000a90:·3132·2863·293c·6272·2f3e·434d·2d36·2861··12(c)<br/>CM-6(a
00000aa0:·4576·656e·7473·202d·2074·616c·6c79·6c6f··Events·-·tallylo00000aa0:·293c·2f74·643e·0a20·2020·2020·203c·7464··)</td>.······<td
00000ab0:·673c·2f74·643e·0a20·2020·2020·203c·7464··g</td>.······<td00000ab0:·3e45·6e73·7572·6520·6175·6469·7464·2043··>Ensure·auditd·C
00000ac0:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US00000ac0:·6f6c·6c65·6374·7320·4669·6c65·2044·656c··ollects·File·Del
00000ad0:·223e·0a20·2020·2020·2020·2054·6865·2061··">.········The·a00000ad0:·6574·696f·6e20·4576·656e·7473·2062·7920··etion·Events·by·
00000ae0:·7564·6974·2073·7973·7465·6d20·616c·7265··udit·system·alre00000ae0:·5573·6572·202d·2075·6e6c·696e·6b3c·2f74··User·-·unlink</t
00000af0:·6164·7920·636f·6c6c·6563·7473·206c·6f67··ady·collects·log00000af0:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
00000b00:·696e·2069·6e66·6f72·6d61·7469·6f6e·2066··in·information·f00000b00:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
00000b10:·6f72·2061·6c6c·2075·7365·7273·0a61·6e64··or·all·users.and00000b10:·2020·2020·2020·2041·7420·6120·6d69·6e69·········At·a·mini
00000b20:·2072·6f6f·742e·2049·6620·7468·6520·3c74···root.·If·the·<t00000b20:·6d75·6d2c·2074·6865·2061·7564·6974·2073··mum,·the·audit·s
00000b30:·743e·6175·6469·7464·3c2f·7474·3e20·6461··t>auditd</tt>·da00000b30:·7973·7465·6d20·7368·6f75·6c64·2063·6f6c··ystem·should·col
00000b40:·656d·6f6e·2069·7320·636f·6e66·6967·7572··emon·is·configur00000b40:·6c65·6374·2066·696c·6520·6465·6c65·7469··lect·file·deleti
00000b50:·6564·2074·6f20·7573·6520·7468·650a·3c74··ed·to·use·the.<t00000b50:·6f6e·2065·7665·6e74·730a·666f·7220·616c··on·events.for·al
00000b60:·743e·6175·6765·6e72·756c·6573·3c2f·7474··t>augenrules</tt00000b60:·6c20·7573·6572·7320·616e·6420·726f·6f74··l·users·and·root
00000b70:·3e20·7072·6f67·7261·6d20·746f·2072·6561··>·program·to·rea00000b70:·2e20·4966·2074·6865·203c·7474·3e61·7564··.·If·the·<tt>aud
00000b80:·6420·6175·6469·7420·7275·6c65·7320·6475··d·audit·rules·du00000b80:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·
00000b90:·7269·6e67·2064·6165·6d6f·6e20·7374·6172··ring·daemon·star00000b90:·6973·2063·6f6e·6669·6775·7265·6420·746f··is·configured·to
00000ba0:·7475·7020·2874·6865·0a64·6566·6175·6c74··tup·(the.default00000ba0:·2075·7365·2074·6865·0a3c·7474·3e61·7567···use·the.<tt>aug
00000bb0:·292c·2061·6464·2074·6865·2066·6f6c·6c6f··),·add·the·follo00000bb0:·656e·7275·6c65·733c·2f74·743e·2070·726f··enrules</tt>·pro
00000bc0:·7769·6e67·206c·696e·6573·2074·6f20·6120··wing·lines·to·a·00000bc0:·6772·616d·2074·6f20·7265·6164·2061·7564··gram·to·read·aud
00000bd0:·6669·6c65·2077·6974·6820·7375·6666·6978··file·with·suffix00000bd0:·6974·2072·756c·6573·2064·7572·696e·6720··it·rules·during·
00000be0:·203c·7474·3e2e·7275·6c65·733c·2f74·743e···<tt>.rules</tt>00000be0:·6461·656d·6f6e·2073·7461·7274·7570·2028··daemon·startup·(
00000bf0:·2069·6e20·7468·650a·6469·7265·6374·6f72···in·the.director00000bf0:·7468·650a·6465·6661·756c·7429·2c20·6164··the.default),·ad
Max diff block lines reached; 5348124/5513472 bytes (97.00%) of diff not shown.
1.14 MB
html2text {}
Max HTML report size reached
777 KB
./usr/share/doc/ssg-nondebian/table-rhel7-ospprefs.html
Ordering differences only
    
Offset 75, 31 lines modifiedOffset 75, 33 lines modified
75 package,·or·the·SCAP·Workbench·GUI·tool·from·the·<tt>scap-workbench</tt>·package,·to·verify75 package,·or·the·SCAP·Workbench·GUI·tool·from·the·<tt>scap-workbench</tt>·package,·to·verify
76 that·the·system·conforms·to·provided·guidelines.·Refer·to·the·scap-security-guide(8)·manual76 that·the·system·conforms·to·provided·guidelines.·Refer·to·the·scap-security-guide(8)·manual
77 page·for·futher·information.77 page·for·futher·information.
78 ······</td>78 ······</td>
79 ····</tr>79 ····</tr>
80 ····<tr>80 ····<tr>
81 ······<td>FAU_GEN.1</td>81 ······<td>FAU_GEN.1</td>
82 ······<td>Disable·SSH·Root·Login</td>82 ······<td>Ensure·the·audit·Subsystem·is·Installed</td>
83 ······<td·xml:lang="en-US">83 ······<td·xml:lang="en-US">
 84 ········The·audit·package·should·be·installed.
84 ········The·root·user·should·never·be·allowed·to·login·to·a 
85 system·directly·over·a·network. 
86 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
87 <tt>/etc/ssh/sshd_config</tt>: 
  
88 <pre>PermitRootLogin·no</pre> 
89 ······</td>85 ······</td>
90 ······<td·xml:lang="en-US">86 ······<td·xml:lang="en-US">
91 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
92 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
93 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
94 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
95 direct·attack·attempts·on·root's·password.87 ········The·auditd·service·is·an·access·monitoring·and·accounting·daemon,·watching·system·calls·to·audit·any·access,·in·comparison·with·potential·local·access·control·policy·such·as·SELinux·policy.
 88 ······</td>
 89 ····</tr>
 90 ····<tr>
 91 ······<td>FAU_GEN.1</td>
 92 ······<td>Include·Local·Events·in·Audit·Logs</td>
 93 ······<td·xml:lang="en-US">
 94 ········To·configure·Audit·daemon·to·include·local·events·in·Audit·logs,·set
 95 <tt>local_events</tt>·to·<tt>yes</tt>·in·<tt>/etc/audit/auditd.conf</tt>.
 96 This·is·the·default·setting.
 97 ······</td>
 98 ······<td·xml:lang="en-US">
 99 ········If·option·<tt>local_events</tt>·isn't·set·to·<tt>yes</tt>·only·events·from
 100 network·will·be·aggregated.
96 ······</td>101 ······</td>
97 ····</tr>102 ····</tr>
98 ····<tr>103 ····<tr>
99 ······<td>FAU_GEN.1</td>104 ······<td>FAU_GEN.1</td>
100 ······<td>Enable·Auditing·for·Processes·Which·Start·Prior·to·the·Audit·Daemon</td>105 ······<td>Enable·Auditing·for·Processes·Which·Start·Prior·to·the·Audit·Daemon</td>
101 ······<td·xml:lang="en-US">106 ······<td·xml:lang="en-US">
102 ········To·ensure·all·processes·can·be·audited,·even·those·which·start107 ········To·ensure·all·processes·can·be·audited,·even·those·which·start
Offset 117, 51 lines modifiedOffset 119, 28 lines modified
117 its·activities·can·be·audited.·Although·<tt>auditd</tt>·takes·care·of·enabling119 its·activities·can·be·audited.·Although·<tt>auditd</tt>·takes·care·of·enabling
118 this·for·all·processes·which·launch·after·it·does,·adding·the·kernel·argument120 this·for·all·processes·which·launch·after·it·does,·adding·the·kernel·argument
119 ensures·it·is·set·for·every·process·during·boot.121 ensures·it·is·set·for·every·process·during·boot.
120 ······</td>122 ······</td>
121 ····</tr>123 ····</tr>
122 ····<tr>124 ····<tr>
123 ······<td>FAU_GEN.1</td>125 ······<td>FAU_GEN.1</td>
124 ······<td>Include·Local·Events·in·Audit·Logs</td> 
125 ······<td·xml:lang="en-US"> 
126 ········To·configure·Audit·daemon·to·include·local·events·in·Audit·logs,·set 
127 <tt>local_events</tt>·to·<tt>yes</tt>·in·<tt>/etc/audit/auditd.conf</tt>. 
128 This·is·the·default·setting. 
129 ······</td> 
130 ······<td·xml:lang="en-US"> 
131 ········If·option·<tt>local_events</tt>·isn't·set·to·<tt>yes</tt>·only·events·from 
132 network·will·be·aggregated. 
133 ······</td> 
134 ····</tr> 
135 ····<tr> 
136 ······<td>FAU_GEN.1</td> 
137 ······<td>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</td>126 ······<td>Set·number·of·records·to·cause·an·explicit·flush·to·audit·logs</td>
138 ······<td·xml:lang="en-US">127 ······<td·xml:lang="en-US">
139 ········To·configure·Audit·daemon·to·issue·an·explicit·flush·to·disk·command128 ········To·configure·Audit·daemon·to·issue·an·explicit·flush·to·disk·command
140 after·writing·<abbr·title="$var_auditd_freq"><tt>50</tt></abbr>·records,·set·<tt>freq</tt>·to·<tt><abbr·title="$var_auditd_freq"><tt>50</tt></abbr></tt>129 after·writing·<abbr·title="$var_auditd_freq"><tt>50</tt></abbr>·records,·set·<tt>freq</tt>·to·<tt><abbr·title="$var_auditd_freq"><tt>50</tt></abbr></tt>
141 in·<tt>/etc/audit/auditd.conf</tt>.130 in·<tt>/etc/audit/auditd.conf</tt>.
142 ······</td>131 ······</td>
143 ······<td·xml:lang="en-US">132 ······<td·xml:lang="en-US">
144 ········If·option·<tt>freq</tt>·isn't·set·to·<tt><sub·idref="var_auditd_freq"·/></tt>,·the·flush·to·disk133 ········If·option·<tt>freq</tt>·isn't·set·to·<tt><sub·idref="var_auditd_freq"·/></tt>,·the·flush·to·disk
145 may·happen·after·higher·number·of·records,·increasing·the·danger134 may·happen·after·higher·number·of·records,·increasing·the·danger
146 of·audit·loss.135 of·audit·loss.
147 ······</td>136 ······</td>
148 ····</tr>137 ····</tr>
149 ····<tr>138 ····<tr>
150 ······<td>FAU_GEN.1</td>139 ······<td>FAU_GEN.1</td>
151 ······<td>Ensure·the·audit·Subsystem·is·Installed</td> 
152 ······<td·xml:lang="en-US"> 
153 ········The·audit·package·should·be·installed. 
154 ······</td> 
155 ······<td·xml:lang="en-US"> 
156 ········The·auditd·service·is·an·access·monitoring·and·accounting·daemon,·watching·system·calls·to·audit·any·access,·in·comparison·with·potential·local·access·control·policy·such·as·SELinux·policy. 
157 ······</td> 
158 ····</tr> 
159 ····<tr> 
160 ······<td>FAU_GEN.1</td> 
161 ······<td>Enable·auditd·Service</td>140 ······<td>Enable·auditd·Service</td>
162 ······<td·xml:lang="en-US">141 ······<td·xml:lang="en-US">
163 ········The·<tt>auditd</tt>·service·is·an·essential·userspace·component·of142 ········The·<tt>auditd</tt>·service·is·an·essential·userspace·component·of
164 the·Linux·Auditing·System,·as·it·is·responsible·for·writing·audit·records·to143 the·Linux·Auditing·System,·as·it·is·responsible·for·writing·audit·records·to
165 disk.144 disk.
  
166 The·<code>auditd</code>·service·can·be·enabled·with·the·following·command:145 The·<code>auditd</code>·service·can·be·enabled·with·the·following·command:
Offset 175, 177 lines modifiedOffset 154, 126 lines modified
175 <br·/><br·/>154 <br·/><br·/>
176 Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of155 Additionally,·a·properly·configured·audit·subsystem·ensures·that·actions·of
177 individual·system·users·can·be·uniquely·traced·to·those·users·so·they156 individual·system·users·can·be·uniquely·traced·to·those·users·so·they
178 can·be·held·accountable·for·their·actions.157 can·be·held·accountable·for·their·actions.
179 ······</td>158 ······</td>
180 ····</tr>159 ····</tr>
181 ····<tr>160 ····<tr>
182 ······<td>FAU_GEN.1.1.c</td>161 ······<td>FAU_GEN.1</td>
 162 ······<td>Disable·SSH·Root·Login</td>
183 ······<td>Record·Attempts·to·Alter·Logon·and·Logout·Events·-·tallylog</td> 
184 ······<td·xml:lang="en-US"> 
185 ········The·audit·system·already·collects·login·information·for·all·users 
186 and·root.·If·the·<tt>auditd</tt>·daemon·is·configured·to·use·the 
187 <tt>augenrules</tt>·program·to·read·audit·rules·during·daemon·startup·(the 
188 default),·add·the·following·lines·to·a·file·with·suffix·<tt>.rules</tt>·in·the 
189 directory·<tt>/etc/audit/rules.d</tt>·in·order·to·watch·for·attempted·manual 
190 edits·of·files·involved·in·storing·logon·events: 
191 <pre>-w·/var/log/tallylog·-p·wa·-k·logins</pre> 
192 If·the·<tt>auditd</tt>·daemon·is·configured·to·use·the·<tt>auditctl</tt> 
193 utility·to·read·audit·rules·during·daemon·startup,·add·the·following·lines·to 
194 <tt>/etc/audit/audit.rules</tt>·file·in·order·to·watch·for·unattempted·manual 
195 edits·of·files·involved·in·storing·logon·events: 
196 <pre>-w·/var/log/tallylog·-p·wa·-k·logins</pre> 
197 ······</td> 
198 ······<td·xml:lang="en-US"> 
199 ········Manual·editing·of·these·files·may·indicate·nefarious·activity,·such 
200 as·an·attacker·attempting·to·remove·evidence·of·an·intrusion. 
201 ······</td> 
202 ····</tr> 
Max diff block lines reached; 327291/333120 bytes (98.25%) of diff not shown.
451 KB
html2text {}
    
Offset 22, 22 lines modifiedOffset 22, 23 lines modified
22 ···············································································administrator·can·use·the·oscap·CLI·tool·from22 ···············································································administrator·can·use·the·oscap·CLI·tool·from
23 ···············································································the·openscap-scanner·package,·or·the·SCAP23 ···············································································the·openscap-scanner·package,·or·the·SCAP
24 ···············································································Workbench·GUI·tool·from·the·scap-workbench24 ···············································································Workbench·GUI·tool·from·the·scap-workbench
25 ···············································································package,·to·verify·that·the·system·conforms·to25 ···············································································package,·to·verify·that·the·system·conforms·to
26 ···············································································provided·guidelines.·Refer·to·the·scap-26 ···············································································provided·guidelines.·Refer·to·the·scap-
27 ···············································································security-guide(8)·manual·page·for·futher27 ···············································································security-guide(8)·manual·page·for·futher
28 ···············································································information.28 ···············································································information.
 29 ···············································································The·auditd·service·is·an·access·monitoring·and
 30 ·················Ensure·the·audit··············································accounting·daemon,·watching·system·calls·to
 31 FAU_GEN.1········Subsystem·is······The·audit·package·should·be·installed.······audit·any·access,·in·comparison·with·potential
 32 ·················Installed·····················································local·access·control·policy·such·as·SELinux
29 ···············································································Even·though·the·communications·channel·may·be 
30 ···································The·root·user·should·never·be·allowed·to····encrypted,·an·additional·layer·of·security·is 
31 ···································login·to·a·system·directly·over·a·network.··gained·by·extending·the·policy·of·not·logging 
32 FAU_GEN.1········Disable·SSH·Root··To·disable·root·login·via·SSH,·add·or·······directly·on·as·root.·In·addition,·logging·in 
33 ·················Login·············correct·the·following·line·in·/etc/ssh/·····with·a·user-specific·account·provides 
34 ···································sshd_config:································individual·accountability·of·actions·performed 
35 ···································PermitRootLogin·no··························on·the·system·and·also·helps·to·minimize 
36 ···············································································direct·attack·attempts·on·root's·password.33 ···············································································policy.
 34 ·················Include·Local·····To·configure·Audit·daemon·to·include·local
 35 FAU_GEN.1········Events·in·Audit···events·in·Audit·logs,·set·local_events·to···If·option·local_events·isn't·set·to·yes·only
 36 ·················Logs··············yes·in·/etc/audit/auditd.conf.·This·is·the··events·from·network·will·be·aggregated.
 37 ···································default·setting.
37 ···································To·ensure·all·processes·can·be·audited,38 ···································To·ensure·all·processes·can·be·audited,
38 ···································even·those·which·start·prior·to·the·audit39 ···································even·those·which·start·prior·to·the·audit
39 ···································daemon,·add·the·argument·audit=1·to·the40 ···································daemon,·add·the·argument·audit=1·to·the
40 ···································default·GRUB·2·command·line·for·the·Linux41 ···································default·GRUB·2·command·line·for·the·Linux
41 ···································operating·system.·To·ensure·that·audit=1·is·Each·process·on·the·system·carries·an42 ···································operating·system.·To·ensure·that·audit=1·is·Each·process·on·the·system·carries·an
42 ·················Enable·Auditing···added·as·a·kernel·command·line·argument·to··"auditable"·flag·which·indicates·whether·its43 ·················Enable·Auditing···added·as·a·kernel·command·line·argument·to··"auditable"·flag·which·indicates·whether·its
43 ·················for·Processes·····newly·installed·kernels,·add·audit=1·to·the·activities·can·be·audited.·Although·auditd44 ·················for·Processes·····newly·installed·kernels,·add·audit=1·to·the·activities·can·be·audited.·Although·auditd
Offset 45, 283 lines modifiedOffset 46, 344 lines modified
45 ·················to·the·Audit······operating·systems.·Modify·the·line·within·/·which·launch·after·it·does,·adding·the·kernel46 ·················to·the·Audit······operating·systems.·Modify·the·line·within·/·which·launch·after·it·does,·adding·the·kernel
46 ·················Daemon············etc/default/grub·as·shown·below:············argument·ensures·it·is·set·for·every·process47 ·················Daemon············etc/default/grub·as·shown·below:············argument·ensures·it·is·set·for·every·process
47 ···································GRUB_CMDLINE_LINUX="...·audit=1·..."········during·boot.48 ···································GRUB_CMDLINE_LINUX="...·audit=1·..."········during·boot.
48 ···································Run·the·following·command·to·update·command49 ···································Run·the·following·command·to·update·command
49 ···································line·for·already·installed·kernels:50 ···································line·for·already·installed·kernels:
50 ···································#·grubby·--update-kernel=ALL·--51 ···································#·grubby·--update-kernel=ALL·--
51 ···································args="audit=1"52 ···································args="audit=1"
52 ·················Include·Local·····To·configure·Audit·daemon·to·include·local 
53 FAU_GEN.1········Events·in·Audit···events·in·Audit·logs,·set·local_events·to···If·option·local_events·isn't·set·to·yes·only 
54 ·················Logs··············yes·in·/etc/audit/auditd.conf.·This·is·the··events·from·network·will·be·aggregated. 
55 ···································default·setting. 
56 ·················Set·number·of·····To·configure·Audit·daemon·to·issue·an·······If·option·freq·isn't·set·to·,·the·flush·to53 ·················Set·number·of·····To·configure·Audit·daemon·to·issue·an·······If·option·freq·isn't·set·to·,·the·flush·to
57 FAU_GEN.1········records·to·cause··explicit·flush·to·disk·command·after········disk·may·happen·after·higher·number·of54 FAU_GEN.1········records·to·cause··explicit·flush·to·disk·command·after········disk·may·happen·after·higher·number·of
58 ·················an·explicit·flush·writing·50·records,·set·freq·to·50·in·/etc/·records,·increasing·the·danger·of·audit·loss.55 ·················an·explicit·flush·writing·50·records,·set·freq·to·50·in·/etc/·records,·increasing·the·danger·of·audit·loss.
59 ·················to·audit·logs·····audit/auditd.conf.56 ·················to·audit·logs·····audit/auditd.conf.
60 ···············································································The·auditd·service·is·an·access·monitoring·and 
61 ·················Ensure·the·audit··············································accounting·daemon,·watching·system·calls·to 
62 FAU_GEN.1········Subsystem·is······The·audit·package·should·be·installed.······audit·any·access,·in·comparison·with·potential 
63 ·················Installed·····················································local·access·control·policy·such·as·SELinux 
64 ···············································································policy. 
65 ···············································································Without·establishing·what·type·of·events57 ···············································································Without·establishing·what·type·of·events
66 ···············································································occurred,·it·would·be·difficult·to·establish,58 ···············································································occurred,·it·would·be·difficult·to·establish,
67 ···············································································correlate,·and·investigate·the·events·leading59 ···············································································correlate,·and·investigate·the·events·leading
68 ···································The·auditd·service·is·an·essential··········up·to·an·outage·or·attack.·Ensuring·the·auditd60 ···································The·auditd·service·is·an·essential··········up·to·an·outage·or·attack.·Ensuring·the·auditd
69 ···································userspace·component·of·the·Linux·Auditing···service·is·active·ensures·audit·records61 ···································userspace·component·of·the·Linux·Auditing···service·is·active·ensures·audit·records
70 ·················Enable·auditd·····System,·as·it·is·responsible·for·writing····generated·by·the·kernel·are·appropriately62 ·················Enable·auditd·····System,·as·it·is·responsible·for·writing····generated·by·the·kernel·are·appropriately
71 FAU_GEN.1········Service···········audit·records·to·disk.·The·auditd·service···recorded.63 FAU_GEN.1········Service···········audit·records·to·disk.·The·auditd·service···recorded.
72 ···································can·be·enabled·with·the·following·command:64 ···································can·be·enabled·with·the·following·command:
73 ···································$·sudo·systemctl·enable·auditd.service······Additionally,·a·properly·configured·audit65 ···································$·sudo·systemctl·enable·auditd.service······Additionally,·a·properly·configured·audit
74 ···············································································subsystem·ensures·that·actions·of·individual66 ···············································································subsystem·ensures·that·actions·of·individual
75 ···············································································system·users·can·be·uniquely·traced·to·those67 ···············································································system·users·can·be·uniquely·traced·to·those
76 ···············································································users·so·they·can·be·held·accountable·for68 ···············································································users·so·they·can·be·held·accountable·for
77 ···············································································their·actions.69 ···············································································their·actions.
 70 ···············································································Even·though·the·communications·channel·may·be
 71 ···································The·root·user·should·never·be·allowed·to····encrypted,·an·additional·layer·of·security·is
 72 ···································login·to·a·system·directly·over·a·network.··gained·by·extending·the·policy·of·not·logging
 73 FAU_GEN.1········Disable·SSH·Root··To·disable·root·login·via·SSH,·add·or·······directly·on·as·root.·In·addition,·logging·in
 74 ·················Login·············correct·the·following·line·in·/etc/ssh/·····with·a·user-specific·account·provides
 75 ···································sshd_config:································individual·accountability·of·actions·performed
 76 ···································PermitRootLogin·no··························on·the·system·and·also·helps·to·minimize
 77 ···············································································direct·attack·attempts·on·root's·password.
78 ···································The·audit·system·already·collects·login 
79 ···································information·for·all·users·and·root.·If·the 
80 ···································auditd·daemon·is·configured·to·use·the 
81 ···································augenrules·program·to·read·audit·rules 
82 ···································during·daemon·startup·(the·default),·add 
83 ···································the·following·lines·to·a·file·with·suffix 
84 ···································.rules·in·the·directory·/etc/audit/rules.d 
85 ·················Record·Attempts···in·order·to·watch·for·attempted·manual······Manual·editing·of·these·files·may·indicate 
86 FAU_GEN.1.1.c····to·Alter·Logon····edits·of·files·involved·in·storing·logon····nefarious·activity,·such·as·an·attacker 
87 ·················and·Logout·Events·events:·····································attempting·to·remove·evidence·of·an·intrusion. 
88 ·················-·tallylog········-w·/var/log/tallylog·-p·wa·-k·logins 
89 ···································If·the·auditd·daemon·is·configured·to·use 
90 ···································the·auditctl·utility·to·read·audit·rules 
91 ···································during·daemon·startup,·add·the·following 
92 ···································lines·to·/etc/audit/audit.rules·file·in 
93 ···································order·to·watch·for·unattempted·manual·edits 
94 ···································of·files·involved·in·storing·logon·events: 
95 ···································-w·/var/log/tallylog·-p·wa·-k·logins 
96 ···································If·the·auditd·daemon·is·configured·to·use 
97 ···································the·augenrules·program·to·read·audit·rules 
98 ···································during·daemon·startup·(the·default),·add 
99 ···································the·following·lines·to·a·file·with·suffix 
100 ···································.rules·in·the·directory·/etc/audit/rules.d, 
101 ···································in·order·to·capture·events·that·modify 
102 ···································account·changes: 
  
103 ·················Record·Events·····-w·/etc/gshadow·-p·wa·-·····················In·addition·to·auditing·new·user·and·group 
104 ·················that·Modify·User/·k·audit_rules_usergroup_modification········accounts,·these·watches·will·alert·the·system 
105 FAU_GEN.1.1.c····Group·Information·············································administrator(s)·to·any·modifications.·Any 
106 ·················-·/etc/gshadow················································unexpected·users,·groups,·or·modifications 
107 ···································If·the·auditd·daemon·is·configured·to·use···should·be·investigated·for·legitimacy. 
108 ···································the·auditctl·utility·to·read·audit·rules 
109 ···································during·daemon·startup,·add·the·following 
110 ···································lines·to·/etc/audit/audit.rules·file,·in 
111 ···································order·to·capture·events·that·modify·account 
112 ···································changes: 
  
113 ···································-w·/etc/gshadow·-p·wa·- 
114 ···································k·audit_rules_usergroup_modification 
115 ···································At·a·minimum,·the·audit·system·should78 ···································At·a·minimum,·the·audit·system·should
116 ···································collect·file·permission·changes·for·all79 ···································collect·file·permission·changes·for·all
117 ···································users·and·root.80 ···································users·and·root.·If·the·auditd·daemon·is
 81 ···································configured·to·use·the·augenrules·program·to
 82 ···································read·audit·rules·during·daemon·startup·(the
 83 ···································default),·add·the·following·line·to·a·file
 84 ···································with·suffix·.rules·in·the·directory·/etc/
 85 ···································audit/rules.d:
 86 ···································-a·always,exit·-F·arch=b32·-S·setxattr·-····The·changing·of·file·permissions·could
 87 ·················Record·Events·····F·auid>=1000·-F·auid!=unset·-F·key=perm_mod·indicate·that·a·user·is·attempting·to·gain
 88 ·················that·Modify·the···If·the·system·is·64·bit·then·also·add·the···access·to·information·that·would·otherwise·be
 89 FAU_GEN.1.1.c····System's··········following·line:·····························disallowed.·Auditing·DAC·modifications·can
 90 ·················Discretionary·····-a·always,exit·-F·arch=b64·-S·setxattr·-····facilitate·the·identification·of·patterns·of
 91 ·················Access·Controls·-·F·auid>=1000·-F·auid!=unset·-F·key=perm_mod·abuse·among·both·authorized·and·unauthorized
118 ···································If·the·auditd·daemon·is·configured·to·use92 ·················setxattr··········If·the·auditd·daemon·is·configured·to·use···users.
119 ···································the·augenrules·program·to·read·audit·rules 
Max diff block lines reached; 447989/462154 bytes (96.94%) of diff not shown.
703 KB
./usr/share/doc/ssg-nondebian/table-rhel7-pcidssrefs.html
Ordering differences only
    
Offset 95, 14 lines modifiedOffset 95, 50 lines modified
95 attacker·to·monitor·and·record·network·traffic.·These·malicious·APs·can·also95 attacker·to·monitor·and·record·network·traffic.·These·malicious·APs·can·also
96 serve·to·create·a·man-in-the-middle·attack·or·be·used·to·create·a·denial·of96 serve·to·create·a·man-in-the-middle·attack·or·be·used·to·create·a·denial·of
97 service·to·valid·network·resources.97 service·to·valid·network·resources.
98 ······</td>98 ······</td>
99 ····</tr>99 ····</tr>
100 ····<tr>100 ····<tr>
101 ······<td>Req-1.4.1</td>101 ······<td>Req-1.4.1</td>
 102 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
 103 ······<td·xml:lang="en-US">
 104 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
 105 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
 106 ······</td>
 107 ······<td·xml:lang="en-US">
 108 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
 109 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state.
 110 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received,
 111 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
 112 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
 113 enables·the·system·to·continue·servicing·valid·connection·requests.
 114 ······</td>
 115 ····</tr>
 116 ····<tr>
 117 ······<td>Req-1.4.1</td>
 118 ······<td>Set·Default·ip6tables·Policy·for·Incoming·Packets</td>
 119 ······<td·xml:lang="en-US">
 120 ········To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)·for
 121 the·built-in·INPUT·chain·which·processes·incoming·packets,
 122 add·or·correct·the·following·line·in
 123 <tt>/etc/sysconfig/ip6tables</tt>:
 124 <pre>:INPUT·DROP·[0:0]</pre>
 125 If·changes·were·required,·reload·the·ip6tables·rules:
 126 <pre>$·sudo·service·ip6tables·reload</pre>
 127 ······</td>
 128 ······<td·xml:lang="en-US">
 129 ········In·<tt>ip6tables</tt>,·the·default·policy·is·applied·only·after·all
 130 the·applicable·rules·in·the·table·are·examined·for·a·match.·Setting·the
 131 default·policy·to·<tt>DROP</tt>·implements·proper·design·for·a·firewall,·i.e.
 132 any·packets·which·are·not·explicitly·permitted·should·not·be
 133 accepted.
 134 ······</td>
 135 ····</tr>
 136 ····<tr>
 137 ······<td>Req-1.4.1</td>
102 ······<td>Set·configuration·for·loopback·traffic</td>138 ······<td>Set·configuration·for·loopback·traffic</td>
103 ······<td·xml:lang="en-US">139 ······<td·xml:lang="en-US">
104 ········Configure·the·loopback·interface·to·accept·traffic.·140 ········Configure·the·loopback·interface·to·accept·traffic.·
105 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback·141 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback·
106 network.142 network.
107 ······</td>143 ······</td>
108 ······<td·xml:lang="en-US">144 ······<td·xml:lang="en-US">
Offset 140, 47 lines modifiedOffset 176, 33 lines modified
140 ······<td·xml:lang="en-US">176 ······<td·xml:lang="en-US">
141 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering177 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
142 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP178 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
143 masquerading,·etc.179 masquerading,·etc.
144 ······</td>180 ······</td>
145 ····</tr>181 ····</tr>
146 ····<tr>182 ····<tr>
147 ······<td>Req-1.4.1</td>183 ······<td>Req-1.4.2</td>
 184 ······<td>Disable·SCTP·Support</td>
148 ······<td>Set·Default·ip6tables·Policy·for·Incoming·Packets</td> 
149 ······<td·xml:lang="en-US"> 
150 ········To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)·for 
151 the·built-in·INPUT·chain·which·processes·incoming·packets, 
152 add·or·correct·the·following·line·in 
153 <tt>/etc/sysconfig/ip6tables</tt>: 
154 <pre>:INPUT·DROP·[0:0]</pre> 
155 If·changes·were·required,·reload·the·ip6tables·rules: 
156 <pre>$·sudo·service·ip6tables·reload</pre> 
157 ······</td> 
158 ······<td·xml:lang="en-US"> 
159 ········In·<tt>ip6tables</tt>,·the·default·policy·is·applied·only·after·all 
160 the·applicable·rules·in·the·table·are·examined·for·a·match.·Setting·the 
161 default·policy·to·<tt>DROP</tt>·implements·proper·design·for·a·firewall,·i.e. 
162 any·packets·which·are·not·explicitly·permitted·should·not·be 
163 accepted. 
164 ······</td> 
165 ····</tr> 
166 ····<tr> 
167 ······<td>Req-1.4.1</td> 
168 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td> 
169 ······<td·xml:lang="en-US">185 ······<td·xml:lang="en-US">
170 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre> 
171 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>186 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
 187 transport·layer·protocol,·designed·to·support·the·idea·of
 188 message-oriented·communication,·with·several·streams·of·messages
 189 within·one·connection.
  
 190 To·configure·the·system·to·prevent·the·<code>sctp</code>
 191 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/sctp.conf</code>:
 192 <pre>install·sctp·/bin/true</pre>
  
 193 To·configure·the·system·to·prevent·the·<code>sctp</code>·from·being·used,
 194 add·the·following·line·to·file·<code>/etc/modprobe.d/sctp.conf</code>:
 195 <pre>blacklist·sctp</pre>
172 ······</td>196 ······</td>
173 ······<td·xml:lang="en-US">197 ······<td·xml:lang="en-US">
 198 ········Disabling·SCTP·protects
 199 the·system·against·exploitation·of·any·flaws·in·its·implementation.
174 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a 
175 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state. 
176 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received, 
177 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood 
178 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and 
179 enables·the·system·to·continue·servicing·valid·connection·requests. 
180 ······</td>200 ······</td>
181 ····</tr>201 ····</tr>
182 ····<tr>202 ····<tr>
183 ······<td>Req-1.4.2</td>203 ······<td>Req-1.4.2</td>
184 ······<td>Disable·DCCP·Support</td>204 ······<td>Disable·DCCP·Support</td>
185 ······<td·xml:lang="en-US">205 ······<td·xml:lang="en-US">
186 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a206 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
Offset 197, 33 lines modifiedOffset 219, 44 lines modified
197 ······</td>219 ······</td>
198 ······<td·xml:lang="en-US">220 ······<td·xml:lang="en-US">
199 ········Disabling·DCCP·protects221 ········Disabling·DCCP·protects
200 the·system·against·exploitation·of·any·flaws·in·its·implementation.222 the·system·against·exploitation·of·any·flaws·in·its·implementation.
201 ······</td>223 ······</td>
202 ····</tr>224 ····</tr>
203 ····<tr>225 ····<tr>
204 ······<td>Req-1.4.2</td>226 ······<td>Req-1.4.3</td>
205 ······<td>Disable·SCTP·Support</td>227 ······<td>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</td>
206 ······<td·xml:lang="en-US">228 ······<td·xml:lang="en-US">
 229 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_echo_ignore_broadcasts</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_echo_ignore_broadcasts=1</pre>
 230 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_echo_ignore_broadcasts·=·1</pre>
207 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a 
208 transport·layer·protocol,·designed·to·support·the·idea·of 
Max diff block lines reached; 267317/274075 bytes (97.53%) of diff not shown.
435 KB
html2text {}
    
Offset 56, 14 lines modifiedOffset 56, 55 lines modified
56 ····················································································also·serve·to56 ····················································································also·serve·to
57 ····················································································create·a·man-in-57 ····················································································create·a·man-in-
58 ····················································································the-middle·attack58 ····················································································the-middle·attack
59 ····················································································or·be·used·to59 ····················································································or·be·used·to
60 ····················································································create·a·denial·of60 ····················································································create·a·denial·of
61 ····················································································service·to·valid61 ····················································································service·to·valid
62 ····················································································network·resources.62 ····················································································network·resources.
 63 ····················································································A·TCP·SYN·flood
 64 ····················································································attack·can·cause·a
 65 ····················································································denial·of·service
 66 ····················································································by·filling·a
 67 ····················································································system's·TCP
 68 ····················································································connection·table
 69 ····················································································with·connections·in
 70 ····················································································the·SYN_RCVD·state.
 71 ····················································································Syncookies·can·be
 72 ·····························To·set·the·runtime·status·of·the·······················used·to·track·a
 73 ·····························net.ipv4.tcp_syncookies·kernel·parameter,·run·the······connection·when·a
 74 ·········Enable·Kernel·······following·command:·····································subsequent·ACK·is
 75 Req-·····Parameter·to·Use····$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1·············received,·verifying
 76 1.4.1····TCP·Syncookies·on···To·make·sure·that·the·setting·is·persistent,·add·the···the·initiator·is
 77 ·········Network·Interfaces··following·line·to·a·file·in·the·directory·/etc/········attempting·a·valid
 78 ·····························sysctl.d:··············································connection·and·is
 79 ·····························net.ipv4.tcp_syncookies·=·1····························not·a·flood·source.
 80 ····················································································This·feature·is
 81 ····················································································activated·when·a
 82 ····················································································flood·condition·is
 83 ····················································································detected,·and
 84 ····················································································enables·the·system
 85 ····················································································to·continue
 86 ····················································································servicing·valid
 87 ····················································································connection
 88 ····················································································requests.
 89 ····················································································In·ip6tables,·the
 90 ····················································································default·policy·is
 91 ····················································································applied·only·after
 92 ····················································································all·the·applicable
 93 ·····························To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)··rules·in·the·table
 94 ·········Set·Default·········for·the·built-in·INPUT·chain·which·processes·incoming··are·examined·for·a
 95 Req-·····ip6tables·Policy····packets,·add·or·correct·the·following·line·in·/etc/····match.·Setting·the
 96 1.4.1····for·Incoming········sysconfig/ip6tables:···································default·policy·to
 97 ·········Packets·············:INPUT·DROP·[0:0]······································DROP·implements
 98 ·····························If·changes·were·required,·reload·the·ip6tables·rules:··proper·design·for·a
 99 ·····························$·sudo·service·ip6tables·reload························firewall,·i.e.·any
 100 ····················································································packets·which·are
 101 ····················································································not·explicitly
 102 ····················································································permitted·should
 103 ····················································································not·be·accepted.
63 ····················································································Loopback·traffic·is104 ····················································································Loopback·traffic·is
64 ····················································································generated·between105 ····················································································generated·between
65 ····················································································processes·on106 ····················································································processes·on
66 ····················································································machine·and·is107 ····················································································machine·and·is
67 ····················································································typically·critical108 ····················································································typically·critical
68 ····················································································to·operation·of·the109 ····················································································to·operation·of·the
69 ····················································································system.·The110 ····················································································system.·The
Offset 99, 78 lines modifiedOffset 140, 84 lines modified
99 ····················································································network·packet140 ····················································································network·packet
100 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.141 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.
101 1.4.1····Package·············following·command:·····································iptables·allows142 1.4.1····Package·············following·command:·····································iptables·allows
102 ·····························$·sudo·yum·install·iptables····························system·operators·to143 ·····························$·sudo·yum·install·iptables····························system·operators·to
103 ····················································································set·up·firewalls144 ····················································································set·up·firewalls
104 ····················································································and·IP145 ····················································································and·IP
105 ····················································································masquerading,·etc.146 ····················································································masquerading,·etc.
106 ····················································································In·ip6tables,·the 
107 ····················································································default·policy·is 
108 ····················································································applied·only·after 
109 ····················································································all·the·applicable 
110 ·····························To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)··rules·in·the·table 
111 ·········Set·Default·········for·the·built-in·INPUT·chain·which·processes·incoming··are·examined·for·a 
112 Req-·····ip6tables·Policy····packets,·add·or·correct·the·following·line·in·/etc/····match.·Setting·the 
113 1.4.1····for·Incoming········sysconfig/ip6tables:···································default·policy·to 
114 ·········Packets·············:INPUT·DROP·[0:0]······································DROP·implements 
115 ·····························If·changes·were·required,·reload·the·ip6tables·rules:··proper·design·for·a 
116 ·····························$·sudo·service·ip6tables·reload························firewall,·i.e.·any 
117 ····················································································packets·which·are 
118 ····················································································not·explicitly 
119 ····················································································permitted·should 
120 ····················································································not·be·accepted. 
121 ····················································································A·TCP·SYN·flood 
122 ····················································································attack·can·cause·a 
123 ····················································································denial·of·service 
124 ····················································································by·filling·a 
125 ····················································································system's·TCP 
126 ····················································································connection·table 
127 ····················································································with·connections·in 
128 ····················································································the·SYN_RCVD·state. 
129 ····················································································Syncookies·can·be 
130 ·····························To·set·the·runtime·status·of·the·······················used·to·track·a 
131 ·····························net.ipv4.tcp_syncookies·kernel·parameter,·run·the······connection·when·a 
132 ·········Enable·Kernel·······following·command:·····································subsequent·ACK·is 
133 Req-·····Parameter·to·Use····$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1·············received,·verifying 
134 1.4.1····TCP·Syncookies·on···To·make·sure·that·the·setting·is·persistent,·add·the···the·initiator·is 
135 ·········Network·Interfaces··following·line·to·a·file·in·the·directory·/etc/········attempting·a·valid 
136 ·····························sysctl.d:··············································connection·and·is 
137 ·····························net.ipv4.tcp_syncookies·=·1····························not·a·flood·source. 
138 ····················································································This·feature·is 
139 ····················································································activated·when·a 
140 ····················································································flood·condition·is 
141 ····················································································detected,·and 
142 ····················································································enables·the·system 
143 ····················································································to·continue 
144 ····················································································servicing·valid 
145 ····················································································connection 
146 ····················································································requests. 
147 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
148 ·····························relatively·new·transport·layer·protocol,·designed·to 
149 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP 
150 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system 
151 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against 
152 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any 
153 ·····························install·dccp·/bin/true·································flaws·in·its 
154 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation. 
155 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/ 
156 ·····························dccp.conf: 
157 ·····························blacklist·dccp 
158 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a147 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
159 ·····························transport·layer·protocol,·designed·to·support·the·idea148 ·····························transport·layer·protocol,·designed·to·support·the·idea
160 ·····························of·message-oriented·communication,·with·several149 ·····························of·message-oriented·communication,·with·several
161 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP150 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP
162 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system151 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system
163 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against152 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against
164 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any153 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any
165 ·····························install·sctp·/bin/true·································flaws·in·its154 ·····························install·sctp·/bin/true·································flaws·in·its
166 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.155 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.
167 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/156 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
168 ·····························sctp.conf:157 ·····························sctp.conf:
169 ·····························blacklist·sctp158 ·····························blacklist·sctp
Max diff block lines reached; 427628/445921 bytes (95.90%) of diff not shown.
1.48 MB
./usr/share/doc/ssg-nondebian/table-rhel8-anssirefs.html
    
Offset 65, 569 lines modifiedOffset 65, 569 lines modified
00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc
00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···
00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</
00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·
00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.
00000450:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R00000450:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R
Diff chunk too large, falling back to line-by-line diff (555 lines added, 555 lines removed)
00000460:·3129·3c2f·7464·3e0a·2020·2020·2020·3c74··1)</td>.······<t00000460:·3129·3c2f·7464·3e0a·2020·2020·2020·3c74··1)</td>.······<t
00000470:·643e·5265·6d6f·7665·2074·6674·7020·4461··d>Remove·tftp·Da00000470:·643e·556e·696e·7374·616c·6c20·5365·6e64··d>Uninstall·Send
00000480:·656d·6f6e·3c2f·7464·3e0a·2020·2020·2020··emon</td>.······00000480:·6d61·696c·2050·6163·6b61·6765·3c2f·7464··mail·Package</td
00000490:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en00000490:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:
000004a0:·2d55·5322·3e0a·2020·2020·2020·2020·5472··-US">.········Tr000004a0:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··
000004b0:·6976·6961·6c20·4669·6c65·2054·7261·6e73··ivial·File·Trans000004b0:·2020·2020·2020·5365·6e64·6d61·696c·2069········Sendmail·i
000004c0:·6665·7220·5072·6f74·6f63·6f6c·2028·5446··fer·Protocol·(TF000004c0:·7320·6e6f·7420·7468·6520·6465·6661·756c··s·not·the·defaul
000004d0:·5450·2920·6973·2061·2073·696d·706c·6520··TP)·is·a·simple·000004d0:·7420·6d61·696c·2074·7261·6e73·6665·7220··t·mail·transfer·
000004e0:·6669·6c65·2074·7261·6e73·6665·7220·7072··file·transfer·pr000004e0:·6167·656e·7420·616e·6420·6973·0a6e·6f74··agent·and·is.not
000004f0:·6f74·6f63·6f6c·2c0a·7479·7069·6361·6c6c··otocol,.typicall000004f0:·2069·6e73·7461·6c6c·6564·2062·7920·6465···installed·by·de
00000500:·7920·7573·6564·2074·6f20·6175·746f·6d61··y·used·to·automa00000500:·6661·756c·742e·0a54·6865·203c·636f·6465··fault..The·<code
00000510:·7469·6361·6c6c·7920·7472·616e·7366·6572··tically·transfer00000510:·3e73·656e·646d·6169·6c3c·2f63·6f64·653e··>sendmail</code>
00000520:·2063·6f6e·6669·6775·7261·7469·6f6e·206f···configuration·o00000520:·2070·6163·6b61·6765·2063·616e·2062·6520···package·can·be·
00000530:·7220·626f·6f74·2066·696c·6573·2062·6574··r·boot·files·bet00000530:·7265·6d6f·7665·6420·7769·7468·2074·6865··removed·with·the
00000540:·7765·656e·2073·7973·7465·6d73·2e0a·5446··ween·systems..TF00000540:·2066·6f6c·6c6f·7769·6e67·2063·6f6d·6d61···following·comma
00000550:·5450·2064·6f65·7320·6e6f·7420·7375·7070··TP·does·not·supp00000550:·6e64·3a0a·3c70·7265·3e0a·2420·7375·646f··nd:.<pre>.$·sudo
00000560:·6f72·7420·6175·7468·656e·7469·6361·7469··ort·authenticati00000560:·2079·756d·2065·7261·7365·2073·656e·646d···yum·erase·sendm
00000570:·6f6e·2061·6e64·2063·616e·2062·6520·6561··on·and·can·be·ea00000570:·6169·6c3c·2f70·7265·3e0a·2020·2020·2020··ail</pre>.······
00000580:·7369·6c79·2068·6163·6b65·642e·2054·6865··sily·hacked.·The00000580:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000590:·2070·6163·6b61·6765·0a3c·7474·3e74·6674···package.<tt>tft00000590:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
000005a0:·703c·2f74·743e·2069·7320·6120·636c·6965··p</tt>·is·a·clie000005a0:·3e0a·2020·2020·2020·2020·5468·6520·7365··>.········The·se
000005b0:·6e74·2070·726f·6772·616d·2074·6861·7420··nt·program·that·000005b0:·6e64·6d61·696c·2073·6f66·7477·6172·6520··ndmail·software·
000005c0:·616c·6c6f·7773·2066·6f72·2063·6f6e·6e65··allows·for·conne000005c0:·7761·7320·6e6f·7420·6465·7665·6c6f·7065··was·not·develope
000005d0:·6374·696f·6e73·2074·6f20·6120·3c74·743e··ctions·to·a·<tt>000005d0:·6420·7769·7468·2073·6563·7572·6974·7920··d·with·security·
000005e0:·7466·7470·3c2f·7474·3e20·7365·7276·6572··tftp</tt>·server000005e0:·696e·206d·696e·6420·616e·640a·6974·7320··in·mind·and.its·
000005f0:·2e0a·2020·2020·2020·3c2f·7464·3e0a·2020··..······</td>.··000005f0:·6465·7369·676e·2070·7265·7665·6e74·7320··design·prevents·
00000600:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang00000600:·6974·2066·726f·6d20·6265·696e·6720·6566··it·from·being·ef
00000610:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······00000610:·6665·6374·6976·656c·7920·636f·6e74·6169··fectively·contai
00000620:·2020·4974·2069·7320·7265·636f·6d6d·656e····It·is·recommen00000620:·6e65·6420·6279·2053·454c·696e·7578·2e20··ned·by·SELinux.·
00000630:·6465·6420·7468·6174·2054·4654·5020·6265··ded·that·TFTP·be00000630:·2050·6f73·7466·6978·0a73·686f·756c·6420···Postfix.should·
00000640:·2072·656d·6f76·6564·2c20·756e·6c65·7373···removed,·unless00000640:·6265·2075·7365·6420·696e·7374·6561·642e··be·used·instead.
00000650:·2074·6865·7265·2069·7320·6120·7370·6563···there·is·a·spec00000650:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00000660:·6966·6963·206e·6565·640a·666f·7220·5446··ific·need.for·TF00000660:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.
00000670:·5450·2028·7375·6368·2061·7320·6120·626f··TP·(such·as·a·bo00000670:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R
00000680:·6f74·2073·6572·7665·7229·2e20·496e·2074··ot·server).·In·t00000680:·3129·3c62·722f·3e4e·5430·3037·2852·3033··1)<br/>NT007(R03
00000690:·6861·7420·6361·7365·2c20·7573·6520·6578··hat·case,·use·ex00000690:·293c·2f74·643e·0a20·2020·2020·203c·7464··)</td>.······<td
000006a0:·7472·656d·6520·6361·7574·696f·6e20·7768··treme·caution·wh000006a0:·3e55·6e69·6e73·7461·6c6c·2074·6865·2074··>Uninstall·the·t
000006b0:·656e·2063·6f6e·6669·6775·7269·6e67·0a74··en·configuring.t000006b0:·656c·6e65·7420·7365·7276·6572·3c2f·7464··elnet·server</td
000006c0:·6865·2073·6572·7669·6365·732e·0a20·2020··he·services..···000006c0:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:
000006d0:·2020·203c·2f74·643e·0a20·2020·203c·2f74·····</td>.····</t000006d0:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··
000006e0:·723e·0a20·2020·203c·7472·3e0a·2020·2020··r>.····<tr>.····000006e0:·2020·2020·2020·5468·6520·7465·6c6e·6574········The·telnet
000006f0:·2020·3c74·643e·4250·3238·2852·3129·3c2f····<td>BP28(R1)</000006f0:·2064·6165·6d6f·6e20·7368·6f75·6c64·2062···daemon·should·b
00000700:·7464·3e0a·2020·2020·2020·3c74·643e·556e··td>.······<td>Un00000700:·6520·756e·696e·7374·616c·6c65·642e·0a20··e·uninstalled..·
00000710:·696e·7374·616c·6c20·7869·6e65·7464·2050··install·xinetd·P00000710:·2020·2020·203c·2f74·643e·0a20·2020·2020·······</td>.·····
00000720:·6163·6b61·6765·3c2f·7464·3e0a·2020·2020··ackage</td>.····00000720:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
00000730:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="00000730:·6e2d·5553·223e·0a20·2020·2020·2020·203c··n-US">.········<
00000740:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········00000740:·7474·3e74·656c·6e65·743c·2f74·743e·2061··tt>telnet</tt>·a
00000750:·5468·6520·3c63·6f64·653e·7869·6e65·7464··The·<code>xinetd00000750:·6c6c·6f77·7320·636c·6561·7220·7465·7874··llows·clear·text
00000760:·3c2f·636f·6465·3e20·7061·636b·6167·6520··</code>·package·00000760:·2063·6f6d·6d75·6e69·6361·7469·6f6e·732c···communications,
00000770:·6361·6e20·6265·2072·656d·6f76·6564·2077··can·be·removed·w00000770:·2061·6e64·2064·6f65·7320·6e6f·7420·7072···and·does·not·pr
00000780:·6974·6820·7468·6520·666f·6c6c·6f77·696e··ith·the·followin00000780:·6f74·6563·740a·616e·7920·6461·7461·2074··otect.any·data·t
00000790:·6720·636f·6d6d·616e·643a·0a3c·7072·653e··g·command:.<pre>00000790:·7261·6e73·6d69·7373·696f·6e20·6265·7477··ransmission·betw
000007a0:·0a24·2073·7564·6f20·7975·6d20·6572·6173··.$·sudo·yum·eras000007a0:·6565·6e20·636c·6965·6e74·2061·6e64·2073··een·client·and·s
000007b0:·6520·7869·6e65·7464·3c2f·7072·653e·0a20··e·xinetd</pre>.·000007b0:·6572·7665·722e·2041·6e79·2063·6f6e·6669··erver.·Any·confi
000007c0:·2020·2020·203c·2f74·643e·0a20·2020·2020·······</td>.·····000007c0:·6465·6e74·6961·6c20·6461·7461·0a63·616e··dential·data.can
000007d0:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e000007d0:·2062·6520·6c69·7374·656e·6564·2061·6e64···be·listened·and
000007e0:·6e2d·5553·223e·0a20·2020·2020·2020·2052··n-US">.········R000007e0:·206e·6f20·696e·7465·6772·6974·7920·6368···no·integrity·ch
000007f0:·656d·6f76·696e·6720·7468·6520·3c74·743e··emoving·the·<tt>000007f0:·6563·6b69·6e67·2069·7320·6d61·6465·2e27··ecking·is·made.'
00000800:·7869·6e65·7464·3c2f·7474·3e20·7061·636b··xinetd</tt>·pack00000800:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00000810:·6167·6520·6465·6372·6561·7365·7320·7468··age·decreases·th00000810:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.
00000820:·6520·7269·736b·206f·6620·7468·650a·7869··e·risk·of·the.xi00000820:·2020·2020·2020·3c74·643e·4250·3238·2852········<td>BP28(R
00000830:·6e65·7464·2073·6572·7669·6365·2773·2061··netd·service's·a00000830:·3129·3c2f·7464·3e0a·2020·2020·2020·3c74··1)</td>.······<t
00000840:·6363·6964·656e·7461·6c20·286f·7220·696e··ccidental·(or·in00000840:·643e·556e·696e·7374·616c·6c20·7461·6c6b··d>Uninstall·talk
00000850:·7465·6e74·696f·6e61·6c29·2061·6374·6976··tentional)·activ00000850:·2d73·6572·7665·7220·5061·636b·6167·653c··-server·Package<
00000860:·6174·696f·6e2e·0a20·2020·2020·203c·2f74··ation..······</t00000860:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x
00000870:·643e·0a20·2020·203c·2f74·723e·0a20·2020··d>.····</tr>.···00000870:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
00000880:·203c·7472·3e0a·2020·2020·2020·3c74·643e···<tr>.······<td>00000880:·0a20·2020·2020·2020·2054·6865·203c·636f··.········The·<co
00000890:·4250·3238·2852·3129·3c2f·7464·3e0a·2020··BP28(R1)</td>.··00000890:·6465·3e74·616c·6b2d·7365·7276·6572·3c2f··de>talk-server</
000008a0:·2020·2020·3c74·643e·556e·696e·7374·616c······<td>Uninstal000008a0:·636f·6465·3e20·7061·636b·6167·6520·6361··code>·package·ca
000008b0:·6c20·7465·6c6e·6574·2d73·6572·7665·7220··l·telnet-server·000008b0:·6e20·6265·2072·656d·6f76·6564·2077·6974··n·be·removed·wit
000008c0:·5061·636b·6167·653c·2f74·643e·0a20·2020··Package</td>.···000008c0:·6820·7468·6520·666f·6c6c·6f77·696e·6720··h·the·following·
000008d0:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=000008d0:·636f·6d6d·616e·643a·203c·7072·653e·2024··command:·<pre>·$
000008e0:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······000008e0:·2073·7564·6f20·7975·6d20·6572·6173·6520···sudo·yum·erase·
000008f0:·2054·6865·203c·636f·6465·3e74·656c·6e65···The·<code>telne000008f0:·7461·6c6b·2d73·6572·7665·723c·2f70·7265··talk-server</pre
00000900:·742d·7365·7276·6572·3c2f·636f·6465·3e20··t-server</code>·00000900:·3e0a·2020·2020·2020·3c2f·7464·3e0a·2020··>.······</td>.··
00000910:·7061·636b·6167·6520·6361·6e20·6265·2072··package·can·be·r00000910:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
00000920:·656d·6f76·6564·2077·6974·6820·7468·6520··emoved·with·the·00000920:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
00000930:·666f·6c6c·6f77·696e·6720·636f·6d6d·616e··following·comman00000930:·2020·5468·6520·7461·6c6b·2073·6f66·7477····The·talk·softw
00000940:·643a·0a3c·7072·653e·0a24·2073·7564·6f20··d:.<pre>.$·sudo·00000940:·6172·6520·7072·6573·656e·7473·2061·2073··are·presents·a·s
00000950:·7975·6d20·6572·6173·6520·7465·6c6e·6574··yum·erase·telnet00000950:·6563·7572·6974·7920·7269·736b·2061·7320··ecurity·risk·as·
00000960:·2d73·6572·7665·723c·2f70·7265·3e0a·2020··-server</pre>.··00000960:·6974·2075·7365·7320·756e·656e·6372·7970··it·uses·unencryp
00000970:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······00000970:·7465·6420·7072·6f74·6f63·6f6c·730a·666f··ted·protocols.fo
00000980:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en00000980:·7220·636f·6d6d·756e·6963·6174·696f·6e73··r·communications
00000990:·2d55·5322·3e0a·2020·2020·2020·2020·4974··-US">.········It00000990:·2e20·5265·6d6f·7669·6e67·2074·6865·203c··.·Removing·the·<
000009a0:·2069·7320·6465·7472·696d·656e·7461·6c20···is·detrimental·000009a0:·7474·3e74·616c·6b2d·7365·7276·6572·3c2f··tt>talk-server</
000009b0:·666f·7220·6f70·6572·6174·696e·6720·7379··for·operating·sy000009b0:·7474·3e20·7061·636b·6167·6520·6465·6372··tt>·package·decr
000009c0:·7374·656d·7320·746f·2070·726f·7669·6465··stems·to·provide000009c0:·6561·7365·7320·7468·650a·7269·736b·206f··eases·the.risk·o
000009d0:·2c20·6f72·2069·6e73·7461·6c6c·2062·7920··,·or·install·by·000009d0:·6620·7468·6520·6163·6369·6465·6e74·616c··f·the·accidental
000009e0:·6465·6661·756c·742c·0a66·756e·6374·696f··default,.functio000009e0:·2028·6f72·2069·6e74·656e·7469·6f6e·616c···(or·intentional
000009f0:·6e61·6c69·7479·2065·7863·6565·6469·6e67··nality·exceeding000009f0:·2920·6163·7469·7661·7469·6f6e·206f·6620··)·activation·of·
00000a00:·2072·6571·7569·7265·6d65·6e74·7320·6f72···requirements·or00000a00:·7461·6c6b·2073·6572·7669·6365·732e·0a20··talk·services..·
00000a10:·206d·6973·7369·6f6e·206f·626a·6563·7469···mission·objecti00000a10:·2020·2020·203c·2f74·643e·0a20·2020·203c·······</td>.····<
00000a20:·7665·732e·2054·6865·7365·0a75·6e6e·6563··ves.·These.unnec00000a20:·2f74·723e·0a20·2020·203c·7472·3e0a·2020··/tr>.····<tr>.··
00000a30:·6573·7361·7279·2063·6170·6162·696c·6974··essary·capabilit00000a30:·2020·2020·3c74·643e·4250·3238·2852·3129······<td>BP28(R1)
00000a40:·6965·7320·6172·6520·6f66·7465·6e20·6f76··ies·are·often·ov00000a40:·3c2f·7464·3e0a·2020·2020·2020·3c74·643e··</td>.······<td>
00000a50:·6572·6c6f·6f6b·6564·2061·6e64·2074·6865··erlooked·and·the00000a50:·556e·696e·7374·616c·6c20·7869·6e65·7464··Uninstall·xinetd
00000a60:·7265·666f·7265·206d·6179·2072·656d·6169··refore·may·remai00000a60:·2050·6163·6b61·6765·3c2f·7464·3e0a·2020···Package</td>.··
00000a70:·6e0a·756e·7365·6375·7265·2e20·5468·6579··n.unsecure.·They00000a70:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
00000a80:·2069·6e63·7265·6173·6520·7468·6520·7269···increase·the·ri00000a80:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
00000a90:·736b·2074·6f20·7468·6520·706c·6174·666f··sk·to·the·platfo00000a90:·2020·5468·6520·3c63·6f64·653e·7869·6e65····The·<code>xine
00000aa0:·726d·2062·7920·7072·6f76·6964·696e·6720··rm·by·providing·00000aa0:·7464·3c2f·636f·6465·3e20·7061·636b·6167··td</code>·packag
00000ab0:·6164·6469·7469·6f6e·616c·0a61·7474·6163··additional.attac00000ab0:·6520·6361·6e20·6265·2072·656d·6f76·6564··e·can·be·removed
00000ac0:·6b20·7665·6374·6f72·732e·0a3c·6272·202f··k·vectors..<br·/00000ac0:·2077·6974·6820·7468·6520·666f·6c6c·6f77···with·the·follow
00000ad0:·3e0a·5468·6520·7465·6c6e·6574·2073·6572··>.The·telnet·ser00000ad0:·696e·6720·636f·6d6d·616e·643a·0a3c·7072··ing·command:.<pr
00000ae0:·7669·6365·2070·726f·7669·6465·7320·616e··vice·provides·an00000ae0:·653e·0a24·2073·7564·6f20·7975·6d20·6572··e>.$·sudo·yum·er
00000af0:·2075·6e65·6e63·7279·7074·6564·2072·656d···unencrypted·rem00000af0:·6173·6520·7869·6e65·7464·3c2f·7072·653e··ase·xinetd</pre>
00000b00:·6f74·6520·6163·6365·7373·2073·6572·7669··ote·access·servi00000b00:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···
00000b10:·6365·2077·6869·6368·2064·6f65·730a·6e6f··ce·which·does.no00000b10:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=
00000b20:·7420·7072·6f76·6964·6520·666f·7220·7468··t·provide·for·th00000b20:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······
00000b30:·6520·636f·6e66·6964·656e·7469·616c·6974··e·confidentialit00000b30:·2052·656d·6f76·696e·6720·7468·6520·3c74···Removing·the·<t
00000b40:·7920·616e·6420·696e·7465·6772·6974·7920··y·and·integrity·00000b40:·743e·7869·6e65·7464·3c2f·7474·3e20·7061··t>xinetd</tt>·pa
00000b50:·6f66·2075·7365·7220·7061·7373·776f·7264··of·user·password00000b50:·636b·6167·6520·6465·6372·6561·7365·7320··ckage·decreases·
00000b60:·7320·6f72·2074·6865·0a72·656d·6f74·6520··s·or·the.remote·00000b60:·7468·6520·7269·736b·206f·6620·7468·650a··the·risk·of·the.
00000b70:·7365·7373·696f·6e2e·2049·6620·6120·7072··session.·If·a·pr00000b70:·7869·6e65·7464·2073·6572·7669·6365·2773··xinetd·service's
00000b80:·6976·696c·6567·6564·2075·7365·7220·7765··ivileged·user·we00000b80:·2061·6363·6964·656e·7461·6c20·286f·7220···accidental·(or·
00000b90:·7265·2074·6f20·6c6f·6769·6e20·7573·696e··re·to·login·usin00000b90:·696e·7465·6e74·696f·6e61·6c29·2061·6374··intentional)·act
00000ba0:·6720·7468·6973·2073·6572·7669·6365·2c20··g·this·service,·00000ba0:·6976·6174·696f·6e2e·0a20·2020·2020·203c··ivation..······<
00000bb0:·7468·650a·7072·6976·696c·6567·6564·2075··the.privileged·u00000bb0:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·
00000bc0:·7365·7220·7061·7373·776f·7264·2063·6f75··ser·password·cou00000bc0:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t
00000bd0:·6c64·2062·6520·636f·6d70·726f·6d69·7365··ld·be·compromise00000bd0:·643e·4250·3238·2852·3129·3c2f·7464·3e0a··d>BP28(R1)</td>.
Max diff block lines reached; 1227126/1304290 bytes (94.08%) of diff not shown.
246 KB
html2text {}
    
Offset 1, 102 lines modifiedOffset 1, 107 lines modified
  
  
1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Red·Hat1 Rules·with·ANSSI·Reference·in·Guide·to·the·Secure·Configuration·of·Red·Hat
2 Enterprise·Linux·82 Enterprise·Linux·8
  
  
3 ································Trivial·File·Transfer·Protocol·(TFTP)·is·a 
4 ································simple·file·transfer·protocol,·typically 
5 ································used·to·automatically·transfer·configuration·It·is·recommended·that·TFTP·be·removed,·unless·there·is·a·specific·need·for 
6 BP28··Remove·tftp·Daemon········or·boot·files·between·systems.·TFTP·does·not·TFTP·(such·as·a·boot·server).·In·that·case,·use·extreme·caution·when 
7 (R1)····························support·authentication·and·can·be·easily·····configuring·the·services. 
8 ································hacked.·The·package·tftp·is·a·client·program 
9 ································that·allows·for·connections·to·a·tftp 
10 ································server. 
11 BP28····························The·xinetd·package·can·be·removed·with·the···Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's 
12 (R1)··Uninstall·xinetd·Package··following·command:···························accidental·(or·intentional)·activation. 
13 ································$·sudo·yum·erase·xinetd 
14 ·············································································It·is·detrimental·for·operating·systems·to·provide,·or·install·by·default, 
15 ·············································································functionality·exceeding·requirements·or·mission·objectives.·These 
16 ·············································································unnecessary·capabilities·are·often·overlooked·and·therefore·may·remain 
17 ·············································································unsecure.·They·increase·the·risk·to·the·platform·by·providing·additional 
18 BP28··Uninstall·telnet-server···The·telnet-server·package·can·be·removed·····attack·vectors. 
19 (R1)··Package···················with·the·following·command:··················The·telnet·service·provides·an·unencrypted·remote·access·service·which·does 
20 ································$·sudo·yum·erase·telnet-server···············not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the 
21 ·············································································remote·session.·If·a·privileged·user·were·to·login·using·this·service,·the 
22 ·············································································privileged·user·password·could·be·compromised. 
23 ·············································································Removing·the·telnet-server·package·decreases·the·risk·of·the·telnet 
24 ·············································································service's·accidental·(or·intentional)·activation. 
25 ································The·Network·Information·Service·(NIS), 
26 ································formerly·known·as·Yellow·Pages,·is·a·client-·The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to 
27 BP28····························server·directory·service·protocol·used·to····DOS·attacks,·buffer·overflows·and·has·poor·authentication·for·querying·NIS 
28 (R1)··Remove·NIS·Client·········distribute·system·configuration·files.·The···maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight 
29 ································NIS·client·(ypbind)·was·used·to·bind·a·······Directory·Access·Protocol·(LDAP).·It·is·recommended·that·the·service·be 
30 ································system·to·an·NIS·server·and·receive·the······removed. 
31 ································distributed·configuration·files. 
32 BP28··Uninstall·talk-server·····The·talk-server·package·can·be·removed·with··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols 
33 (R1)··Package···················the·following·command:·······················for·communications.·Removing·the·talk-server·package·decreases·the·risk·of 
34 ·································$·sudo·yum·erase·talk-server················the·accidental·(or·intentional)·activation·of·talk·services. 
35 ································Sendmail·is·not·the·default·mail·transfer3 ································Sendmail·is·not·the·default·mail·transfer
36 BP28··Uninstall·Sendmail········agent·and·is·not·installed·by·default.·The···The·sendmail·software·was·not·developed·with·security·in·mind·and·its·design4 BP28··Uninstall·Sendmail········agent·and·is·not·installed·by·default.·The···The·sendmail·software·was·not·developed·with·security·in·mind·and·its·design
37 (R1)··Package···················sendmail·package·can·be·removed·with·the·····prevents·it·from·being·effectively·contained·by·SELinux.·Postfix·should·be5 (R1)··Package···················sendmail·package·can·be·removed·with·the·····prevents·it·from·being·effectively·contained·by·SELinux.·Postfix·should·be
38 ································following·command:···························used·instead.6 ································following·command:···························used·instead.
39 ································$·sudo·yum·erase·sendmail7 ································$·sudo·yum·erase·sendmail
40 BP28·········································································telnet·allows·clear·text·communications,·and·does·not·protect·any·data8 BP28·········································································telnet·allows·clear·text·communications,·and·does·not·protect·any·data
41 (R1)··Uninstall·the·telnet······The·telnet·daemon·should·be·uninstalled.·····transmission·between·client·and·server.·Any·confidential·data·can·be9 (R1)··Uninstall·the·telnet······The·telnet·daemon·should·be·uninstalled.·····transmission·between·client·and·server.·Any·confidential·data·can·be
42 NT007·server·································································listened·and·no·integrity·checking·is·made.'10 NT007·server·································································listened·and·no·integrity·checking·is·made.'
43 (R03)11 (R03)
44 ································The·ypserv·package·can·be·removed·with·the···The·NIS·service·provides·an·unencrypted·authentication·service·which·does 
45 BP28··Uninstall·ypserv·Package··following·command:···························not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the 
46 (R1)····························$·sudo·yum·erase·ypserv······················remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the 
47 ·············································································accidental·(or·intentional)·activation·of·NIS·or·NIS+·services. 
48 ·············································································Removing·the·tftp-server·package·decreases·the·risk·of·the·accidental·(or 
49 ·············································································intentional)·activation·of·tftp·services. 
50 BP28··Uninstall·tftp-server·····The·tftp-server·package·can·be·removed·with 
51 (R1)··Package···················the·following·command:·······················If·TFTP·is·required·for·operational·support·(such·as·transmission·of·router 
52 ·································$·sudo·yum·erase·tftp-server················configurations),·its·use·must·be·documented·with·the·Information·Systems 
53 ·············································································Securty·Manager·(ISSM),·restricted·to·only·authorized·personnel,·and·have 
54 ·············································································access·control·rules·established.12 BP28··Uninstall·talk-server·····The·talk-server·package·can·be·removed·with··The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols
 13 (R1)··Package···················the·following·command:·······················for·communications.·Removing·the·talk-server·package·decreases·the·risk·of
 14 ·································$·sudo·yum·erase·talk-server················the·accidental·(or·intentional)·activation·of·talk·services.
 15 BP28····························The·xinetd·package·can·be·removed·with·the···Removing·the·xinetd·package·decreases·the·risk·of·the·xinetd·service's
 16 (R1)··Uninstall·xinetd·Package··following·command:···························accidental·(or·intentional)·activation.
 17 ································$·sudo·yum·erase·xinetd
 18 ································Trivial·File·Transfer·Protocol·(TFTP)·is·a
 19 ································simple·file·transfer·protocol,·typically
 20 ································used·to·automatically·transfer·configuration·It·is·recommended·that·TFTP·be·removed,·unless·there·is·a·specific·need·for
 21 BP28··Remove·tftp·Daemon········or·boot·files·between·systems.·TFTP·does·not·TFTP·(such·as·a·boot·server).·In·that·case,·use·extreme·caution·when
 22 (R1)····························support·authentication·and·can·be·easily·····configuring·the·services.
 23 ································hacked.·The·package·tftp·is·a·client·program
 24 ································that·allows·for·connections·to·a·tftp
 25 ································server.
55 ································The·talk·package·contains·the·client·program26 ································The·talk·package·contains·the·client·program
56 ································for·the·Internet·talk·protocol,·which·allows27 ································for·the·Internet·talk·protocol,·which·allows
57 ································the·user·to·chat·with·other·users·on28 ································the·user·to·chat·with·other·users·on
58 BP28····························different·systems.·Talk·is·a·communication···The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols29 BP28····························different·systems.·Talk·is·a·communication···The·talk·software·presents·a·security·risk·as·it·uses·unencrypted·protocols
59 (R1)··Uninstall·talk·Package····program·which·copies·lines·from·one·terminal·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the30 (R1)··Uninstall·talk·Package····program·which·copies·lines·from·one·terminal·for·communications.·Removing·the·talk·package·decreases·the·risk·of·the
60 ································to·the·terminal·of·another·user.·The·talk····accidental·(or·intentional)·activation·of·talk·client·program.31 ································to·the·terminal·of·another·user.·The·talk····accidental·(or·intentional)·activation·of·talk·client·program.
61 ································package·can·be·removed·with·the·following32 ································package·can·be·removed·with·the·following
62 ································command:33 ································command:
63 ································$·sudo·yum·erase·talk34 ································$·sudo·yum·erase·talk
64 ·············································································These·legacy·clients·contain·numerous·security·exposures·and·have·been 
65 ·············································································replaced·with·the·more·secure·SSH·package.·Even·if·the·server·is·removed,·it 
66 BP28··Uninstall·rsh·Package·····The·rsh·package·contains·the·client·commands·is·best·to·ensure·the·clients·are·also·removed·to·prevent·users·from 
67 (R1)····························for·the·rsh·services·························inadvertently·attempting·to·use·these·commands·and·therefore·exposing·their 
68 ·············································································credentials.·Note·that·removing·the·rsh·package·removes·the·clients·for35 ································The·Network·Information·Service·(NIS),
 36 ································formerly·known·as·Yellow·Pages,·is·a·client-·The·NIS·service·is·inherently·an·insecure·system·that·has·been·vulnerable·to
 37 BP28····························server·directory·service·protocol·used·to····DOS·attacks,·buffer·overflows·and·has·poor·authentication·for·querying·NIS
 38 (R1)··Remove·NIS·Client·········distribute·system·configuration·files.·The···maps.·NIS·generally·has·been·replaced·by·such·protocols·as·Lightweight
 39 ································NIS·client·(ypbind)·was·used·to·bind·a·······Directory·Access·Protocol·(LDAP).·It·is·recommended·that·the·service·be
 40 ································system·to·an·NIS·server·and·receive·the······removed.
 41 ································distributed·configuration·files.
 42 ································The·telnet·client·allows·users·to·start······The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted
 43 BP28··Remove·telnet·Clients·····connections·to·other·systems·via·the·telnet··transmission·medium·could·allow·an·unauthorized·user·to·steal·credentials.
 44 (R1)····························protocol.····································The·ssh·package·provides·an·encrypted·session·and·stronger·security·and·is
69 ·············································································rsh,rcp,·and·rlogin.45 ·············································································included·in·Red·Hat·Enterprise·Linux·8.
70 ································If·the·system·does·not·need·to·act·as·a·DHCP46 ································If·the·system·does·not·need·to·act·as·a·DHCP
71 BP28··Uninstall·DHCP·Server·····server,·the·dhcp·package·can·be·uninstalled.·Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally47 BP28··Uninstall·DHCP·Server·····server,·the·dhcp·package·can·be·uninstalled.·Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally
72 (R1)··Package···················The·dhcp-server·package·can·be·removed·with··reactivated·and·disrupt·network·operation.48 (R1)··Package···················The·dhcp-server·package·can·be·removed·with··reactivated·and·disrupt·network·operation.
73 ································the·following·command:49 ································the·following·command:
74 ································$·sudo·yum·erase·dhcp-server50 ································$·sudo·yum·erase·dhcp-server
 51 ·············································································Removing·the·tftp-server·package·decreases·the·risk·of·the·accidental·(or
75 ································The·telnet·client·allows·users·to·start······The·telnet·protocol·is·insecure·and·unencrypted.·The·use·of·an·unencrypted 
76 BP28··Remove·telnet·Clients·····connections·to·other·systems·via·the·telnet··transmission·medium·could·allow·an·unauthorized·user·to·steal·credentials. 
77 (R1)····························protocol.····································The·ssh·package·provides·an·encrypted·session·and·stronger·security·and·is 
78 ·············································································included·in·Red·Hat·Enterprise·Linux·8.52 ·············································································intentional)·activation·of·tftp·services.
 53 BP28··Uninstall·tftp-server·····The·tftp-server·package·can·be·removed·with
 54 (R1)··Package···················the·following·command:·······················If·TFTP·is·required·for·operational·support·(such·as·transmission·of·router
 55 ·································$·sudo·yum·erase·tftp-server················configurations),·its·use·must·be·documented·with·the·Information·Systems
 56 ·············································································Securty·Manager·(ISSM),·restricted·to·only·authorized·personnel,·and·have
 57 ·············································································access·control·rules·established.
79 ·············································································The·rsh-server·service·provides·unencrypted·remote·access·service·which·does58 ·············································································The·rsh-server·service·provides·unencrypted·remote·access·service·which·does
80 ·············································································not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the59 ·············································································not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the
81 BP28··Uninstall·rsh-server······The·rsh-server·package·can·be·removed·with···remote·session·and·has·very·weak·authentication.·If·a·privileged·user·were60 BP28··Uninstall·rsh-server······The·rsh-server·package·can·be·removed·with···remote·session·and·has·very·weak·authentication.·If·a·privileged·user·were
82 (R1)··Package···················the·following·command:·······················to·login·using·this·service,·the·privileged·user·password·could·be61 (R1)··Package···················the·following·command:·······················to·login·using·this·service,·the·privileged·user·password·could·be
83 ································$·sudo·yum·erase·rsh-server··················compromised.·The·rsh-server·package·provides·several·obsolete·and·insecure62 ································$·sudo·yum·erase·rsh-server··················compromised.·The·rsh-server·package·provides·several·obsolete·and·insecure
84 ·············································································network·services.·Removing·it·decreases·the·risk·of·those·services'63 ·············································································network·services.·Removing·it·decreases·the·risk·of·those·services'
85 ·············································································accidental·(or·intentional)·activation.64 ·············································································accidental·(or·intentional)·activation.
 65 ································The·ypserv·package·can·be·removed·with·the···The·NIS·service·provides·an·unencrypted·authentication·service·which·does
 66 BP28··Uninstall·ypserv·Package··following·command:···························not·provide·for·the·confidentiality·and·integrity·of·user·passwords·or·the
 67 (R1)····························$·sudo·yum·erase·ypserv······················remote·session.·Removing·the·ypserv·package·decreases·the·risk·of·the
 68 ·············································································accidental·(or·intentional)·activation·of·NIS·or·NIS+·services.
 69 ·············································································These·legacy·clients·contain·numerous·security·exposures·and·have·been
 70 ·············································································replaced·with·the·more·secure·SSH·package.·Even·if·the·server·is·removed,·it
 71 BP28··Uninstall·rsh·Package·····The·rsh·package·contains·the·client·commands·is·best·to·ensure·the·clients·are·also·removed·to·prevent·users·from
 72 (R1)····························for·the·rsh·services·························inadvertently·attempting·to·use·these·commands·and·therefore·exposing·their
 73 ·············································································credentials.·Note·that·removing·the·rsh·package·removes·the·clients·for
 74 ·············································································rsh,rcp,·and·rlogin.
Max diff block lines reached; 235040/252219 bytes (93.19%) of diff not shown.
1.23 MB
./usr/share/doc/ssg-nondebian/table-rhel8-cisrefs.html
    
Offset 1789, 150 lines modifiedOffset 1789, 150 lines modified
00006fc0:·6173·2055·5342·206b·6579·7320·6578·706f··as·USB·keys·expo00006fc0:·6173·2055·5342·206b·6579·7320·6578·706f··as·USB·keys·expo
00006fd0:·7365·730a·7468·6520·7379·7374·656d·2074··ses.the·system·t00006fd0:·7365·730a·7468·6520·7379·7374·656d·2074··ses.the·system·t
00006fe0:·6f20·706f·7465·6e74·6961·6c20·636f·6d70··o·potential·comp00006fe0:·6f20·706f·7465·6e74·6961·6c20·636f·6d70··o·potential·comp
00006ff0:·726f·6d69·7365·2e0a·2020·2020·2020·3c2f··romise..······</00006ff0:·726f·6d69·7365·2e0a·2020·2020·2020·3c2f··romise..······</
00007000:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··00007000:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··
00007010:·2020·3c74·723e·0a20·2020·2020·203c·7464····<tr>.······<td00007010:·2020·3c74·723e·0a20·2020·2020·203c·7464····<tr>.······<td
00007020:·3e31·2e32·2e32·3c2f·7464·3e0a·2020·2020··>1.2.2</td>.····00007020:·3e31·2e32·2e32·3c2f·7464·3e0a·2020·2020··>1.2.2</td>.····
00007030:·2020·3c74·643e·4469·7361·626c·6520·5265····<td>Disable·Re00007030:·2020·3c74·643e·456e·7375·7265·2052·6564····<td>Ensure·Red
 00007040:·2048·6174·2047·5047·204b·6579·2049·6e73···Hat·GPG·Key·Ins
 00007050:·7461·6c6c·6564·3c2f·7464·3e0a·2020·2020··talled</td>.····
 00007060:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="
 00007070:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········
 00007080:·546f·2065·6e73·7572·6520·7468·6520·7379··To·ensure·the·sy
 00007090:·7374·656d·2063·616e·2063·7279·7074·6f67··stem·can·cryptog
 000070a0:·7261·7068·6963·616c·6c79·2076·6572·6966··raphically·verif
 000070b0:·7920·6261·7365·2073·6f66·7477·6172·6520··y·base·software·
 000070c0:·7061·636b·6167·6573·0a63·6f6d·6520·6672··packages.come·fr
 000070d0:·6f6d·2052·6564·2048·6174·2028·616e·6420··om·Red·Hat·(and·
 000070e0:·746f·2063·6f6e·6e65·6374·2074·6f20·7468··to·connect·to·th
 000070f0:·6520·5265·6420·4861·7420·4e65·7477·6f72··e·Red·Hat·Networ
 00007100:·6b20·746f·2072·6563·6569·7665·2074·6865··k·to·receive·the
 00007110:·6d29·2c0a·7468·6520·5265·6420·4861·7420··m),.the·Red·Hat·
 00007120:·4750·4720·6b65·7920·6d75·7374·2070·726f··GPG·key·must·pro
 00007130:·7065·726c·7920·6265·2069·6e73·7461·6c6c··perly·be·install
 00007140:·6564·2e20·546f·2069·6e73·7461·6c6c·2074··ed.·To·install·t
 00007150:·6865·2052·6564·2048·6174·2047·5047·0a6b··he·Red·Hat·GPG.k
 00007160:·6579·2c20·7275·6e3a·0a3c·7072·653e·2420··ey,·run:.<pre>$·
 00007170:·7375·646f·2073·7562·7363·7269·7074·696f··sudo·subscriptio
 00007180:·6e2d·6d61·6e61·6765·7220·7265·6769·7374··n-manager·regist
 00007190:·6572·3c2f·7072·653e·0a0a·4966·2074·6865··er</pre>..If·the
 000071a0:·2073·7973·7465·6d20·6973·206e·6f74·2063···system·is·not·c
 000071b0:·6f6e·6e65·6374·6564·2074·6f20·7468·6520··onnected·to·the·
 000071c0:·496e·7465·726e·6574·206f·7220·616e·2052··Internet·or·an·R
 000071d0:·484e·2053·6174·656c·6c69·7465·2c20·7468··HN·Satellite,·th
 000071e0:·656e·0a69·6e73·7461·6c6c·2074·6865·2052··en.install·the·R
 000071f0:·6564·2048·6174·2047·5047·206b·6579·2066··ed·Hat·GPG·key·f
 00007200:·726f·6d20·7472·7573·7465·6420·6d65·6469··rom·trusted·medi
 00007210:·6120·7375·6368·2061·7320·7468·6520·5265··a·such·as·the·Re
 00007220:·6420·4861·740a·696e·7374·616c·6c61·7469··d·Hat.installati
 00007230:·6f6e·2043·442d·524f·4d20·6f72·2044·5644··on·CD-ROM·or·DVD
 00007240:·2e20·4173·7375·6d69·6e67·2074·6865·2064··.·Assuming·the·d
 00007250:·6973·6320·6973·206d·6f75·6e74·6564·2069··isc·is·mounted·i
 00007260:·6e0a·3c74·743e·2f6d·6564·6961·2f63·6472··n.<tt>/media/cdr
 00007270:·6f6d·3c2f·7474·3e2c·2075·7365·2074·6865··om</tt>,·use·the
 00007280:·2066·6f6c·6c6f·7769·6e67·2063·6f6d·6d61···following·comma
 00007290:·6e64·2061·7320·7468·6520·726f·6f74·2075··nd·as·the·root·u
 000072a0:·7365·7220·746f·2069·6d70·6f72·740a·6974··ser·to·import.it
 000072b0:·2069·6e74·6f20·7468·6520·6b65·7972·696e···into·the·keyrin
 000072c0:·673a·0a3c·7072·653e·2420·7375·646f·2072··g:.<pre>$·sudo·r
 000072d0:·706d·202d·2d69·6d70·6f72·7420·2f6d·6564··pm·--import·/med
 000072e0:·6961·2f63·6472·6f6d·2f52·504d·2d47·5047··ia/cdrom/RPM-GPG
 000072f0:·2d4b·4559·3c2f·7072·653e·0a0a·416c·7465··-KEY</pre>..Alte
 00007300:·726e·6174·6976·656c·792c·2074·6865·206b··rnatively,·the·k
 00007310:·6579·206d·6179·2062·6520·7072·652d·6c6f··ey·may·be·pre-lo
 00007320:·6164·6564·2064·7572·696e·6720·7468·6520··aded·during·the·
 00007330:·5248·454c·2069·6e73·7461·6c6c·6174·696f··RHEL·installatio
 00007340:·6e2e·2049·6e0a·7375·6368·2063·6173·6573··n.·In.such·cases
 00007350:·2c20·7468·6520·6b65·7920·6361·6e20·6265··,·the·key·can·be
 00007360:·2069·6e73·7461·6c6c·6564·2062·7920·7275···installed·by·ru
 00007370:·6e6e·696e·6720·7468·6520·666f·6c6c·6f77··nning·the·follow
 00007380:·696e·6720·636f·6d6d·616e·643a·0a3c·7072··ing·command:.<pr
 00007390:·653e·7375·646f·2072·706d·202d·2d69·6d70··e>sudo·rpm·--imp
 000073a0:·6f72·7420·2f65·7463·2f70·6b69·2f72·706d··ort·/etc/pki/rpm
 000073b0:·2d67·7067·2f52·504d·2d47·5047·2d4b·4559··-gpg/RPM-GPG-KEY
 000073c0:·2d72·6564·6861·742d·7265·6c65·6173·653c··-redhat-release<
 000073d0:·2f70·7265·3e0a·2020·2020·2020·3c2f·7464··/pre>.······</td
 000073e0:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml:
 000073f0:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.··
 00007400:·2020·2020·2020·4368·616e·6765·7320·746f········Changes·to
 00007410:·2073·6f66·7477·6172·6520·636f·6d70·6f6e···software·compon
 00007420:·656e·7473·2063·616e·2068·6176·6520·7369··ents·can·have·si
 00007430:·676e·6966·6963·616e·7420·6566·6665·6374··gnificant·effect
 00007440:·7320·6f6e·2074·6865·206f·7665·7261·6c6c··s·on·the·overall
 00007450:·0a73·6563·7572·6974·7920·6f66·2074·6865··.security·of·the
 00007460:·206f·7065·7261·7469·6e67·2073·7973·7465···operating·syste
 00007470:·6d2e·2054·6869·7320·7265·7175·6972·656d··m.·This·requirem
 00007480:·656e·7420·656e·7375·7265·7320·7468·6520··ent·ensures·the·
 00007490:·736f·6674·7761·7265·2068·6173·0a6e·6f74··software·has.not
 000074a0:·2062·6565·6e20·7461·6d70·6572·6564·2077···been·tampered·w
 000074b0:·6974·6820·616e·6420·7468·6174·2069·7420··ith·and·that·it·
 000074c0:·6861·7320·6265·656e·2070·726f·7669·6465··has·been·provide
 000074d0:·6420·6279·2061·2074·7275·7374·6564·2076··d·by·a·trusted·v
 000074e0:·656e·646f·722e·0a54·6865·2052·6564·2048··endor..The·Red·H
 000074f0:·6174·2047·5047·206b·6579·2069·7320·6e65··at·GPG·key·is·ne
 00007500:·6365·7373·6172·7920·746f·2063·7279·7074··cessary·to·crypt
 00007510:·6f67·7261·7068·6963·616c·6c79·2076·6572··ographically·ver
 00007520:·6966·7920·7061·636b·6167·6573·2061·7265··ify·packages·are
 00007530:·0a66·726f·6d20·5265·6420·4861·742e·0a20··.from·Red·Hat..·
 00007540:·2020·2020·203c·2f74·643e·0a20·2020·203c·······</td>.····<
 00007550:·2f74·723e·0a20·2020·203c·7472·3e0a·2020··/tr>.····<tr>.··
 00007560:·2020·2020·3c74·643e·312e·322e·323c·2f74······<td>1.2.2</t
 00007570:·643e·0a20·2020·2020·203c·7464·3e44·6973··d>.······<td>Dis
 00007580:·6162·6c65·2052·6564·2048·6174·204e·6574··able·Red·Hat·Net
 00007590:·776f·726b·2053·6572·7669·6365·2028·7268··work·Service·(rh
 000075a0:·6e73·6429·3c2f·7464·3e0a·2020·2020·2020··nsd)</td>.······
 000075b0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
 000075c0:·2d55·5322·3e0a·2020·2020·2020·2020·5468··-US">.········Th
 000075d0:·6520·5265·6420·4861·7420·4e65·7477·6f72··e·Red·Hat·Networ
 000075e0:·6b20·7365·7276·6963·6520·6175·746f·6d61··k·service·automa
 000075f0:·7469·6361·6c6c·7920·7175·6572·6965·7320··tically·queries·
00007040:·6420·4861·7420·4e65·7477·6f72·6b20·5365··d·Hat·Network·Se00007600:·5265·6420·4861·7420·4e65·7477·6f72·6b0a··Red·Hat·Network.
00007050:·7276·6963·6520·2872·686e·7364·293c·2f74··rvice·(rhnsd)</t00007610:·7365·7276·6572·7320·746f·2064·6574·6572··servers·to·deter
 00007620:·6d69·6e65·2077·6865·7468·6572·2074·6865··mine·whether·the
 00007630:·7265·2061·7265·2061·6e79·2061·6374·696f··re·are·any·actio
 00007640:·6e73·2074·6861·7420·7368·6f75·6c64·2062··ns·that·should·b
 00007650:·6520·6578·6563·7574·6564·2c0a·7375·6368··e·executed,.such
 00007660:·2061·7320·7061·636b·6167·6520·7570·6461···as·package·upda
 00007670:·7465·732e·2054·6869·7320·6f6e·6c79·206f··tes.·This·only·o
 00007680:·6363·7572·7320·6966·2074·6865·2073·7973··ccurs·if·the·sys
 00007690:·7465·6d20·7761·7320·7265·6769·7374·6572··tem·was·register
 000076a0:·6564·2074·6f20·616e·0a52·484e·2073·6572··ed·to·an.RHN·ser
 000076b0:·7665·7220·6f72·2073·6174·656c·6c69·7465··ver·or·satellite
 000076c0:·2061·6e64·206d·616e·6167·6564·2061·7320···and·managed·as·
 000076d0:·7375·6368·2e0a·0a54·6865·203c·636f·6465··such...The·<code
 000076e0:·3e72·686e·7364·3c2f·636f·6465·3e20·7365··>rhnsd</code>·se
 000076f0:·7276·6963·6520·6361·6e20·6265·2064·6973··rvice·can·be·dis
 00007700:·6162·6c65·6420·7769·7468·2074·6865·2066··abled·with·the·f
 00007710:·6f6c·6c6f·7769·6e67·2063·6f6d·6d61·6e64··ollowing·command
 00007720:·3a0a·3c70·7265·3e24·2073·7564·6f20·7379··:.<pre>$·sudo·sy
 00007730:·7374·656d·6374·6c20·6d61·736b·202d·2d6e··stemctl·mask·--n
 00007740:·6f77·2072·686e·7364·2e73·6572·7669·6365··ow·rhnsd.service
 00007750:·3c2f·7072·653e·0a20·2020·2020·203c·2f74··</pre>.······</t
00007060:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml00007760:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
00007070:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·00007770:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
00007080:·2020·2020·2020·2054·6865·2052·6564·2048·········The·Red·H 
00007090:·6174·204e·6574·776f·726b·2073·6572·7669··at·Network·servi 
000070a0:·6365·2061·7574·6f6d·6174·6963·616c·6c79··ce·automatically 
Max diff block lines reached; 975069/994415 bytes (98.05%) of diff not shown.
292 KB
html2text {}
    
Offset 403, 30 lines modifiedOffset 403, 14 lines modified
403 ······························Preventing·the·direct·execution·of·binaries·from····execute·binaries403 ······························Preventing·the·direct·execution·of·binaries·from····execute·binaries
404 ··········Add·noexec·Option···removable·media·(such·as·a·USB·key)·provides·a······from·removable·media404 ··········Add·noexec·Option···removable·media·(such·as·a·USB·key)·provides·a······from·removable·media
405 1.1.20····to·Removable·Media··defense·against·malicious·software·that·may·be······such·as·USB·keys405 1.1.20····to·Removable·Media··defense·against·malicious·software·that·may·be······such·as·USB·keys
406 ··········Partitions··········present·on·such·untrusted·media.·Add·the·noexec·····exposes·the·system406 ··········Partitions··········present·on·such·untrusted·media.·Add·the·noexec·····exposes·the·system
407 ······························option·to·the·fourth·column·of·/etc/fstab·for·the···to·potential407 ······························option·to·the·fourth·column·of·/etc/fstab·for·the···to·potential
408 ······························line·which·controls·mounting·of·any·removable·media·compromise.408 ······························line·which·controls·mounting·of·any·removable·media·compromise.
409 ······························partitions.409 ······························partitions.
410 ··················································································Although·systems 
411 ··················································································management·and 
412 ··················································································patching·is 
413 ··················································································extremely·important 
414 ······························The·Red·Hat·Network·service·automatically·queries···to·system·security, 
415 ······························Red·Hat·Network·servers·to·determine·whether·there··management·by·a 
416 ··········Disable·Red·Hat·····are·any·actions·that·should·be·executed,·such·as····system·outside·the 
417 1.2.2·····Network·Service·····package·updates.·This·only·occurs·if·the·system·was·enterprise·enclave 
418 ··········(rhnsd)·············registered·to·an·RHN·server·or·satellite·and········is·not·desirable·for 
419 ······························managed·as·such.·The·rhnsd·service·can·be·disabled··some·environments. 
420 ······························with·the·following·command:·························However,·if·the 
421 ······························$·sudo·systemctl·mask·--now·rhnsd.service···········system·is·being 
422 ··················································································managed·by·RHN·or 
423 ··················································································RHN·Satellite·Server 
424 ··················································································the·rhnsd·daemon·can 
425 ··················································································remain·on. 
426 ······························To·ensure·the·system·can·cryptographically·verify···Changes·to·software410 ······························To·ensure·the·system·can·cryptographically·verify···Changes·to·software
427 ······························base·software·packages·come·from·Red·Hat·(and·to····components·can·have411 ······························base·software·packages·come·from·Red·Hat·(and·to····components·can·have
428 ······························connect·to·the·Red·Hat·Network·to·receive·them),····significant·effects412 ······························connect·to·the·Red·Hat·Network·to·receive·them),····significant·effects
429 ······························the·Red·Hat·GPG·key·must·properly·be·installed.·To··on·the·overall413 ······························the·Red·Hat·GPG·key·must·properly·be·installed.·To··on·the·overall
430 ······························install·the·Red·Hat·GPG·key,·run:···················security·of·the414 ······························install·the·Red·Hat·GPG·key,·run:···················security·of·the
431 ······························$·sudo·subscription-manager·register················operating·system.415 ······························$·sudo·subscription-manager·register················operating·system.
432 ······························If·the·system·is·not·connected·to·the·Internet·or···This·requirement416 ······························If·the·system·is·not·connected·to·the·Internet·or···This·requirement
Offset 437, 14 lines modifiedOffset 421, 30 lines modified
437 ······························user·to·import·it·into·the·keyring:·················provided·by·a421 ······························user·to·import·it·into·the·keyring:·················provided·by·a
438 ······························$·sudo·rpm·--import·/media/cdrom/RPM-GPG-KEY········trusted·vendor.·The422 ······························$·sudo·rpm·--import·/media/cdrom/RPM-GPG-KEY········trusted·vendor.·The
439 ······························Alternatively,·the·key·may·be·pre-loaded·during·the·Red·Hat·GPG·key·is423 ······························Alternatively,·the·key·may·be·pre-loaded·during·the·Red·Hat·GPG·key·is
440 ······························RHEL·installation.·In·such·cases,·the·key·can·be····necessary·to424 ······························RHEL·installation.·In·such·cases,·the·key·can·be····necessary·to
441 ······························installed·by·running·the·following·command:·········cryptographically425 ······························installed·by·running·the·following·command:·········cryptographically
442 ······························sudo·rpm·--import·/etc/pki/rpm-gpg/RPM-GPG-KEY-·····verify·packages·are426 ······························sudo·rpm·--import·/etc/pki/rpm-gpg/RPM-GPG-KEY-·····verify·packages·are
443 ······························redhat-release······································from·Red·Hat.427 ······························redhat-release······································from·Red·Hat.
 428 ··················································································Although·systems
 429 ··················································································management·and
 430 ··················································································patching·is
 431 ··················································································extremely·important
 432 ······························The·Red·Hat·Network·service·automatically·queries···to·system·security,
 433 ······························Red·Hat·Network·servers·to·determine·whether·there··management·by·a
 434 ··········Disable·Red·Hat·····are·any·actions·that·should·be·executed,·such·as····system·outside·the
 435 1.2.2·····Network·Service·····package·updates.·This·only·occurs·if·the·system·was·enterprise·enclave
 436 ··········(rhnsd)·············registered·to·an·RHN·server·or·satellite·and········is·not·desirable·for
 437 ······························managed·as·such.·The·rhnsd·service·can·be·disabled··some·environments.
 438 ······························with·the·following·command:·························However,·if·the
 439 ······························$·sudo·systemctl·mask·--now·rhnsd.service···········system·is·being
 440 ··················································································managed·by·RHN·or
 441 ··················································································RHN·Satellite·Server
 442 ··················································································the·rhnsd·daemon·can
 443 ··················································································remain·on.
444 ··················································································Changes·to·any444 ··················································································Changes·to·any
445 ··················································································software·components445 ··················································································software·components
446 ··················································································can·have·significant446 ··················································································can·have·significant
447 ··················································································effects·on·the447 ··················································································effects·on·the
448 ··················································································overall·security·of448 ··················································································overall·security·of
449 ··················································································the·operating449 ··················································································the·operating
450 ··················································································system.·This450 ··················································································system.·This
Offset 505, 14 lines modifiedOffset 505, 19 lines modified
505 ··················································································breakage·of505 ··················································································breakage·of
506 ··················································································configuration,·as·it506 ··················································································configuration,·as·it
507 ··················································································ships·several·tested507 ··················································································ships·several·tested
508 ··················································································profiles·that·are508 ··················································································profiles·that·are
509 ··················································································well·tested·and509 ··················································································well·tested·and
510 ··················································································supported·to·solve510 ··················································································supported·to·solve
511 ··················································································different·use-cases.511 ··················································································different·use-cases.
 512 ··················································································The·AIDE·package
 513 ······························The·aide·package·can·be·installed·with·the··········must·be·installed·if
 514 1.3.1·····Install·AIDE········following·command:··································it·is·to·be
 515 ······························$·sudo·yum·install·aide·····························available·for
 516 ··················································································integrity·checking.
512 ······························Run·the·following·command·to·generate·a·new517 ······························Run·the·following·command·to·generate·a·new
513 ······························database:518 ······························database:
514 ······························$·sudo·/usr/sbin/aide·--init519 ······························$·sudo·/usr/sbin/aide·--init
515 ······························By·default,·the·database·will·be·written·to·the520 ······························By·default,·the·database·will·be·written·to·the
516 ······························file·/var/lib/aide/aide.db.new.gz.·Storing·the······For·AIDE·to·be521 ······························file·/var/lib/aide/aide.db.new.gz.·Storing·the······For·AIDE·to·be
517 ······························database,·the·configuration·file·/etc/aide.conf,····effective,·an522 ······························database,·the·configuration·file·/etc/aide.conf,····effective,·an
518 ······························and·the·binary·/usr/sbin/aide·(or·hashes·of·these···initial·database·of523 ······························and·the·binary·/usr/sbin/aide·(or·hashes·of·these···initial·database·of
Offset 523, 19 lines modifiedOffset 528, 14 lines modified
523 ······························$·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/····should·be·able·to·be528 ······························$·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/····should·be·able·to·be
524 ······························aide/aide.db.gz·····································verified·against·the529 ······························aide/aide.db.gz·····································verified·against·the
525 ······························To·initiate·a·manual·check,·run·the·following·······installed·files.530 ······························To·initiate·a·manual·check,·run·the·following·······installed·files.
526 ······························command:531 ······························command:
527 ······························$·sudo·/usr/sbin/aide·--check532 ······························$·sudo·/usr/sbin/aide·--check
528 ······························If·this·check·produces·any·unexpected·output,533 ······························If·this·check·produces·any·unexpected·output,
529 ······························investigate.534 ······························investigate.
530 ··················································································The·AIDE·package 
531 ······························The·aide·package·can·be·installed·with·the··········must·be·installed·if 
532 1.3.1·····Install·AIDE········following·command:··································it·is·to·be 
533 ······························$·sudo·yum·install·aide·····························available·for 
534 ··················································································integrity·checking. 
535 ··················································································By·default,·AIDE535 ··················································································By·default,·AIDE
536 ··················································································does·not·install536 ··················································································does·not·install
537 ··················································································itself·for·periodic537 ··················································································itself·for·periodic
538 ··················································································execution.538 ··················································································execution.
539 ··················································································Periodically·running539 ··················································································Periodically·running
540 ··················································································AIDE·is·necessary·to540 ··················································································AIDE·is·necessary·to
541 ··················································································reveal·unexpected541 ··················································································reveal·unexpected
Offset 606, 55 lines modifiedOffset 606, 21 lines modified
606 1.4.1·····Set·the·UEFI·Boot···generate·a·hash·for·the·password·by·running·the·····cannot·trivially606 1.4.1·····Set·the·UEFI·Boot···generate·a·hash·for·the·password·by·running·the·····cannot·trivially
607 ··········Loader·Password·····following·command:··································alter·important607 ··········Loader·Password·····following·command:··································alter·important
608 ······························#·grub2-setpassword·································bootloader·settings.608 ······························#·grub2-setpassword·································bootloader·settings.
609 ······························When·prompted,·enter·the·password·that·was··········These·include·which609 ······························When·prompted,·enter·the·password·that·was··········These·include·which
610 ······························selected.···········································kernel·to·use,·and610 ······························selected.···········································kernel·to·use,·and
611 ··················································································whether·to·enter611 ··················································································whether·to·enter
612 ··················································································single-user·mode.612 ··················································································single-user·mode.
613 ··················································································The·root·group·is·a 
614 ······························The·file·/boot/grub2/grub.cfg·should·be·group-owned·highly-privileged 
615 ··········Verify·/boot/grub2/·by·the·root·group·to·prevent·destruction·or·········group.·Furthermore, 
616 1.4.2·····grub.cfg·Group······modification·of·the·file.·To·properly·set·the·group·the·group-owner·of 
617 ··········Ownership···········owner·of·/boot/grub2/grub.cfg,·run·the·command:·····this·file·should·not 
618 ······························$·sudo·chgrp·root·/boot/grub2/grub.cfg··············have·any·access 
619 ··················································································privileges·anyway. 
620 ··················································································Only·root·should·be 
621 ··················································································able·to·modify 
622 ··················································································important·boot 
623 ······························The·file·/boot/grub2/user.cfg·should·be·owned·by····parameters.·Also, 
624 ··········Verify·/boot/grub2/·the·root·user·to·prevent·reading·or·modification·of·non-root·users·who 
625 1.4.2·····user.cfg·User·······the·file.·To·properly·set·the·owner·of·/boot/grub2/·read·the·boot 
626 ··········Ownership···········user.cfg,·run·the·command:··························parameters·may·be 
627 ······························$·sudo·chown·root·/boot/grub2/user.cfg··············able·to·identify 
628 ··················································································weaknesses·in 
629 ··················································································security·upon·boot 
630 ··················································································and·be·able·to 
Max diff block lines reached; 285810/298610 bytes (95.71%) of diff not shown.
1.2 MB
./usr/share/doc/ssg-nondebian/table-rhel8-cuirefs.html
Ordering differences only
    
Offset 41, 104 lines modifiedOffset 41, 14 lines modified
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td>47 ······<td>3.1.1<br/>3.1.5</td>
48 ······<td>Disable·SSH·Root·Login</td> 
49 ······<td·xml:lang="en-US"> 
50 ········The·root·user·should·never·be·allowed·to·login·to·a 
51 system·directly·over·a·network. 
52 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
  
  
53 <tt>/etc/ssh/sshd_config</tt>: 
  
54 <pre>PermitRootLogin·no</pre> 
55 ······</td> 
56 ······<td·xml:lang="en-US"> 
57 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
58 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
59 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
60 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
61 direct·attack·attempts·on·root's·password. 
62 ······</td> 
63 ····</tr> 
64 ····<tr> 
65 ······<td>3.1.1</td> 
66 ······<td>Disable·GDM·Guest·Login</td> 
67 ······<td·xml:lang="en-US"> 
68 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·login·without·credentials 
69 which·can·be·useful·for·public·kiosk·scenarios.·Allowing·users·to·login·without·credentials 
70 or·"guest"·account·access·has·inherent·security·risks·and·should·be·disabled.·To·do·disable 
71 timed·logins·or·guest·account·access,·set·the·<tt>TimedLoginEnable</tt>·to·<tt>false</tt>·in 
72 the·<tt>[daemon]</tt>·section·in·<tt>/etc/gdm/custom.conf</tt>.·For·example: 
73 <pre>[daemon] 
74 TimedLoginEnable=false</pre> 
75 ······</td> 
76 ······<td·xml:lang="en-US"> 
77 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating 
78 system·security. 
79 ······</td> 
80 ····</tr> 
81 ····<tr> 
82 ······<td>3.1.1<br/>3.4.5</td> 
83 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td> 
84 ······<td·xml:lang="en-US"> 
85 ········Emergency·mode·is·intended·as·a·system·recovery 
86 method,·providing·a·single·user·root·access·to·the·system 
87 during·a·failed·boot·sequence. 
88 <br·/><br·/> 
89 By·default,·Emergency·mode·is·protected·by·requiring·a·password·and·is·set 
90 in·<tt>/usr/lib/systemd/system/emergency.service</tt>. 
91 ······</td> 
92 ······<td·xml:lang="en-US"> 
93 ········This·prevents·attackers·with·physical·access·from·trivially·bypassing·security 
94 on·the·machine·and·gaining·root·access.·Such·accesses·are·further·prevented 
95 by·configuring·the·bootloader·password. 
96 ······</td> 
97 ····</tr> 
98 ····<tr> 
99 ······<td>3.1.1<br/>3.1.5</td> 
100 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td> 
101 ······<td·xml:lang="en-US"> 
102 ········If·an·account·is·configured·for·password·authentication 
103 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log 
104 into·the·account·without·authentication.·Remove·any·instances·of·the 
105 <tt>nullok</tt>·in 
  
106 <tt>/etc/pam.d/system-auth</tt>·and 
107 <tt>/etc/pam.d/password-auth</tt> 
  
108 to·prevent·logins·with·empty·passwords. 
109 ······</td> 
110 ······<td·xml:lang="en-US"> 
111 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and 
112 run·commands·with·the·privileges·of·that·account.·Accounts·with 
113 empty·passwords·should·never·be·used·in·operational·environments. 
114 ······</td> 
115 ····</tr> 
116 ····<tr> 
117 ······<td>3.1.1<br/>3.1.5</td> 
118 ······<td>Restrict·Serial·Port·Root·Logins</td> 
119 ······<td·xml:lang="en-US"> 
120 ········To·restrict·root·logins·on·serial·ports, 
121 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
122 <pre>ttyS0 
123 ttyS1</pre> 
124 ······</td> 
125 ······<td·xml:lang="en-US"> 
126 ········Preventing·direct·root·login·to·serial·port·interfaces 
127 helps·ensure·accountability·for·actions·taken·on·the·systems 
128 using·the·root·account. 
129 ······</td> 
130 ····</tr> 
131 ····<tr> 
132 ······<td>3.1.1<br/>3.1.5</td> 
133 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>48 ······<td>Disable·SSH·Access·via·Empty·Passwords</td>
134 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
135 ········Disallow·SSH·login·with·empty·passwords.50 ········Disallow·SSH·login·with·empty·passwords.
136 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate51 The·default·SSH·configuration·disables·logins·with·empty·passwords.·The·appropriate
137 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.52 configuration·is·used·if·no·value·is·set·for·<tt>PermitEmptyPasswords</tt>.
138 <br·/>53 <br·/>
139 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,54 To·explicitly·disallow·SSH·login·from·accounts·with·empty·passwords,
Offset 189, 14 lines modifiedOffset 99, 40 lines modified
189 ······</td>99 ······</td>
190 ······<td·xml:lang="en-US">100 ······<td·xml:lang="en-US">
191 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating101 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
192 system·security.102 system·security.
193 ······</td>103 ······</td>
194 ····</tr>104 ····</tr>
195 ····<tr>105 ····<tr>
 106 ······<td>3.1.1<br/>3.1.6</td>
 107 ······<td>Direct·root·Logins·Not·Allowed</td>
 108 ······<td·xml:lang="en-US">
 109 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators
 110 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file.
 111 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does
 112 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the
 113 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous
 114 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in
 115 plain·text·over·the·network.·By·default,·Red·Hat·Enterprise·Linux·8's
 116 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console
 117 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the
 118 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this
 119 file·by·typing·the·following·command:
 120 <pre>
Max diff block lines reached; 449652/455240 bytes (98.77%) of diff not shown.
782 KB
html2text {}
Max HTML report size reached
3.82 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-ospp.html
    
Offset 4083, 15 lines modifiedOffset 4083, 15 lines modified
4083 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4083 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4084 ··</td>4084 ··</td>
4085 ··<td·xml:lang="en-US">4085 ··<td·xml:lang="en-US">
4086 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4086 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4087 time-based·limit,·effects·of·potential·attacks·against4087 time-based·limit,·effects·of·potential·attacks·against
4088 encryption·keys·are·limited.4088 encryption·keys·are·limited.
4089 ··</td>4089 ··</td>
4090 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>4090 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>
4091 </tr>4091 </tr>
4092 <tr>4092 <tr>
4093 ··<td></td>4093 ··<td></td>
4094 ··<td>CCE-82462-3</td>4094 ··<td>CCE-82462-3</td>
4095 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4095 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4096 ··<td·xml:lang="en-US">4096 ··<td·xml:lang="en-US">
4097 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4097 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
3.08 KB
html2text {}
    
Offset 1884, 16 lines modifiedOffset 1884, 16 lines modified
1884 ············SSH·client·uses··appropriate·shell·environment·variable·is·configured.·The·SSH_USE_STRONG_RNG·environment·which·by·default,·doesn't·use·high-entropy·sources.·Randomness1884 ············SSH·client·uses··appropriate·shell·environment·variable·is·configured.·The·SSH_USE_STRONG_RNG·environment·which·by·default,·doesn't·use·high-entropy·sources.·Randomness
1885 ·····CCE-···strong·entropy···variable·determines·how·many·bytes·of·entropy·to·use.·Make·sure·that·the·file·/etc/······is·needed·to·generate·considerably·more·secure·data-encryption1885 ·····CCE-···strong·entropy···variable·determines·how·many·bytes·of·entropy·to·use.·Make·sure·that·the·file·/etc/······is·needed·to·generate·considerably·more·secure·data-encryption
1886 ·····83346-·to·seed·(Bash-···profile.d/cc-ssh-strong-rng.sh·contains·line·············································keys.·Plaintext·padding,·initialization·vectors·in·encryption1886 ·····83346-·to·seed·(Bash-···profile.d/cc-ssh-strong-rng.sh·contains·line·············································keys.·Plaintext·padding,·initialization·vectors·in·encryption
1887 ·····7······like·shells)·····export·SSH_USE_STRONG_RNG=32·····························································algorithms,·and·high-quality·entropy·eliminates·the1887 ·····7······like·shells)·····export·SSH_USE_STRONG_RNG=32·····························································algorithms,·and·high-quality·entropy·eliminates·the
1888 ·····························.························································································possibility·that·the·output·of·the·random·number·generator1888 ·····························.························································································possibility·that·the·output·of·the·random·number·generator
1889 ······················································································································used·by·SSH·would·be·known·to·potential·attackers.1889 ······················································································································used·by·SSH·would·be·known·to·potential·attackers.
1890 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,1890 ·····························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,
1891 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············By·decreasing·the·limit·based·on·the·amount·of·data·and········var_rekey_limit_size=1G1891 ·····CCE-···Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············By·decreasing·the·limit·based·on·the·amount·of·data·and········var_rekey_limit_time=1hour
1892 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·limit,·effects·of·potential·attacks········var_rekey_limit_time=1hour1892 ·····82177-·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·limit,·effects·of·potential·attacks········var_rekey_limit_size=1G
1893 ·····7······renegotiation····sshd_config:·············································································against·encryption·keys·are·limited.1893 ·····7······renegotiation····sshd_config:·············································································against·encryption·keys·are·limited.
1894 ·····························RekeyLimit·1G·1hour1894 ·····························RekeyLimit·1G·1hour
1895 ······················································································································SSH·implementation·in·Red·Hat·Enterprise·Linux·8·uses·the1895 ······················································································································SSH·implementation·in·Red·Hat·Enterprise·Linux·8·uses·the
1896 ·····························To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·/etc/sysconfig/·openssl·library,·which·doesn't·use·high-entropy·sources·by1896 ·····························To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·/etc/sysconfig/·openssl·library,·which·doesn't·use·high-entropy·sources·by
1897 ·····CCE-···SSH·server·uses··sshd·file.·The·SSH_USE_STRONG_RNG·configuration·value·determines·how·many·bytes·of·······default.·Randomness·is·needed·to·generate·data-encryption1897 ·····CCE-···SSH·server·uses··sshd·file.·The·SSH_USE_STRONG_RNG·configuration·value·determines·how·many·bytes·of·······default.·Randomness·is·needed·to·generate·data-encryption
1898 ·····82462-·strong·entropy···entropy·to·use,·so·make·sure·that·the·file·contains·line·································keys,·and·as·plaintext·padding·and·initialization·vectors·in1898 ·····82462-·strong·entropy···entropy·to·use,·so·make·sure·that·the·file·contains·line·································keys,·and·as·plaintext·padding·and·initialization·vectors·in
1899 ·····3······to·seed··········SSH_USE_STRONG_RNG=32····································································encryption·algorithms,·and·high-quality·entropy·elliminates1899 ·····3······to·seed··········SSH_USE_STRONG_RNG=32····································································encryption·algorithms,·and·high-quality·entropy·elliminates
6.72 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-stig.html
    
Offset 7842, 18 lines modifiedOffset 7842, 18 lines modified
0001ea10:·2070·6173·7377·6f72·6473·2068·656c·7073···passwords·helps0001ea10:·2070·6173·7377·6f72·6473·2068·656c·7073···passwords·helps
0001ea20:·2065·6e73·7572·6520·7468·6174·2061·2063···ensure·that·a·c0001ea20:·2065·6e73·7572·6520·7468·6174·2061·2063···ensure·that·a·c
0001ea30:·6f6d·7072·6f6d·6973·6564·2070·6173·7377··ompromised·passw0001ea30:·6f6d·7072·6f6d·6973·6564·2070·6173·7377··ompromised·passw
0001ea40:·6f72·6420·6973·206e·6f74·2072·652d·7573··ord·is·not·re-us0001ea40:·6f72·6420·6973·206e·6f74·2072·652d·7573··ord·is·not·re-us
0001ea50:·6564·2062·7920·6120·7573·6572·2e0a·2020··ed·by·a·user..··0001ea50:·6564·2062·7920·6120·7573·6572·2e0a·2020··ed·by·a·user..··
0001ea60:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_0001ea60:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_
0001ea70:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem0001ea70:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem
0001ea80:·656d·6265·723d·353c·6272·2f3e·7661·725f··ember=5<br/>var_ 
0001ea90:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem 
0001eaa0:·656d·6265·725f·636f·6e74·726f·6c5f·666c··ember_control_fl0001ea80:·656d·6265·725f·636f·6e74·726f·6c5f·666c··ember_control_fl
0001eab0:·6167·3d72·6571·7569·7265·643c·2f74·643e··ag=required</td>0001ea90:·6167·3d72·6571·7569·7265·643c·6272·2f3e··ag=required<br/>
 0001eaa0:·7661·725f·7061·7373·776f·7264·5f70·616d··var_password_pam
 0001eab0:·5f72·656d·656d·6265·723d·353c·2f74·643e··_remember=5</td>
0001eac0:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t0001eac0:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t
0001ead0:·643e·4941·2d35·2866·293c·6272·2f3e·4941··d>IA-5(f)<br/>IA0001ead0:·643e·4941·2d35·2866·293c·6272·2f3e·4941··d>IA-5(f)<br/>IA
0001eae0:·2d35·2831·2928·6529·3c2f·7464·3e0a·2020··-5(1)(e)</td>.··0001eae0:·2d35·2831·2928·6529·3c2f·7464·3e0a·2020··-5(1)(e)</td>.··
0001eaf0:·3c74·643e·4343·452d·3833·3438·302d·343c··<td>CCE-83480-4<0001eaf0:·3c74·643e·4343·452d·3833·3438·302d·343c··<td>CCE-83480-4<
0001eb00:·2f74·643e·0a20·203c·7464·3e4c·696d·6974··/td>.··<td>Limit0001eb00:·2f74·643e·0a20·203c·7464·3e4c·696d·6974··/td>.··<td>Limit
0001eb10:·2050·6173·7377·6f72·6420·5265·7573·653a···Password·Reuse:0001eb10:·2050·6173·7377·6f72·6420·5265·7573·653a···Password·Reuse:
0001eb20:·2073·7973·7465·6d2d·6175·7468·3c2f·7464···system-auth</td0001eb20:·2073·7973·7465·6d2d·6175·7468·3c2f·7464···system-auth</td
Offset 7899, 18 lines modifiedOffset 7899, 18 lines modified
0001eda0:·2070·6173·7377·6f72·6473·2068·656c·7073···passwords·helps0001eda0:·2070·6173·7377·6f72·6473·2068·656c·7073···passwords·helps
0001edb0:·2065·6e73·7572·6520·7468·6174·2061·2063···ensure·that·a·c0001edb0:·2065·6e73·7572·6520·7468·6174·2061·2063···ensure·that·a·c
0001edc0:·6f6d·7072·6f6d·6973·6564·2070·6173·7377··ompromised·passw0001edc0:·6f6d·7072·6f6d·6973·6564·2070·6173·7377··ompromised·passw
0001edd0:·6f72·6420·6973·206e·6f74·2072·652d·7573··ord·is·not·re-us0001edd0:·6f72·6420·6973·206e·6f74·2072·652d·7573··ord·is·not·re-us
0001ede0:·6564·2062·7920·6120·7573·6572·2e0a·2020··ed·by·a·user..··0001ede0:·6564·2062·7920·6120·7573·6572·2e0a·2020··ed·by·a·user..··
0001edf0:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_0001edf0:·3c2f·7464·3e0a·2020·3c74·643e·7661·725f··</td>.··<td>var_
0001ee00:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem0001ee00:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem
0001ee10:·656d·6265·723d·353c·6272·2f3e·7661·725f··ember=5<br/>var_ 
0001ee20:·7061·7373·776f·7264·5f70·616d·5f72·656d··password_pam_rem 
0001ee30:·656d·6265·725f·636f·6e74·726f·6c5f·666c··ember_control_fl0001ee10:·656d·6265·725f·636f·6e74·726f·6c5f·666c··ember_control_fl
0001ee40:·6167·3d72·6571·7569·7265·643c·2f74·643e··ag=required</td>0001ee20:·6167·3d72·6571·7569·7265·643c·6272·2f3e··ag=required<br/>
 0001ee30:·7661·725f·7061·7373·776f·7264·5f70·616d··var_password_pam
 0001ee40:·5f72·656d·656d·6265·723d·353c·2f74·643e··_remember=5</td>
0001ee50:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t0001ee50:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t
0001ee60:·643e·4941·2d35·2863·293c·6272·2f3e·4941··d>IA-5(c)<br/>IA0001ee60:·643e·4941·2d35·2863·293c·6272·2f3e·4941··d>IA-5(c)<br/>IA
0001ee70:·2d35·2831·2928·6129·3c62·722f·3e43·4d2d··-5(1)(a)<br/>CM-0001ee70:·2d35·2831·2928·6129·3c62·722f·3e43·4d2d··-5(1)(a)<br/>CM-
0001ee80:·3628·6129·3c62·722f·3e49·412d·3528·3429··6(a)<br/>IA-5(4)0001ee80:·3628·6129·3c62·722f·3e49·412d·3528·3429··6(a)<br/>IA-5(4)
0001ee90:·3c2f·7464·3e0a·2020·3c74·643e·4343·452d··</td>.··<td>CCE-0001ee90:·3c2f·7464·3e0a·2020·3c74·643e·4343·452d··</td>.··<td>CCE-
0001eea0:·3830·3636·352d·333c·2f74·643e·0a20·203c··80665-3</td>.··<0001eea0:·3830·3636·352d·333c·2f74·643e·0a20·203c··80665-3</td>.··<
0001eeb0:·7464·3e45·6e73·7572·6520·5041·4d20·456e··td>Ensure·PAM·En0001eeb0:·7464·3e45·6e73·7572·6520·5041·4d20·456e··td>Ensure·PAM·En
3.59 KB
html2text {}
    
Offset 1472, 27 lines modifiedOffset 1472, 27 lines modified
1472 ·····································pwquality.conf·to·equal·1·to·require·use·of·a·special·is·compromised.·Requiring·a·minimum·number·of·special·characters·makes1472 ·····································pwquality.conf·to·equal·1·to·require·use·of·a·special·is·compromised.·Requiring·a·minimum·number·of·special·characters·makes
1473 ·····································character·in·passwords.·······························password·guessing·attacks·more·difficult·by·ensuring·a·larger·search1473 ·····································character·in·passwords.·······························password·guessing·attacks·more·difficult·by·ensuring·a·larger·search
1474 ···························································································space.1474 ···························································································space.
1475 ·····································Do·not·allow·users·to·reuse·recent·passwords.·This1475 ·····································Do·not·allow·users·to·reuse·recent·passwords.·This
1476 ·····································can·be·accomplished·by·using·the·remember·option·for1476 ·····································can·be·accomplished·by·using·the·remember·option·for
1477 ·····································the·pam_pwhistory·PAM·module.1477 ·····································the·pam_pwhistory·PAM·module.
  
1478 IA-5(f)·CCE-···Limit·Password·Reuse:·In·the·file·/etc/pam.d/password-auth,·make·sure·the···Preventing·re-use·of·previous·passwords·helps·ensure·that·a·compromised····var_password_pam_remember=51478 IA-5(f)·CCE-···Limit·Password·Reuse:·In·the·file·/etc/pam.d/password-auth,·make·sure·the···Preventing·re-use·of·previous·passwords·helps·ensure·that·a·compromised····var_password_pam_remember_control_flag=required
1479 IA-5(1)·83478-·password-auth·········parameter·remember·is·present·and·it·has·a·value······password·is·not·re-used·by·a·user.·········································var_password_pam_remember_control_flag=required1479 IA-5(1)·83478-·password-auth·········parameter·remember·is·present·and·it·has·a·value······password·is·not·re-used·by·a·user.·········································var_password_pam_remember=5
1480 (e)·····8····························equal·to·or·greater·than·5.·For·example:1480 (e)·····8····························equal·to·or·greater·than·5.·For·example:
1481 ·····································password·control_flag·pam_pwhistory.so1481 ·····································password·control_flag·pam_pwhistory.so
1482 ·····································...existing_options...·remember=5·use_authtok1482 ·····································...existing_options...·remember=5·use_authtok
1483 ·····································control_flag·should·be·one·of·the·next·values:1483 ·····································control_flag·should·be·one·of·the·next·values:
1484 ·····································required1484 ·····································required
1485 ·····································Do·not·allow·users·to·reuse·recent·passwords.·This1485 ·····································Do·not·allow·users·to·reuse·recent·passwords.·This
1486 ·····································can·be·accomplished·by·using·the·remember·option·for1486 ·····································can·be·accomplished·by·using·the·remember·option·for
1487 ·····································the·pam_pwhistory·PAM·module.1487 ·····································the·pam_pwhistory·PAM·module.
  
1488 IA-5(f)·CCE-···Limit·Password·Reuse:·In·the·file·/etc/pam.d/system-auth,·make·sure·the·····Preventing·re-use·of·previous·passwords·helps·ensure·that·a·compromised····var_password_pam_remember=51488 IA-5(f)·CCE-···Limit·Password·Reuse:·In·the·file·/etc/pam.d/system-auth,·make·sure·the·····Preventing·re-use·of·previous·passwords·helps·ensure·that·a·compromised····var_password_pam_remember_control_flag=required
1489 IA-5(1)·83480-·system-auth···········parameter·remember·is·present·and·it·has·a·value······password·is·not·re-used·by·a·user.·········································var_password_pam_remember_control_flag=required1489 IA-5(1)·83480-·system-auth···········parameter·remember·is·present·and·it·has·a·value······password·is·not·re-used·by·a·user.·········································var_password_pam_remember=5
1490 (e)·····4····························equal·to·or·greater·than·5·For·example:1490 (e)·····4····························equal·to·or·greater·than·5·For·example:
1491 ·····································password·control_flag·pam_pwhistory.so1491 ·····································password·control_flag·pam_pwhistory.so
1492 ·····································...existing_options...·remember=5·use_authtok1492 ·····································...existing_options...·remember=5·use_authtok
1493 ·····································control_flag·should·be·one·of·the·next·values:1493 ·····································control_flag·should·be·one·of·the·next·values:
1494 ·····································required1494 ·····································required
1495 ·····································The·pam_pwquality·module's·ucredit=·parameter·········Use·of·a·complex·password·helps·to·increase·the·time·and·resources1495 ·····································The·pam_pwquality·module's·ucredit=·parameter·········Use·of·a·complex·password·helps·to·increase·the·time·and·resources
1496 ·····································controls·requirements·for·usage·of·uppercase·letters··required·to·compromise·the·password.·Password·complexity,·or·strength,·is1496 ·····································controls·requirements·for·usage·of·uppercase·letters··required·to·compromise·the·password.·Password·complexity,·or·strength,·is
7.13 MB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs.html
    
Offset 67, 11913 lines modifiedOffset 67, 11913 lines modified
00000420:·696f·6e3c·2f74·683e·0a20·2020·203c·7468··ion</th>.····<th00000420:·696f·6e3c·2f74·683e·0a20·2020·203c·7468··ion</th>.····<th
00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.
00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb
00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····
00000460:·2020·3c74·643e·4155·2d32·2864·293c·6272····<td>AU-2(d)<br00000460:·2020·3c74·643e·4155·2d32·2864·293c·6272····<td>AU-2(d)<br
00000470:·2f3e·4155·2d31·3228·6329·3c62·722f·3e43··/>AU-12(c)<br/>C00000470:·2f3e·4155·2d31·3228·6329·3c62·722f·3e43··/>AU-12(c)<br/>C
Diff chunk too large, falling back to line-by-line diff (4906 lines added, 4906 lines removed)
00000480:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····00000480:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····
00000490:·2020·3c74·643e·5265·636f·7264·2055·6e73····<td>Record·Uns00000490:·2020·3c74·643e·5265·636f·7264·2045·7665····<td>Record·Eve
000004a0:·7563·6365·7373·6675·6c20·5065·726d·6973··uccessful·Permis000004a0:·6e74·7320·7468·6174·204d·6f64·6966·7920··nts·that·Modify·
000004b0:·7369·6f6e·2043·6861·6e67·6573·2074·6f20··sion·Changes·to·000004b0:·7468·6520·5379·7374·656d·2773·2044·6973··the·System's·Dis
000004c0:·4669·6c65·7320·2d20·6663·686d·6f64·3c2f··Files·-·fchmod</000004c0:·6372·6574·696f·6e61·7279·2041·6363·6573··cretionary·Acces
000004d0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm000004d0:·7320·436f·6e74·726f·6c73·202d·2073·6574··s·Controls·-·set
000004e0:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">.000004e0:·7861·7474·723c·2f74·643e·0a20·2020·2020··xattr</td>.·····
000004f0:·2020·2020·2020·2020·5468·6520·6175·6469··········The·audi000004f0:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
00000500:·7420·7379·7374·656d·2073·686f·756c·6420··t·system·should·00000500:·6e2d·5553·223e·0a20·2020·2020·2020·2041··n-US">.········A
00000510:·636f·6c6c·6563·7420·756e·7375·6363·6573··collect·unsucces00000510:·7420·6120·6d69·6e69·6d75·6d2c·2074·6865··t·a·minimum,·the
00000520:·7366·756c·2066·696c·6520·7065·726d·6973··sful·file·permis00000520:·2061·7564·6974·2073·7973·7465·6d20·7368···audit·system·sh
00000530:·7369·6f6e·2063·6861·6e67·650a·6174·7465··sion·change.atte00000530:·6f75·6c64·2063·6f6c·6c65·6374·2066·696c··ould·collect·fil
00000540:·6d70·7473·2066·6f72·2061·6c6c·2075·7365··mpts·for·all·use00000540:·6520·7065·726d·6973·7369·6f6e·0a63·6861··e·permission.cha
00000550:·7273·2061·6e64·2072·6f6f·742e·0a49·6620··rs·and·root..If·00000550:·6e67·6573·2066·6f72·2061·6c6c·2075·7365··nges·for·all·use
00000560:·7468·6520·3c74·743e·6175·6469·7464·3c2f··the·<tt>auditd</00000560:·7273·2061·6e64·2072·6f6f·742e·2049·6620··rs·and·root.·If·
00000570:·7474·3e20·6461·656d·6f6e·2069·7320·636f··tt>·daemon·is·co00000570:·7468·6520·3c74·743e·6175·6469·7464·3c2f··the·<tt>auditd</
00000580:·6e66·6967·7572·6564·0a74·6f20·7573·6520··nfigured.to·use·00000580:·7474·3e20·6461·656d·6f6e·2069·7320·636f··tt>·daemon·is·co
00000590:·7468·6520·3c74·743e·6175·6765·6e72·756c··the·<tt>augenrul00000590:·6e66·6967·7572·6564·0a74·6f20·7573·6520··nfigured.to·use·
000005a0:·6573·3c2f·7474·3e20·7072·6f67·7261·6d20··es</tt>·program·000005a0:·7468·6520·3c74·743e·6175·6765·6e72·756c··the·<tt>augenrul
000005b0:·746f·2072·6561·6420·6175·6469·7420·7275··to·read·audit·ru000005b0:·6573·3c2f·7474·3e20·7072·6f67·7261·6d20··es</tt>·program·
000005c0:·6c65·7320·6475·7269·6e67·2064·6165·6d6f··les·during·daemo000005c0:·746f·2072·6561·6420·6175·6469·7420·7275··to·read·audit·ru
000005d0:·6e0a·7374·6172·7475·7020·2874·6865·2064··n.startup·(the·d000005d0:·6c65·7320·6475·7269·6e67·2064·6165·6d6f··les·during·daemo
000005e0:·6566·6175·6c74·292c·2061·6464·2074·6865··efault),·add·the000005e0:·6e0a·7374·6172·7475·7020·2874·6865·2064··n.startup·(the·d
000005f0:·2066·6f6c·6c6f·7769·6e67·206c·696e·6573···following·lines000005f0:·6566·6175·6c74·292c·2061·6464·2074·6865··efault),·add·the
00000600:·2074·6f20·6120·6669·6c65·2077·6974·6820···to·a·file·with·00000600:·2066·6f6c·6c6f·7769·6e67·206c·696e·6520···following·line·
00000610:·7375·6666·6978·0a3c·7474·3e2e·7275·6c65··suffix.<tt>.rule00000610:·746f·2061·2066·696c·6520·7769·7468·2073··to·a·file·with·s
00000620:·733c·2f74·743e·2069·6e20·7468·6520·6469··s</tt>·in·the·di00000620:·7566·6669·780a·3c74·743e·2e72·756c·6573··uffix.<tt>.rules
00000630:·7265·6374·6f72·7920·3c74·743e·2f65·7463··rectory·<tt>/etc00000630:·3c2f·7474·3e20·696e·2074·6865·2064·6972··</tt>·in·the·dir
00000640:·2f61·7564·6974·2f72·756c·6573·2e64·3c2f··/audit/rules.d</00000640:·6563·746f·7279·203c·7474·3e2f·6574·632f··ectory·<tt>/etc/
00000650:·7474·3e2e·0a49·6620·7468·6520·3c74·743e··tt>..If·the·<tt>00000650:·6175·6469·742f·7275·6c65·732e·643c·2f74··audit/rules.d</t
00000660:·6175·6469·7464·3c2f·7474·3e20·6461·656d··auditd</tt>·daem00000660:·743e·3a0a·3c70·7265·3e2d·6120·616c·7761··t>:.<pre>-a·alwa
00000670:·6f6e·2069·7320·636f·6e66·6967·7572·6564··on·is·configured00000670:·7973·2c65·7869·7420·2d46·2061·7263·683d··ys,exit·-F·arch=
00000680:·2074·6f20·7573·6520·7468·6520·3c74·743e···to·use·the·<tt>00000680:·6233·3220·2d53·2073·6574·7861·7474·7220··b32·-S·setxattr·
00000690:·6175·6469·7463·746c·3c2f·7474·3e0a·7574··auditctl</tt>.ut00000690:·2d46·2061·7569·6426·6774·3b3d·3130·3030··-F·auid&gt;=1000
000006a0:·696c·6974·7920·746f·2072·6561·6420·6175··ility·to·read·au000006a0:·202d·4620·6175·6964·213d·756e·7365·7420···-F·auid!=unset·
000006b0:·6469·7420·7275·6c65·7320·6475·7269·6e67··dit·rules·during000006b0:·2d46·206b·6579·3d70·6572·6d5f·6d6f·643c··-F·key=perm_mod<
000006c0:·2064·6165·6d6f·6e20·7374·6172·7475·702c···daemon·startup,000006c0:·2f70·7265·3e0a·3c70·7265·3e2d·6120·616c··/pre>.<pre>-a·al
000006d0:·2061·6464·2074·6865·2066·6f6c·6c6f·7769···add·the·followi000006d0:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc
000006e0:·6e67·206c·696e·6573·2074·6f0a·3c74·743e··ng·lines·to.<tt>000006e0:·683d·6233·3220·2d53·2073·6574·7861·7474··h=b32·-S·setxatt
000006f0:·2f65·7463·2f61·7564·6974·2f61·7564·6974··/etc/audit/audit000006f0:·7220·2d46·2061·7569·643d·3020·2d46·206b··r·-F·auid=0·-F·k
00000700:·2e72·756c·6573·3c2f·7474·3e20·6669·6c65··.rules</tt>·file00000700:·6579·3d70·6572·6d5f·6d6f·643c·2f70·7265··ey=perm_mod</pre
00000710:·2e0a·3c70·7265·3e2d·6120·616c·7761·7973··..<pre>-a·always00000710:·3e0a·4966·2074·6865·2073·7973·7465·6d20··>.If·the·system·
00000720:·2c65·7869·7420·2d46·2061·7263·683d·6233··,exit·-F·arch=b300000720:·6973·2036·3420·6269·7420·7468·656e·2061··is·64·bit·then·a
00000730:·3220·2d53·2066·6368·6d6f·6420·2d46·2065··2·-S·fchmod·-F·e00000730:·6c73·6f20·6164·6420·7468·6520·666f·6c6c··lso·add·the·foll
00000740:·7869·743d·2d45·4143·4345·5320·2d46·2061··xit=-EACCES·-F·a00000740:·6f77·696e·6720·6c69·6e65·3a0a·3c70·7265··owing·line:.<pre
00000750:·7569·643e·3d31·3030·3020·2d46·2061·7569··uid>=1000·-F·aui00000750:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·
00000760:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=00000760:·2d46·2061·7263·683d·6236·3420·2d53·2073··-F·arch=b64·-S·s
00000770:·756e·7375·6363·6573·6675·6c2d·7065·726d··unsuccesful-perm00000770:·6574·7861·7474·7220·2d46·2061·7569·6426··etxattr·-F·auid&
00000780:·2d63·6861·6e67·650a·2d61·2061·6c77·6179··-change.-a·alway00000780:·6774·3b3d·3130·3030·202d·4620·6175·6964··gt;=1000·-F·auid
00000790:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b00000790:·213d·756e·7365·7420·2d46·206b·6579·3d70··!=unset·-F·key=p
000007a0:·3332·202d·5320·6663·686d·6f64·202d·4620··32·-S·fchmod·-F·000007a0:·6572·6d5f·6d6f·643c·2f70·7265·3e0a·3c70··erm_mod</pre>.<p
000007b0:·6578·6974·3d2d·4550·4552·4d20·2d46·2061··exit=-EPERM·-F·a000007b0:·7265·3e2d·6120·616c·7761·7973·2c65·7869··re>-a·always,exi
000007c0:·7569·643e·3d31·3030·3020·2d46·2061·7569··uid>=1000·-F·aui000007c0:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S
000007d0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=000007d0:·2073·6574·7861·7474·7220·2d46·2061·7569···setxattr·-F·aui
000007e0:·756e·7375·6363·6573·6675·6c2d·7065·726d··unsuccesful-perm000007e0:·643d·3020·2d46·206b·6579·3d70·6572·6d5f··d=0·-F·key=perm_
000007f0:·2d63·6861·6e67·653c·2f70·7265·3e0a·4966··-change</pre>.If000007f0:·6d6f·643c·2f70·7265·3e0a·4966·2074·6865··mod</pre>.If·the
00000800:·2074·6865·2073·7973·7465·6d20·6973·2036···the·system·is·600000800:·203c·7474·3e61·7564·6974·643c·2f74·743e···<tt>auditd</tt>
00000810:·3420·6269·7420·7468·656e·2061·6c73·6f20··4·bit·then·also·00000810:·2064·6165·6d6f·6e20·6973·2063·6f6e·6669···daemon·is·confi
00000820:·6164·6420·7468·6520·666f·6c6c·6f77·696e··add·the·followin00000820:·6775·7265·6420·746f·2075·7365·2074·6865··gured·to·use·the
00000830:·6720·6c69·6e65·733a·0a3c·7072·653e·2d61··g·lines:.<pre>-a00000830:·203c·7474·3e61·7564·6974·6374·6c3c·2f74···<tt>auditctl</t
00000840:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·00000840:·743e·0a75·7469·6c69·7479·2074·6f20·7265··t>.utility·to·re
00000850:·6172·6368·3d62·3634·202d·5320·6663·686d··arch=b64·-S·fchm00000850:·6164·2061·7564·6974·2072·756c·6573·2064··ad·audit·rules·d
00000860:·6f64·202d·4620·6578·6974·3d2d·4541·4343··od·-F·exit=-EACC00000860:·7572·696e·6720·6461·656d·6f6e·2073·7461··uring·daemon·sta
00000870:·4553·202d·4620·6175·6964·3e3d·3130·3030··ES·-F·auid>=100000000870:·7274·7570·2c20·6164·6420·7468·6520·666f··rtup,·add·the·fo
00000880:·202d·4620·6175·6964·213d·756e·7365·7420···-F·auid!=unset·00000880:·6c6c·6f77·696e·6720·6c69·6e65·2074·6f0a··llowing·line·to.
00000890:·2d46·206b·6579·3d75·6e73·7563·6365·7366··-F·key=unsuccesf00000890:·3c74·743e·2f65·7463·2f61·7564·6974·2f61··<tt>/etc/audit/a
000008a0:·756c·2d70·6572·6d2d·6368·616e·6765·0a2d··ul-perm-change.-000008a0:·7564·6974·2e72·756c·6573·3c2f·7474·3e20··udit.rules</tt>·
000008b0:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F000008b0:·6669·6c65·3a0a·3c70·7265·3e2d·6120·616c··file:.<pre>-a·al
000008c0:·2061·7263·683d·6236·3420·2d53·2066·6368···arch=b64·-S·fch000008c0:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc
000008d0:·6d6f·6420·2d46·2065·7869·743d·2d45·5045··mod·-F·exit=-EPE000008d0:·683d·6233·3220·2d53·2073·6574·7861·7474··h=b32·-S·setxatt
000008e0:·524d·202d·4620·6175·6964·3e3d·3130·3030··RM·-F·auid>=1000000008e0:·7220·2d46·2061·7569·6426·6774·3b3d·3130··r·-F·auid&gt;=10
000008f0:·202d·4620·6175·6964·213d·756e·7365·7420···-F·auid!=unset·000008f0:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
00000900:·2d46·206b·6579·3d75·6e73·7563·6365·7366··-F·key=unsuccesf00000900:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo
00000910:·756c·2d70·6572·6d2d·6368·616e·6765·3c2f··ul-perm-change</00000910:·643c·2f70·7265·3e0a·3c70·7265·3e2d·6120··d</pre>.<pre>-a·
00000920:·7072·653e·0a20·2020·2020·203c·2f74·643e··pre>.······</td>00000920:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a
00000930:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000930:·7263·683d·6233·3220·2d53·2073·6574·7861··rch=b32·-S·setxa
00000940:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000940:·7474·7220·2d46·2061·7569·643d·3020·2d46··ttr·-F·auid=0·-F
00000950:·2020·2020·2055·6e73·7563·6365·7373·6675·······Unsuccessfu00000950:·206b·6579·3d70·6572·6d5f·6d6f·643c·2f70···key=perm_mod</p
00000960:·6c20·6174·7465·6d70·7473·2074·6f20·6368··l·attempts·to·ch00000960:·7265·3e0a·4966·2074·6865·2073·7973·7465··re>.If·the·syste
00000970:·616e·6765·2070·6572·6d69·7373·696f·6e73··ange·permissions00000970:·6d20·6973·2036·3420·6269·7420·7468·656e··m·is·64·bit·then
00000980:·206f·6620·6669·6c65·7320·636f·756c·6420···of·files·could·00000980:·2061·6c73·6f20·6164·6420·7468·6520·666f···also·add·the·fo
00000990:·6265·2061·6e20·696e·6469·6361·746f·7220··be·an·indicator·00000990:·6c6c·6f77·696e·6720·6c69·6e65·3a0a·3c70··llowing·line:.<p
000009a0:·6f66·206d·616c·6963·696f·7573·2061·6374··of·malicious·act000009a0:·7265·3e2d·6120·616c·7761·7973·2c65·7869··re>-a·always,exi
000009b0:·6976·6974·7920·6f6e·2061·2073·7973·7465··ivity·on·a·syste000009b0:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S
000009c0:·6d2e·2041·7564·6974·696e·670a·7468·6573··m.·Auditing.thes000009c0:·2073·6574·7861·7474·7220·2d46·2061·7569···setxattr·-F·aui
000009d0:·6520·6576·656e·7473·2063·6f75·6c64·2073··e·events·could·s000009d0:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au
000009e0:·6572·7665·2061·7320·6576·6964·656e·6365··erve·as·evidence000009e0:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
000009f0:·206f·6620·706f·7465·6e74·6961·6c20·7379···of·potential·sy000009f0:·3d70·6572·6d5f·6d6f·643c·2f70·7265·3e0a··=perm_mod</pre>.
00000a00:·7374·656d·2063·6f6d·7072·6f6d·6973·652e··stem·compromise.00000a00:·3c70·7265·3e2d·6120·616c·7761·7973·2c65··<pre>-a·always,e
00000a10:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···00000a10:·7869·7420·2d46·2061·7263·683d·6236·3420··xit·-F·arch=b64·
00000a20:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.00000a20:·2d53·2073·6574·7861·7474·7220·2d46·2061··-S·setxattr·-F·a
00000a30:·2020·2020·2020·3c74·643e·4155·2d32·2864········<td>AU-2(d00000a30:·7569·643d·3020·2d46·206b·6579·3d70·6572··uid=0·-F·key=per
00000a40:·293c·6272·2f3e·4155·2d31·3228·6329·3c62··)<br/>AU-12(c)<b00000a40:·6d5f·6d6f·643c·2f70·7265·3e0a·2020·2020··m_mod</pre>.····
00000a50:·722f·3e41·432d·3628·3929·3c62·722f·3e43··r/>AC-6(9)<br/>C00000a50:·2020·3c2f·7464·3e0a·2020·2020·2020·3c74····</td>.······<t
00000a60:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····00000a60:·6420·786d·6c3a·6c61·6e67·3d22·656e·2d55··d·xml:lang="en-U
00000a70:·2020·3c74·643e·5265·636f·7264·2041·7474····<td>Record·Att00000a70:·5322·3e0a·2020·2020·2020·2020·5468·6520··S">.········The·
00000a80:·656d·7074·7320·746f·2041·6c74·6572·204c··empts·to·Alter·L00000a80:·6368·616e·6769·6e67·206f·6620·6669·6c65··changing·of·file
00000a90:·6f67·6f6e·2061·6e64·204c·6f67·6f75·7420··ogon·and·Logout·00000a90:·2070·6572·6d69·7373·696f·6e73·2063·6f75···permissions·cou
00000aa0:·4576·656e·7473·202d·2074·616c·6c79·6c6f··Events·-·tallylo00000aa0:·6c64·2069·6e64·6963·6174·6520·7468·6174··ld·indicate·that
00000ab0:·673c·2f74·643e·0a20·2020·2020·203c·7464··g</td>.······<td00000ab0:·2061·2075·7365·7220·6973·2061·7474·656d···a·user·is·attem
00000ac0:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US00000ac0:·7074·696e·6720·746f·0a67·6169·6e20·6163··pting·to.gain·ac
00000ad0:·223e·0a20·2020·2020·2020·2054·6865·2061··">.········The·a00000ad0:·6365·7373·2074·6f20·696e·666f·726d·6174··cess·to·informat
00000ae0:·7564·6974·2073·7973·7465·6d20·616c·7265··udit·system·alre00000ae0:·696f·6e20·7468·6174·2077·6f75·6c64·206f··ion·that·would·o
00000af0:·6164·7920·636f·6c6c·6563·7473·206c·6f67··ady·collects·log00000af0:·7468·6572·7769·7365·2062·6520·6469·7361··therwise·be·disa
00000b00:·696e·2069·6e66·6f72·6d61·7469·6f6e·2066··in·information·f00000b00:·6c6c·6f77·6564·2e20·4175·6469·7469·6e67··llowed.·Auditing
00000b10:·6f72·2061·6c6c·2075·7365·7273·0a61·6e64··or·all·users.and00000b10:·2044·4143·206d·6f64·6966·6963·6174·696f···DAC·modificatio
00000b20:·2072·6f6f·742e·2049·6620·7468·6520·3c74···root.·If·the·<t00000b20:·6e73·0a63·616e·2066·6163·696c·6974·6174··ns.can·facilitat
00000b30:·743e·6175·6469·7464·3c2f·7474·3e20·6461··t>auditd</tt>·da00000b30:·6520·7468·6520·6964·656e·7469·6669·6361··e·the·identifica
00000b40:·656d·6f6e·2069·7320·636f·6e66·6967·7572··emon·is·configur00000b40:·7469·6f6e·206f·6620·7061·7474·6572·6e73··tion·of·patterns
00000b50:·6564·2074·6f20·7573·6520·7468·650a·3c74··ed·to·use·the.<t00000b50:·206f·6620·6162·7573·6520·616d·6f6e·6720···of·abuse·among·
00000b60:·743e·6175·6765·6e72·756c·6573·3c2f·7474··t>augenrules</tt00000b60:·626f·7468·2061·7574·686f·7269·7a65·6420··both·authorized·
00000b70:·3e20·7072·6f67·7261·6d20·746f·2072·6561··>·program·to·rea00000b70:·616e·640a·756e·6175·7468·6f72·697a·6564··and.unauthorized
00000b80:·6420·6175·6469·7420·7275·6c65·7320·6475··d·audit·rules·du00000b80:·2075·7365·7273·2e0a·2020·2020·2020·3c2f···users..······</
00000b90:·7269·6e67·2064·6165·6d6f·6e20·7374·6172··ring·daemon·star00000b90:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··
00000ba0:·7475·7020·2874·6865·0a64·6566·6175·6c74··tup·(the.default00000ba0:·2020·3c74·723e·0a20·2020·2020·203c·7464····<tr>.······<td
00000bb0:·292c·2061·6464·2074·6865·2066·6f6c·6c6f··),·add·the·follo00000bb0:·3e41·552d·3228·6429·3c62·722f·3e41·552d··>AU-2(d)<br/>AU-
00000bc0:·7769·6e67·206c·696e·6573·2074·6f20·6120··wing·lines·to·a·00000bc0:·3132·2863·293c·6272·2f3e·434d·2d36·2861··12(c)<br/>CM-6(a
00000bd0:·6669·6c65·2077·6974·6820·7375·6666·6978··file·with·suffix00000bd0:·293c·2f74·643e·0a20·2020·2020·203c·7464··)</td>.······<td
00000be0:·203c·7474·3e2e·7275·6c65·733c·2f74·743e···<tt>.rules</tt>00000be0:·3e45·6e73·7572·6520·6175·6469·7464·2043··>Ensure·auditd·C
00000bf0:·2069·6e20·7468·650a·6469·7265·6374·6f72···in·the.director00000bf0:·6f6c·6c65·6374·7320·4669·6c65·2044·656c··ollects·File·Del
Max diff block lines reached; 5437606/6115212 bytes (88.92%) of diff not shown.
1.3 MB
html2text {}
Max HTML report size reached
714 KB
./usr/share/doc/ssg-nondebian/table-rhel8-pcidssrefs.html
Ordering differences only
    
Offset 95, 14 lines modifiedOffset 95, 50 lines modified
95 attacker·to·monitor·and·record·network·traffic.·These·malicious·APs·can·also95 attacker·to·monitor·and·record·network·traffic.·These·malicious·APs·can·also
96 serve·to·create·a·man-in-the-middle·attack·or·be·used·to·create·a·denial·of96 serve·to·create·a·man-in-the-middle·attack·or·be·used·to·create·a·denial·of
97 service·to·valid·network·resources.97 service·to·valid·network·resources.
98 ······</td>98 ······</td>
99 ····</tr>99 ····</tr>
100 ····<tr>100 ····<tr>
101 ······<td>Req-1.4.1</td>101 ······<td>Req-1.4.1</td>
 102 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
 103 ······<td·xml:lang="en-US">
 104 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
 105 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
 106 ······</td>
 107 ······<td·xml:lang="en-US">
 108 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
 109 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state.
 110 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received,
 111 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
 112 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
 113 enables·the·system·to·continue·servicing·valid·connection·requests.
 114 ······</td>
 115 ····</tr>
 116 ····<tr>
 117 ······<td>Req-1.4.1</td>
 118 ······<td>Set·Default·ip6tables·Policy·for·Incoming·Packets</td>
 119 ······<td·xml:lang="en-US">
 120 ········To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)·for
 121 the·built-in·INPUT·chain·which·processes·incoming·packets,
 122 add·or·correct·the·following·line·in
 123 <tt>/etc/sysconfig/ip6tables</tt>:
 124 <pre>:INPUT·DROP·[0:0]</pre>
 125 If·changes·were·required,·reload·the·ip6tables·rules:
 126 <pre>$·sudo·service·ip6tables·reload</pre>
 127 ······</td>
 128 ······<td·xml:lang="en-US">
 129 ········In·<tt>ip6tables</tt>,·the·default·policy·is·applied·only·after·all
 130 the·applicable·rules·in·the·table·are·examined·for·a·match.·Setting·the
 131 default·policy·to·<tt>DROP</tt>·implements·proper·design·for·a·firewall,·i.e.
 132 any·packets·which·are·not·explicitly·permitted·should·not·be
 133 accepted.
 134 ······</td>
 135 ····</tr>
 136 ····<tr>
 137 ······<td>Req-1.4.1</td>
102 ······<td>Set·configuration·for·loopback·traffic</td>138 ······<td>Set·configuration·for·loopback·traffic</td>
103 ······<td·xml:lang="en-US">139 ······<td·xml:lang="en-US">
104 ········Configure·the·loopback·interface·to·accept·traffic.·140 ········Configure·the·loopback·interface·to·accept·traffic.·
105 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback·141 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback·
106 network.142 network.
107 ······</td>143 ······</td>
108 ······<td·xml:lang="en-US">144 ······<td·xml:lang="en-US">
Offset 140, 47 lines modifiedOffset 176, 33 lines modified
140 ······<td·xml:lang="en-US">176 ······<td·xml:lang="en-US">
141 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering177 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
142 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP178 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
143 masquerading,·etc.179 masquerading,·etc.
144 ······</td>180 ······</td>
145 ····</tr>181 ····</tr>
146 ····<tr>182 ····<tr>
147 ······<td>Req-1.4.1</td>183 ······<td>Req-1.4.2</td>
 184 ······<td>Disable·SCTP·Support</td>
148 ······<td>Set·Default·ip6tables·Policy·for·Incoming·Packets</td> 
149 ······<td·xml:lang="en-US"> 
150 ········To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)·for 
151 the·built-in·INPUT·chain·which·processes·incoming·packets, 
152 add·or·correct·the·following·line·in 
153 <tt>/etc/sysconfig/ip6tables</tt>: 
154 <pre>:INPUT·DROP·[0:0]</pre> 
155 If·changes·were·required,·reload·the·ip6tables·rules: 
156 <pre>$·sudo·service·ip6tables·reload</pre> 
157 ······</td> 
158 ······<td·xml:lang="en-US"> 
159 ········In·<tt>ip6tables</tt>,·the·default·policy·is·applied·only·after·all 
160 the·applicable·rules·in·the·table·are·examined·for·a·match.·Setting·the 
161 default·policy·to·<tt>DROP</tt>·implements·proper·design·for·a·firewall,·i.e. 
162 any·packets·which·are·not·explicitly·permitted·should·not·be 
163 accepted. 
164 ······</td> 
165 ····</tr> 
166 ····<tr> 
167 ······<td>Req-1.4.1</td> 
168 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td> 
169 ······<td·xml:lang="en-US">185 ······<td·xml:lang="en-US">
170 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre> 
171 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>186 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
 187 transport·layer·protocol,·designed·to·support·the·idea·of
 188 message-oriented·communication,·with·several·streams·of·messages
 189 within·one·connection.
  
 190 To·configure·the·system·to·prevent·the·<code>sctp</code>
 191 kernel·module·from·being·loaded,·add·the·following·line·to·the·file·<code>/etc/modprobe.d/sctp.conf</code>:
 192 <pre>install·sctp·/bin/true</pre>
  
 193 To·configure·the·system·to·prevent·the·<code>sctp</code>·from·being·used,
 194 add·the·following·line·to·file·<code>/etc/modprobe.d/sctp.conf</code>:
 195 <pre>blacklist·sctp</pre>
172 ······</td>196 ······</td>
173 ······<td·xml:lang="en-US">197 ······<td·xml:lang="en-US">
 198 ········Disabling·SCTP·protects
 199 the·system·against·exploitation·of·any·flaws·in·its·implementation.
174 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a 
175 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state. 
176 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received, 
177 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood 
178 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and 
179 enables·the·system·to·continue·servicing·valid·connection·requests. 
180 ······</td>200 ······</td>
181 ····</tr>201 ····</tr>
182 ····<tr>202 ····<tr>
183 ······<td>Req-1.4.2</td>203 ······<td>Req-1.4.2</td>
184 ······<td>Disable·DCCP·Support</td>204 ······<td>Disable·DCCP·Support</td>
185 ······<td·xml:lang="en-US">205 ······<td·xml:lang="en-US">
186 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a206 ········The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a
Offset 197, 33 lines modifiedOffset 219, 44 lines modified
197 ······</td>219 ······</td>
198 ······<td·xml:lang="en-US">220 ······<td·xml:lang="en-US">
199 ········Disabling·DCCP·protects221 ········Disabling·DCCP·protects
200 the·system·against·exploitation·of·any·flaws·in·its·implementation.222 the·system·against·exploitation·of·any·flaws·in·its·implementation.
201 ······</td>223 ······</td>
202 ····</tr>224 ····</tr>
203 ····<tr>225 ····<tr>
204 ······<td>Req-1.4.2</td>226 ······<td>Req-1.4.3</td>
205 ······<td>Disable·SCTP·Support</td>227 ······<td>Enable·Kernel·Parameter·to·Ignore·ICMP·Broadcast·Echo·Requests·on·IPv4·Interfaces</td>
206 ······<td·xml:lang="en-US">228 ······<td·xml:lang="en-US">
 229 ········To·set·the·runtime·status·of·the·<code>net.ipv4.icmp_echo_ignore_broadcasts</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.icmp_echo_ignore_broadcasts=1</pre>
 230 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.icmp_echo_ignore_broadcasts·=·1</pre>
207 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a 
208 transport·layer·protocol,·designed·to·support·the·idea·of 
Max diff block lines reached; 275673/282431 bytes (97.61%) of diff not shown.
438 KB
html2text {}
    
Offset 56, 14 lines modifiedOffset 56, 55 lines modified
56 ····················································································also·serve·to56 ····················································································also·serve·to
57 ····················································································create·a·man-in-57 ····················································································create·a·man-in-
58 ····················································································the-middle·attack58 ····················································································the-middle·attack
59 ····················································································or·be·used·to59 ····················································································or·be·used·to
60 ····················································································create·a·denial·of60 ····················································································create·a·denial·of
61 ····················································································service·to·valid61 ····················································································service·to·valid
62 ····················································································network·resources.62 ····················································································network·resources.
 63 ····················································································A·TCP·SYN·flood
 64 ····················································································attack·can·cause·a
 65 ····················································································denial·of·service
 66 ····················································································by·filling·a
 67 ····················································································system's·TCP
 68 ····················································································connection·table
 69 ····················································································with·connections·in
 70 ····················································································the·SYN_RCVD·state.
 71 ····················································································Syncookies·can·be
 72 ·····························To·set·the·runtime·status·of·the·······················used·to·track·a
 73 ·····························net.ipv4.tcp_syncookies·kernel·parameter,·run·the······connection·when·a
 74 ·········Enable·Kernel·······following·command:·····································subsequent·ACK·is
 75 Req-·····Parameter·to·Use····$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1·············received,·verifying
 76 1.4.1····TCP·Syncookies·on···To·make·sure·that·the·setting·is·persistent,·add·the···the·initiator·is
 77 ·········Network·Interfaces··following·line·to·a·file·in·the·directory·/etc/········attempting·a·valid
 78 ·····························sysctl.d:··············································connection·and·is
 79 ·····························net.ipv4.tcp_syncookies·=·1····························not·a·flood·source.
 80 ····················································································This·feature·is
 81 ····················································································activated·when·a
 82 ····················································································flood·condition·is
 83 ····················································································detected,·and
 84 ····················································································enables·the·system
 85 ····················································································to·continue
 86 ····················································································servicing·valid
 87 ····················································································connection
 88 ····················································································requests.
 89 ····················································································In·ip6tables,·the
 90 ····················································································default·policy·is
 91 ····················································································applied·only·after
 92 ····················································································all·the·applicable
 93 ·····························To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)··rules·in·the·table
 94 ·········Set·Default·········for·the·built-in·INPUT·chain·which·processes·incoming··are·examined·for·a
 95 Req-·····ip6tables·Policy····packets,·add·or·correct·the·following·line·in·/etc/····match.·Setting·the
 96 1.4.1····for·Incoming········sysconfig/ip6tables:···································default·policy·to
 97 ·········Packets·············:INPUT·DROP·[0:0]······································DROP·implements
 98 ·····························If·changes·were·required,·reload·the·ip6tables·rules:··proper·design·for·a
 99 ·····························$·sudo·service·ip6tables·reload························firewall,·i.e.·any
 100 ····················································································packets·which·are
 101 ····················································································not·explicitly
 102 ····················································································permitted·should
 103 ····················································································not·be·accepted.
63 ····················································································Loopback·traffic·is104 ····················································································Loopback·traffic·is
64 ····················································································generated·between105 ····················································································generated·between
65 ····················································································processes·on106 ····················································································processes·on
66 ····················································································machine·and·is107 ····················································································machine·and·is
67 ····················································································typically·critical108 ····················································································typically·critical
68 ····················································································to·operation·of·the109 ····················································································to·operation·of·the
69 ····················································································system.·The110 ····················································································system.·The
Offset 99, 78 lines modifiedOffset 140, 84 lines modified
99 ····················································································network·packet140 ····················································································network·packet
100 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.141 Req-·····Install·iptables····The·iptables·package·can·be·installed·with·the·········filtering·code.
101 1.4.1····Package·············following·command:·····································iptables·allows142 1.4.1····Package·············following·command:·····································iptables·allows
102 ·····························$·sudo·yum·install·iptables····························system·operators·to143 ·····························$·sudo·yum·install·iptables····························system·operators·to
103 ····················································································set·up·firewalls144 ····················································································set·up·firewalls
104 ····················································································and·IP145 ····················································································and·IP
105 ····················································································masquerading,·etc.146 ····················································································masquerading,·etc.
106 ····················································································In·ip6tables,·the 
107 ····················································································default·policy·is 
108 ····················································································applied·only·after 
109 ····················································································all·the·applicable 
110 ·····························To·set·the·default·policy·to·DROP·(instead·of·ACCEPT)··rules·in·the·table 
111 ·········Set·Default·········for·the·built-in·INPUT·chain·which·processes·incoming··are·examined·for·a 
112 Req-·····ip6tables·Policy····packets,·add·or·correct·the·following·line·in·/etc/····match.·Setting·the 
113 1.4.1····for·Incoming········sysconfig/ip6tables:···································default·policy·to 
114 ·········Packets·············:INPUT·DROP·[0:0]······································DROP·implements 
115 ·····························If·changes·were·required,·reload·the·ip6tables·rules:··proper·design·for·a 
116 ·····························$·sudo·service·ip6tables·reload························firewall,·i.e.·any 
117 ····················································································packets·which·are 
118 ····················································································not·explicitly 
119 ····················································································permitted·should 
120 ····················································································not·be·accepted. 
121 ····················································································A·TCP·SYN·flood 
122 ····················································································attack·can·cause·a 
123 ····················································································denial·of·service 
124 ····················································································by·filling·a 
125 ····················································································system's·TCP 
126 ····················································································connection·table 
127 ····················································································with·connections·in 
128 ····················································································the·SYN_RCVD·state. 
129 ····················································································Syncookies·can·be 
130 ·····························To·set·the·runtime·status·of·the·······················used·to·track·a 
131 ·····························net.ipv4.tcp_syncookies·kernel·parameter,·run·the······connection·when·a 
132 ·········Enable·Kernel·······following·command:·····································subsequent·ACK·is 
133 Req-·····Parameter·to·Use····$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1·············received,·verifying 
134 1.4.1····TCP·Syncookies·on···To·make·sure·that·the·setting·is·persistent,·add·the···the·initiator·is 
135 ·········Network·Interfaces··following·line·to·a·file·in·the·directory·/etc/········attempting·a·valid 
136 ·····························sysctl.d:··············································connection·and·is 
137 ·····························net.ipv4.tcp_syncookies·=·1····························not·a·flood·source. 
138 ····················································································This·feature·is 
139 ····················································································activated·when·a 
140 ····················································································flood·condition·is 
141 ····················································································detected,·and 
142 ····················································································enables·the·system 
143 ····················································································to·continue 
144 ····················································································servicing·valid 
145 ····················································································connection 
146 ····················································································requests. 
147 ·····························The·Datagram·Congestion·Control·Protocol·(DCCP)·is·a 
148 ·····························relatively·new·transport·layer·protocol,·designed·to 
149 ·····························support·streaming·media·and·telephony.·To·configure····Disabling·DCCP 
150 ·····························the·system·to·prevent·the·dccp·kernel·module·from······protects·the·system 
151 Req-·····Disable·DCCP········being·loaded,·add·the·following·line·to·the·file·/etc/·against 
152 1.4.2····Support·············modprobe.d/dccp.conf:··································exploitation·of·any 
153 ·····························install·dccp·/bin/true·································flaws·in·its 
154 ·····························To·configure·the·system·to·prevent·the·dccp·from·being·implementation. 
155 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/ 
156 ·····························dccp.conf: 
157 ·····························blacklist·dccp 
158 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a147 ·····························The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
159 ·····························transport·layer·protocol,·designed·to·support·the·idea148 ·····························transport·layer·protocol,·designed·to·support·the·idea
160 ·····························of·message-oriented·communication,·with·several149 ·····························of·message-oriented·communication,·with·several
161 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP150 ·····························streams·of·messages·within·one·connection.·To··········Disabling·SCTP
162 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system151 ·····························configure·the·system·to·prevent·the·sctp·kernel·module·protects·the·system
163 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against152 Req-·····Disable·SCTP········from·being·loaded,·add·the·following·line·to·the·file··against
164 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any153 1.4.2····Support·············/etc/modprobe.d/sctp.conf:·····························exploitation·of·any
165 ·····························install·sctp·/bin/true·································flaws·in·its154 ·····························install·sctp·/bin/true·································flaws·in·its
166 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.155 ·····························To·configure·the·system·to·prevent·the·sctp·from·being·implementation.
167 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/156 ·····························used,·add·the·following·line·to·file·/etc/modprobe.d/
168 ·····························sctp.conf:157 ·····························sctp.conf:
169 ·····························blacklist·sctp158 ·····························blacklist·sctp
Max diff block lines reached; 430536/448829 bytes (95.92%) of diff not shown.
24.3 KB
./usr/share/scap-security-guide/ansible/alinux2-playbook-cis.yml
Ordering differences only
    
Offset 1124, 16 lines modifiedOffset 1124, 16 lines modified
  
1124 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1124 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1125 ······find:1125 ······find:
1126 ········paths:·/etc/audit/rules.d/1126 ········paths:·/etc/audit/rules.d/
1127 ········patterns:·'*.rules'1127 ········patterns:·'*.rules'
1128 ······register:·find_rules_d1128 ······register:·find_rules_d
1129 ······when:1129 ······when:
1130 ······-·'"audit"·in·ansible_facts.packages' 
1131 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1130 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1131 ······-·'"audit"·in·ansible_facts.packages'
1132 ······tags:1132 ······tags:
1133 ······-·CJIS-5.4.1.11133 ······-·CJIS-5.4.1.1
1134 ······-·NIST-800-171-3.3.11134 ······-·NIST-800-171-3.3.1
1135 ······-·NIST-800-171-3.4.31135 ······-·NIST-800-171-3.4.3
1136 ······-·NIST-800-53-AC-6(9)1136 ······-·NIST-800-53-AC-6(9)
1137 ······-·NIST-800-53-CM-6(a)1137 ······-·NIST-800-53-CM-6(a)
1138 ······-·PCI-DSS-Req-10.5.21138 ······-·PCI-DSS-Req-10.5.2
Offset 1148, 16 lines modifiedOffset 1148, 16 lines modified
1148 ······lineinfile:1148 ······lineinfile:
1149 ········path:·'{{·item·}}'1149 ········path:·'{{·item·}}'
1150 ········regexp:·^\s*(?:-e)\s+.*$1150 ········regexp:·^\s*(?:-e)\s+.*$
1151 ········state:·absent1151 ········state:·absent
1152 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1152 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1153 ········}}'1153 ········}}'
1154 ······when:1154 ······when:
1155 ······-·'"audit"·in·ansible_facts.packages' 
1156 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1155 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1156 ······-·'"audit"·in·ansible_facts.packages'
1157 ······tags:1157 ······tags:
1158 ······-·CJIS-5.4.1.11158 ······-·CJIS-5.4.1.1
1159 ······-·NIST-800-171-3.3.11159 ······-·NIST-800-171-3.3.1
1160 ······-·NIST-800-171-3.4.31160 ······-·NIST-800-171-3.4.3
1161 ······-·NIST-800-53-AC-6(9)1161 ······-·NIST-800-53-AC-6(9)
1162 ······-·NIST-800-53-CM-6(a)1162 ······-·NIST-800-53-CM-6(a)
1163 ······-·PCI-DSS-Req-10.5.21163 ······-·PCI-DSS-Req-10.5.2
Offset 1174, 16 lines modifiedOffset 1174, 16 lines modified
1174 ········create:·true1174 ········create:·true
1175 ········line:·-e·21175 ········line:·-e·2
1176 ········mode:·o-rwx1176 ········mode:·o-rwx
1177 ······loop:1177 ······loop:
1178 ······-·/etc/audit/audit.rules1178 ······-·/etc/audit/audit.rules
1179 ······-·/etc/audit/rules.d/immutable.rules1179 ······-·/etc/audit/rules.d/immutable.rules
1180 ······when:1180 ······when:
1181 ······-·'"audit"·in·ansible_facts.packages' 
1182 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1181 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1182 ······-·'"audit"·in·ansible_facts.packages'
1183 ······tags:1183 ······tags:
1184 ······-·CJIS-5.4.1.11184 ······-·CJIS-5.4.1.1
1185 ······-·NIST-800-171-3.3.11185 ······-·NIST-800-171-3.3.1
1186 ······-·NIST-800-171-3.4.31186 ······-·NIST-800-171-3.4.3
1187 ······-·NIST-800-53-AC-6(9)1187 ······-·NIST-800-53-AC-6(9)
1188 ······-·NIST-800-53-CM-6(a)1188 ······-·NIST-800-53-CM-6(a)
1189 ······-·PCI-DSS-Req-10.5.21189 ······-·PCI-DSS-Req-10.5.2
Offset 1218, 16 lines modifiedOffset 1218, 16 lines modified
1218 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/1218 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
1219 ······find:1219 ······find:
1220 ········paths:·/etc/audit/rules.d1220 ········paths:·/etc/audit/rules.d
1221 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+1221 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
1222 ········patterns:·'*.rules'1222 ········patterns:·'*.rules'
1223 ······register:·find_existing_watch_rules_d1223 ······register:·find_existing_watch_rules_d
1224 ······when:1224 ······when:
1225 ······-·'"audit"·in·ansible_facts.packages' 
1226 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1225 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1226 ······-·'"audit"·in·ansible_facts.packages'
1227 ······tags:1227 ······tags:
1228 ······-·CJIS-5.4.1.11228 ······-·CJIS-5.4.1.1
1229 ······-·NIST-800-171-3.1.71229 ······-·NIST-800-171-3.1.7
1230 ······-·NIST-800-53-AC-2(7)(b)1230 ······-·NIST-800-53-AC-2(7)(b)
1231 ······-·NIST-800-53-AC-6(9)1231 ······-·NIST-800-53-AC-6(9)
1232 ······-·NIST-800-53-AU-12(c)1232 ······-·NIST-800-53-AU-12(c)
1233 ······-·NIST-800-53-AU-2(d)1233 ······-·NIST-800-53-AU-2(d)
Offset 1244, 16 lines modifiedOffset 1244, 16 lines modified
1244 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions1244 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
1245 ······find:1245 ······find:
1246 ········paths:·/etc/audit/rules.d1246 ········paths:·/etc/audit/rules.d
1247 ········contains:·^.*(?:-F·key=|-k\s+)actions$1247 ········contains:·^.*(?:-F·key=|-k\s+)actions$
1248 ········patterns:·'*.rules'1248 ········patterns:·'*.rules'
1249 ······register:·find_watch_key1249 ······register:·find_watch_key
1250 ······when:1250 ······when:
1251 ······-·'"audit"·in·ansible_facts.packages' 
1252 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1251 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1252 ······-·'"audit"·in·ansible_facts.packages'
1253 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1253 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1254 ········==·01254 ········==·0
1255 ······tags:1255 ······tags:
1256 ······-·CJIS-5.4.1.11256 ······-·CJIS-5.4.1.1
1257 ······-·NIST-800-171-3.1.71257 ······-·NIST-800-171-3.1.7
1258 ······-·NIST-800-53-AC-2(7)(b)1258 ······-·NIST-800-53-AC-2(7)(b)
1259 ······-·NIST-800-53-AC-6(9)1259 ······-·NIST-800-53-AC-6(9)
Offset 1270, 16 lines modifiedOffset 1270, 16 lines modified
1270 ······-·restrict_strategy1270 ······-·restrict_strategy
  
1271 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule1271 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule
1272 ······set_fact:1272 ······set_fact:
1273 ········all_files:1273 ········all_files:
1274 ········-·/etc/audit/rules.d/actions.rules1274 ········-·/etc/audit/rules.d/actions.rules
1275 ······when:1275 ······when:
1276 ······-·'"audit"·in·ansible_facts.packages' 
1277 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1276 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1277 ······-·'"audit"·in·ansible_facts.packages'
1278 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1278 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1279 ········is·defined·and·find_existing_watch_rules_d.matched·==·01279 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1280 ······tags:1280 ······tags:
1281 ······-·CJIS-5.4.1.11281 ······-·CJIS-5.4.1.1
1282 ······-·NIST-800-171-3.1.71282 ······-·NIST-800-171-3.1.7
1283 ······-·NIST-800-53-AC-2(7)(b)1283 ······-·NIST-800-53-AC-2(7)(b)
1284 ······-·NIST-800-53-AC-6(9)1284 ······-·NIST-800-53-AC-6(9)
Offset 1296, 16 lines modifiedOffset 1296, 16 lines modified
1296 ······-·restrict_strategy1296 ······-·restrict_strategy
  
1297 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1297 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1298 ······set_fact:1298 ······set_fact:
1299 ········all_files:1299 ········all_files:
1300 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1300 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1301 ······when:1301 ······when:
1302 ······-·'"audit"·in·ansible_facts.packages' 
1303 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1302 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1303 ······-·'"audit"·in·ansible_facts.packages'
1304 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1304 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1305 ········is·defined·and·find_existing_watch_rules_d.matched·==·01305 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1306 ······tags:1306 ······tags:
1307 ······-·CJIS-5.4.1.11307 ······-·CJIS-5.4.1.1
1308 ······-·NIST-800-171-3.1.71308 ······-·NIST-800-171-3.1.7
1309 ······-·NIST-800-53-AC-2(7)(b)1309 ······-·NIST-800-53-AC-2(7)(b)
1310 ······-·NIST-800-53-AC-6(9)1310 ······-·NIST-800-53-AC-6(9)
Offset 1324, 16 lines modifiedOffset 1324, 16 lines modified
1324 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/1324 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/
Max diff block lines reached; 20013/24693 bytes (81.05%) of diff not shown.
3.91 KB
./usr/share/scap-security-guide/ansible/alinux2-playbook-cis_l1.yml
Ordering differences only
    
Offset 1230, 16 lines modifiedOffset 1230, 16 lines modified
1230 ······-·no_reboot_needed1230 ······-·no_reboot_needed
  
1231 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg1231 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
1232 ······stat:1232 ······stat:
1233 ········path:·/boot/grub2/grub.cfg1233 ········path:·/boot/grub2/grub.cfg
1234 ······register:·file_exists1234 ······register:·file_exists
1235 ······when:1235 ······when:
1236 ······-·'"grub2-common"·in·ansible_facts.packages' 
1237 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'1236 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1237 ······-·'"grub2-common"·in·ansible_facts.packages'
1238 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1238 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1239 ······tags:1239 ······tags:
1240 ······-·CJIS-5.5.2.21240 ······-·CJIS-5.5.2.2
1241 ······-·NIST-800-171-3.4.51241 ······-·NIST-800-171-3.4.5
1242 ······-·NIST-800-53-AC-6(1)1242 ······-·NIST-800-53-AC-6(1)
1243 ······-·NIST-800-53-CM-6(a)1243 ······-·NIST-800-53-CM-6(a)
1244 ······-·PCI-DSS-Req-7.11244 ······-·PCI-DSS-Req-7.1
Offset 1251, 16 lines modifiedOffset 1251, 16 lines modified
1251 ······-·no_reboot_needed1251 ······-·no_reboot_needed
  
1252 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg1252 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
1253 ······file:1253 ······file:
1254 ········path:·/boot/grub2/grub.cfg1254 ········path:·/boot/grub2/grub.cfg
1255 ········group:·'0'1255 ········group:·'0'
1256 ······when:1256 ······when:
1257 ······-·'"grub2-common"·in·ansible_facts.packages' 
1258 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'1257 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1258 ······-·'"grub2-common"·in·ansible_facts.packages'
1259 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1259 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1260 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1260 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1261 ······tags:1261 ······tags:
1262 ······-·CJIS-5.5.2.21262 ······-·CJIS-5.5.2.2
1263 ······-·NIST-800-171-3.4.51263 ······-·NIST-800-171-3.4.5
1264 ······-·NIST-800-53-AC-6(1)1264 ······-·NIST-800-53-AC-6(1)
1265 ······-·NIST-800-53-CM-6(a)1265 ······-·NIST-800-53-CM-6(a)
Offset 1290, 16 lines modifiedOffset 1290, 16 lines modified
1290 ······-·no_reboot_needed1290 ······-·no_reboot_needed
  
1291 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg1291 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
1292 ······stat:1292 ······stat:
1293 ········path:·/boot/grub2/grub.cfg1293 ········path:·/boot/grub2/grub.cfg
1294 ······register:·file_exists1294 ······register:·file_exists
1295 ······when:1295 ······when:
1296 ······-·'"grub2-common"·in·ansible_facts.packages' 
1297 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'1296 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1297 ······-·'"grub2-common"·in·ansible_facts.packages'
1298 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1298 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1299 ······tags:1299 ······tags:
1300 ······-·CJIS-5.5.2.21300 ······-·CJIS-5.5.2.2
1301 ······-·NIST-800-171-3.4.51301 ······-·NIST-800-171-3.4.5
1302 ······-·NIST-800-53-AC-6(1)1302 ······-·NIST-800-53-AC-6(1)
1303 ······-·NIST-800-53-CM-6(a)1303 ······-·NIST-800-53-CM-6(a)
1304 ······-·PCI-DSS-Req-7.11304 ······-·PCI-DSS-Req-7.1
Offset 1311, 16 lines modifiedOffset 1311, 16 lines modified
1311 ······-·no_reboot_needed1311 ······-·no_reboot_needed
  
1312 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg1312 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
1313 ······file:1313 ······file:
1314 ········path:·/boot/grub2/grub.cfg1314 ········path:·/boot/grub2/grub.cfg
1315 ········owner:·'0'1315 ········owner:·'0'
1316 ······when:1316 ······when:
1317 ······-·'"grub2-common"·in·ansible_facts.packages' 
1318 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'1317 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1318 ······-·'"grub2-common"·in·ansible_facts.packages'
1319 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1319 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1320 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1320 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1321 ······tags:1321 ······tags:
1322 ······-·CJIS-5.5.2.21322 ······-·CJIS-5.5.2.2
1323 ······-·NIST-800-171-3.4.51323 ······-·NIST-800-171-3.4.5
1324 ······-·NIST-800-53-AC-6(1)1324 ······-·NIST-800-53-AC-6(1)
1325 ······-·NIST-800-53-CM-6(a)1325 ······-·NIST-800-53-CM-6(a)
Offset 1348, 16 lines modifiedOffset 1348, 16 lines modified
1348 ······-·no_reboot_needed1348 ······-·no_reboot_needed
  
1349 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg1349 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
1350 ······stat:1350 ······stat:
1351 ········path:·/boot/grub2/grub.cfg1351 ········path:·/boot/grub2/grub.cfg
1352 ······register:·file_exists1352 ······register:·file_exists
1353 ······when:1353 ······when:
1354 ······-·'"grub2-common"·in·ansible_facts.packages' 
1355 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'1354 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1355 ······-·'"grub2-common"·in·ansible_facts.packages'
1356 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1356 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1357 ······tags:1357 ······tags:
1358 ······-·NIST-800-171-3.4.51358 ······-·NIST-800-171-3.4.5
1359 ······-·NIST-800-53-AC-6(1)1359 ······-·NIST-800-53-AC-6(1)
1360 ······-·NIST-800-53-CM-6(a)1360 ······-·NIST-800-53-CM-6(a)
1361 ······-·configure_strategy1361 ······-·configure_strategy
1362 ······-·file_permissions_efi_grub2_cfg1362 ······-·file_permissions_efi_grub2_cfg
Offset 1367, 16 lines modifiedOffset 1367, 16 lines modified
1367 ······-·no_reboot_needed1367 ······-·no_reboot_needed
  
1368 ····-·name:·Ensure·permission·u-s,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg1368 ····-·name:·Ensure·permission·u-s,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg
1369 ······file:1369 ······file:
1370 ········path:·/boot/grub2/grub.cfg1370 ········path:·/boot/grub2/grub.cfg
1371 ········mode:·u-s,g-xwrs,o-xwrt1371 ········mode:·u-s,g-xwrs,o-xwrt
1372 ······when:1372 ······when:
1373 ······-·'"grub2-common"·in·ansible_facts.packages' 
1374 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'1373 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
 1374 ······-·'"grub2-common"·in·ansible_facts.packages'
1375 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1375 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1376 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1376 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1377 ······tags:1377 ······tags:
1378 ······-·NIST-800-171-3.4.51378 ······-·NIST-800-171-3.4.5
1379 ······-·NIST-800-53-AC-6(1)1379 ······-·NIST-800-53-AC-6(1)
1380 ······-·NIST-800-53-CM-6(a)1380 ······-·NIST-800-53-CM-6(a)
1381 ······-·configure_strategy1381 ······-·configure_strategy
28.3 KB
./usr/share/scap-security-guide/ansible/alinux3-playbook-cis.yml
Ordering differences only
    
Offset 1115, 16 lines modifiedOffset 1115, 16 lines modified
  
1115 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1115 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1116 ······find:1116 ······find:
1117 ········paths:·/etc/audit/rules.d/1117 ········paths:·/etc/audit/rules.d/
1118 ········patterns:·'*.rules'1118 ········patterns:·'*.rules'
1119 ······register:·find_rules_d1119 ······register:·find_rules_d
1120 ······when:1120 ······when:
1121 ······-·'"audit"·in·ansible_facts.packages' 
1122 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1121 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1122 ······-·'"audit"·in·ansible_facts.packages'
1123 ······tags:1123 ······tags:
1124 ······-·CJIS-5.4.1.11124 ······-·CJIS-5.4.1.1
1125 ······-·NIST-800-171-3.3.11125 ······-·NIST-800-171-3.3.1
1126 ······-·NIST-800-171-3.4.31126 ······-·NIST-800-171-3.4.3
1127 ······-·NIST-800-53-AC-6(9)1127 ······-·NIST-800-53-AC-6(9)
1128 ······-·NIST-800-53-CM-6(a)1128 ······-·NIST-800-53-CM-6(a)
1129 ······-·PCI-DSS-Req-10.5.21129 ······-·PCI-DSS-Req-10.5.2
Offset 1139, 16 lines modifiedOffset 1139, 16 lines modified
1139 ······lineinfile:1139 ······lineinfile:
1140 ········path:·'{{·item·}}'1140 ········path:·'{{·item·}}'
1141 ········regexp:·^\s*(?:-e)\s+.*$1141 ········regexp:·^\s*(?:-e)\s+.*$
1142 ········state:·absent1142 ········state:·absent
1143 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1143 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1144 ········}}'1144 ········}}'
1145 ······when:1145 ······when:
1146 ······-·'"audit"·in·ansible_facts.packages' 
1147 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1146 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1147 ······-·'"audit"·in·ansible_facts.packages'
1148 ······tags:1148 ······tags:
1149 ······-·CJIS-5.4.1.11149 ······-·CJIS-5.4.1.1
1150 ······-·NIST-800-171-3.3.11150 ······-·NIST-800-171-3.3.1
1151 ······-·NIST-800-171-3.4.31151 ······-·NIST-800-171-3.4.3
1152 ······-·NIST-800-53-AC-6(9)1152 ······-·NIST-800-53-AC-6(9)
1153 ······-·NIST-800-53-CM-6(a)1153 ······-·NIST-800-53-CM-6(a)
1154 ······-·PCI-DSS-Req-10.5.21154 ······-·PCI-DSS-Req-10.5.2
Offset 1165, 16 lines modifiedOffset 1165, 16 lines modified
1165 ········create:·true1165 ········create:·true
1166 ········line:·-e·21166 ········line:·-e·2
1167 ········mode:·o-rwx1167 ········mode:·o-rwx
1168 ······loop:1168 ······loop:
1169 ······-·/etc/audit/audit.rules1169 ······-·/etc/audit/audit.rules
1170 ······-·/etc/audit/rules.d/immutable.rules1170 ······-·/etc/audit/rules.d/immutable.rules
1171 ······when:1171 ······when:
1172 ······-·'"audit"·in·ansible_facts.packages' 
1173 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1172 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1173 ······-·'"audit"·in·ansible_facts.packages'
1174 ······tags:1174 ······tags:
1175 ······-·CJIS-5.4.1.11175 ······-·CJIS-5.4.1.1
1176 ······-·NIST-800-171-3.3.11176 ······-·NIST-800-171-3.3.1
1177 ······-·NIST-800-171-3.4.31177 ······-·NIST-800-171-3.4.3
1178 ······-·NIST-800-53-AC-6(9)1178 ······-·NIST-800-53-AC-6(9)
1179 ······-·NIST-800-53-CM-6(a)1179 ······-·NIST-800-53-CM-6(a)
1180 ······-·PCI-DSS-Req-10.5.21180 ······-·PCI-DSS-Req-10.5.2
Offset 1209, 16 lines modifiedOffset 1209, 16 lines modified
1209 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/1209 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
1210 ······find:1210 ······find:
1211 ········paths:·/etc/audit/rules.d1211 ········paths:·/etc/audit/rules.d
1212 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+1212 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
1213 ········patterns:·'*.rules'1213 ········patterns:·'*.rules'
1214 ······register:·find_existing_watch_rules_d1214 ······register:·find_existing_watch_rules_d
1215 ······when:1215 ······when:
1216 ······-·'"audit"·in·ansible_facts.packages' 
1217 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1216 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1217 ······-·'"audit"·in·ansible_facts.packages'
1218 ······tags:1218 ······tags:
1219 ······-·CJIS-5.4.1.11219 ······-·CJIS-5.4.1.1
1220 ······-·NIST-800-171-3.1.71220 ······-·NIST-800-171-3.1.7
1221 ······-·NIST-800-53-AC-2(7)(b)1221 ······-·NIST-800-53-AC-2(7)(b)
1222 ······-·NIST-800-53-AC-6(9)1222 ······-·NIST-800-53-AC-6(9)
1223 ······-·NIST-800-53-AU-12(c)1223 ······-·NIST-800-53-AU-12(c)
1224 ······-·NIST-800-53-AU-2(d)1224 ······-·NIST-800-53-AU-2(d)
Offset 1235, 16 lines modifiedOffset 1235, 16 lines modified
1235 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions1235 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
1236 ······find:1236 ······find:
1237 ········paths:·/etc/audit/rules.d1237 ········paths:·/etc/audit/rules.d
1238 ········contains:·^.*(?:-F·key=|-k\s+)actions$1238 ········contains:·^.*(?:-F·key=|-k\s+)actions$
1239 ········patterns:·'*.rules'1239 ········patterns:·'*.rules'
1240 ······register:·find_watch_key1240 ······register:·find_watch_key
1241 ······when:1241 ······when:
1242 ······-·'"audit"·in·ansible_facts.packages' 
1243 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1242 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1243 ······-·'"audit"·in·ansible_facts.packages'
1244 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1244 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1245 ········==·01245 ········==·0
1246 ······tags:1246 ······tags:
1247 ······-·CJIS-5.4.1.11247 ······-·CJIS-5.4.1.1
1248 ······-·NIST-800-171-3.1.71248 ······-·NIST-800-171-3.1.7
1249 ······-·NIST-800-53-AC-2(7)(b)1249 ······-·NIST-800-53-AC-2(7)(b)
1250 ······-·NIST-800-53-AC-6(9)1250 ······-·NIST-800-53-AC-6(9)
Offset 1261, 16 lines modifiedOffset 1261, 16 lines modified
1261 ······-·restrict_strategy1261 ······-·restrict_strategy
  
1262 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule1262 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule
1263 ······set_fact:1263 ······set_fact:
1264 ········all_files:1264 ········all_files:
1265 ········-·/etc/audit/rules.d/actions.rules1265 ········-·/etc/audit/rules.d/actions.rules
1266 ······when:1266 ······when:
1267 ······-·'"audit"·in·ansible_facts.packages' 
1268 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1267 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1268 ······-·'"audit"·in·ansible_facts.packages'
1269 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1269 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1270 ········is·defined·and·find_existing_watch_rules_d.matched·==·01270 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1271 ······tags:1271 ······tags:
1272 ······-·CJIS-5.4.1.11272 ······-·CJIS-5.4.1.1
1273 ······-·NIST-800-171-3.1.71273 ······-·NIST-800-171-3.1.7
1274 ······-·NIST-800-53-AC-2(7)(b)1274 ······-·NIST-800-53-AC-2(7)(b)
1275 ······-·NIST-800-53-AC-6(9)1275 ······-·NIST-800-53-AC-6(9)
Offset 1287, 16 lines modifiedOffset 1287, 16 lines modified
1287 ······-·restrict_strategy1287 ······-·restrict_strategy
  
1288 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1288 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1289 ······set_fact:1289 ······set_fact:
1290 ········all_files:1290 ········all_files:
1291 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1291 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1292 ······when:1292 ······when:
1293 ······-·'"audit"·in·ansible_facts.packages' 
1294 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1293 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1294 ······-·'"audit"·in·ansible_facts.packages'
1295 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1295 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1296 ········is·defined·and·find_existing_watch_rules_d.matched·==·01296 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1297 ······tags:1297 ······tags:
1298 ······-·CJIS-5.4.1.11298 ······-·CJIS-5.4.1.1
1299 ······-·NIST-800-171-3.1.71299 ······-·NIST-800-171-3.1.7
1300 ······-·NIST-800-53-AC-2(7)(b)1300 ······-·NIST-800-53-AC-2(7)(b)
1301 ······-·NIST-800-53-AC-6(9)1301 ······-·NIST-800-53-AC-6(9)
Offset 1315, 16 lines modifiedOffset 1315, 16 lines modified
1315 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/1315 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/
Max diff block lines reached; 24116/28796 bytes (83.75%) of diff not shown.
7.95 KB
./usr/share/scap-security-guide/ansible/alinux3-playbook-cis_l1.yml
Ordering differences only
    
Offset 1025, 16 lines modifiedOffset 1025, 16 lines modified
1025 ······-·no_reboot_needed1025 ······-·no_reboot_needed
  
1026 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg1026 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
1027 ······stat:1027 ······stat:
1028 ········path:·/boot/grub2/grub.cfg1028 ········path:·/boot/grub2/grub.cfg
1029 ······register:·file_exists1029 ······register:·file_exists
1030 ······when:1030 ······when:
1031 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
1032 ······-·'"grub2-common"·in·ansible_facts.packages'1031 ······-·'"grub2-common"·in·ansible_facts.packages'
 1032 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
1033 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1033 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1034 ······tags:1034 ······tags:
1035 ······-·CJIS-5.5.2.21035 ······-·CJIS-5.5.2.2
1036 ······-·NIST-800-171-3.4.51036 ······-·NIST-800-171-3.4.5
1037 ······-·NIST-800-53-AC-6(1)1037 ······-·NIST-800-53-AC-6(1)
1038 ······-·NIST-800-53-CM-6(a)1038 ······-·NIST-800-53-CM-6(a)
1039 ······-·PCI-DSS-Req-7.11039 ······-·PCI-DSS-Req-7.1
Offset 1046, 16 lines modifiedOffset 1046, 16 lines modified
1046 ······-·no_reboot_needed1046 ······-·no_reboot_needed
  
1047 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg1047 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
1048 ······file:1048 ······file:
1049 ········path:·/boot/grub2/grub.cfg1049 ········path:·/boot/grub2/grub.cfg
1050 ········group:·'0'1050 ········group:·'0'
1051 ······when:1051 ······when:
1052 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
1053 ······-·'"grub2-common"·in·ansible_facts.packages'1052 ······-·'"grub2-common"·in·ansible_facts.packages'
 1053 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
1054 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1054 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1055 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1055 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1056 ······tags:1056 ······tags:
1057 ······-·CJIS-5.5.2.21057 ······-·CJIS-5.5.2.2
1058 ······-·NIST-800-171-3.4.51058 ······-·NIST-800-171-3.4.5
1059 ······-·NIST-800-53-AC-6(1)1059 ······-·NIST-800-53-AC-6(1)
1060 ······-·NIST-800-53-CM-6(a)1060 ······-·NIST-800-53-CM-6(a)
Offset 1085, 16 lines modifiedOffset 1085, 16 lines modified
1085 ······-·no_reboot_needed1085 ······-·no_reboot_needed
  
1086 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg1086 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
1087 ······stat:1087 ······stat:
1088 ········path:·/boot/grub2/grub.cfg1088 ········path:·/boot/grub2/grub.cfg
1089 ······register:·file_exists1089 ······register:·file_exists
1090 ······when:1090 ······when:
1091 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
1092 ······-·'"grub2-common"·in·ansible_facts.packages'1091 ······-·'"grub2-common"·in·ansible_facts.packages'
 1092 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
1093 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1093 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1094 ······tags:1094 ······tags:
1095 ······-·CJIS-5.5.2.21095 ······-·CJIS-5.5.2.2
1096 ······-·NIST-800-171-3.4.51096 ······-·NIST-800-171-3.4.5
1097 ······-·NIST-800-53-AC-6(1)1097 ······-·NIST-800-53-AC-6(1)
1098 ······-·NIST-800-53-CM-6(a)1098 ······-·NIST-800-53-CM-6(a)
1099 ······-·PCI-DSS-Req-7.11099 ······-·PCI-DSS-Req-7.1
Offset 1106, 16 lines modifiedOffset 1106, 16 lines modified
1106 ······-·no_reboot_needed1106 ······-·no_reboot_needed
  
1107 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg1107 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
1108 ······file:1108 ······file:
1109 ········path:·/boot/grub2/grub.cfg1109 ········path:·/boot/grub2/grub.cfg
1110 ········owner:·'0'1110 ········owner:·'0'
1111 ······when:1111 ······when:
1112 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
1113 ······-·'"grub2-common"·in·ansible_facts.packages'1112 ······-·'"grub2-common"·in·ansible_facts.packages'
 1113 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
1114 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1114 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1115 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1115 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1116 ······tags:1116 ······tags:
1117 ······-·CJIS-5.5.2.21117 ······-·CJIS-5.5.2.2
1118 ······-·NIST-800-171-3.4.51118 ······-·NIST-800-171-3.4.5
1119 ······-·NIST-800-53-AC-6(1)1119 ······-·NIST-800-53-AC-6(1)
1120 ······-·NIST-800-53-CM-6(a)1120 ······-·NIST-800-53-CM-6(a)
Offset 1143, 16 lines modifiedOffset 1143, 16 lines modified
1143 ······-·no_reboot_needed1143 ······-·no_reboot_needed
  
1144 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg1144 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
1145 ······stat:1145 ······stat:
1146 ········path:·/boot/grub2/grub.cfg1146 ········path:·/boot/grub2/grub.cfg
1147 ······register:·file_exists1147 ······register:·file_exists
1148 ······when:1148 ······when:
1149 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
1150 ······-·'"grub2-common"·in·ansible_facts.packages'1149 ······-·'"grub2-common"·in·ansible_facts.packages'
 1150 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
1151 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1151 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1152 ······tags:1152 ······tags:
1153 ······-·NIST-800-171-3.4.51153 ······-·NIST-800-171-3.4.5
1154 ······-·NIST-800-53-AC-6(1)1154 ······-·NIST-800-53-AC-6(1)
1155 ······-·NIST-800-53-CM-6(a)1155 ······-·NIST-800-53-CM-6(a)
1156 ······-·configure_strategy1156 ······-·configure_strategy
1157 ······-·file_permissions_grub2_cfg1157 ······-·file_permissions_grub2_cfg
Offset 1162, 16 lines modifiedOffset 1162, 16 lines modified
1162 ······-·no_reboot_needed1162 ······-·no_reboot_needed
  
1163 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg1163 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg
1164 ······file:1164 ······file:
1165 ········path:·/boot/grub2/grub.cfg1165 ········path:·/boot/grub2/grub.cfg
1166 ········mode:·u-xs,g-xwrs,o-xwrt1166 ········mode:·u-xs,g-xwrs,o-xwrt
1167 ······when:1167 ······when:
1168 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
1169 ······-·'"grub2-common"·in·ansible_facts.packages'1168 ······-·'"grub2-common"·in·ansible_facts.packages'
 1169 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
1170 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1170 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1171 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists1171 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
1172 ······tags:1172 ······tags:
1173 ······-·NIST-800-171-3.4.51173 ······-·NIST-800-171-3.4.5
1174 ······-·NIST-800-53-AC-6(1)1174 ······-·NIST-800-53-AC-6(1)
1175 ······-·NIST-800-53-CM-6(a)1175 ······-·NIST-800-53-CM-6(a)
1176 ······-·configure_strategy1176 ······-·configure_strategy
Offset 1199, 16 lines modifiedOffset 1199, 16 lines modified
1199 ······-·no_reboot_needed1199 ······-·no_reboot_needed
  
1200 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg1200 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
1201 ······stat:1201 ······stat:
1202 ········path:·/boot/grub2/grub.cfg1202 ········path:·/boot/grub2/grub.cfg
1203 ······register:·file_exists1203 ······register:·file_exists
1204 ······when:1204 ······when:
1205 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list' 
1206 ······-·'"grub2-common"·in·ansible_facts.packages'1205 ······-·'"grub2-common"·in·ansible_facts.packages'
 1206 ······-·'"/boot/efi"·in·ansible_mounts·|·map(attribute="mount")·|·list'
1207 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1207 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1208 ······tags:1208 ······tags:
1209 ······-·CJIS-5.5.2.21209 ······-·CJIS-5.5.2.2
1210 ······-·NIST-800-171-3.4.51210 ······-·NIST-800-171-3.4.5
1211 ······-·NIST-800-53-AC-6(1)1211 ······-·NIST-800-53-AC-6(1)
1212 ······-·NIST-800-53-CM-6(a)1212 ······-·NIST-800-53-CM-6(a)
1213 ······-·PCI-DSS-Req-7.11213 ······-·PCI-DSS-Req-7.1
Offset 1220, 16 lines modifiedOffset 1220, 16 lines modified
1220 ······-·no_reboot_needed1220 ······-·no_reboot_needed
Max diff block lines reached; 3280/7980 bytes (41.10%) of diff not shown.
109 KB
./usr/share/scap-security-guide/ansible/centos7-playbook-pci-dss.yml
Ordering differences only
    
Offset 4494, 16 lines modifiedOffset 4494, 16 lines modified
  
4494 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension4494 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
4495 ······find:4495 ······find:
4496 ········paths:·/etc/audit/rules.d/4496 ········paths:·/etc/audit/rules.d/
4497 ········patterns:·'*.rules'4497 ········patterns:·'*.rules'
4498 ······register:·find_rules_d4498 ······register:·find_rules_d
4499 ······when:4499 ······when:
4500 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4501 ······-·'"audit"·in·ansible_facts.packages'4500 ······-·'"audit"·in·ansible_facts.packages'
 4501 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4502 ······tags:4502 ······tags:
4503 ······-·CJIS-5.4.1.14503 ······-·CJIS-5.4.1.1
4504 ······-·NIST-800-171-3.3.14504 ······-·NIST-800-171-3.3.1
4505 ······-·NIST-800-171-3.4.34505 ······-·NIST-800-171-3.4.3
4506 ······-·NIST-800-53-AC-6(9)4506 ······-·NIST-800-53-AC-6(9)
4507 ······-·NIST-800-53-CM-6(a)4507 ······-·NIST-800-53-CM-6(a)
4508 ······-·PCI-DSS-Req-10.5.24508 ······-·PCI-DSS-Req-10.5.2
Offset 4518, 16 lines modifiedOffset 4518, 16 lines modified
4518 ······lineinfile:4518 ······lineinfile:
4519 ········path:·'{{·item·}}'4519 ········path:·'{{·item·}}'
4520 ········regexp:·^\s*(?:-e)\s+.*$4520 ········regexp:·^\s*(?:-e)\s+.*$
4521 ········state:·absent4521 ········state:·absent
4522 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']4522 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
4523 ········}}'4523 ········}}'
4524 ······when:4524 ······when:
4525 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4526 ······-·'"audit"·in·ansible_facts.packages'4525 ······-·'"audit"·in·ansible_facts.packages'
 4526 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4527 ······tags:4527 ······tags:
4528 ······-·CJIS-5.4.1.14528 ······-·CJIS-5.4.1.1
4529 ······-·NIST-800-171-3.3.14529 ······-·NIST-800-171-3.3.1
4530 ······-·NIST-800-171-3.4.34530 ······-·NIST-800-171-3.4.3
4531 ······-·NIST-800-53-AC-6(9)4531 ······-·NIST-800-53-AC-6(9)
4532 ······-·NIST-800-53-CM-6(a)4532 ······-·NIST-800-53-CM-6(a)
4533 ······-·PCI-DSS-Req-10.5.24533 ······-·PCI-DSS-Req-10.5.2
Offset 4544, 16 lines modifiedOffset 4544, 16 lines modified
4544 ········create:·true4544 ········create:·true
4545 ········line:·-e·24545 ········line:·-e·2
4546 ········mode:·o-rwx4546 ········mode:·o-rwx
4547 ······loop:4547 ······loop:
4548 ······-·/etc/audit/audit.rules4548 ······-·/etc/audit/audit.rules
4549 ······-·/etc/audit/rules.d/immutable.rules4549 ······-·/etc/audit/rules.d/immutable.rules
4550 ······when:4550 ······when:
4551 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4552 ······-·'"audit"·in·ansible_facts.packages'4551 ······-·'"audit"·in·ansible_facts.packages'
 4552 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4553 ······tags:4553 ······tags:
4554 ······-·CJIS-5.4.1.14554 ······-·CJIS-5.4.1.1
4555 ······-·NIST-800-171-3.3.14555 ······-·NIST-800-171-3.3.1
4556 ······-·NIST-800-171-3.4.34556 ······-·NIST-800-171-3.4.3
4557 ······-·NIST-800-53-AC-6(9)4557 ······-·NIST-800-53-AC-6(9)
4558 ······-·NIST-800-53-CM-6(a)4558 ······-·NIST-800-53-CM-6(a)
4559 ······-·PCI-DSS-Req-10.5.24559 ······-·PCI-DSS-Req-10.5.2
Offset 4585, 16 lines modifiedOffset 4585, 16 lines modified
4585 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/4585 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
4586 ······find:4586 ······find:
4587 ········paths:·/etc/audit/rules.d4587 ········paths:·/etc/audit/rules.d
4588 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+4588 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
4589 ········patterns:·'*.rules'4589 ········patterns:·'*.rules'
4590 ······register:·find_existing_watch_rules_d4590 ······register:·find_existing_watch_rules_d
4591 ······when:4591 ······when:
4592 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4593 ······-·'"audit"·in·ansible_facts.packages'4592 ······-·'"audit"·in·ansible_facts.packages'
 4593 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4594 ······tags:4594 ······tags:
4595 ······-·CJIS-5.4.1.14595 ······-·CJIS-5.4.1.1
4596 ······-·NIST-800-171-3.1.84596 ······-·NIST-800-171-3.1.8
4597 ······-·NIST-800-53-AU-12(c)4597 ······-·NIST-800-53-AU-12(c)
4598 ······-·NIST-800-53-AU-2(d)4598 ······-·NIST-800-53-AU-2(d)
4599 ······-·NIST-800-53-CM-6(a)4599 ······-·NIST-800-53-CM-6(a)
4600 ······-·PCI-DSS-Req-10.5.54600 ······-·PCI-DSS-Req-10.5.5
Offset 4608, 16 lines modifiedOffset 4608, 16 lines modified
4608 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy4608 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
4609 ······find:4609 ······find:
4610 ········paths:·/etc/audit/rules.d4610 ········paths:·/etc/audit/rules.d
4611 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$4611 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
4612 ········patterns:·'*.rules'4612 ········patterns:·'*.rules'
4613 ······register:·find_watch_key4613 ······register:·find_watch_key
4614 ······when:4614 ······when:
4615 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4616 ······-·'"audit"·in·ansible_facts.packages'4615 ······-·'"audit"·in·ansible_facts.packages'
 4616 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4617 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4617 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4618 ········==·04618 ········==·0
4619 ······tags:4619 ······tags:
4620 ······-·CJIS-5.4.1.14620 ······-·CJIS-5.4.1.1
4621 ······-·NIST-800-171-3.1.84621 ······-·NIST-800-171-3.1.8
4622 ······-·NIST-800-53-AU-12(c)4622 ······-·NIST-800-53-AU-12(c)
4623 ······-·NIST-800-53-AU-2(d)4623 ······-·NIST-800-53-AU-2(d)
Offset 4631, 16 lines modifiedOffset 4631, 16 lines modified
4631 ······-·restrict_strategy4631 ······-·restrict_strategy
  
4632 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule4632 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
4633 ······set_fact:4633 ······set_fact:
4634 ········all_files:4634 ········all_files:
4635 ········-·/etc/audit/rules.d/MAC-policy.rules4635 ········-·/etc/audit/rules.d/MAC-policy.rules
4636 ······when:4636 ······when:
4637 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4638 ······-·'"audit"·in·ansible_facts.packages'4637 ······-·'"audit"·in·ansible_facts.packages'
 4638 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4639 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched4639 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
4640 ········is·defined·and·find_existing_watch_rules_d.matched·==·04640 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4641 ······tags:4641 ······tags:
4642 ······-·CJIS-5.4.1.14642 ······-·CJIS-5.4.1.1
4643 ······-·NIST-800-171-3.1.84643 ······-·NIST-800-171-3.1.8
4644 ······-·NIST-800-53-AU-12(c)4644 ······-·NIST-800-53-AU-12(c)
4645 ······-·NIST-800-53-AU-2(d)4645 ······-·NIST-800-53-AU-2(d)
Offset 4654, 16 lines modifiedOffset 4654, 16 lines modified
4654 ······-·restrict_strategy4654 ······-·restrict_strategy
  
4655 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule4655 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
4656 ······set_fact:4656 ······set_fact:
4657 ········all_files:4657 ········all_files:
4658 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'4658 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
4659 ······when:4659 ······when:
4660 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4661 ······-·'"audit"·in·ansible_facts.packages'4660 ······-·'"audit"·in·ansible_facts.packages'
 4661 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4662 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched4662 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
4663 ········is·defined·and·find_existing_watch_rules_d.matched·==·04663 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4664 ······tags:4664 ······tags:
4665 ······-·CJIS-5.4.1.14665 ······-·CJIS-5.4.1.1
4666 ······-·NIST-800-171-3.1.84666 ······-·NIST-800-171-3.1.8
4667 ······-·NIST-800-53-AU-12(c)4667 ······-·NIST-800-53-AU-12(c)
4668 ······-·NIST-800-53-AU-2(d)4668 ······-·NIST-800-53-AU-2(d)
Offset 4679, 16 lines modifiedOffset 4679, 16 lines modified
4679 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/4679 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 106634/111669 bytes (95.49%) of diff not shown.
85.0 KB
./usr/share/scap-security-guide/ansible/centos7-playbook-standard.yml
Ordering differences only
    
Offset 644, 16 lines modifiedOffset 644, 16 lines modified
644 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/644 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
645 ······find:645 ······find:
646 ········paths:·/etc/audit/rules.d646 ········paths:·/etc/audit/rules.d
647 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+647 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
648 ········patterns:·'*.rules'648 ········patterns:·'*.rules'
649 ······register:·find_existing_watch_rules_d649 ······register:·find_existing_watch_rules_d
650 ······when:650 ······when:
651 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
652 ······-·'"audit"·in·ansible_facts.packages'651 ······-·'"audit"·in·ansible_facts.packages'
 652 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
653 ······tags:653 ······tags:
654 ······-·CJIS-5.4.1.1654 ······-·CJIS-5.4.1.1
655 ······-·NIST-800-171-3.1.8655 ······-·NIST-800-171-3.1.8
656 ······-·NIST-800-53-AU-12(c)656 ······-·NIST-800-53-AU-12(c)
657 ······-·NIST-800-53-AU-2(d)657 ······-·NIST-800-53-AU-2(d)
658 ······-·NIST-800-53-CM-6(a)658 ······-·NIST-800-53-CM-6(a)
659 ······-·PCI-DSS-Req-10.5.5659 ······-·PCI-DSS-Req-10.5.5
Offset 667, 16 lines modifiedOffset 667, 16 lines modified
667 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy667 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
668 ······find:668 ······find:
669 ········paths:·/etc/audit/rules.d669 ········paths:·/etc/audit/rules.d
670 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$670 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
671 ········patterns:·'*.rules'671 ········patterns:·'*.rules'
672 ······register:·find_watch_key672 ······register:·find_watch_key
673 ······when:673 ······when:
674 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
675 ······-·'"audit"·in·ansible_facts.packages'674 ······-·'"audit"·in·ansible_facts.packages'
 675 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
676 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched676 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
677 ········==·0677 ········==·0
678 ······tags:678 ······tags:
679 ······-·CJIS-5.4.1.1679 ······-·CJIS-5.4.1.1
680 ······-·NIST-800-171-3.1.8680 ······-·NIST-800-171-3.1.8
681 ······-·NIST-800-53-AU-12(c)681 ······-·NIST-800-53-AU-12(c)
682 ······-·NIST-800-53-AU-2(d)682 ······-·NIST-800-53-AU-2(d)
Offset 690, 16 lines modifiedOffset 690, 16 lines modified
690 ······-·restrict_strategy690 ······-·restrict_strategy
  
691 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule691 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
692 ······set_fact:692 ······set_fact:
693 ········all_files:693 ········all_files:
694 ········-·/etc/audit/rules.d/MAC-policy.rules694 ········-·/etc/audit/rules.d/MAC-policy.rules
695 ······when:695 ······when:
696 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
697 ······-·'"audit"·in·ansible_facts.packages'696 ······-·'"audit"·in·ansible_facts.packages'
 697 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
698 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched698 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
699 ········is·defined·and·find_existing_watch_rules_d.matched·==·0699 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
700 ······tags:700 ······tags:
701 ······-·CJIS-5.4.1.1701 ······-·CJIS-5.4.1.1
702 ······-·NIST-800-171-3.1.8702 ······-·NIST-800-171-3.1.8
703 ······-·NIST-800-53-AU-12(c)703 ······-·NIST-800-53-AU-12(c)
704 ······-·NIST-800-53-AU-2(d)704 ······-·NIST-800-53-AU-2(d)
Offset 713, 16 lines modifiedOffset 713, 16 lines modified
713 ······-·restrict_strategy713 ······-·restrict_strategy
  
714 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule714 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
715 ······set_fact:715 ······set_fact:
716 ········all_files:716 ········all_files:
717 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'717 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
718 ······when:718 ······when:
719 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
720 ······-·'"audit"·in·ansible_facts.packages'719 ······-·'"audit"·in·ansible_facts.packages'
 720 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
721 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched721 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
722 ········is·defined·and·find_existing_watch_rules_d.matched·==·0722 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
723 ······tags:723 ······tags:
724 ······-·CJIS-5.4.1.1724 ······-·CJIS-5.4.1.1
725 ······-·NIST-800-171-3.1.8725 ······-·NIST-800-171-3.1.8
726 ······-·NIST-800-53-AU-12(c)726 ······-·NIST-800-53-AU-12(c)
727 ······-·NIST-800-53-AU-2(d)727 ······-·NIST-800-53-AU-2(d)
Offset 738, 16 lines modifiedOffset 738, 16 lines modified
738 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/738 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
739 ······lineinfile:739 ······lineinfile:
740 ········path:·'{{·all_files[0]·}}'740 ········path:·'{{·all_files[0]·}}'
741 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy741 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
742 ········create:·true742 ········create:·true
743 ········mode:·'0640'743 ········mode:·'0640'
744 ······when:744 ······when:
745 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
746 ······-·'"audit"·in·ansible_facts.packages'745 ······-·'"audit"·in·ansible_facts.packages'
 746 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
747 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched747 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
748 ········==·0748 ········==·0
749 ······tags:749 ······tags:
750 ······-·CJIS-5.4.1.1750 ······-·CJIS-5.4.1.1
751 ······-·NIST-800-171-3.1.8751 ······-·NIST-800-171-3.1.8
752 ······-·NIST-800-53-AU-12(c)752 ······-·NIST-800-53-AU-12(c)
753 ······-·NIST-800-53-AU-2(d)753 ······-·NIST-800-53-AU-2(d)
Offset 763, 16 lines modifiedOffset 763, 16 lines modified
763 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules763 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules
764 ······find:764 ······find:
765 ········paths:·/etc/audit/765 ········paths:·/etc/audit/
766 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+766 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
767 ········patterns:·audit.rules767 ········patterns:·audit.rules
768 ······register:·find_existing_watch_audit_rules768 ······register:·find_existing_watch_audit_rules
769 ······when:769 ······when:
770 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
771 ······-·'"audit"·in·ansible_facts.packages'770 ······-·'"audit"·in·ansible_facts.packages'
 771 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
772 ······tags:772 ······tags:
773 ······-·CJIS-5.4.1.1773 ······-·CJIS-5.4.1.1
774 ······-·NIST-800-171-3.1.8774 ······-·NIST-800-171-3.1.8
775 ······-·NIST-800-53-AU-12(c)775 ······-·NIST-800-53-AU-12(c)
776 ······-·NIST-800-53-AU-2(d)776 ······-·NIST-800-53-AU-2(d)
777 ······-·NIST-800-53-CM-6(a)777 ······-·NIST-800-53-CM-6(a)
778 ······-·PCI-DSS-Req-10.5.5778 ······-·PCI-DSS-Req-10.5.5
Offset 787, 16 lines modifiedOffset 787, 16 lines modified
787 ······lineinfile:787 ······lineinfile:
788 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy788 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
789 ········state:·present789 ········state:·present
790 ········dest:·/etc/audit/audit.rules790 ········dest:·/etc/audit/audit.rules
791 ········create:·true791 ········create:·true
792 ········mode:·'0640'792 ········mode:·'0640'
793 ······when:793 ······when:
794 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
795 ······-·'"audit"·in·ansible_facts.packages'794 ······-·'"audit"·in·ansible_facts.packages'
 795 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
796 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched796 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
797 ········==·0797 ········==·0
798 ······tags:798 ······tags:
799 ······-·CJIS-5.4.1.1799 ······-·CJIS-5.4.1.1
800 ······-·NIST-800-171-3.1.8800 ······-·NIST-800-171-3.1.8
801 ······-·NIST-800-53-AU-12(c)801 ······-·NIST-800-53-AU-12(c)
802 ······-·NIST-800-53-AU-2(d)802 ······-·NIST-800-53-AU-2(d)
Offset 829, 16 lines modifiedOffset 829, 16 lines modified
829 ······-·reboot_required829 ······-·reboot_required
Max diff block lines reached; 81679/86895 bytes (94.00%) of diff not shown.
866 B
./usr/share/scap-security-guide/ansible/centos8-playbook-anssi_bp28_enhanced.yml
Ordering differences only
    
Offset 5628, 16 lines modifiedOffset 5628, 16 lines modified
5628 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5628 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5629 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5629 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5630 ··········create:·true5630 ··········create:·true
5631 ··········mode:·o-rwx5631 ··········mode:·o-rwx
5632 ··········state:·present5632 ··········state:·present
5633 ········when:·syscalls_found·|·length·==·05633 ········when:·syscalls_found·|·length·==·0
5634 ······when:5634 ······when:
5635 ······-·'"audit"·in·ansible_facts.packages' 
5636 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5635 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5636 ······-·'"audit"·in·ansible_facts.packages'
5637 ······tags:5637 ······tags:
5638 ······-·DISA-STIG-RHEL-08-0305505638 ······-·DISA-STIG-RHEL-08-030550
5639 ······-·NIST-800-171-3.1.75639 ······-·NIST-800-171-3.1.7
5640 ······-·NIST-800-53-AC-6(9)5640 ······-·NIST-800-53-AC-6(9)
5641 ······-·NIST-800-53-AU-12(c)5641 ······-·NIST-800-53-AU-12(c)
5642 ······-·NIST-800-53-AU-2(d)5642 ······-·NIST-800-53-AU-2(d)
5643 ······-·NIST-800-53-CM-6(a)5643 ······-·NIST-800-53-CM-6(a)
858 B
./usr/share/scap-security-guide/ansible/centos8-playbook-anssi_bp28_high.yml
Ordering differences only
    
Offset 5775, 16 lines modifiedOffset 5775, 16 lines modified
5775 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5775 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5776 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5776 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5777 ··········create:·true5777 ··········create:·true
5778 ··········mode:·o-rwx5778 ··········mode:·o-rwx
5779 ··········state:·present5779 ··········state:·present
5780 ········when:·syscalls_found·|·length·==·05780 ········when:·syscalls_found·|·length·==·0
5781 ······when:5781 ······when:
5782 ······-·'"audit"·in·ansible_facts.packages' 
5783 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5782 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5783 ······-·'"audit"·in·ansible_facts.packages'
5784 ······tags:5784 ······tags:
5785 ······-·DISA-STIG-RHEL-08-0305505785 ······-·DISA-STIG-RHEL-08-030550
5786 ······-·NIST-800-171-3.1.75786 ······-·NIST-800-171-3.1.7
5787 ······-·NIST-800-53-AC-6(9)5787 ······-·NIST-800-53-AC-6(9)
5788 ······-·NIST-800-53-AU-12(c)5788 ······-·NIST-800-53-AU-12(c)
5789 ······-·NIST-800-53-AU-2(d)5789 ······-·NIST-800-53-AU-2(d)
5790 ······-·NIST-800-53-CM-6(a)5790 ······-·NIST-800-53-CM-6(a)
874 B
./usr/share/scap-security-guide/ansible/centos8-playbook-anssi_bp28_intermediary.yml
Ordering differences only
    
Offset 5352, 16 lines modifiedOffset 5352, 16 lines modified
5352 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5352 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5353 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5353 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5354 ··········create:·true5354 ··········create:·true
5355 ··········mode:·o-rwx5355 ··········mode:·o-rwx
5356 ··········state:·present5356 ··········state:·present
5357 ········when:·syscalls_found·|·length·==·05357 ········when:·syscalls_found·|·length·==·0
5358 ······when:5358 ······when:
5359 ······-·'"audit"·in·ansible_facts.packages' 
5360 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5359 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5360 ······-·'"audit"·in·ansible_facts.packages'
5361 ······tags:5361 ······tags:
5362 ······-·DISA-STIG-RHEL-08-0305505362 ······-·DISA-STIG-RHEL-08-030550
5363 ······-·NIST-800-171-3.1.75363 ······-·NIST-800-171-3.1.7
5364 ······-·NIST-800-53-AC-6(9)5364 ······-·NIST-800-53-AC-6(9)
5365 ······-·NIST-800-53-AU-12(c)5365 ······-·NIST-800-53-AU-12(c)
5366 ······-·NIST-800-53-AU-2(d)5366 ······-·NIST-800-53-AU-2(d)
5367 ······-·NIST-800-53-CM-6(a)5367 ······-·NIST-800-53-CM-6(a)
161 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-cis.yml
Ordering differences only
    
Offset 5485, 16 lines modifiedOffset 5485, 16 lines modified
  
5485 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5485 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5486 ······find:5486 ······find:
5487 ········paths:·/etc/audit/rules.d/5487 ········paths:·/etc/audit/rules.d/
5488 ········patterns:·'*.rules'5488 ········patterns:·'*.rules'
5489 ······register:·find_rules_d5489 ······register:·find_rules_d
5490 ······when:5490 ······when:
5491 ······-·'"audit"·in·ansible_facts.packages' 
5492 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5491 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5492 ······-·'"audit"·in·ansible_facts.packages'
5493 ······tags:5493 ······tags:
5494 ······-·CJIS-5.4.1.15494 ······-·CJIS-5.4.1.1
5495 ······-·DISA-STIG-RHEL-08-0301215495 ······-·DISA-STIG-RHEL-08-030121
5496 ······-·NIST-800-171-3.3.15496 ······-·NIST-800-171-3.3.1
5497 ······-·NIST-800-171-3.4.35497 ······-·NIST-800-171-3.4.3
5498 ······-·NIST-800-53-AC-6(9)5498 ······-·NIST-800-53-AC-6(9)
5499 ······-·NIST-800-53-CM-6(a)5499 ······-·NIST-800-53-CM-6(a)
Offset 5510, 16 lines modifiedOffset 5510, 16 lines modified
5510 ······lineinfile:5510 ······lineinfile:
5511 ········path:·'{{·item·}}'5511 ········path:·'{{·item·}}'
5512 ········regexp:·^\s*(?:-e)\s+.*$5512 ········regexp:·^\s*(?:-e)\s+.*$
5513 ········state:·absent5513 ········state:·absent
5514 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5514 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5515 ········}}'5515 ········}}'
5516 ······when:5516 ······when:
5517 ······-·'"audit"·in·ansible_facts.packages' 
5518 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5517 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5518 ······-·'"audit"·in·ansible_facts.packages'
5519 ······tags:5519 ······tags:
5520 ······-·CJIS-5.4.1.15520 ······-·CJIS-5.4.1.1
5521 ······-·DISA-STIG-RHEL-08-0301215521 ······-·DISA-STIG-RHEL-08-030121
5522 ······-·NIST-800-171-3.3.15522 ······-·NIST-800-171-3.3.1
5523 ······-·NIST-800-171-3.4.35523 ······-·NIST-800-171-3.4.3
5524 ······-·NIST-800-53-AC-6(9)5524 ······-·NIST-800-53-AC-6(9)
5525 ······-·NIST-800-53-CM-6(a)5525 ······-·NIST-800-53-CM-6(a)
Offset 5537, 16 lines modifiedOffset 5537, 16 lines modified
5537 ········create:·true5537 ········create:·true
5538 ········line:·-e·25538 ········line:·-e·2
5539 ········mode:·o-rwx5539 ········mode:·o-rwx
5540 ······loop:5540 ······loop:
5541 ······-·/etc/audit/audit.rules5541 ······-·/etc/audit/audit.rules
5542 ······-·/etc/audit/rules.d/immutable.rules5542 ······-·/etc/audit/rules.d/immutable.rules
5543 ······when:5543 ······when:
5544 ······-·'"audit"·in·ansible_facts.packages' 
5545 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5544 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5545 ······-·'"audit"·in·ansible_facts.packages'
5546 ······tags:5546 ······tags:
5547 ······-·CJIS-5.4.1.15547 ······-·CJIS-5.4.1.1
5548 ······-·DISA-STIG-RHEL-08-0301215548 ······-·DISA-STIG-RHEL-08-030121
5549 ······-·NIST-800-171-3.3.15549 ······-·NIST-800-171-3.3.1
5550 ······-·NIST-800-171-3.4.35550 ······-·NIST-800-171-3.4.3
5551 ······-·NIST-800-53-AC-6(9)5551 ······-·NIST-800-53-AC-6(9)
5552 ······-·NIST-800-53-CM-6(a)5552 ······-·NIST-800-53-CM-6(a)
Offset 5579, 16 lines modifiedOffset 5579, 16 lines modified
5579 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5579 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5580 ······find:5580 ······find:
5581 ········paths:·/etc/audit/rules.d5581 ········paths:·/etc/audit/rules.d
5582 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5582 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5583 ········patterns:·'*.rules'5583 ········patterns:·'*.rules'
5584 ······register:·find_existing_watch_rules_d5584 ······register:·find_existing_watch_rules_d
5585 ······when:5585 ······when:
5586 ······-·'"audit"·in·ansible_facts.packages' 
5587 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5586 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5587 ······-·'"audit"·in·ansible_facts.packages'
5588 ······tags:5588 ······tags:
5589 ······-·CJIS-5.4.1.15589 ······-·CJIS-5.4.1.1
5590 ······-·NIST-800-171-3.1.85590 ······-·NIST-800-171-3.1.8
5591 ······-·NIST-800-53-AU-12(c)5591 ······-·NIST-800-53-AU-12(c)
5592 ······-·NIST-800-53-AU-2(d)5592 ······-·NIST-800-53-AU-2(d)
5593 ······-·NIST-800-53-CM-6(a)5593 ······-·NIST-800-53-CM-6(a)
5594 ······-·PCI-DSS-Req-10.5.55594 ······-·PCI-DSS-Req-10.5.5
Offset 5602, 16 lines modifiedOffset 5602, 16 lines modified
5602 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5602 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5603 ······find:5603 ······find:
5604 ········paths:·/etc/audit/rules.d5604 ········paths:·/etc/audit/rules.d
5605 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5605 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5606 ········patterns:·'*.rules'5606 ········patterns:·'*.rules'
5607 ······register:·find_watch_key5607 ······register:·find_watch_key
5608 ······when:5608 ······when:
5609 ······-·'"audit"·in·ansible_facts.packages' 
5610 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5609 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5610 ······-·'"audit"·in·ansible_facts.packages'
5611 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5611 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5612 ········==·05612 ········==·0
5613 ······tags:5613 ······tags:
5614 ······-·CJIS-5.4.1.15614 ······-·CJIS-5.4.1.1
5615 ······-·NIST-800-171-3.1.85615 ······-·NIST-800-171-3.1.8
5616 ······-·NIST-800-53-AU-12(c)5616 ······-·NIST-800-53-AU-12(c)
5617 ······-·NIST-800-53-AU-2(d)5617 ······-·NIST-800-53-AU-2(d)
Offset 5625, 16 lines modifiedOffset 5625, 16 lines modified
5625 ······-·restrict_strategy5625 ······-·restrict_strategy
  
5626 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5626 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5627 ······set_fact:5627 ······set_fact:
5628 ········all_files:5628 ········all_files:
5629 ········-·/etc/audit/rules.d/MAC-policy.rules5629 ········-·/etc/audit/rules.d/MAC-policy.rules
5630 ······when:5630 ······when:
5631 ······-·'"audit"·in·ansible_facts.packages' 
5632 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5631 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5632 ······-·'"audit"·in·ansible_facts.packages'
5633 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5633 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5634 ········is·defined·and·find_existing_watch_rules_d.matched·==·05634 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5635 ······tags:5635 ······tags:
5636 ······-·CJIS-5.4.1.15636 ······-·CJIS-5.4.1.1
5637 ······-·NIST-800-171-3.1.85637 ······-·NIST-800-171-3.1.8
5638 ······-·NIST-800-53-AU-12(c)5638 ······-·NIST-800-53-AU-12(c)
5639 ······-·NIST-800-53-AU-2(d)5639 ······-·NIST-800-53-AU-2(d)
Offset 5648, 16 lines modifiedOffset 5648, 16 lines modified
5648 ······-·restrict_strategy5648 ······-·restrict_strategy
  
5649 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5649 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5650 ······set_fact:5650 ······set_fact:
5651 ········all_files:5651 ········all_files:
5652 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5652 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5653 ······when:5653 ······when:
5654 ······-·'"audit"·in·ansible_facts.packages' 
5655 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5654 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5655 ······-·'"audit"·in·ansible_facts.packages'
5656 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5656 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5657 ········is·defined·and·find_existing_watch_rules_d.matched·==·05657 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5658 ······tags:5658 ······tags:
5659 ······-·CJIS-5.4.1.15659 ······-·CJIS-5.4.1.1
5660 ······-·NIST-800-171-3.1.85660 ······-·NIST-800-171-3.1.8
5661 ······-·NIST-800-53-AU-12(c)5661 ······-·NIST-800-53-AU-12(c)
5662 ······-·NIST-800-53-AU-2(d)5662 ······-·NIST-800-53-AU-2(d)
Offset 5673, 16 lines modifiedOffset 5673, 16 lines modified
5673 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5673 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 159975/164678 bytes (97.14%) of diff not shown.
7.71 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-cis_server_l1.yml
Ordering differences only
    
Offset 5312, 16 lines modifiedOffset 5312, 16 lines modified
5312 ······-·no_reboot_needed5312 ······-·no_reboot_needed
  
5313 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5313 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5314 ······stat:5314 ······stat:
5315 ········path:·/boot/grub2/grub.cfg5315 ········path:·/boot/grub2/grub.cfg
5316 ······register:·file_exists5316 ······register:·file_exists
5317 ······when:5317 ······when:
5318 ······-·'"grub2-common"·in·ansible_facts.packages' 
5319 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5318 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5319 ······-·'"grub2-common"·in·ansible_facts.packages'
5320 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5320 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5321 ······tags:5321 ······tags:
5322 ······-·CJIS-5.5.2.25322 ······-·CJIS-5.5.2.2
5323 ······-·NIST-800-171-3.4.55323 ······-·NIST-800-171-3.4.5
5324 ······-·NIST-800-53-AC-6(1)5324 ······-·NIST-800-53-AC-6(1)
5325 ······-·NIST-800-53-CM-6(a)5325 ······-·NIST-800-53-CM-6(a)
5326 ······-·PCI-DSS-Req-7.15326 ······-·PCI-DSS-Req-7.1
Offset 5333, 16 lines modifiedOffset 5333, 16 lines modified
5333 ······-·no_reboot_needed5333 ······-·no_reboot_needed
  
5334 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg5334 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
5335 ······file:5335 ······file:
5336 ········path:·/boot/grub2/grub.cfg5336 ········path:·/boot/grub2/grub.cfg
5337 ········group:·'0'5337 ········group:·'0'
5338 ······when:5338 ······when:
5339 ······-·'"grub2-common"·in·ansible_facts.packages' 
5340 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5339 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5340 ······-·'"grub2-common"·in·ansible_facts.packages'
5341 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5341 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5342 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5342 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5343 ······tags:5343 ······tags:
5344 ······-·CJIS-5.5.2.25344 ······-·CJIS-5.5.2.2
5345 ······-·NIST-800-171-3.4.55345 ······-·NIST-800-171-3.4.5
5346 ······-·NIST-800-53-AC-6(1)5346 ······-·NIST-800-53-AC-6(1)
5347 ······-·NIST-800-53-CM-6(a)5347 ······-·NIST-800-53-CM-6(a)
Offset 5372, 16 lines modifiedOffset 5372, 16 lines modified
5372 ······-·no_reboot_needed5372 ······-·no_reboot_needed
  
5373 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5373 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5374 ······stat:5374 ······stat:
5375 ········path:·/boot/grub2/user.cfg5375 ········path:·/boot/grub2/user.cfg
5376 ······register:·file_exists5376 ······register:·file_exists
5377 ······when:5377 ······when:
5378 ······-·'"grub2-common"·in·ansible_facts.packages' 
5379 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5378 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5379 ······-·'"grub2-common"·in·ansible_facts.packages'
5380 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5380 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5381 ······tags:5381 ······tags:
5382 ······-·CJIS-5.5.2.25382 ······-·CJIS-5.5.2.2
5383 ······-·NIST-800-171-3.4.55383 ······-·NIST-800-171-3.4.5
5384 ······-·NIST-800-53-AC-6(1)5384 ······-·NIST-800-53-AC-6(1)
5385 ······-·NIST-800-53-CM-6(a)5385 ······-·NIST-800-53-CM-6(a)
5386 ······-·PCI-DSS-Req-7.15386 ······-·PCI-DSS-Req-7.1
Offset 5393, 16 lines modifiedOffset 5393, 16 lines modified
5393 ······-·no_reboot_needed5393 ······-·no_reboot_needed
  
5394 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg5394 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
5395 ······file:5395 ······file:
5396 ········path:·/boot/grub2/user.cfg5396 ········path:·/boot/grub2/user.cfg
5397 ········group:·'0'5397 ········group:·'0'
5398 ······when:5398 ······when:
5399 ······-·'"grub2-common"·in·ansible_facts.packages' 
5400 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5399 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5400 ······-·'"grub2-common"·in·ansible_facts.packages'
5401 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5401 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5402 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5402 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5403 ······tags:5403 ······tags:
5404 ······-·CJIS-5.5.2.25404 ······-·CJIS-5.5.2.2
5405 ······-·NIST-800-171-3.4.55405 ······-·NIST-800-171-3.4.5
5406 ······-·NIST-800-53-AC-6(1)5406 ······-·NIST-800-53-AC-6(1)
5407 ······-·NIST-800-53-CM-6(a)5407 ······-·NIST-800-53-CM-6(a)
Offset 5432, 16 lines modifiedOffset 5432, 16 lines modified
5432 ······-·no_reboot_needed5432 ······-·no_reboot_needed
  
5433 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5433 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5434 ······stat:5434 ······stat:
5435 ········path:·/boot/grub2/grub.cfg5435 ········path:·/boot/grub2/grub.cfg
5436 ······register:·file_exists5436 ······register:·file_exists
5437 ······when:5437 ······when:
5438 ······-·'"grub2-common"·in·ansible_facts.packages' 
5439 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5438 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5439 ······-·'"grub2-common"·in·ansible_facts.packages'
5440 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5440 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5441 ······tags:5441 ······tags:
5442 ······-·CJIS-5.5.2.25442 ······-·CJIS-5.5.2.2
5443 ······-·NIST-800-171-3.4.55443 ······-·NIST-800-171-3.4.5
5444 ······-·NIST-800-53-AC-6(1)5444 ······-·NIST-800-53-AC-6(1)
5445 ······-·NIST-800-53-CM-6(a)5445 ······-·NIST-800-53-CM-6(a)
5446 ······-·PCI-DSS-Req-7.15446 ······-·PCI-DSS-Req-7.1
Offset 5453, 16 lines modifiedOffset 5453, 16 lines modified
5453 ······-·no_reboot_needed5453 ······-·no_reboot_needed
  
5454 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg5454 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
5455 ······file:5455 ······file:
5456 ········path:·/boot/grub2/grub.cfg5456 ········path:·/boot/grub2/grub.cfg
5457 ········owner:·'0'5457 ········owner:·'0'
5458 ······when:5458 ······when:
5459 ······-·'"grub2-common"·in·ansible_facts.packages' 
5460 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5459 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5460 ······-·'"grub2-common"·in·ansible_facts.packages'
5461 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5461 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5462 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5462 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5463 ······tags:5463 ······tags:
5464 ······-·CJIS-5.5.2.25464 ······-·CJIS-5.5.2.2
5465 ······-·NIST-800-171-3.4.55465 ······-·NIST-800-171-3.4.5
5466 ······-·NIST-800-53-AC-6(1)5466 ······-·NIST-800-53-AC-6(1)
5467 ······-·NIST-800-53-CM-6(a)5467 ······-·NIST-800-53-CM-6(a)
Offset 5492, 16 lines modifiedOffset 5492, 16 lines modified
5492 ······-·no_reboot_needed5492 ······-·no_reboot_needed
  
5493 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5493 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5494 ······stat:5494 ······stat:
5495 ········path:·/boot/grub2/user.cfg5495 ········path:·/boot/grub2/user.cfg
5496 ······register:·file_exists5496 ······register:·file_exists
5497 ······when:5497 ······when:
5498 ······-·'"grub2-common"·in·ansible_facts.packages' 
5499 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5498 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5499 ······-·'"grub2-common"·in·ansible_facts.packages'
5500 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5500 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5501 ······tags:5501 ······tags:
5502 ······-·CJIS-5.5.2.25502 ······-·CJIS-5.5.2.2
5503 ······-·NIST-800-171-3.4.55503 ······-·NIST-800-171-3.4.5
5504 ······-·NIST-800-53-AC-6(1)5504 ······-·NIST-800-53-AC-6(1)
5505 ······-·NIST-800-53-CM-6(a)5505 ······-·NIST-800-53-CM-6(a)
5506 ······-·PCI-DSS-Req-7.15506 ······-·PCI-DSS-Req-7.1
Offset 5513, 16 lines modifiedOffset 5513, 16 lines modified
5513 ······-·no_reboot_needed5513 ······-·no_reboot_needed
Max diff block lines reached; 3245/7725 bytes (42.01%) of diff not shown.
7.72 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-cis_workstation_l1.yml
Ordering differences only
    
Offset 5312, 16 lines modifiedOffset 5312, 16 lines modified
5312 ······-·no_reboot_needed5312 ······-·no_reboot_needed
  
5313 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5313 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5314 ······stat:5314 ······stat:
5315 ········path:·/boot/grub2/grub.cfg5315 ········path:·/boot/grub2/grub.cfg
5316 ······register:·file_exists5316 ······register:·file_exists
5317 ······when:5317 ······when:
5318 ······-·'"grub2-common"·in·ansible_facts.packages' 
5319 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5318 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5319 ······-·'"grub2-common"·in·ansible_facts.packages'
5320 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5320 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5321 ······tags:5321 ······tags:
5322 ······-·CJIS-5.5.2.25322 ······-·CJIS-5.5.2.2
5323 ······-·NIST-800-171-3.4.55323 ······-·NIST-800-171-3.4.5
5324 ······-·NIST-800-53-AC-6(1)5324 ······-·NIST-800-53-AC-6(1)
5325 ······-·NIST-800-53-CM-6(a)5325 ······-·NIST-800-53-CM-6(a)
5326 ······-·PCI-DSS-Req-7.15326 ······-·PCI-DSS-Req-7.1
Offset 5333, 16 lines modifiedOffset 5333, 16 lines modified
5333 ······-·no_reboot_needed5333 ······-·no_reboot_needed
  
5334 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg5334 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
5335 ······file:5335 ······file:
5336 ········path:·/boot/grub2/grub.cfg5336 ········path:·/boot/grub2/grub.cfg
5337 ········group:·'0'5337 ········group:·'0'
5338 ······when:5338 ······when:
5339 ······-·'"grub2-common"·in·ansible_facts.packages' 
5340 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5339 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5340 ······-·'"grub2-common"·in·ansible_facts.packages'
5341 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5341 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5342 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5342 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5343 ······tags:5343 ······tags:
5344 ······-·CJIS-5.5.2.25344 ······-·CJIS-5.5.2.2
5345 ······-·NIST-800-171-3.4.55345 ······-·NIST-800-171-3.4.5
5346 ······-·NIST-800-53-AC-6(1)5346 ······-·NIST-800-53-AC-6(1)
5347 ······-·NIST-800-53-CM-6(a)5347 ······-·NIST-800-53-CM-6(a)
Offset 5372, 16 lines modifiedOffset 5372, 16 lines modified
5372 ······-·no_reboot_needed5372 ······-·no_reboot_needed
  
5373 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5373 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5374 ······stat:5374 ······stat:
5375 ········path:·/boot/grub2/user.cfg5375 ········path:·/boot/grub2/user.cfg
5376 ······register:·file_exists5376 ······register:·file_exists
5377 ······when:5377 ······when:
5378 ······-·'"grub2-common"·in·ansible_facts.packages' 
5379 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5378 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5379 ······-·'"grub2-common"·in·ansible_facts.packages'
5380 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5380 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5381 ······tags:5381 ······tags:
5382 ······-·CJIS-5.5.2.25382 ······-·CJIS-5.5.2.2
5383 ······-·NIST-800-171-3.4.55383 ······-·NIST-800-171-3.4.5
5384 ······-·NIST-800-53-AC-6(1)5384 ······-·NIST-800-53-AC-6(1)
5385 ······-·NIST-800-53-CM-6(a)5385 ······-·NIST-800-53-CM-6(a)
5386 ······-·PCI-DSS-Req-7.15386 ······-·PCI-DSS-Req-7.1
Offset 5393, 16 lines modifiedOffset 5393, 16 lines modified
5393 ······-·no_reboot_needed5393 ······-·no_reboot_needed
  
5394 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg5394 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
5395 ······file:5395 ······file:
5396 ········path:·/boot/grub2/user.cfg5396 ········path:·/boot/grub2/user.cfg
5397 ········group:·'0'5397 ········group:·'0'
5398 ······when:5398 ······when:
5399 ······-·'"grub2-common"·in·ansible_facts.packages' 
5400 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5399 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5400 ······-·'"grub2-common"·in·ansible_facts.packages'
5401 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5401 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5402 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5402 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5403 ······tags:5403 ······tags:
5404 ······-·CJIS-5.5.2.25404 ······-·CJIS-5.5.2.2
5405 ······-·NIST-800-171-3.4.55405 ······-·NIST-800-171-3.4.5
5406 ······-·NIST-800-53-AC-6(1)5406 ······-·NIST-800-53-AC-6(1)
5407 ······-·NIST-800-53-CM-6(a)5407 ······-·NIST-800-53-CM-6(a)
Offset 5432, 16 lines modifiedOffset 5432, 16 lines modified
5432 ······-·no_reboot_needed5432 ······-·no_reboot_needed
  
5433 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5433 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5434 ······stat:5434 ······stat:
5435 ········path:·/boot/grub2/grub.cfg5435 ········path:·/boot/grub2/grub.cfg
5436 ······register:·file_exists5436 ······register:·file_exists
5437 ······when:5437 ······when:
5438 ······-·'"grub2-common"·in·ansible_facts.packages' 
5439 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5438 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5439 ······-·'"grub2-common"·in·ansible_facts.packages'
5440 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5440 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5441 ······tags:5441 ······tags:
5442 ······-·CJIS-5.5.2.25442 ······-·CJIS-5.5.2.2
5443 ······-·NIST-800-171-3.4.55443 ······-·NIST-800-171-3.4.5
5444 ······-·NIST-800-53-AC-6(1)5444 ······-·NIST-800-53-AC-6(1)
5445 ······-·NIST-800-53-CM-6(a)5445 ······-·NIST-800-53-CM-6(a)
5446 ······-·PCI-DSS-Req-7.15446 ······-·PCI-DSS-Req-7.1
Offset 5453, 16 lines modifiedOffset 5453, 16 lines modified
5453 ······-·no_reboot_needed5453 ······-·no_reboot_needed
  
5454 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg5454 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
5455 ······file:5455 ······file:
5456 ········path:·/boot/grub2/grub.cfg5456 ········path:·/boot/grub2/grub.cfg
5457 ········owner:·'0'5457 ········owner:·'0'
5458 ······when:5458 ······when:
5459 ······-·'"grub2-common"·in·ansible_facts.packages' 
5460 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5459 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5460 ······-·'"grub2-common"·in·ansible_facts.packages'
5461 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5461 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5462 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5462 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5463 ······tags:5463 ······tags:
5464 ······-·CJIS-5.5.2.25464 ······-·CJIS-5.5.2.2
5465 ······-·NIST-800-171-3.4.55465 ······-·NIST-800-171-3.4.5
5466 ······-·NIST-800-53-AC-6(1)5466 ······-·NIST-800-53-AC-6(1)
5467 ······-·NIST-800-53-CM-6(a)5467 ······-·NIST-800-53-CM-6(a)
Offset 5492, 16 lines modifiedOffset 5492, 16 lines modified
5492 ······-·no_reboot_needed5492 ······-·no_reboot_needed
  
5493 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5493 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5494 ······stat:5494 ······stat:
5495 ········path:·/boot/grub2/user.cfg5495 ········path:·/boot/grub2/user.cfg
5496 ······register:·file_exists5496 ······register:·file_exists
5497 ······when:5497 ······when:
5498 ······-·'"grub2-common"·in·ansible_facts.packages' 
5499 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5498 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5499 ······-·'"grub2-common"·in·ansible_facts.packages'
5500 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5500 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5501 ······tags:5501 ······tags:
5502 ······-·CJIS-5.5.2.25502 ······-·CJIS-5.5.2.2
5503 ······-·NIST-800-171-3.4.55503 ······-·NIST-800-171-3.4.5
5504 ······-·NIST-800-53-AC-6(1)5504 ······-·NIST-800-53-AC-6(1)
5505 ······-·NIST-800-53-CM-6(a)5505 ······-·NIST-800-53-CM-6(a)
5506 ······-·PCI-DSS-Req-7.15506 ······-·PCI-DSS-Req-7.1
Offset 5513, 16 lines modifiedOffset 5513, 16 lines modified
5513 ······-·no_reboot_needed5513 ······-·no_reboot_needed
Max diff block lines reached; 3245/7725 bytes (42.01%) of diff not shown.
161 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-cis_workstation_l2.yml
Ordering differences only
    
Offset 5485, 16 lines modifiedOffset 5485, 16 lines modified
  
5485 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5485 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5486 ······find:5486 ······find:
5487 ········paths:·/etc/audit/rules.d/5487 ········paths:·/etc/audit/rules.d/
5488 ········patterns:·'*.rules'5488 ········patterns:·'*.rules'
5489 ······register:·find_rules_d5489 ······register:·find_rules_d
5490 ······when:5490 ······when:
5491 ······-·'"audit"·in·ansible_facts.packages' 
5492 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5491 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5492 ······-·'"audit"·in·ansible_facts.packages'
5493 ······tags:5493 ······tags:
5494 ······-·CJIS-5.4.1.15494 ······-·CJIS-5.4.1.1
5495 ······-·DISA-STIG-RHEL-08-0301215495 ······-·DISA-STIG-RHEL-08-030121
5496 ······-·NIST-800-171-3.3.15496 ······-·NIST-800-171-3.3.1
5497 ······-·NIST-800-171-3.4.35497 ······-·NIST-800-171-3.4.3
5498 ······-·NIST-800-53-AC-6(9)5498 ······-·NIST-800-53-AC-6(9)
5499 ······-·NIST-800-53-CM-6(a)5499 ······-·NIST-800-53-CM-6(a)
Offset 5510, 16 lines modifiedOffset 5510, 16 lines modified
5510 ······lineinfile:5510 ······lineinfile:
5511 ········path:·'{{·item·}}'5511 ········path:·'{{·item·}}'
5512 ········regexp:·^\s*(?:-e)\s+.*$5512 ········regexp:·^\s*(?:-e)\s+.*$
5513 ········state:·absent5513 ········state:·absent
5514 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5514 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5515 ········}}'5515 ········}}'
5516 ······when:5516 ······when:
5517 ······-·'"audit"·in·ansible_facts.packages' 
5518 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5517 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5518 ······-·'"audit"·in·ansible_facts.packages'
5519 ······tags:5519 ······tags:
5520 ······-·CJIS-5.4.1.15520 ······-·CJIS-5.4.1.1
5521 ······-·DISA-STIG-RHEL-08-0301215521 ······-·DISA-STIG-RHEL-08-030121
5522 ······-·NIST-800-171-3.3.15522 ······-·NIST-800-171-3.3.1
5523 ······-·NIST-800-171-3.4.35523 ······-·NIST-800-171-3.4.3
5524 ······-·NIST-800-53-AC-6(9)5524 ······-·NIST-800-53-AC-6(9)
5525 ······-·NIST-800-53-CM-6(a)5525 ······-·NIST-800-53-CM-6(a)
Offset 5537, 16 lines modifiedOffset 5537, 16 lines modified
5537 ········create:·true5537 ········create:·true
5538 ········line:·-e·25538 ········line:·-e·2
5539 ········mode:·o-rwx5539 ········mode:·o-rwx
5540 ······loop:5540 ······loop:
5541 ······-·/etc/audit/audit.rules5541 ······-·/etc/audit/audit.rules
5542 ······-·/etc/audit/rules.d/immutable.rules5542 ······-·/etc/audit/rules.d/immutable.rules
5543 ······when:5543 ······when:
5544 ······-·'"audit"·in·ansible_facts.packages' 
5545 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5544 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5545 ······-·'"audit"·in·ansible_facts.packages'
5546 ······tags:5546 ······tags:
5547 ······-·CJIS-5.4.1.15547 ······-·CJIS-5.4.1.1
5548 ······-·DISA-STIG-RHEL-08-0301215548 ······-·DISA-STIG-RHEL-08-030121
5549 ······-·NIST-800-171-3.3.15549 ······-·NIST-800-171-3.3.1
5550 ······-·NIST-800-171-3.4.35550 ······-·NIST-800-171-3.4.3
5551 ······-·NIST-800-53-AC-6(9)5551 ······-·NIST-800-53-AC-6(9)
5552 ······-·NIST-800-53-CM-6(a)5552 ······-·NIST-800-53-CM-6(a)
Offset 5579, 16 lines modifiedOffset 5579, 16 lines modified
5579 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5579 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5580 ······find:5580 ······find:
5581 ········paths:·/etc/audit/rules.d5581 ········paths:·/etc/audit/rules.d
5582 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5582 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5583 ········patterns:·'*.rules'5583 ········patterns:·'*.rules'
5584 ······register:·find_existing_watch_rules_d5584 ······register:·find_existing_watch_rules_d
5585 ······when:5585 ······when:
5586 ······-·'"audit"·in·ansible_facts.packages' 
5587 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5586 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5587 ······-·'"audit"·in·ansible_facts.packages'
5588 ······tags:5588 ······tags:
5589 ······-·CJIS-5.4.1.15589 ······-·CJIS-5.4.1.1
5590 ······-·NIST-800-171-3.1.85590 ······-·NIST-800-171-3.1.8
5591 ······-·NIST-800-53-AU-12(c)5591 ······-·NIST-800-53-AU-12(c)
5592 ······-·NIST-800-53-AU-2(d)5592 ······-·NIST-800-53-AU-2(d)
5593 ······-·NIST-800-53-CM-6(a)5593 ······-·NIST-800-53-CM-6(a)
5594 ······-·PCI-DSS-Req-10.5.55594 ······-·PCI-DSS-Req-10.5.5
Offset 5602, 16 lines modifiedOffset 5602, 16 lines modified
5602 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5602 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5603 ······find:5603 ······find:
5604 ········paths:·/etc/audit/rules.d5604 ········paths:·/etc/audit/rules.d
5605 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5605 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5606 ········patterns:·'*.rules'5606 ········patterns:·'*.rules'
5607 ······register:·find_watch_key5607 ······register:·find_watch_key
5608 ······when:5608 ······when:
5609 ······-·'"audit"·in·ansible_facts.packages' 
5610 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5609 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5610 ······-·'"audit"·in·ansible_facts.packages'
5611 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5611 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5612 ········==·05612 ········==·0
5613 ······tags:5613 ······tags:
5614 ······-·CJIS-5.4.1.15614 ······-·CJIS-5.4.1.1
5615 ······-·NIST-800-171-3.1.85615 ······-·NIST-800-171-3.1.8
5616 ······-·NIST-800-53-AU-12(c)5616 ······-·NIST-800-53-AU-12(c)
5617 ······-·NIST-800-53-AU-2(d)5617 ······-·NIST-800-53-AU-2(d)
Offset 5625, 16 lines modifiedOffset 5625, 16 lines modified
5625 ······-·restrict_strategy5625 ······-·restrict_strategy
  
5626 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5626 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5627 ······set_fact:5627 ······set_fact:
5628 ········all_files:5628 ········all_files:
5629 ········-·/etc/audit/rules.d/MAC-policy.rules5629 ········-·/etc/audit/rules.d/MAC-policy.rules
5630 ······when:5630 ······when:
5631 ······-·'"audit"·in·ansible_facts.packages' 
5632 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5631 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5632 ······-·'"audit"·in·ansible_facts.packages'
5633 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5633 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5634 ········is·defined·and·find_existing_watch_rules_d.matched·==·05634 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5635 ······tags:5635 ······tags:
5636 ······-·CJIS-5.4.1.15636 ······-·CJIS-5.4.1.1
5637 ······-·NIST-800-171-3.1.85637 ······-·NIST-800-171-3.1.8
5638 ······-·NIST-800-53-AU-12(c)5638 ······-·NIST-800-53-AU-12(c)
5639 ······-·NIST-800-53-AU-2(d)5639 ······-·NIST-800-53-AU-2(d)
Offset 5648, 16 lines modifiedOffset 5648, 16 lines modified
5648 ······-·restrict_strategy5648 ······-·restrict_strategy
  
5649 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5649 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5650 ······set_fact:5650 ······set_fact:
5651 ········all_files:5651 ········all_files:
5652 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5652 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5653 ······when:5653 ······when:
5654 ······-·'"audit"·in·ansible_facts.packages' 
5655 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5654 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5655 ······-·'"audit"·in·ansible_facts.packages'
5656 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5656 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5657 ········is·defined·and·find_existing_watch_rules_d.matched·==·05657 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5658 ······tags:5658 ······tags:
5659 ······-·CJIS-5.4.1.15659 ······-·CJIS-5.4.1.1
5660 ······-·NIST-800-171-3.1.85660 ······-·NIST-800-171-3.1.8
5661 ······-·NIST-800-53-AU-12(c)5661 ······-·NIST-800-53-AU-12(c)
5662 ······-·NIST-800-53-AU-2(d)5662 ······-·NIST-800-53-AU-2(d)
Offset 5673, 16 lines modifiedOffset 5673, 16 lines modified
5673 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5673 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 159975/164678 bytes (97.14%) of diff not shown.
101 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-cjis.yml
Ordering differences only
    
Offset 2955, 16 lines modifiedOffset 2955, 16 lines modified
  
2955 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension2955 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
2956 ······find:2956 ······find:
2957 ········paths:·/etc/audit/rules.d/2957 ········paths:·/etc/audit/rules.d/
2958 ········patterns:·'*.rules'2958 ········patterns:·'*.rules'
2959 ······register:·find_rules_d2959 ······register:·find_rules_d
2960 ······when:2960 ······when:
2961 ······-·'"audit"·in·ansible_facts.packages' 
2962 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2961 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2962 ······-·'"audit"·in·ansible_facts.packages'
2963 ······tags:2963 ······tags:
2964 ······-·CJIS-5.4.1.12964 ······-·CJIS-5.4.1.1
2965 ······-·DISA-STIG-RHEL-08-0301212965 ······-·DISA-STIG-RHEL-08-030121
2966 ······-·NIST-800-171-3.3.12966 ······-·NIST-800-171-3.3.1
2967 ······-·NIST-800-171-3.4.32967 ······-·NIST-800-171-3.4.3
2968 ······-·NIST-800-53-AC-6(9)2968 ······-·NIST-800-53-AC-6(9)
2969 ······-·NIST-800-53-CM-6(a)2969 ······-·NIST-800-53-CM-6(a)
Offset 2980, 16 lines modifiedOffset 2980, 16 lines modified
2980 ······lineinfile:2980 ······lineinfile:
2981 ········path:·'{{·item·}}'2981 ········path:·'{{·item·}}'
2982 ········regexp:·^\s*(?:-e)\s+.*$2982 ········regexp:·^\s*(?:-e)\s+.*$
2983 ········state:·absent2983 ········state:·absent
2984 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']2984 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
2985 ········}}'2985 ········}}'
2986 ······when:2986 ······when:
2987 ······-·'"audit"·in·ansible_facts.packages' 
2988 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2987 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2988 ······-·'"audit"·in·ansible_facts.packages'
2989 ······tags:2989 ······tags:
2990 ······-·CJIS-5.4.1.12990 ······-·CJIS-5.4.1.1
2991 ······-·DISA-STIG-RHEL-08-0301212991 ······-·DISA-STIG-RHEL-08-030121
2992 ······-·NIST-800-171-3.3.12992 ······-·NIST-800-171-3.3.1
2993 ······-·NIST-800-171-3.4.32993 ······-·NIST-800-171-3.4.3
2994 ······-·NIST-800-53-AC-6(9)2994 ······-·NIST-800-53-AC-6(9)
2995 ······-·NIST-800-53-CM-6(a)2995 ······-·NIST-800-53-CM-6(a)
Offset 3007, 16 lines modifiedOffset 3007, 16 lines modified
3007 ········create:·true3007 ········create:·true
3008 ········line:·-e·23008 ········line:·-e·2
3009 ········mode:·o-rwx3009 ········mode:·o-rwx
3010 ······loop:3010 ······loop:
3011 ······-·/etc/audit/audit.rules3011 ······-·/etc/audit/audit.rules
3012 ······-·/etc/audit/rules.d/immutable.rules3012 ······-·/etc/audit/rules.d/immutable.rules
3013 ······when:3013 ······when:
3014 ······-·'"audit"·in·ansible_facts.packages' 
3015 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3014 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3015 ······-·'"audit"·in·ansible_facts.packages'
3016 ······tags:3016 ······tags:
3017 ······-·CJIS-5.4.1.13017 ······-·CJIS-5.4.1.1
3018 ······-·DISA-STIG-RHEL-08-0301213018 ······-·DISA-STIG-RHEL-08-030121
3019 ······-·NIST-800-171-3.3.13019 ······-·NIST-800-171-3.3.1
3020 ······-·NIST-800-171-3.4.33020 ······-·NIST-800-171-3.4.3
3021 ······-·NIST-800-53-AC-6(9)3021 ······-·NIST-800-53-AC-6(9)
3022 ······-·NIST-800-53-CM-6(a)3022 ······-·NIST-800-53-CM-6(a)
Offset 3049, 16 lines modifiedOffset 3049, 16 lines modified
3049 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/3049 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
3050 ······find:3050 ······find:
3051 ········paths:·/etc/audit/rules.d3051 ········paths:·/etc/audit/rules.d
3052 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+3052 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
3053 ········patterns:·'*.rules'3053 ········patterns:·'*.rules'
3054 ······register:·find_existing_watch_rules_d3054 ······register:·find_existing_watch_rules_d
3055 ······when:3055 ······when:
3056 ······-·'"audit"·in·ansible_facts.packages' 
3057 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3056 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3057 ······-·'"audit"·in·ansible_facts.packages'
3058 ······tags:3058 ······tags:
3059 ······-·CJIS-5.4.1.13059 ······-·CJIS-5.4.1.1
3060 ······-·NIST-800-171-3.1.83060 ······-·NIST-800-171-3.1.8
3061 ······-·NIST-800-53-AU-12(c)3061 ······-·NIST-800-53-AU-12(c)
3062 ······-·NIST-800-53-AU-2(d)3062 ······-·NIST-800-53-AU-2(d)
3063 ······-·NIST-800-53-CM-6(a)3063 ······-·NIST-800-53-CM-6(a)
3064 ······-·PCI-DSS-Req-10.5.53064 ······-·PCI-DSS-Req-10.5.5
Offset 3072, 16 lines modifiedOffset 3072, 16 lines modified
3072 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy3072 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
3073 ······find:3073 ······find:
3074 ········paths:·/etc/audit/rules.d3074 ········paths:·/etc/audit/rules.d
3075 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$3075 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
3076 ········patterns:·'*.rules'3076 ········patterns:·'*.rules'
3077 ······register:·find_watch_key3077 ······register:·find_watch_key
3078 ······when:3078 ······when:
3079 ······-·'"audit"·in·ansible_facts.packages' 
3080 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3079 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3080 ······-·'"audit"·in·ansible_facts.packages'
3081 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3081 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3082 ········==·03082 ········==·0
3083 ······tags:3083 ······tags:
3084 ······-·CJIS-5.4.1.13084 ······-·CJIS-5.4.1.1
3085 ······-·NIST-800-171-3.1.83085 ······-·NIST-800-171-3.1.8
3086 ······-·NIST-800-53-AU-12(c)3086 ······-·NIST-800-53-AU-12(c)
3087 ······-·NIST-800-53-AU-2(d)3087 ······-·NIST-800-53-AU-2(d)
Offset 3095, 16 lines modifiedOffset 3095, 16 lines modified
3095 ······-·restrict_strategy3095 ······-·restrict_strategy
  
3096 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule3096 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
3097 ······set_fact:3097 ······set_fact:
3098 ········all_files:3098 ········all_files:
3099 ········-·/etc/audit/rules.d/MAC-policy.rules3099 ········-·/etc/audit/rules.d/MAC-policy.rules
3100 ······when:3100 ······when:
3101 ······-·'"audit"·in·ansible_facts.packages' 
3102 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3101 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3102 ······-·'"audit"·in·ansible_facts.packages'
3103 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched3103 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
3104 ········is·defined·and·find_existing_watch_rules_d.matched·==·03104 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3105 ······tags:3105 ······tags:
3106 ······-·CJIS-5.4.1.13106 ······-·CJIS-5.4.1.1
3107 ······-·NIST-800-171-3.1.83107 ······-·NIST-800-171-3.1.8
3108 ······-·NIST-800-53-AU-12(c)3108 ······-·NIST-800-53-AU-12(c)
3109 ······-·NIST-800-53-AU-2(d)3109 ······-·NIST-800-53-AU-2(d)
Offset 3118, 16 lines modifiedOffset 3118, 16 lines modified
3118 ······-·restrict_strategy3118 ······-·restrict_strategy
  
3119 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule3119 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
3120 ······set_fact:3120 ······set_fact:
3121 ········all_files:3121 ········all_files:
3122 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'3122 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
3123 ······when:3123 ······when:
3124 ······-·'"audit"·in·ansible_facts.packages' 
3125 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3124 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3125 ······-·'"audit"·in·ansible_facts.packages'
3126 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched3126 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
3127 ········is·defined·and·find_existing_watch_rules_d.matched·==·03127 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3128 ······tags:3128 ······tags:
3129 ······-·CJIS-5.4.1.13129 ······-·CJIS-5.4.1.1
3130 ······-·NIST-800-171-3.1.83130 ······-·NIST-800-171-3.1.8
3131 ······-·NIST-800-53-AU-12(c)3131 ······-·NIST-800-53-AU-12(c)
3132 ······-·NIST-800-53-AU-2(d)3132 ······-·NIST-800-53-AU-2(d)
Offset 3143, 16 lines modifiedOffset 3143, 16 lines modified
3143 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/3143 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 99073/103776 bytes (95.47%) of diff not shown.
3.57 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-cui.yml
Ordering differences only
    
Offset 4838, 16 lines modifiedOffset 4838, 16 lines modified
4838 ······lineinfile:4838 ······lineinfile:
4839 ········dest:·/etc/audit/auditd.conf4839 ········dest:·/etc/audit/auditd.conf
4840 ········regexp:·^\s*flush\s*=\s*.*$4840 ········regexp:·^\s*flush\s*=\s*.*$
4841 ········line:·flush·=·{{·var_auditd_flush·}}4841 ········line:·flush·=·{{·var_auditd_flush·}}
4842 ········state:·present4842 ········state:·present
4843 ········create:·true4843 ········create:·true
4844 ······when:4844 ······when:
4845 ······-·'"audit"·in·ansible_facts.packages' 
4846 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4845 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4846 ······-·'"audit"·in·ansible_facts.packages'
4847 ······tags:4847 ······tags:
4848 ······-·NIST-800-171-3.3.14848 ······-·NIST-800-171-3.3.1
4849 ······-·NIST-800-53-AU-114849 ······-·NIST-800-53-AU-11
4850 ······-·NIST-800-53-CM-6(a)4850 ······-·NIST-800-53-CM-6(a)
4851 ······-·auditd_data_retention_flush4851 ······-·auditd_data_retention_flush
4852 ······-·low_complexity4852 ······-·low_complexity
4853 ······-·low_disruption4853 ······-·low_disruption
Offset 4893, 16 lines modifiedOffset 4893, 16 lines modified
4893 ········lineinfile:4893 ········lineinfile:
4894 ··········path:·/etc/audit/auditd.conf4894 ··········path:·/etc/audit/auditd.conf
4895 ··········create:·true4895 ··········create:·true
4896 ··········regexp:·(?i)^\s*freq\s*=\s*4896 ··········regexp:·(?i)^\s*freq\s*=\s*
4897 ··········line:·freq·=·504897 ··········line:·freq·=·50
4898 ··········state:·present4898 ··········state:·present
4899 ······when:4899 ······when:
4900 ······-·'"audit"·in·ansible_facts.packages' 
4901 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4900 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4901 ······-·'"audit"·in·ansible_facts.packages'
4902 ······tags:4902 ······tags:
4903 ······-·NIST-800-53-CM-64903 ······-·NIST-800-53-CM-6
4904 ······-·auditd_freq4904 ······-·auditd_freq
4905 ······-·low_complexity4905 ······-·low_complexity
4906 ······-·low_disruption4906 ······-·low_disruption
4907 ······-·medium_severity4907 ······-·medium_severity
4908 ······-·no_reboot_needed4908 ······-·no_reboot_needed
Offset 4947, 16 lines modifiedOffset 4947, 16 lines modified
4947 ········lineinfile:4947 ········lineinfile:
4948 ··········path:·/etc/audit/auditd.conf4948 ··········path:·/etc/audit/auditd.conf
4949 ··········create:·true4949 ··········create:·true
4950 ··········regexp:·(?i)^\s*local_events\s*=\s*4950 ··········regexp:·(?i)^\s*local_events\s*=\s*
4951 ··········line:·local_events·=·yes4951 ··········line:·local_events·=·yes
4952 ··········state:·present4952 ··········state:·present
4953 ······when:4953 ······when:
4954 ······-·'"audit"·in·ansible_facts.packages' 
4955 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4954 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4955 ······-·'"audit"·in·ansible_facts.packages'
4956 ······tags:4956 ······tags:
4957 ······-·DISA-STIG-RHEL-08-0300614957 ······-·DISA-STIG-RHEL-08-030061
4958 ······-·NIST-800-53-CM-64958 ······-·NIST-800-53-CM-6
4959 ······-·auditd_local_events4959 ······-·auditd_local_events
4960 ······-·low_complexity4960 ······-·low_complexity
4961 ······-·low_disruption4961 ······-·low_disruption
4962 ······-·medium_severity4962 ······-·medium_severity
Offset 5003, 16 lines modifiedOffset 5003, 16 lines modified
5003 ········lineinfile:5003 ········lineinfile:
5004 ··········path:·/etc/audit/auditd.conf5004 ··········path:·/etc/audit/auditd.conf
5005 ··········create:·true5005 ··········create:·true
5006 ··········regexp:·(?i)^\s*log_format\s*=\s*5006 ··········regexp:·(?i)^\s*log_format\s*=\s*
5007 ··········line:·log_format·=·ENRICHED5007 ··········line:·log_format·=·ENRICHED
5008 ··········state:·present5008 ··········state:·present
5009 ······when:5009 ······when:
5010 ······-·'"audit"·in·ansible_facts.packages' 
5011 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5010 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5011 ······-·'"audit"·in·ansible_facts.packages'
5012 ······tags:5012 ······tags:
5013 ······-·DISA-STIG-RHEL-08-0300635013 ······-·DISA-STIG-RHEL-08-030063
5014 ······-·NIST-800-53-AU-35014 ······-·NIST-800-53-AU-3
5015 ······-·NIST-800-53-CM-65015 ······-·NIST-800-53-CM-6
5016 ······-·auditd_log_format5016 ······-·auditd_log_format
5017 ······-·low_complexity5017 ······-·low_complexity
5018 ······-·low_disruption5018 ······-·low_disruption
Offset 5060, 16 lines modifiedOffset 5060, 16 lines modified
5060 ········lineinfile:5060 ········lineinfile:
5061 ··········path:·/etc/audit/auditd.conf5061 ··········path:·/etc/audit/auditd.conf
5062 ··········create:·true5062 ··········create:·true
5063 ··········regexp:·(?i)^\s*name_format\s*=\s*5063 ··········regexp:·(?i)^\s*name_format\s*=\s*
5064 ··········line:·name_format·=·hostname5064 ··········line:·name_format·=·hostname
5065 ··········state:·present5065 ··········state:·present
5066 ······when:5066 ······when:
5067 ······-·'"audit"·in·ansible_facts.packages' 
5068 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5067 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5068 ······-·'"audit"·in·ansible_facts.packages'
5069 ······tags:5069 ······tags:
5070 ······-·DISA-STIG-RHEL-08-0300625070 ······-·DISA-STIG-RHEL-08-030062
5071 ······-·NIST-800-53-AU-35071 ······-·NIST-800-53-AU-3
5072 ······-·NIST-800-53-CM-65072 ······-·NIST-800-53-CM-6
5073 ······-·auditd_name_format5073 ······-·auditd_name_format
5074 ······-·low_complexity5074 ······-·low_complexity
5075 ······-·low_disruption5075 ······-·low_disruption
Offset 5115, 16 lines modifiedOffset 5115, 16 lines modified
5115 ········lineinfile:5115 ········lineinfile:
5116 ··········path:·/etc/audit/auditd.conf5116 ··········path:·/etc/audit/auditd.conf
5117 ··········create:·true5117 ··········create:·true
5118 ··········regexp:·(?i)^\s*write_logs\s*=\s*5118 ··········regexp:·(?i)^\s*write_logs\s*=\s*
5119 ··········line:·write_logs·=·yes5119 ··········line:·write_logs·=·yes
5120 ··········state:·present5120 ··········state:·present
5121 ······when:5121 ······when:
5122 ······-·'"audit"·in·ansible_facts.packages' 
5123 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5122 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5123 ······-·'"audit"·in·ansible_facts.packages'
5124 ······tags:5124 ······tags:
5125 ······-·NIST-800-53-CM-65125 ······-·NIST-800-53-CM-6
5126 ······-·auditd_write_logs5126 ······-·auditd_write_logs
5127 ······-·low_complexity5127 ······-·low_complexity
5128 ······-·low_disruption5128 ······-·low_disruption
5129 ······-·medium_severity5129 ······-·medium_severity
5130 ······-·no_reboot_needed5130 ······-·no_reboot_needed
69.7 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-e8.yml
Ordering differences only
    
Offset 1154, 16 lines modifiedOffset 1154, 16 lines modified
1154 ······-·no_reboot_needed1154 ······-·no_reboot_needed
1155 ······-·restrict_strategy1155 ······-·restrict_strategy
  
1156 ····-·name:·Set·architecture·for·audit·tasks1156 ····-·name:·Set·architecture·for·audit·tasks
1157 ······set_fact:1157 ······set_fact:
1158 ········audit_arch:·b641158 ········audit_arch:·b64
1159 ······when:1159 ······when:
1160 ······-·'"audit"·in·ansible_facts.packages' 
1161 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1160 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1161 ······-·'"audit"·in·ansible_facts.packages'
1162 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1162 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1163 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1163 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1164 ······tags:1164 ······tags:
1165 ······-·CJIS-5.4.1.11165 ······-·CJIS-5.4.1.1
1166 ······-·NIST-800-171-3.1.71166 ······-·NIST-800-171-3.1.7
1167 ······-·NIST-800-53-AC-6(9)1167 ······-·NIST-800-53-AC-6(9)
1168 ······-·NIST-800-53-AU-12(c)1168 ······-·NIST-800-53-AU-12(c)
Offset 1296, 16 lines modifiedOffset 1296, 16 lines modified
1296 ··········path:·'{{·audit_file·}}'1296 ··········path:·'{{·audit_file·}}'
1297 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1297 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1298 ··········create:·true1298 ··········create:·true
1299 ··········mode:·o-rwx1299 ··········mode:·o-rwx
1300 ··········state:·present1300 ··········state:·present
1301 ········when:·syscalls_found·|·length·==·01301 ········when:·syscalls_found·|·length·==·0
1302 ······when:1302 ······when:
1303 ······-·'"audit"·in·ansible_facts.packages' 
1304 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1303 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1304 ······-·'"audit"·in·ansible_facts.packages'
1305 ······tags:1305 ······tags:
1306 ······-·CJIS-5.4.1.11306 ······-·CJIS-5.4.1.1
1307 ······-·NIST-800-171-3.1.71307 ······-·NIST-800-171-3.1.7
1308 ······-·NIST-800-53-AC-6(9)1308 ······-·NIST-800-53-AC-6(9)
1309 ······-·NIST-800-53-AU-12(c)1309 ······-·NIST-800-53-AU-12(c)
1310 ······-·NIST-800-53-AU-2(d)1310 ······-·NIST-800-53-AU-2(d)
1311 ······-·NIST-800-53-CM-6(a)1311 ······-·NIST-800-53-CM-6(a)
Offset 1436, 16 lines modifiedOffset 1436, 16 lines modified
1436 ··········path:·'{{·audit_file·}}'1436 ··········path:·'{{·audit_file·}}'
1437 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1437 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1438 ··········create:·true1438 ··········create:·true
1439 ··········mode:·o-rwx1439 ··········mode:·o-rwx
1440 ··········state:·present1440 ··········state:·present
1441 ········when:·syscalls_found·|·length·==·01441 ········when:·syscalls_found·|·length·==·0
1442 ······when:1442 ······when:
1443 ······-·'"audit"·in·ansible_facts.packages' 
1444 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1443 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1444 ······-·'"audit"·in·ansible_facts.packages'
1445 ······-·audit_arch·==·"b64"1445 ······-·audit_arch·==·"b64"
1446 ······tags:1446 ······tags:
1447 ······-·CJIS-5.4.1.11447 ······-·CJIS-5.4.1.1
1448 ······-·NIST-800-171-3.1.71448 ······-·NIST-800-171-3.1.7
1449 ······-·NIST-800-53-AC-6(9)1449 ······-·NIST-800-53-AC-6(9)
1450 ······-·NIST-800-53-AU-12(c)1450 ······-·NIST-800-53-AU-12(c)
1451 ······-·NIST-800-53-AU-2(d)1451 ······-·NIST-800-53-AU-2(d)
Offset 1461, 16 lines modifiedOffset 1461, 16 lines modified
1461 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/1461 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
1462 ······find:1462 ······find:
1463 ········paths:·/etc/audit/rules.d1463 ········paths:·/etc/audit/rules.d
1464 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+1464 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
1465 ········patterns:·'*.rules'1465 ········patterns:·'*.rules'
1466 ······register:·find_existing_watch_rules_d1466 ······register:·find_existing_watch_rules_d
1467 ······when:1467 ······when:
1468 ······-·'"audit"·in·ansible_facts.packages' 
1469 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1468 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1469 ······-·'"audit"·in·ansible_facts.packages'
1470 ······tags:1470 ······tags:
1471 ······-·CJIS-5.4.1.11471 ······-·CJIS-5.4.1.1
1472 ······-·NIST-800-171-3.1.71472 ······-·NIST-800-171-3.1.7
1473 ······-·NIST-800-53-AC-6(9)1473 ······-·NIST-800-53-AC-6(9)
1474 ······-·NIST-800-53-AU-12(c)1474 ······-·NIST-800-53-AU-12(c)
1475 ······-·NIST-800-53-AU-2(d)1475 ······-·NIST-800-53-AU-2(d)
1476 ······-·NIST-800-53-CM-6(a)1476 ······-·NIST-800-53-CM-6(a)
Offset 1485, 16 lines modifiedOffset 1485, 16 lines modified
1485 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification1485 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
1486 ······find:1486 ······find:
1487 ········paths:·/etc/audit/rules.d1487 ········paths:·/etc/audit/rules.d
1488 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$1488 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
1489 ········patterns:·'*.rules'1489 ········patterns:·'*.rules'
1490 ······register:·find_watch_key1490 ······register:·find_watch_key
1491 ······when:1491 ······when:
1492 ······-·'"audit"·in·ansible_facts.packages' 
1493 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1492 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1493 ······-·'"audit"·in·ansible_facts.packages'
1494 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1494 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1495 ········==·01495 ········==·0
1496 ······tags:1496 ······tags:
1497 ······-·CJIS-5.4.1.11497 ······-·CJIS-5.4.1.1
1498 ······-·NIST-800-171-3.1.71498 ······-·NIST-800-171-3.1.7
1499 ······-·NIST-800-53-AC-6(9)1499 ······-·NIST-800-53-AC-6(9)
1500 ······-·NIST-800-53-AU-12(c)1500 ······-·NIST-800-53-AU-12(c)
Offset 1510, 16 lines modifiedOffset 1510, 16 lines modified
  
1510 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the1510 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
1511 ········recipient·for·the·rule1511 ········recipient·for·the·rule
1512 ······set_fact:1512 ······set_fact:
1513 ········all_files:1513 ········all_files:
1514 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules1514 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
1515 ······when:1515 ······when:
1516 ······-·'"audit"·in·ansible_facts.packages' 
1517 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1516 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1517 ······-·'"audit"·in·ansible_facts.packages'
1518 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1518 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1519 ········is·defined·and·find_existing_watch_rules_d.matched·==·01519 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1520 ······tags:1520 ······tags:
1521 ······-·CJIS-5.4.1.11521 ······-·CJIS-5.4.1.1
1522 ······-·NIST-800-171-3.1.71522 ······-·NIST-800-171-3.1.7
1523 ······-·NIST-800-53-AC-6(9)1523 ······-·NIST-800-53-AC-6(9)
1524 ······-·NIST-800-53-AU-12(c)1524 ······-·NIST-800-53-AU-12(c)
Offset 1534, 16 lines modifiedOffset 1534, 16 lines modified
1534 ······-·restrict_strategy1534 ······-·restrict_strategy
  
1535 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1535 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1536 ······set_fact:1536 ······set_fact:
1537 ········all_files:1537 ········all_files:
1538 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1538 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1539 ······when:1539 ······when:
1540 ······-·'"audit"·in·ansible_facts.packages' 
1541 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1540 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1541 ······-·'"audit"·in·ansible_facts.packages'
1542 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1542 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1543 ········is·defined·and·find_existing_watch_rules_d.matched·==·01543 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1544 ······tags:1544 ······tags:
1545 ······-·CJIS-5.4.1.11545 ······-·CJIS-5.4.1.1
1546 ······-·NIST-800-171-3.1.71546 ······-·NIST-800-171-3.1.7
1547 ······-·NIST-800-53-AC-6(9)1547 ······-·NIST-800-53-AC-6(9)
1548 ······-·NIST-800-53-AU-12(c)1548 ······-·NIST-800-53-AU-12(c)
Offset 1560, 16 lines modifiedOffset 1560, 16 lines modified
1560 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/1560 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 66166/71216 bytes (92.91%) of diff not shown.
181 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-hipaa.yml
Ordering differences only
    
Offset 1358, 16 lines modifiedOffset 1358, 16 lines modified
  
1358 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1358 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1359 ······find:1359 ······find:
1360 ········paths:·/etc/audit/rules.d/1360 ········paths:·/etc/audit/rules.d/
1361 ········patterns:·'*.rules'1361 ········patterns:·'*.rules'
1362 ······register:·find_rules_d1362 ······register:·find_rules_d
1363 ······when:1363 ······when:
1364 ······-·'"audit"·in·ansible_facts.packages' 
1365 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1364 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1365 ······-·'"audit"·in·ansible_facts.packages'
1366 ······tags:1366 ······tags:
1367 ······-·CJIS-5.4.1.11367 ······-·CJIS-5.4.1.1
1368 ······-·DISA-STIG-RHEL-08-0301211368 ······-·DISA-STIG-RHEL-08-030121
1369 ······-·NIST-800-171-3.3.11369 ······-·NIST-800-171-3.3.1
1370 ······-·NIST-800-171-3.4.31370 ······-·NIST-800-171-3.4.3
1371 ······-·NIST-800-53-AC-6(9)1371 ······-·NIST-800-53-AC-6(9)
1372 ······-·NIST-800-53-CM-6(a)1372 ······-·NIST-800-53-CM-6(a)
Offset 1383, 16 lines modifiedOffset 1383, 16 lines modified
1383 ······lineinfile:1383 ······lineinfile:
1384 ········path:·'{{·item·}}'1384 ········path:·'{{·item·}}'
1385 ········regexp:·^\s*(?:-e)\s+.*$1385 ········regexp:·^\s*(?:-e)\s+.*$
1386 ········state:·absent1386 ········state:·absent
1387 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1387 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1388 ········}}'1388 ········}}'
1389 ······when:1389 ······when:
1390 ······-·'"audit"·in·ansible_facts.packages' 
1391 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1390 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1391 ······-·'"audit"·in·ansible_facts.packages'
1392 ······tags:1392 ······tags:
1393 ······-·CJIS-5.4.1.11393 ······-·CJIS-5.4.1.1
1394 ······-·DISA-STIG-RHEL-08-0301211394 ······-·DISA-STIG-RHEL-08-030121
1395 ······-·NIST-800-171-3.3.11395 ······-·NIST-800-171-3.3.1
1396 ······-·NIST-800-171-3.4.31396 ······-·NIST-800-171-3.4.3
1397 ······-·NIST-800-53-AC-6(9)1397 ······-·NIST-800-53-AC-6(9)
1398 ······-·NIST-800-53-CM-6(a)1398 ······-·NIST-800-53-CM-6(a)
Offset 1410, 16 lines modifiedOffset 1410, 16 lines modified
1410 ········create:·true1410 ········create:·true
1411 ········line:·-e·21411 ········line:·-e·2
1412 ········mode:·o-rwx1412 ········mode:·o-rwx
1413 ······loop:1413 ······loop:
1414 ······-·/etc/audit/audit.rules1414 ······-·/etc/audit/audit.rules
1415 ······-·/etc/audit/rules.d/immutable.rules1415 ······-·/etc/audit/rules.d/immutable.rules
1416 ······when:1416 ······when:
1417 ······-·'"audit"·in·ansible_facts.packages' 
1418 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1417 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1418 ······-·'"audit"·in·ansible_facts.packages'
1419 ······tags:1419 ······tags:
1420 ······-·CJIS-5.4.1.11420 ······-·CJIS-5.4.1.1
1421 ······-·DISA-STIG-RHEL-08-0301211421 ······-·DISA-STIG-RHEL-08-030121
1422 ······-·NIST-800-171-3.3.11422 ······-·NIST-800-171-3.3.1
1423 ······-·NIST-800-171-3.4.31423 ······-·NIST-800-171-3.4.3
1424 ······-·NIST-800-53-AC-6(9)1424 ······-·NIST-800-53-AC-6(9)
1425 ······-·NIST-800-53-CM-6(a)1425 ······-·NIST-800-53-CM-6(a)
Offset 1452, 16 lines modifiedOffset 1452, 16 lines modified
1452 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1452 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1453 ······find:1453 ······find:
1454 ········paths:·/etc/audit/rules.d1454 ········paths:·/etc/audit/rules.d
1455 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1455 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1456 ········patterns:·'*.rules'1456 ········patterns:·'*.rules'
1457 ······register:·find_existing_watch_rules_d1457 ······register:·find_existing_watch_rules_d
1458 ······when:1458 ······when:
1459 ······-·'"audit"·in·ansible_facts.packages' 
1460 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1459 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1460 ······-·'"audit"·in·ansible_facts.packages'
1461 ······tags:1461 ······tags:
1462 ······-·CJIS-5.4.1.11462 ······-·CJIS-5.4.1.1
1463 ······-·NIST-800-171-3.1.81463 ······-·NIST-800-171-3.1.8
1464 ······-·NIST-800-53-AU-12(c)1464 ······-·NIST-800-53-AU-12(c)
1465 ······-·NIST-800-53-AU-2(d)1465 ······-·NIST-800-53-AU-2(d)
1466 ······-·NIST-800-53-CM-6(a)1466 ······-·NIST-800-53-CM-6(a)
1467 ······-·PCI-DSS-Req-10.5.51467 ······-·PCI-DSS-Req-10.5.5
Offset 1475, 16 lines modifiedOffset 1475, 16 lines modified
1475 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1475 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1476 ······find:1476 ······find:
1477 ········paths:·/etc/audit/rules.d1477 ········paths:·/etc/audit/rules.d
1478 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1478 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1479 ········patterns:·'*.rules'1479 ········patterns:·'*.rules'
1480 ······register:·find_watch_key1480 ······register:·find_watch_key
1481 ······when:1481 ······when:
1482 ······-·'"audit"·in·ansible_facts.packages' 
1483 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1482 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1483 ······-·'"audit"·in·ansible_facts.packages'
1484 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1484 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1485 ········==·01485 ········==·0
1486 ······tags:1486 ······tags:
1487 ······-·CJIS-5.4.1.11487 ······-·CJIS-5.4.1.1
1488 ······-·NIST-800-171-3.1.81488 ······-·NIST-800-171-3.1.8
1489 ······-·NIST-800-53-AU-12(c)1489 ······-·NIST-800-53-AU-12(c)
1490 ······-·NIST-800-53-AU-2(d)1490 ······-·NIST-800-53-AU-2(d)
Offset 1498, 16 lines modifiedOffset 1498, 16 lines modified
1498 ······-·restrict_strategy1498 ······-·restrict_strategy
  
1499 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1499 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1500 ······set_fact:1500 ······set_fact:
1501 ········all_files:1501 ········all_files:
1502 ········-·/etc/audit/rules.d/MAC-policy.rules1502 ········-·/etc/audit/rules.d/MAC-policy.rules
1503 ······when:1503 ······when:
1504 ······-·'"audit"·in·ansible_facts.packages' 
1505 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1504 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1505 ······-·'"audit"·in·ansible_facts.packages'
1506 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1506 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1507 ········is·defined·and·find_existing_watch_rules_d.matched·==·01507 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1508 ······tags:1508 ······tags:
1509 ······-·CJIS-5.4.1.11509 ······-·CJIS-5.4.1.1
1510 ······-·NIST-800-171-3.1.81510 ······-·NIST-800-171-3.1.8
1511 ······-·NIST-800-53-AU-12(c)1511 ······-·NIST-800-53-AU-12(c)
1512 ······-·NIST-800-53-AU-2(d)1512 ······-·NIST-800-53-AU-2(d)
Offset 1521, 16 lines modifiedOffset 1521, 16 lines modified
1521 ······-·restrict_strategy1521 ······-·restrict_strategy
  
1522 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1522 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1523 ······set_fact:1523 ······set_fact:
1524 ········all_files:1524 ········all_files:
1525 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1525 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1526 ······when:1526 ······when:
1527 ······-·'"audit"·in·ansible_facts.packages' 
1528 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1527 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1528 ······-·'"audit"·in·ansible_facts.packages'
1529 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1529 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1530 ········is·defined·and·find_existing_watch_rules_d.matched·==·01530 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1531 ······tags:1531 ······tags:
1532 ······-·CJIS-5.4.1.11532 ······-·CJIS-5.4.1.1
1533 ······-·NIST-800-171-3.1.81533 ······-·NIST-800-171-3.1.8
1534 ······-·NIST-800-53-AU-12(c)1534 ······-·NIST-800-53-AU-12(c)
1535 ······-·NIST-800-53-AU-2(d)1535 ······-·NIST-800-53-AU-2(d)
Offset 1546, 16 lines modifiedOffset 1546, 16 lines modified
1546 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1546 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 180644/185347 bytes (97.46%) of diff not shown.
86.8 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-ism_o.yml
Ordering differences only
    
Offset 4644, 16 lines modifiedOffset 4644, 16 lines modified
4644 ······-·no_reboot_needed4644 ······-·no_reboot_needed
4645 ······-·restrict_strategy4645 ······-·restrict_strategy
  
4646 ····-·name:·Set·architecture·for·audit·tasks4646 ····-·name:·Set·architecture·for·audit·tasks
4647 ······set_fact:4647 ······set_fact:
4648 ········audit_arch:·b644648 ········audit_arch:·b64
4649 ······when:4649 ······when:
4650 ······-·'"audit"·in·ansible_facts.packages' 
4651 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4650 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4651 ······-·'"audit"·in·ansible_facts.packages'
4652 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4652 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4653 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4653 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4654 ······tags:4654 ······tags:
4655 ······-·CJIS-5.4.1.14655 ······-·CJIS-5.4.1.1
4656 ······-·NIST-800-171-3.1.74656 ······-·NIST-800-171-3.1.7
4657 ······-·NIST-800-53-AC-6(9)4657 ······-·NIST-800-53-AC-6(9)
4658 ······-·NIST-800-53-AU-12(c)4658 ······-·NIST-800-53-AU-12(c)
Offset 4786, 16 lines modifiedOffset 4786, 16 lines modified
4786 ··········path:·'{{·audit_file·}}'4786 ··········path:·'{{·audit_file·}}'
4787 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification4787 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
4788 ··········create:·true4788 ··········create:·true
4789 ··········mode:·o-rwx4789 ··········mode:·o-rwx
4790 ··········state:·present4790 ··········state:·present
4791 ········when:·syscalls_found·|·length·==·04791 ········when:·syscalls_found·|·length·==·0
4792 ······when:4792 ······when:
4793 ······-·'"audit"·in·ansible_facts.packages' 
4794 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4793 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4794 ······-·'"audit"·in·ansible_facts.packages'
4795 ······tags:4795 ······tags:
4796 ······-·CJIS-5.4.1.14796 ······-·CJIS-5.4.1.1
4797 ······-·NIST-800-171-3.1.74797 ······-·NIST-800-171-3.1.7
4798 ······-·NIST-800-53-AC-6(9)4798 ······-·NIST-800-53-AC-6(9)
4799 ······-·NIST-800-53-AU-12(c)4799 ······-·NIST-800-53-AU-12(c)
4800 ······-·NIST-800-53-AU-2(d)4800 ······-·NIST-800-53-AU-2(d)
4801 ······-·NIST-800-53-CM-6(a)4801 ······-·NIST-800-53-CM-6(a)
Offset 4926, 16 lines modifiedOffset 4926, 16 lines modified
4926 ··········path:·'{{·audit_file·}}'4926 ··········path:·'{{·audit_file·}}'
4927 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification4927 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
4928 ··········create:·true4928 ··········create:·true
4929 ··········mode:·o-rwx4929 ··········mode:·o-rwx
4930 ··········state:·present4930 ··········state:·present
4931 ········when:·syscalls_found·|·length·==·04931 ········when:·syscalls_found·|·length·==·0
4932 ······when:4932 ······when:
4933 ······-·'"audit"·in·ansible_facts.packages' 
4934 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4933 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4934 ······-·'"audit"·in·ansible_facts.packages'
4935 ······-·audit_arch·==·"b64"4935 ······-·audit_arch·==·"b64"
4936 ······tags:4936 ······tags:
4937 ······-·CJIS-5.4.1.14937 ······-·CJIS-5.4.1.1
4938 ······-·NIST-800-171-3.1.74938 ······-·NIST-800-171-3.1.7
4939 ······-·NIST-800-53-AC-6(9)4939 ······-·NIST-800-53-AC-6(9)
4940 ······-·NIST-800-53-AU-12(c)4940 ······-·NIST-800-53-AU-12(c)
4941 ······-·NIST-800-53-AU-2(d)4941 ······-·NIST-800-53-AU-2(d)
Offset 4951, 16 lines modifiedOffset 4951, 16 lines modified
4951 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/4951 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
4952 ······find:4952 ······find:
4953 ········paths:·/etc/audit/rules.d4953 ········paths:·/etc/audit/rules.d
4954 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+4954 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
4955 ········patterns:·'*.rules'4955 ········patterns:·'*.rules'
4956 ······register:·find_existing_watch_rules_d4956 ······register:·find_existing_watch_rules_d
4957 ······when:4957 ······when:
4958 ······-·'"audit"·in·ansible_facts.packages' 
4959 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4958 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4959 ······-·'"audit"·in·ansible_facts.packages'
4960 ······tags:4960 ······tags:
4961 ······-·CJIS-5.4.1.14961 ······-·CJIS-5.4.1.1
4962 ······-·NIST-800-171-3.1.74962 ······-·NIST-800-171-3.1.7
4963 ······-·NIST-800-53-AC-6(9)4963 ······-·NIST-800-53-AC-6(9)
4964 ······-·NIST-800-53-AU-12(c)4964 ······-·NIST-800-53-AU-12(c)
4965 ······-·NIST-800-53-AU-2(d)4965 ······-·NIST-800-53-AU-2(d)
4966 ······-·NIST-800-53-CM-6(a)4966 ······-·NIST-800-53-CM-6(a)
Offset 4975, 16 lines modifiedOffset 4975, 16 lines modified
4975 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification4975 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
4976 ······find:4976 ······find:
4977 ········paths:·/etc/audit/rules.d4977 ········paths:·/etc/audit/rules.d
4978 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$4978 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
4979 ········patterns:·'*.rules'4979 ········patterns:·'*.rules'
4980 ······register:·find_watch_key4980 ······register:·find_watch_key
4981 ······when:4981 ······when:
4982 ······-·'"audit"·in·ansible_facts.packages' 
4983 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4982 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4983 ······-·'"audit"·in·ansible_facts.packages'
4984 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4984 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4985 ········==·04985 ········==·0
4986 ······tags:4986 ······tags:
4987 ······-·CJIS-5.4.1.14987 ······-·CJIS-5.4.1.1
4988 ······-·NIST-800-171-3.1.74988 ······-·NIST-800-171-3.1.7
4989 ······-·NIST-800-53-AC-6(9)4989 ······-·NIST-800-53-AC-6(9)
4990 ······-·NIST-800-53-AU-12(c)4990 ······-·NIST-800-53-AU-12(c)
Offset 5000, 16 lines modifiedOffset 5000, 16 lines modified
  
5000 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the5000 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
5001 ········recipient·for·the·rule5001 ········recipient·for·the·rule
5002 ······set_fact:5002 ······set_fact:
5003 ········all_files:5003 ········all_files:
5004 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules5004 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
5005 ······when:5005 ······when:
5006 ······-·'"audit"·in·ansible_facts.packages' 
5007 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5006 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5007 ······-·'"audit"·in·ansible_facts.packages'
5008 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5008 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5009 ········is·defined·and·find_existing_watch_rules_d.matched·==·05009 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5010 ······tags:5010 ······tags:
5011 ······-·CJIS-5.4.1.15011 ······-·CJIS-5.4.1.1
5012 ······-·NIST-800-171-3.1.75012 ······-·NIST-800-171-3.1.7
5013 ······-·NIST-800-53-AC-6(9)5013 ······-·NIST-800-53-AC-6(9)
5014 ······-·NIST-800-53-AU-12(c)5014 ······-·NIST-800-53-AU-12(c)
Offset 5024, 16 lines modifiedOffset 5024, 16 lines modified
5024 ······-·restrict_strategy5024 ······-·restrict_strategy
  
5025 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5025 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5026 ······set_fact:5026 ······set_fact:
5027 ········all_files:5027 ········all_files:
5028 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5028 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5029 ······when:5029 ······when:
5030 ······-·'"audit"·in·ansible_facts.packages' 
5031 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5030 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5031 ······-·'"audit"·in·ansible_facts.packages'
5032 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5032 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5033 ········is·defined·and·find_existing_watch_rules_d.matched·==·05033 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5034 ······tags:5034 ······tags:
5035 ······-·CJIS-5.4.1.15035 ······-·CJIS-5.4.1.1
5036 ······-·NIST-800-171-3.1.75036 ······-·NIST-800-171-3.1.7
5037 ······-·NIST-800-53-AC-6(9)5037 ······-·NIST-800-53-AC-6(9)
5038 ······-·NIST-800-53-AU-12(c)5038 ······-·NIST-800-53-AU-12(c)
Offset 5050, 16 lines modifiedOffset 5050, 16 lines modified
5050 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/5050 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 83630/88680 bytes (94.31%) of diff not shown.
3.57 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-ospp.yml
Ordering differences only
    
Offset 4831, 16 lines modifiedOffset 4831, 16 lines modified
4831 ······lineinfile:4831 ······lineinfile:
4832 ········dest:·/etc/audit/auditd.conf4832 ········dest:·/etc/audit/auditd.conf
4833 ········regexp:·^\s*flush\s*=\s*.*$4833 ········regexp:·^\s*flush\s*=\s*.*$
4834 ········line:·flush·=·{{·var_auditd_flush·}}4834 ········line:·flush·=·{{·var_auditd_flush·}}
4835 ········state:·present4835 ········state:·present
4836 ········create:·true4836 ········create:·true
4837 ······when:4837 ······when:
4838 ······-·'"audit"·in·ansible_facts.packages' 
4839 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4838 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4839 ······-·'"audit"·in·ansible_facts.packages'
4840 ······tags:4840 ······tags:
4841 ······-·NIST-800-171-3.3.14841 ······-·NIST-800-171-3.3.1
4842 ······-·NIST-800-53-AU-114842 ······-·NIST-800-53-AU-11
4843 ······-·NIST-800-53-CM-6(a)4843 ······-·NIST-800-53-CM-6(a)
4844 ······-·auditd_data_retention_flush4844 ······-·auditd_data_retention_flush
4845 ······-·low_complexity4845 ······-·low_complexity
4846 ······-·low_disruption4846 ······-·low_disruption
Offset 4886, 16 lines modifiedOffset 4886, 16 lines modified
4886 ········lineinfile:4886 ········lineinfile:
4887 ··········path:·/etc/audit/auditd.conf4887 ··········path:·/etc/audit/auditd.conf
4888 ··········create:·true4888 ··········create:·true
4889 ··········regexp:·(?i)^\s*freq\s*=\s*4889 ··········regexp:·(?i)^\s*freq\s*=\s*
4890 ··········line:·freq·=·504890 ··········line:·freq·=·50
4891 ··········state:·present4891 ··········state:·present
4892 ······when:4892 ······when:
4893 ······-·'"audit"·in·ansible_facts.packages' 
4894 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4893 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4894 ······-·'"audit"·in·ansible_facts.packages'
4895 ······tags:4895 ······tags:
4896 ······-·NIST-800-53-CM-64896 ······-·NIST-800-53-CM-6
4897 ······-·auditd_freq4897 ······-·auditd_freq
4898 ······-·low_complexity4898 ······-·low_complexity
4899 ······-·low_disruption4899 ······-·low_disruption
4900 ······-·medium_severity4900 ······-·medium_severity
4901 ······-·no_reboot_needed4901 ······-·no_reboot_needed
Offset 4940, 16 lines modifiedOffset 4940, 16 lines modified
4940 ········lineinfile:4940 ········lineinfile:
4941 ··········path:·/etc/audit/auditd.conf4941 ··········path:·/etc/audit/auditd.conf
4942 ··········create:·true4942 ··········create:·true
4943 ··········regexp:·(?i)^\s*local_events\s*=\s*4943 ··········regexp:·(?i)^\s*local_events\s*=\s*
4944 ··········line:·local_events·=·yes4944 ··········line:·local_events·=·yes
4945 ··········state:·present4945 ··········state:·present
4946 ······when:4946 ······when:
4947 ······-·'"audit"·in·ansible_facts.packages' 
4948 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4947 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4948 ······-·'"audit"·in·ansible_facts.packages'
4949 ······tags:4949 ······tags:
4950 ······-·DISA-STIG-RHEL-08-0300614950 ······-·DISA-STIG-RHEL-08-030061
4951 ······-·NIST-800-53-CM-64951 ······-·NIST-800-53-CM-6
4952 ······-·auditd_local_events4952 ······-·auditd_local_events
4953 ······-·low_complexity4953 ······-·low_complexity
4954 ······-·low_disruption4954 ······-·low_disruption
4955 ······-·medium_severity4955 ······-·medium_severity
Offset 4996, 16 lines modifiedOffset 4996, 16 lines modified
4996 ········lineinfile:4996 ········lineinfile:
4997 ··········path:·/etc/audit/auditd.conf4997 ··········path:·/etc/audit/auditd.conf
4998 ··········create:·true4998 ··········create:·true
4999 ··········regexp:·(?i)^\s*log_format\s*=\s*4999 ··········regexp:·(?i)^\s*log_format\s*=\s*
5000 ··········line:·log_format·=·ENRICHED5000 ··········line:·log_format·=·ENRICHED
5001 ··········state:·present5001 ··········state:·present
5002 ······when:5002 ······when:
5003 ······-·'"audit"·in·ansible_facts.packages' 
5004 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5003 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5004 ······-·'"audit"·in·ansible_facts.packages'
5005 ······tags:5005 ······tags:
5006 ······-·DISA-STIG-RHEL-08-0300635006 ······-·DISA-STIG-RHEL-08-030063
5007 ······-·NIST-800-53-AU-35007 ······-·NIST-800-53-AU-3
5008 ······-·NIST-800-53-CM-65008 ······-·NIST-800-53-CM-6
5009 ······-·auditd_log_format5009 ······-·auditd_log_format
5010 ······-·low_complexity5010 ······-·low_complexity
5011 ······-·low_disruption5011 ······-·low_disruption
Offset 5053, 16 lines modifiedOffset 5053, 16 lines modified
5053 ········lineinfile:5053 ········lineinfile:
5054 ··········path:·/etc/audit/auditd.conf5054 ··········path:·/etc/audit/auditd.conf
5055 ··········create:·true5055 ··········create:·true
5056 ··········regexp:·(?i)^\s*name_format\s*=\s*5056 ··········regexp:·(?i)^\s*name_format\s*=\s*
5057 ··········line:·name_format·=·hostname5057 ··········line:·name_format·=·hostname
5058 ··········state:·present5058 ··········state:·present
5059 ······when:5059 ······when:
5060 ······-·'"audit"·in·ansible_facts.packages' 
5061 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5060 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5061 ······-·'"audit"·in·ansible_facts.packages'
5062 ······tags:5062 ······tags:
5063 ······-·DISA-STIG-RHEL-08-0300625063 ······-·DISA-STIG-RHEL-08-030062
5064 ······-·NIST-800-53-AU-35064 ······-·NIST-800-53-AU-3
5065 ······-·NIST-800-53-CM-65065 ······-·NIST-800-53-CM-6
5066 ······-·auditd_name_format5066 ······-·auditd_name_format
5067 ······-·low_complexity5067 ······-·low_complexity
5068 ······-·low_disruption5068 ······-·low_disruption
Offset 5108, 16 lines modifiedOffset 5108, 16 lines modified
5108 ········lineinfile:5108 ········lineinfile:
5109 ··········path:·/etc/audit/auditd.conf5109 ··········path:·/etc/audit/auditd.conf
5110 ··········create:·true5110 ··········create:·true
5111 ··········regexp:·(?i)^\s*write_logs\s*=\s*5111 ··········regexp:·(?i)^\s*write_logs\s*=\s*
5112 ··········line:·write_logs·=·yes5112 ··········line:·write_logs·=·yes
5113 ··········state:·present5113 ··········state:·present
5114 ······when:5114 ······when:
5115 ······-·'"audit"·in·ansible_facts.packages' 
5116 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5115 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5116 ······-·'"audit"·in·ansible_facts.packages'
5117 ······tags:5117 ······tags:
5118 ······-·NIST-800-53-CM-65118 ······-·NIST-800-53-CM-6
5119 ······-·auditd_write_logs5119 ······-·auditd_write_logs
5120 ······-·low_complexity5120 ······-·low_complexity
5121 ······-·low_disruption5121 ······-·low_disruption
5122 ······-·medium_severity5122 ······-·medium_severity
5123 ······-·no_reboot_needed5123 ······-·no_reboot_needed
160 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-pci-dss.yml
Ordering differences only
    
Offset 5162, 16 lines modifiedOffset 5162, 16 lines modified
  
5162 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5162 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5163 ······find:5163 ······find:
5164 ········paths:·/etc/audit/rules.d/5164 ········paths:·/etc/audit/rules.d/
5165 ········patterns:·'*.rules'5165 ········patterns:·'*.rules'
5166 ······register:·find_rules_d5166 ······register:·find_rules_d
5167 ······when:5167 ······when:
5168 ······-·'"audit"·in·ansible_facts.packages' 
5169 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5168 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5169 ······-·'"audit"·in·ansible_facts.packages'
5170 ······tags:5170 ······tags:
5171 ······-·CJIS-5.4.1.15171 ······-·CJIS-5.4.1.1
5172 ······-·DISA-STIG-RHEL-08-0301215172 ······-·DISA-STIG-RHEL-08-030121
5173 ······-·NIST-800-171-3.3.15173 ······-·NIST-800-171-3.3.1
5174 ······-·NIST-800-171-3.4.35174 ······-·NIST-800-171-3.4.3
5175 ······-·NIST-800-53-AC-6(9)5175 ······-·NIST-800-53-AC-6(9)
5176 ······-·NIST-800-53-CM-6(a)5176 ······-·NIST-800-53-CM-6(a)
Offset 5187, 16 lines modifiedOffset 5187, 16 lines modified
5187 ······lineinfile:5187 ······lineinfile:
5188 ········path:·'{{·item·}}'5188 ········path:·'{{·item·}}'
5189 ········regexp:·^\s*(?:-e)\s+.*$5189 ········regexp:·^\s*(?:-e)\s+.*$
5190 ········state:·absent5190 ········state:·absent
5191 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5191 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5192 ········}}'5192 ········}}'
5193 ······when:5193 ······when:
5194 ······-·'"audit"·in·ansible_facts.packages' 
5195 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5194 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5195 ······-·'"audit"·in·ansible_facts.packages'
5196 ······tags:5196 ······tags:
5197 ······-·CJIS-5.4.1.15197 ······-·CJIS-5.4.1.1
5198 ······-·DISA-STIG-RHEL-08-0301215198 ······-·DISA-STIG-RHEL-08-030121
5199 ······-·NIST-800-171-3.3.15199 ······-·NIST-800-171-3.3.1
5200 ······-·NIST-800-171-3.4.35200 ······-·NIST-800-171-3.4.3
5201 ······-·NIST-800-53-AC-6(9)5201 ······-·NIST-800-53-AC-6(9)
5202 ······-·NIST-800-53-CM-6(a)5202 ······-·NIST-800-53-CM-6(a)
Offset 5214, 16 lines modifiedOffset 5214, 16 lines modified
5214 ········create:·true5214 ········create:·true
5215 ········line:·-e·25215 ········line:·-e·2
5216 ········mode:·o-rwx5216 ········mode:·o-rwx
5217 ······loop:5217 ······loop:
5218 ······-·/etc/audit/audit.rules5218 ······-·/etc/audit/audit.rules
5219 ······-·/etc/audit/rules.d/immutable.rules5219 ······-·/etc/audit/rules.d/immutable.rules
5220 ······when:5220 ······when:
5221 ······-·'"audit"·in·ansible_facts.packages' 
5222 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5221 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5222 ······-·'"audit"·in·ansible_facts.packages'
5223 ······tags:5223 ······tags:
5224 ······-·CJIS-5.4.1.15224 ······-·CJIS-5.4.1.1
5225 ······-·DISA-STIG-RHEL-08-0301215225 ······-·DISA-STIG-RHEL-08-030121
5226 ······-·NIST-800-171-3.3.15226 ······-·NIST-800-171-3.3.1
5227 ······-·NIST-800-171-3.4.35227 ······-·NIST-800-171-3.4.3
5228 ······-·NIST-800-53-AC-6(9)5228 ······-·NIST-800-53-AC-6(9)
5229 ······-·NIST-800-53-CM-6(a)5229 ······-·NIST-800-53-CM-6(a)
Offset 5256, 16 lines modifiedOffset 5256, 16 lines modified
5256 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5256 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5257 ······find:5257 ······find:
5258 ········paths:·/etc/audit/rules.d5258 ········paths:·/etc/audit/rules.d
5259 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5259 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5260 ········patterns:·'*.rules'5260 ········patterns:·'*.rules'
5261 ······register:·find_existing_watch_rules_d5261 ······register:·find_existing_watch_rules_d
5262 ······when:5262 ······when:
5263 ······-·'"audit"·in·ansible_facts.packages' 
5264 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5263 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5264 ······-·'"audit"·in·ansible_facts.packages'
5265 ······tags:5265 ······tags:
5266 ······-·CJIS-5.4.1.15266 ······-·CJIS-5.4.1.1
5267 ······-·NIST-800-171-3.1.85267 ······-·NIST-800-171-3.1.8
5268 ······-·NIST-800-53-AU-12(c)5268 ······-·NIST-800-53-AU-12(c)
5269 ······-·NIST-800-53-AU-2(d)5269 ······-·NIST-800-53-AU-2(d)
5270 ······-·NIST-800-53-CM-6(a)5270 ······-·NIST-800-53-CM-6(a)
5271 ······-·PCI-DSS-Req-10.5.55271 ······-·PCI-DSS-Req-10.5.5
Offset 5279, 16 lines modifiedOffset 5279, 16 lines modified
5279 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5279 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5280 ······find:5280 ······find:
5281 ········paths:·/etc/audit/rules.d5281 ········paths:·/etc/audit/rules.d
5282 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5282 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5283 ········patterns:·'*.rules'5283 ········patterns:·'*.rules'
5284 ······register:·find_watch_key5284 ······register:·find_watch_key
5285 ······when:5285 ······when:
5286 ······-·'"audit"·in·ansible_facts.packages' 
5287 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5286 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5287 ······-·'"audit"·in·ansible_facts.packages'
5288 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5288 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5289 ········==·05289 ········==·0
5290 ······tags:5290 ······tags:
5291 ······-·CJIS-5.4.1.15291 ······-·CJIS-5.4.1.1
5292 ······-·NIST-800-171-3.1.85292 ······-·NIST-800-171-3.1.8
5293 ······-·NIST-800-53-AU-12(c)5293 ······-·NIST-800-53-AU-12(c)
5294 ······-·NIST-800-53-AU-2(d)5294 ······-·NIST-800-53-AU-2(d)
Offset 5302, 16 lines modifiedOffset 5302, 16 lines modified
5302 ······-·restrict_strategy5302 ······-·restrict_strategy
  
5303 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5303 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5304 ······set_fact:5304 ······set_fact:
5305 ········all_files:5305 ········all_files:
5306 ········-·/etc/audit/rules.d/MAC-policy.rules5306 ········-·/etc/audit/rules.d/MAC-policy.rules
5307 ······when:5307 ······when:
5308 ······-·'"audit"·in·ansible_facts.packages' 
5309 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5308 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5309 ······-·'"audit"·in·ansible_facts.packages'
5310 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5310 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5311 ········is·defined·and·find_existing_watch_rules_d.matched·==·05311 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5312 ······tags:5312 ······tags:
5313 ······-·CJIS-5.4.1.15313 ······-·CJIS-5.4.1.1
5314 ······-·NIST-800-171-3.1.85314 ······-·NIST-800-171-3.1.8
5315 ······-·NIST-800-53-AU-12(c)5315 ······-·NIST-800-53-AU-12(c)
5316 ······-·NIST-800-53-AU-2(d)5316 ······-·NIST-800-53-AU-2(d)
Offset 5325, 16 lines modifiedOffset 5325, 16 lines modified
5325 ······-·restrict_strategy5325 ······-·restrict_strategy
  
5326 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5326 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5327 ······set_fact:5327 ······set_fact:
5328 ········all_files:5328 ········all_files:
5329 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5329 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5330 ······when:5330 ······when:
5331 ······-·'"audit"·in·ansible_facts.packages' 
5332 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5331 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5332 ······-·'"audit"·in·ansible_facts.packages'
5333 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5333 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5334 ········is·defined·and·find_existing_watch_rules_d.matched·==·05334 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5335 ······tags:5335 ······tags:
5336 ······-·CJIS-5.4.1.15336 ······-·CJIS-5.4.1.1
5337 ······-·NIST-800-171-3.1.85337 ······-·NIST-800-171-3.1.8
5338 ······-·NIST-800-53-AU-12(c)5338 ······-·NIST-800-53-AU-12(c)
5339 ······-·NIST-800-53-AU-2(d)5339 ······-·NIST-800-53-AU-2(d)
Offset 5350, 16 lines modifiedOffset 5350, 16 lines modified
5350 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5350 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 158724/163427 bytes (97.12%) of diff not shown.
3.93 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-rht-ccp.yml
Ordering differences only
    
Offset 3210, 16 lines modifiedOffset 3210, 16 lines modified
3210 ······-·no_reboot_needed3210 ······-·no_reboot_needed
  
3211 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg3211 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
3212 ······stat:3212 ······stat:
3213 ········path:·/boot/grub2/grub.cfg3213 ········path:·/boot/grub2/grub.cfg
3214 ······register:·file_exists3214 ······register:·file_exists
3215 ······when:3215 ······when:
3216 ······-·'"grub2-common"·in·ansible_facts.packages' 
3217 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3216 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3217 ······-·'"grub2-common"·in·ansible_facts.packages'
3218 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3218 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3219 ······tags:3219 ······tags:
3220 ······-·CJIS-5.5.2.23220 ······-·CJIS-5.5.2.2
3221 ······-·NIST-800-171-3.4.53221 ······-·NIST-800-171-3.4.5
3222 ······-·NIST-800-53-AC-6(1)3222 ······-·NIST-800-53-AC-6(1)
3223 ······-·NIST-800-53-CM-6(a)3223 ······-·NIST-800-53-CM-6(a)
3224 ······-·PCI-DSS-Req-7.13224 ······-·PCI-DSS-Req-7.1
Offset 3231, 16 lines modifiedOffset 3231, 16 lines modified
3231 ······-·no_reboot_needed3231 ······-·no_reboot_needed
  
3232 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg3232 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
3233 ······file:3233 ······file:
3234 ········path:·/boot/grub2/grub.cfg3234 ········path:·/boot/grub2/grub.cfg
3235 ········group:·'0'3235 ········group:·'0'
3236 ······when:3236 ······when:
3237 ······-·'"grub2-common"·in·ansible_facts.packages' 
3238 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3237 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3238 ······-·'"grub2-common"·in·ansible_facts.packages'
3239 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3239 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3240 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists3240 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
3241 ······tags:3241 ······tags:
3242 ······-·CJIS-5.5.2.23242 ······-·CJIS-5.5.2.2
3243 ······-·NIST-800-171-3.4.53243 ······-·NIST-800-171-3.4.5
3244 ······-·NIST-800-53-AC-6(1)3244 ······-·NIST-800-53-AC-6(1)
3245 ······-·NIST-800-53-CM-6(a)3245 ······-·NIST-800-53-CM-6(a)
Offset 3270, 16 lines modifiedOffset 3270, 16 lines modified
3270 ······-·no_reboot_needed3270 ······-·no_reboot_needed
  
3271 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg3271 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
3272 ······stat:3272 ······stat:
3273 ········path:·/boot/grub2/grub.cfg3273 ········path:·/boot/grub2/grub.cfg
3274 ······register:·file_exists3274 ······register:·file_exists
3275 ······when:3275 ······when:
3276 ······-·'"grub2-common"·in·ansible_facts.packages' 
3277 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3276 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3277 ······-·'"grub2-common"·in·ansible_facts.packages'
3278 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3278 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3279 ······tags:3279 ······tags:
3280 ······-·CJIS-5.5.2.23280 ······-·CJIS-5.5.2.2
3281 ······-·NIST-800-171-3.4.53281 ······-·NIST-800-171-3.4.5
3282 ······-·NIST-800-53-AC-6(1)3282 ······-·NIST-800-53-AC-6(1)
3283 ······-·NIST-800-53-CM-6(a)3283 ······-·NIST-800-53-CM-6(a)
3284 ······-·PCI-DSS-Req-7.13284 ······-·PCI-DSS-Req-7.1
Offset 3291, 16 lines modifiedOffset 3291, 16 lines modified
3291 ······-·no_reboot_needed3291 ······-·no_reboot_needed
  
3292 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg3292 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
3293 ······file:3293 ······file:
3294 ········path:·/boot/grub2/grub.cfg3294 ········path:·/boot/grub2/grub.cfg
3295 ········owner:·'0'3295 ········owner:·'0'
3296 ······when:3296 ······when:
3297 ······-·'"grub2-common"·in·ansible_facts.packages' 
3298 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3297 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3298 ······-·'"grub2-common"·in·ansible_facts.packages'
3299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3300 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists3300 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
3301 ······tags:3301 ······tags:
3302 ······-·CJIS-5.5.2.23302 ······-·CJIS-5.5.2.2
3303 ······-·NIST-800-171-3.4.53303 ······-·NIST-800-171-3.4.5
3304 ······-·NIST-800-53-AC-6(1)3304 ······-·NIST-800-53-AC-6(1)
3305 ······-·NIST-800-53-CM-6(a)3305 ······-·NIST-800-53-CM-6(a)
Offset 3328, 16 lines modifiedOffset 3328, 16 lines modified
3328 ······-·no_reboot_needed3328 ······-·no_reboot_needed
  
3329 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg3329 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
3330 ······stat:3330 ······stat:
3331 ········path:·/boot/grub2/grub.cfg3331 ········path:·/boot/grub2/grub.cfg
3332 ······register:·file_exists3332 ······register:·file_exists
3333 ······when:3333 ······when:
3334 ······-·'"grub2-common"·in·ansible_facts.packages' 
3335 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3334 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3335 ······-·'"grub2-common"·in·ansible_facts.packages'
3336 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3336 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3337 ······tags:3337 ······tags:
3338 ······-·NIST-800-171-3.4.53338 ······-·NIST-800-171-3.4.5
3339 ······-·NIST-800-53-AC-6(1)3339 ······-·NIST-800-53-AC-6(1)
3340 ······-·NIST-800-53-CM-6(a)3340 ······-·NIST-800-53-CM-6(a)
3341 ······-·configure_strategy3341 ······-·configure_strategy
3342 ······-·file_permissions_grub2_cfg3342 ······-·file_permissions_grub2_cfg
Offset 3347, 16 lines modifiedOffset 3347, 16 lines modified
3347 ······-·no_reboot_needed3347 ······-·no_reboot_needed
  
3348 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg3348 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg
3349 ······file:3349 ······file:
3350 ········path:·/boot/grub2/grub.cfg3350 ········path:·/boot/grub2/grub.cfg
3351 ········mode:·u-xs,g-xwrs,o-xwrt3351 ········mode:·u-xs,g-xwrs,o-xwrt
3352 ······when:3352 ······when:
3353 ······-·'"grub2-common"·in·ansible_facts.packages' 
3354 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3353 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3354 ······-·'"grub2-common"·in·ansible_facts.packages'
3355 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3355 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3356 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists3356 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
3357 ······tags:3357 ······tags:
3358 ······-·NIST-800-171-3.4.53358 ······-·NIST-800-171-3.4.5
3359 ······-·NIST-800-53-AC-6(1)3359 ······-·NIST-800-53-AC-6(1)
3360 ······-·NIST-800-53-CM-6(a)3360 ······-·NIST-800-53-CM-6(a)
3361 ······-·configure_strategy3361 ······-·configure_strategy
78.9 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-standard.yml
Ordering differences only
    
Offset 817, 16 lines modifiedOffset 817, 16 lines modified
817 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/817 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
818 ······find:818 ······find:
819 ········paths:·/etc/audit/rules.d819 ········paths:·/etc/audit/rules.d
820 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+820 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
821 ········patterns:·'*.rules'821 ········patterns:·'*.rules'
822 ······register:·find_existing_watch_rules_d822 ······register:·find_existing_watch_rules_d
823 ······when:823 ······when:
824 ······-·'"audit"·in·ansible_facts.packages' 
825 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]824 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 825 ······-·'"audit"·in·ansible_facts.packages'
826 ······tags:826 ······tags:
827 ······-·CJIS-5.4.1.1827 ······-·CJIS-5.4.1.1
828 ······-·NIST-800-171-3.1.8828 ······-·NIST-800-171-3.1.8
829 ······-·NIST-800-53-AU-12(c)829 ······-·NIST-800-53-AU-12(c)
830 ······-·NIST-800-53-AU-2(d)830 ······-·NIST-800-53-AU-2(d)
831 ······-·NIST-800-53-CM-6(a)831 ······-·NIST-800-53-CM-6(a)
832 ······-·PCI-DSS-Req-10.5.5832 ······-·PCI-DSS-Req-10.5.5
Offset 840, 16 lines modifiedOffset 840, 16 lines modified
840 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy840 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
841 ······find:841 ······find:
842 ········paths:·/etc/audit/rules.d842 ········paths:·/etc/audit/rules.d
843 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$843 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
844 ········patterns:·'*.rules'844 ········patterns:·'*.rules'
845 ······register:·find_watch_key845 ······register:·find_watch_key
846 ······when:846 ······when:
847 ······-·'"audit"·in·ansible_facts.packages' 
848 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]847 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 848 ······-·'"audit"·in·ansible_facts.packages'
849 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched849 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
850 ········==·0850 ········==·0
851 ······tags:851 ······tags:
852 ······-·CJIS-5.4.1.1852 ······-·CJIS-5.4.1.1
853 ······-·NIST-800-171-3.1.8853 ······-·NIST-800-171-3.1.8
854 ······-·NIST-800-53-AU-12(c)854 ······-·NIST-800-53-AU-12(c)
855 ······-·NIST-800-53-AU-2(d)855 ······-·NIST-800-53-AU-2(d)
Offset 863, 16 lines modifiedOffset 863, 16 lines modified
863 ······-·restrict_strategy863 ······-·restrict_strategy
  
864 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule864 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
865 ······set_fact:865 ······set_fact:
866 ········all_files:866 ········all_files:
867 ········-·/etc/audit/rules.d/MAC-policy.rules867 ········-·/etc/audit/rules.d/MAC-policy.rules
868 ······when:868 ······when:
869 ······-·'"audit"·in·ansible_facts.packages' 
870 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]869 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 870 ······-·'"audit"·in·ansible_facts.packages'
871 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched871 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
872 ········is·defined·and·find_existing_watch_rules_d.matched·==·0872 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
873 ······tags:873 ······tags:
874 ······-·CJIS-5.4.1.1874 ······-·CJIS-5.4.1.1
875 ······-·NIST-800-171-3.1.8875 ······-·NIST-800-171-3.1.8
876 ······-·NIST-800-53-AU-12(c)876 ······-·NIST-800-53-AU-12(c)
877 ······-·NIST-800-53-AU-2(d)877 ······-·NIST-800-53-AU-2(d)
Offset 886, 16 lines modifiedOffset 886, 16 lines modified
886 ······-·restrict_strategy886 ······-·restrict_strategy
  
887 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule887 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
888 ······set_fact:888 ······set_fact:
889 ········all_files:889 ········all_files:
890 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'890 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
891 ······when:891 ······when:
892 ······-·'"audit"·in·ansible_facts.packages' 
893 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]892 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 893 ······-·'"audit"·in·ansible_facts.packages'
894 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched894 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
895 ········is·defined·and·find_existing_watch_rules_d.matched·==·0895 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
896 ······tags:896 ······tags:
897 ······-·CJIS-5.4.1.1897 ······-·CJIS-5.4.1.1
898 ······-·NIST-800-171-3.1.8898 ······-·NIST-800-171-3.1.8
899 ······-·NIST-800-53-AU-12(c)899 ······-·NIST-800-53-AU-12(c)
900 ······-·NIST-800-53-AU-2(d)900 ······-·NIST-800-53-AU-2(d)
Offset 911, 16 lines modifiedOffset 911, 16 lines modified
911 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/911 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
912 ······lineinfile:912 ······lineinfile:
913 ········path:·'{{·all_files[0]·}}'913 ········path:·'{{·all_files[0]·}}'
914 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy914 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
915 ········create:·true915 ········create:·true
916 ········mode:·'0640'916 ········mode:·'0640'
917 ······when:917 ······when:
918 ······-·'"audit"·in·ansible_facts.packages' 
919 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]918 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 919 ······-·'"audit"·in·ansible_facts.packages'
920 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched920 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
921 ········==·0921 ········==·0
922 ······tags:922 ······tags:
923 ······-·CJIS-5.4.1.1923 ······-·CJIS-5.4.1.1
924 ······-·NIST-800-171-3.1.8924 ······-·NIST-800-171-3.1.8
925 ······-·NIST-800-53-AU-12(c)925 ······-·NIST-800-53-AU-12(c)
926 ······-·NIST-800-53-AU-2(d)926 ······-·NIST-800-53-AU-2(d)
Offset 936, 16 lines modifiedOffset 936, 16 lines modified
936 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules936 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules
937 ······find:937 ······find:
938 ········paths:·/etc/audit/938 ········paths:·/etc/audit/
939 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+939 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
940 ········patterns:·audit.rules940 ········patterns:·audit.rules
941 ······register:·find_existing_watch_audit_rules941 ······register:·find_existing_watch_audit_rules
942 ······when:942 ······when:
943 ······-·'"audit"·in·ansible_facts.packages' 
944 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]943 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 944 ······-·'"audit"·in·ansible_facts.packages'
945 ······tags:945 ······tags:
946 ······-·CJIS-5.4.1.1946 ······-·CJIS-5.4.1.1
947 ······-·NIST-800-171-3.1.8947 ······-·NIST-800-171-3.1.8
948 ······-·NIST-800-53-AU-12(c)948 ······-·NIST-800-53-AU-12(c)
949 ······-·NIST-800-53-AU-2(d)949 ······-·NIST-800-53-AU-2(d)
950 ······-·NIST-800-53-CM-6(a)950 ······-·NIST-800-53-CM-6(a)
951 ······-·PCI-DSS-Req-10.5.5951 ······-·PCI-DSS-Req-10.5.5
Offset 960, 16 lines modifiedOffset 960, 16 lines modified
960 ······lineinfile:960 ······lineinfile:
961 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy961 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
962 ········state:·present962 ········state:·present
963 ········dest:·/etc/audit/audit.rules963 ········dest:·/etc/audit/audit.rules
964 ········create:·true964 ········create:·true
965 ········mode:·'0640'965 ········mode:·'0640'
966 ······when:966 ······when:
967 ······-·'"audit"·in·ansible_facts.packages' 
968 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]967 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 968 ······-·'"audit"·in·ansible_facts.packages'
969 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched969 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
970 ········==·0970 ········==·0
971 ······tags:971 ······tags:
972 ······-·CJIS-5.4.1.1972 ······-·CJIS-5.4.1.1
973 ······-·NIST-800-171-3.1.8973 ······-·NIST-800-171-3.1.8
974 ······-·NIST-800-53-AU-12(c)974 ······-·NIST-800-53-AU-12(c)
975 ······-·NIST-800-53-AU-2(d)975 ······-·NIST-800-53-AU-2(d)
Offset 1002, 16 lines modifiedOffset 1002, 16 lines modified
1002 ······-·reboot_required1002 ······-·reboot_required
Max diff block lines reached; 75801/80669 bytes (93.97%) of diff not shown.
131 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-stig.yml
Ordering differences only
    
Offset 11479, 16 lines modifiedOffset 11479, 16 lines modified
  
11479 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension11479 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
11480 ······find:11480 ······find:
11481 ········paths:·/etc/audit/rules.d/11481 ········paths:·/etc/audit/rules.d/
11482 ········patterns:·'*.rules'11482 ········patterns:·'*.rules'
11483 ······register:·find_rules_d11483 ······register:·find_rules_d
11484 ······when:11484 ······when:
11485 ······-·'"audit"·in·ansible_facts.packages' 
11486 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11485 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11486 ······-·'"audit"·in·ansible_facts.packages'
11487 ······tags:11487 ······tags:
11488 ······-·CJIS-5.4.1.111488 ······-·CJIS-5.4.1.1
11489 ······-·DISA-STIG-RHEL-08-03012111489 ······-·DISA-STIG-RHEL-08-030121
11490 ······-·NIST-800-171-3.3.111490 ······-·NIST-800-171-3.3.1
11491 ······-·NIST-800-171-3.4.311491 ······-·NIST-800-171-3.4.3
11492 ······-·NIST-800-53-AC-6(9)11492 ······-·NIST-800-53-AC-6(9)
11493 ······-·NIST-800-53-CM-6(a)11493 ······-·NIST-800-53-CM-6(a)
Offset 11504, 16 lines modifiedOffset 11504, 16 lines modified
11504 ······lineinfile:11504 ······lineinfile:
11505 ········path:·'{{·item·}}'11505 ········path:·'{{·item·}}'
11506 ········regexp:·^\s*(?:-e)\s+.*$11506 ········regexp:·^\s*(?:-e)\s+.*$
11507 ········state:·absent11507 ········state:·absent
11508 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']11508 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
11509 ········}}'11509 ········}}'
11510 ······when:11510 ······when:
11511 ······-·'"audit"·in·ansible_facts.packages' 
11512 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11511 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11512 ······-·'"audit"·in·ansible_facts.packages'
11513 ······tags:11513 ······tags:
11514 ······-·CJIS-5.4.1.111514 ······-·CJIS-5.4.1.1
11515 ······-·DISA-STIG-RHEL-08-03012111515 ······-·DISA-STIG-RHEL-08-030121
11516 ······-·NIST-800-171-3.3.111516 ······-·NIST-800-171-3.3.1
11517 ······-·NIST-800-171-3.4.311517 ······-·NIST-800-171-3.4.3
11518 ······-·NIST-800-53-AC-6(9)11518 ······-·NIST-800-53-AC-6(9)
11519 ······-·NIST-800-53-CM-6(a)11519 ······-·NIST-800-53-CM-6(a)
Offset 11531, 16 lines modifiedOffset 11531, 16 lines modified
11531 ········create:·true11531 ········create:·true
11532 ········line:·-e·211532 ········line:·-e·2
11533 ········mode:·o-rwx11533 ········mode:·o-rwx
11534 ······loop:11534 ······loop:
11535 ······-·/etc/audit/audit.rules11535 ······-·/etc/audit/audit.rules
11536 ······-·/etc/audit/rules.d/immutable.rules11536 ······-·/etc/audit/rules.d/immutable.rules
11537 ······when:11537 ······when:
11538 ······-·'"audit"·in·ansible_facts.packages' 
11539 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11538 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11539 ······-·'"audit"·in·ansible_facts.packages'
11540 ······tags:11540 ······tags:
11541 ······-·CJIS-5.4.1.111541 ······-·CJIS-5.4.1.1
11542 ······-·DISA-STIG-RHEL-08-03012111542 ······-·DISA-STIG-RHEL-08-030121
11543 ······-·NIST-800-171-3.3.111543 ······-·NIST-800-171-3.3.1
11544 ······-·NIST-800-171-3.4.311544 ······-·NIST-800-171-3.4.3
11545 ······-·NIST-800-53-AC-6(9)11545 ······-·NIST-800-53-AC-6(9)
11546 ······-·NIST-800-53-CM-6(a)11546 ······-·NIST-800-53-CM-6(a)
Offset 11572, 16 lines modifiedOffset 11572, 16 lines modified
11572 ······-·reboot_required11572 ······-·reboot_required
11573 ······-·restrict_strategy11573 ······-·restrict_strategy
  
11574 ····-·name:·Set·architecture·for·audit·mount·tasks11574 ····-·name:·Set·architecture·for·audit·mount·tasks
11575 ······set_fact:11575 ······set_fact:
11576 ········audit_arch:·b6411576 ········audit_arch:·b64
11577 ······when:11577 ······when:
11578 ······-·'"audit"·in·ansible_facts.packages' 
11579 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11578 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11579 ······-·'"audit"·in·ansible_facts.packages'
11580 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture11580 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
11581 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"11581 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
11582 ······tags:11582 ······tags:
11583 ······-·CJIS-5.4.1.111583 ······-·CJIS-5.4.1.1
11584 ······-·DISA-STIG-RHEL-08-03030211584 ······-·DISA-STIG-RHEL-08-030302
11585 ······-·NIST-800-171-3.1.711585 ······-·NIST-800-171-3.1.7
11586 ······-·NIST-800-53-AC-6(9)11586 ······-·NIST-800-53-AC-6(9)
Offset 11713, 16 lines modifiedOffset 11713, 16 lines modified
11713 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011713 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11714 ············-F·auid!=unset·-F·key=perm_mod11714 ············-F·auid!=unset·-F·key=perm_mod
11715 ··········create:·true11715 ··········create:·true
11716 ··········mode:·o-rwx11716 ··········mode:·o-rwx
11717 ··········state:·present11717 ··········state:·present
11718 ········when:·syscalls_found·|·length·==·011718 ········when:·syscalls_found·|·length·==·0
11719 ······when:11719 ······when:
11720 ······-·'"audit"·in·ansible_facts.packages' 
11721 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11720 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11721 ······-·'"audit"·in·ansible_facts.packages'
11722 ······tags:11722 ······tags:
11723 ······-·CJIS-5.4.1.111723 ······-·CJIS-5.4.1.1
11724 ······-·DISA-STIG-RHEL-08-03030211724 ······-·DISA-STIG-RHEL-08-030302
11725 ······-·NIST-800-171-3.1.711725 ······-·NIST-800-171-3.1.7
11726 ······-·NIST-800-53-AC-6(9)11726 ······-·NIST-800-53-AC-6(9)
11727 ······-·NIST-800-53-AU-12(c)11727 ······-·NIST-800-53-AU-12(c)
11728 ······-·NIST-800-53-AU-2(d)11728 ······-·NIST-800-53-AU-2(d)
Offset 11852, 16 lines modifiedOffset 11852, 16 lines modified
11852 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011852 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11853 ············-F·auid!=unset·-F·key=perm_mod11853 ············-F·auid!=unset·-F·key=perm_mod
11854 ··········create:·true11854 ··········create:·true
11855 ··········mode:·o-rwx11855 ··········mode:·o-rwx
11856 ··········state:·present11856 ··········state:·present
11857 ········when:·syscalls_found·|·length·==·011857 ········when:·syscalls_found·|·length·==·0
11858 ······when:11858 ······when:
11859 ······-·'"audit"·in·ansible_facts.packages' 
11860 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11859 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11860 ······-·'"audit"·in·ansible_facts.packages'
11861 ······-·audit_arch·==·"b64"11861 ······-·audit_arch·==·"b64"
11862 ······tags:11862 ······tags:
11863 ······-·CJIS-5.4.1.111863 ······-·CJIS-5.4.1.1
11864 ······-·DISA-STIG-RHEL-08-03030211864 ······-·DISA-STIG-RHEL-08-030302
11865 ······-·NIST-800-171-3.1.711865 ······-·NIST-800-171-3.1.7
11866 ······-·NIST-800-53-AC-6(9)11866 ······-·NIST-800-53-AC-6(9)
11867 ······-·NIST-800-53-AU-12(c)11867 ······-·NIST-800-53-AU-12(c)
Offset 11891, 16 lines modifiedOffset 11891, 16 lines modified
11891 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/11891 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
11892 ······find:11892 ······find:
11893 ········paths:·/etc/audit/rules.d11893 ········paths:·/etc/audit/rules.d
11894 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+11894 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
11895 ········patterns:·'*.rules'11895 ········patterns:·'*.rules'
11896 ······register:·find_existing_watch_rules_d11896 ······register:·find_existing_watch_rules_d
11897 ······when:11897 ······when:
11898 ······-·'"audit"·in·ansible_facts.packages' 
11899 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11898 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11899 ······-·'"audit"·in·ansible_facts.packages'
11900 ······tags:11900 ······tags:
11901 ······-·DISA-STIG-RHEL-08-03017111901 ······-·DISA-STIG-RHEL-08-030171
11902 ······-·audit_rules_sudoers11902 ······-·audit_rules_sudoers
11903 ······-·low_complexity11903 ······-·low_complexity
11904 ······-·low_disruption11904 ······-·low_disruption
11905 ······-·medium_severity11905 ······-·medium_severity
11906 ······-·no_reboot_needed11906 ······-·no_reboot_needed
Offset 11909, 16 lines modifiedOffset 11909, 16 lines modified
11909 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions11909 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 129021/133595 bytes (96.58%) of diff not shown.
131 KB
./usr/share/scap-security-guide/ansible/centos8-playbook-stig_gui.yml
Ordering differences only
    
Offset 11470, 16 lines modifiedOffset 11470, 16 lines modified
  
11470 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension11470 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
11471 ······find:11471 ······find:
11472 ········paths:·/etc/audit/rules.d/11472 ········paths:·/etc/audit/rules.d/
11473 ········patterns:·'*.rules'11473 ········patterns:·'*.rules'
11474 ······register:·find_rules_d11474 ······register:·find_rules_d
11475 ······when:11475 ······when:
11476 ······-·'"audit"·in·ansible_facts.packages' 
11477 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11476 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11477 ······-·'"audit"·in·ansible_facts.packages'
11478 ······tags:11478 ······tags:
11479 ······-·CJIS-5.4.1.111479 ······-·CJIS-5.4.1.1
11480 ······-·DISA-STIG-RHEL-08-03012111480 ······-·DISA-STIG-RHEL-08-030121
11481 ······-·NIST-800-171-3.3.111481 ······-·NIST-800-171-3.3.1
11482 ······-·NIST-800-171-3.4.311482 ······-·NIST-800-171-3.4.3
11483 ······-·NIST-800-53-AC-6(9)11483 ······-·NIST-800-53-AC-6(9)
11484 ······-·NIST-800-53-CM-6(a)11484 ······-·NIST-800-53-CM-6(a)
Offset 11495, 16 lines modifiedOffset 11495, 16 lines modified
11495 ······lineinfile:11495 ······lineinfile:
11496 ········path:·'{{·item·}}'11496 ········path:·'{{·item·}}'
11497 ········regexp:·^\s*(?:-e)\s+.*$11497 ········regexp:·^\s*(?:-e)\s+.*$
11498 ········state:·absent11498 ········state:·absent
11499 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']11499 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
11500 ········}}'11500 ········}}'
11501 ······when:11501 ······when:
11502 ······-·'"audit"·in·ansible_facts.packages' 
11503 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11502 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11503 ······-·'"audit"·in·ansible_facts.packages'
11504 ······tags:11504 ······tags:
11505 ······-·CJIS-5.4.1.111505 ······-·CJIS-5.4.1.1
11506 ······-·DISA-STIG-RHEL-08-03012111506 ······-·DISA-STIG-RHEL-08-030121
11507 ······-·NIST-800-171-3.3.111507 ······-·NIST-800-171-3.3.1
11508 ······-·NIST-800-171-3.4.311508 ······-·NIST-800-171-3.4.3
11509 ······-·NIST-800-53-AC-6(9)11509 ······-·NIST-800-53-AC-6(9)
11510 ······-·NIST-800-53-CM-6(a)11510 ······-·NIST-800-53-CM-6(a)
Offset 11522, 16 lines modifiedOffset 11522, 16 lines modified
11522 ········create:·true11522 ········create:·true
11523 ········line:·-e·211523 ········line:·-e·2
11524 ········mode:·o-rwx11524 ········mode:·o-rwx
11525 ······loop:11525 ······loop:
11526 ······-·/etc/audit/audit.rules11526 ······-·/etc/audit/audit.rules
11527 ······-·/etc/audit/rules.d/immutable.rules11527 ······-·/etc/audit/rules.d/immutable.rules
11528 ······when:11528 ······when:
11529 ······-·'"audit"·in·ansible_facts.packages' 
11530 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11529 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11530 ······-·'"audit"·in·ansible_facts.packages'
11531 ······tags:11531 ······tags:
11532 ······-·CJIS-5.4.1.111532 ······-·CJIS-5.4.1.1
11533 ······-·DISA-STIG-RHEL-08-03012111533 ······-·DISA-STIG-RHEL-08-030121
11534 ······-·NIST-800-171-3.3.111534 ······-·NIST-800-171-3.3.1
11535 ······-·NIST-800-171-3.4.311535 ······-·NIST-800-171-3.4.3
11536 ······-·NIST-800-53-AC-6(9)11536 ······-·NIST-800-53-AC-6(9)
11537 ······-·NIST-800-53-CM-6(a)11537 ······-·NIST-800-53-CM-6(a)
Offset 11563, 16 lines modifiedOffset 11563, 16 lines modified
11563 ······-·reboot_required11563 ······-·reboot_required
11564 ······-·restrict_strategy11564 ······-·restrict_strategy
  
11565 ····-·name:·Set·architecture·for·audit·mount·tasks11565 ····-·name:·Set·architecture·for·audit·mount·tasks
11566 ······set_fact:11566 ······set_fact:
11567 ········audit_arch:·b6411567 ········audit_arch:·b64
11568 ······when:11568 ······when:
11569 ······-·'"audit"·in·ansible_facts.packages' 
11570 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11569 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11570 ······-·'"audit"·in·ansible_facts.packages'
11571 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture11571 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
11572 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"11572 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
11573 ······tags:11573 ······tags:
11574 ······-·CJIS-5.4.1.111574 ······-·CJIS-5.4.1.1
11575 ······-·DISA-STIG-RHEL-08-03030211575 ······-·DISA-STIG-RHEL-08-030302
11576 ······-·NIST-800-171-3.1.711576 ······-·NIST-800-171-3.1.7
11577 ······-·NIST-800-53-AC-6(9)11577 ······-·NIST-800-53-AC-6(9)
Offset 11704, 16 lines modifiedOffset 11704, 16 lines modified
11704 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011704 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11705 ············-F·auid!=unset·-F·key=perm_mod11705 ············-F·auid!=unset·-F·key=perm_mod
11706 ··········create:·true11706 ··········create:·true
11707 ··········mode:·o-rwx11707 ··········mode:·o-rwx
11708 ··········state:·present11708 ··········state:·present
11709 ········when:·syscalls_found·|·length·==·011709 ········when:·syscalls_found·|·length·==·0
11710 ······when:11710 ······when:
11711 ······-·'"audit"·in·ansible_facts.packages' 
11712 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11711 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11712 ······-·'"audit"·in·ansible_facts.packages'
11713 ······tags:11713 ······tags:
11714 ······-·CJIS-5.4.1.111714 ······-·CJIS-5.4.1.1
11715 ······-·DISA-STIG-RHEL-08-03030211715 ······-·DISA-STIG-RHEL-08-030302
11716 ······-·NIST-800-171-3.1.711716 ······-·NIST-800-171-3.1.7
11717 ······-·NIST-800-53-AC-6(9)11717 ······-·NIST-800-53-AC-6(9)
11718 ······-·NIST-800-53-AU-12(c)11718 ······-·NIST-800-53-AU-12(c)
11719 ······-·NIST-800-53-AU-2(d)11719 ······-·NIST-800-53-AU-2(d)
Offset 11843, 16 lines modifiedOffset 11843, 16 lines modified
11843 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011843 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11844 ············-F·auid!=unset·-F·key=perm_mod11844 ············-F·auid!=unset·-F·key=perm_mod
11845 ··········create:·true11845 ··········create:·true
11846 ··········mode:·o-rwx11846 ··········mode:·o-rwx
11847 ··········state:·present11847 ··········state:·present
11848 ········when:·syscalls_found·|·length·==·011848 ········when:·syscalls_found·|·length·==·0
11849 ······when:11849 ······when:
11850 ······-·'"audit"·in·ansible_facts.packages' 
11851 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11850 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11851 ······-·'"audit"·in·ansible_facts.packages'
11852 ······-·audit_arch·==·"b64"11852 ······-·audit_arch·==·"b64"
11853 ······tags:11853 ······tags:
11854 ······-·CJIS-5.4.1.111854 ······-·CJIS-5.4.1.1
11855 ······-·DISA-STIG-RHEL-08-03030211855 ······-·DISA-STIG-RHEL-08-030302
11856 ······-·NIST-800-171-3.1.711856 ······-·NIST-800-171-3.1.7
11857 ······-·NIST-800-53-AC-6(9)11857 ······-·NIST-800-53-AC-6(9)
11858 ······-·NIST-800-53-AU-12(c)11858 ······-·NIST-800-53-AU-12(c)
Offset 11882, 16 lines modifiedOffset 11882, 16 lines modified
11882 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/11882 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
11883 ······find:11883 ······find:
11884 ········paths:·/etc/audit/rules.d11884 ········paths:·/etc/audit/rules.d
11885 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+11885 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
11886 ········patterns:·'*.rules'11886 ········patterns:·'*.rules'
11887 ······register:·find_existing_watch_rules_d11887 ······register:·find_existing_watch_rules_d
11888 ······when:11888 ······when:
11889 ······-·'"audit"·in·ansible_facts.packages' 
11890 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11889 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11890 ······-·'"audit"·in·ansible_facts.packages'
11891 ······tags:11891 ······tags:
11892 ······-·DISA-STIG-RHEL-08-03017111892 ······-·DISA-STIG-RHEL-08-030171
11893 ······-·audit_rules_sudoers11893 ······-·audit_rules_sudoers
11894 ······-·low_complexity11894 ······-·low_complexity
11895 ······-·low_disruption11895 ······-·low_disruption
11896 ······-·medium_severity11896 ······-·medium_severity
11897 ······-·no_reboot_needed11897 ······-·no_reboot_needed
Offset 11900, 16 lines modifiedOffset 11900, 16 lines modified
11900 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions11900 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 129021/133595 bytes (96.58%) of diff not shown.
870 B
./usr/share/scap-security-guide/ansible/cs9-playbook-anssi_bp28_enhanced.yml
Ordering differences only
    
Offset 5328, 16 lines modifiedOffset 5328, 16 lines modified
5328 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5328 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5329 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5329 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5330 ··········create:·true5330 ··········create:·true
5331 ··········mode:·o-rwx5331 ··········mode:·o-rwx
5332 ··········state:·present5332 ··········state:·present
5333 ········when:·syscalls_found·|·length·==·05333 ········when:·syscalls_found·|·length·==·0
5334 ······when:5334 ······when:
5335 ······-·'"audit"·in·ansible_facts.packages' 
5336 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5335 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5336 ······-·'"audit"·in·ansible_facts.packages'
5337 ······tags:5337 ······tags:
5338 ······-·NIST-800-171-3.1.75338 ······-·NIST-800-171-3.1.7
5339 ······-·NIST-800-53-AC-6(9)5339 ······-·NIST-800-53-AC-6(9)
5340 ······-·NIST-800-53-AU-12(c)5340 ······-·NIST-800-53-AU-12(c)
5341 ······-·NIST-800-53-AU-2(d)5341 ······-·NIST-800-53-AU-2(d)
5342 ······-·NIST-800-53-CM-6(a)5342 ······-·NIST-800-53-CM-6(a)
5343 ······-·audit_rules_privileged_commands_sudo5343 ······-·audit_rules_privileged_commands_sudo
862 B
./usr/share/scap-security-guide/ansible/cs9-playbook-anssi_bp28_high.yml
Ordering differences only
    
Offset 5431, 16 lines modifiedOffset 5431, 16 lines modified
5431 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5431 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5432 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5432 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5433 ··········create:·true5433 ··········create:·true
5434 ··········mode:·o-rwx5434 ··········mode:·o-rwx
5435 ··········state:·present5435 ··········state:·present
5436 ········when:·syscalls_found·|·length·==·05436 ········when:·syscalls_found·|·length·==·0
5437 ······when:5437 ······when:
5438 ······-·'"audit"·in·ansible_facts.packages' 
5439 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5438 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5439 ······-·'"audit"·in·ansible_facts.packages'
5440 ······tags:5440 ······tags:
5441 ······-·NIST-800-171-3.1.75441 ······-·NIST-800-171-3.1.7
5442 ······-·NIST-800-53-AC-6(9)5442 ······-·NIST-800-53-AC-6(9)
5443 ······-·NIST-800-53-AU-12(c)5443 ······-·NIST-800-53-AU-12(c)
5444 ······-·NIST-800-53-AU-2(d)5444 ······-·NIST-800-53-AU-2(d)
5445 ······-·NIST-800-53-CM-6(a)5445 ······-·NIST-800-53-CM-6(a)
5446 ······-·audit_rules_privileged_commands_sudo5446 ······-·audit_rules_privileged_commands_sudo
878 B
./usr/share/scap-security-guide/ansible/cs9-playbook-anssi_bp28_intermediary.yml
Ordering differences only
    
Offset 5062, 16 lines modifiedOffset 5062, 16 lines modified
5062 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5062 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5063 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5063 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5064 ··········create:·true5064 ··········create:·true
5065 ··········mode:·o-rwx5065 ··········mode:·o-rwx
5066 ··········state:·present5066 ··········state:·present
5067 ········when:·syscalls_found·|·length·==·05067 ········when:·syscalls_found·|·length·==·0
5068 ······when:5068 ······when:
5069 ······-·'"audit"·in·ansible_facts.packages' 
5070 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5069 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5070 ······-·'"audit"·in·ansible_facts.packages'
5071 ······tags:5071 ······tags:
5072 ······-·NIST-800-171-3.1.75072 ······-·NIST-800-171-3.1.7
5073 ······-·NIST-800-53-AC-6(9)5073 ······-·NIST-800-53-AC-6(9)
5074 ······-·NIST-800-53-AU-12(c)5074 ······-·NIST-800-53-AU-12(c)
5075 ······-·NIST-800-53-AU-2(d)5075 ······-·NIST-800-53-AU-2(d)
5076 ······-·NIST-800-53-CM-6(a)5076 ······-·NIST-800-53-CM-6(a)
5077 ······-·audit_rules_privileged_commands_sudo5077 ······-·audit_rules_privileged_commands_sudo
160 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-cis.yml
Ordering differences only
    
Offset 5222, 16 lines modifiedOffset 5222, 16 lines modified
  
5222 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5222 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5223 ······find:5223 ······find:
5224 ········paths:·/etc/audit/rules.d/5224 ········paths:·/etc/audit/rules.d/
5225 ········patterns:·'*.rules'5225 ········patterns:·'*.rules'
5226 ······register:·find_rules_d5226 ······register:·find_rules_d
5227 ······when:5227 ······when:
5228 ······-·'"audit"·in·ansible_facts.packages' 
5229 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5228 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5229 ······-·'"audit"·in·ansible_facts.packages'
5230 ······tags:5230 ······tags:
5231 ······-·CJIS-5.4.1.15231 ······-·CJIS-5.4.1.1
5232 ······-·NIST-800-171-3.3.15232 ······-·NIST-800-171-3.3.1
5233 ······-·NIST-800-171-3.4.35233 ······-·NIST-800-171-3.4.3
5234 ······-·NIST-800-53-AC-6(9)5234 ······-·NIST-800-53-AC-6(9)
5235 ······-·NIST-800-53-CM-6(a)5235 ······-·NIST-800-53-CM-6(a)
5236 ······-·PCI-DSS-Req-10.5.25236 ······-·PCI-DSS-Req-10.5.2
Offset 5246, 16 lines modifiedOffset 5246, 16 lines modified
5246 ······lineinfile:5246 ······lineinfile:
5247 ········path:·'{{·item·}}'5247 ········path:·'{{·item·}}'
5248 ········regexp:·^\s*(?:-e)\s+.*$5248 ········regexp:·^\s*(?:-e)\s+.*$
5249 ········state:·absent5249 ········state:·absent
5250 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5250 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5251 ········}}'5251 ········}}'
5252 ······when:5252 ······when:
5253 ······-·'"audit"·in·ansible_facts.packages' 
5254 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5253 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5254 ······-·'"audit"·in·ansible_facts.packages'
5255 ······tags:5255 ······tags:
5256 ······-·CJIS-5.4.1.15256 ······-·CJIS-5.4.1.1
5257 ······-·NIST-800-171-3.3.15257 ······-·NIST-800-171-3.3.1
5258 ······-·NIST-800-171-3.4.35258 ······-·NIST-800-171-3.4.3
5259 ······-·NIST-800-53-AC-6(9)5259 ······-·NIST-800-53-AC-6(9)
5260 ······-·NIST-800-53-CM-6(a)5260 ······-·NIST-800-53-CM-6(a)
5261 ······-·PCI-DSS-Req-10.5.25261 ······-·PCI-DSS-Req-10.5.2
Offset 5272, 16 lines modifiedOffset 5272, 16 lines modified
5272 ········create:·true5272 ········create:·true
5273 ········line:·-e·25273 ········line:·-e·2
5274 ········mode:·o-rwx5274 ········mode:·o-rwx
5275 ······loop:5275 ······loop:
5276 ······-·/etc/audit/audit.rules5276 ······-·/etc/audit/audit.rules
5277 ······-·/etc/audit/rules.d/immutable.rules5277 ······-·/etc/audit/rules.d/immutable.rules
5278 ······when:5278 ······when:
5279 ······-·'"audit"·in·ansible_facts.packages' 
5280 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5279 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5280 ······-·'"audit"·in·ansible_facts.packages'
5281 ······tags:5281 ······tags:
5282 ······-·CJIS-5.4.1.15282 ······-·CJIS-5.4.1.1
5283 ······-·NIST-800-171-3.3.15283 ······-·NIST-800-171-3.3.1
5284 ······-·NIST-800-171-3.4.35284 ······-·NIST-800-171-3.4.3
5285 ······-·NIST-800-53-AC-6(9)5285 ······-·NIST-800-53-AC-6(9)
5286 ······-·NIST-800-53-CM-6(a)5286 ······-·NIST-800-53-CM-6(a)
5287 ······-·PCI-DSS-Req-10.5.25287 ······-·PCI-DSS-Req-10.5.2
Offset 5313, 16 lines modifiedOffset 5313, 16 lines modified
5313 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5313 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5314 ······find:5314 ······find:
5315 ········paths:·/etc/audit/rules.d5315 ········paths:·/etc/audit/rules.d
5316 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5316 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5317 ········patterns:·'*.rules'5317 ········patterns:·'*.rules'
5318 ······register:·find_existing_watch_rules_d5318 ······register:·find_existing_watch_rules_d
5319 ······when:5319 ······when:
5320 ······-·'"audit"·in·ansible_facts.packages' 
5321 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5320 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5321 ······-·'"audit"·in·ansible_facts.packages'
5322 ······tags:5322 ······tags:
5323 ······-·CJIS-5.4.1.15323 ······-·CJIS-5.4.1.1
5324 ······-·NIST-800-171-3.1.85324 ······-·NIST-800-171-3.1.8
5325 ······-·NIST-800-53-AU-12(c)5325 ······-·NIST-800-53-AU-12(c)
5326 ······-·NIST-800-53-AU-2(d)5326 ······-·NIST-800-53-AU-2(d)
5327 ······-·NIST-800-53-CM-6(a)5327 ······-·NIST-800-53-CM-6(a)
5328 ······-·PCI-DSS-Req-10.5.55328 ······-·PCI-DSS-Req-10.5.5
Offset 5336, 16 lines modifiedOffset 5336, 16 lines modified
5336 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5336 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5337 ······find:5337 ······find:
5338 ········paths:·/etc/audit/rules.d5338 ········paths:·/etc/audit/rules.d
5339 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5339 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5340 ········patterns:·'*.rules'5340 ········patterns:·'*.rules'
5341 ······register:·find_watch_key5341 ······register:·find_watch_key
5342 ······when:5342 ······when:
5343 ······-·'"audit"·in·ansible_facts.packages' 
5344 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5343 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5344 ······-·'"audit"·in·ansible_facts.packages'
5345 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5345 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5346 ········==·05346 ········==·0
5347 ······tags:5347 ······tags:
5348 ······-·CJIS-5.4.1.15348 ······-·CJIS-5.4.1.1
5349 ······-·NIST-800-171-3.1.85349 ······-·NIST-800-171-3.1.8
5350 ······-·NIST-800-53-AU-12(c)5350 ······-·NIST-800-53-AU-12(c)
5351 ······-·NIST-800-53-AU-2(d)5351 ······-·NIST-800-53-AU-2(d)
Offset 5359, 16 lines modifiedOffset 5359, 16 lines modified
5359 ······-·restrict_strategy5359 ······-·restrict_strategy
  
5360 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5360 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5361 ······set_fact:5361 ······set_fact:
5362 ········all_files:5362 ········all_files:
5363 ········-·/etc/audit/rules.d/MAC-policy.rules5363 ········-·/etc/audit/rules.d/MAC-policy.rules
5364 ······when:5364 ······when:
5365 ······-·'"audit"·in·ansible_facts.packages' 
5366 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5365 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5366 ······-·'"audit"·in·ansible_facts.packages'
5367 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5367 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5368 ········is·defined·and·find_existing_watch_rules_d.matched·==·05368 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5369 ······tags:5369 ······tags:
5370 ······-·CJIS-5.4.1.15370 ······-·CJIS-5.4.1.1
5371 ······-·NIST-800-171-3.1.85371 ······-·NIST-800-171-3.1.8
5372 ······-·NIST-800-53-AU-12(c)5372 ······-·NIST-800-53-AU-12(c)
5373 ······-·NIST-800-53-AU-2(d)5373 ······-·NIST-800-53-AU-2(d)
Offset 5382, 16 lines modifiedOffset 5382, 16 lines modified
5382 ······-·restrict_strategy5382 ······-·restrict_strategy
  
5383 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5383 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5384 ······set_fact:5384 ······set_fact:
5385 ········all_files:5385 ········all_files:
5386 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5386 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5387 ······when:5387 ······when:
5388 ······-·'"audit"·in·ansible_facts.packages' 
5389 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5388 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5389 ······-·'"audit"·in·ansible_facts.packages'
5390 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5390 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5391 ········is·defined·and·find_existing_watch_rules_d.matched·==·05391 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5392 ······tags:5392 ······tags:
5393 ······-·CJIS-5.4.1.15393 ······-·CJIS-5.4.1.1
5394 ······-·NIST-800-171-3.1.85394 ······-·NIST-800-171-3.1.8
5395 ······-·NIST-800-53-AU-12(c)5395 ······-·NIST-800-53-AU-12(c)
5396 ······-·NIST-800-53-AU-2(d)5396 ······-·NIST-800-53-AU-2(d)
Offset 5407, 16 lines modifiedOffset 5407, 16 lines modified
5407 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5407 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 159331/164016 bytes (97.14%) of diff not shown.
7.71 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-cis_server_l1.yml
Ordering differences only
    
Offset 5057, 16 lines modifiedOffset 5057, 16 lines modified
5057 ······-·no_reboot_needed5057 ······-·no_reboot_needed
  
5058 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5058 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5059 ······stat:5059 ······stat:
5060 ········path:·/boot/grub2/grub.cfg5060 ········path:·/boot/grub2/grub.cfg
5061 ······register:·file_exists5061 ······register:·file_exists
5062 ······when:5062 ······when:
5063 ······-·'"grub2-common"·in·ansible_facts.packages' 
5064 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5063 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5064 ······-·'"grub2-common"·in·ansible_facts.packages'
5065 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5065 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5066 ······tags:5066 ······tags:
5067 ······-·CJIS-5.5.2.25067 ······-·CJIS-5.5.2.2
5068 ······-·NIST-800-171-3.4.55068 ······-·NIST-800-171-3.4.5
5069 ······-·NIST-800-53-AC-6(1)5069 ······-·NIST-800-53-AC-6(1)
5070 ······-·NIST-800-53-CM-6(a)5070 ······-·NIST-800-53-CM-6(a)
5071 ······-·PCI-DSS-Req-7.15071 ······-·PCI-DSS-Req-7.1
Offset 5078, 16 lines modifiedOffset 5078, 16 lines modified
5078 ······-·no_reboot_needed5078 ······-·no_reboot_needed
  
5079 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg5079 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
5080 ······file:5080 ······file:
5081 ········path:·/boot/grub2/grub.cfg5081 ········path:·/boot/grub2/grub.cfg
5082 ········group:·'0'5082 ········group:·'0'
5083 ······when:5083 ······when:
5084 ······-·'"grub2-common"·in·ansible_facts.packages' 
5085 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5084 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5085 ······-·'"grub2-common"·in·ansible_facts.packages'
5086 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5086 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5087 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5087 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5088 ······tags:5088 ······tags:
5089 ······-·CJIS-5.5.2.25089 ······-·CJIS-5.5.2.2
5090 ······-·NIST-800-171-3.4.55090 ······-·NIST-800-171-3.4.5
5091 ······-·NIST-800-53-AC-6(1)5091 ······-·NIST-800-53-AC-6(1)
5092 ······-·NIST-800-53-CM-6(a)5092 ······-·NIST-800-53-CM-6(a)
Offset 5117, 16 lines modifiedOffset 5117, 16 lines modified
5117 ······-·no_reboot_needed5117 ······-·no_reboot_needed
  
5118 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5118 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5119 ······stat:5119 ······stat:
5120 ········path:·/boot/grub2/user.cfg5120 ········path:·/boot/grub2/user.cfg
5121 ······register:·file_exists5121 ······register:·file_exists
5122 ······when:5122 ······when:
5123 ······-·'"grub2-common"·in·ansible_facts.packages' 
5124 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5123 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5124 ······-·'"grub2-common"·in·ansible_facts.packages'
5125 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5125 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5126 ······tags:5126 ······tags:
5127 ······-·CJIS-5.5.2.25127 ······-·CJIS-5.5.2.2
5128 ······-·NIST-800-171-3.4.55128 ······-·NIST-800-171-3.4.5
5129 ······-·NIST-800-53-AC-6(1)5129 ······-·NIST-800-53-AC-6(1)
5130 ······-·NIST-800-53-CM-6(a)5130 ······-·NIST-800-53-CM-6(a)
5131 ······-·PCI-DSS-Req-7.15131 ······-·PCI-DSS-Req-7.1
Offset 5138, 16 lines modifiedOffset 5138, 16 lines modified
5138 ······-·no_reboot_needed5138 ······-·no_reboot_needed
  
5139 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg5139 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
5140 ······file:5140 ······file:
5141 ········path:·/boot/grub2/user.cfg5141 ········path:·/boot/grub2/user.cfg
5142 ········group:·'0'5142 ········group:·'0'
5143 ······when:5143 ······when:
5144 ······-·'"grub2-common"·in·ansible_facts.packages' 
5145 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5144 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5145 ······-·'"grub2-common"·in·ansible_facts.packages'
5146 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5146 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5147 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5147 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5148 ······tags:5148 ······tags:
5149 ······-·CJIS-5.5.2.25149 ······-·CJIS-5.5.2.2
5150 ······-·NIST-800-171-3.4.55150 ······-·NIST-800-171-3.4.5
5151 ······-·NIST-800-53-AC-6(1)5151 ······-·NIST-800-53-AC-6(1)
5152 ······-·NIST-800-53-CM-6(a)5152 ······-·NIST-800-53-CM-6(a)
Offset 5177, 16 lines modifiedOffset 5177, 16 lines modified
5177 ······-·no_reboot_needed5177 ······-·no_reboot_needed
  
5178 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5178 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5179 ······stat:5179 ······stat:
5180 ········path:·/boot/grub2/grub.cfg5180 ········path:·/boot/grub2/grub.cfg
5181 ······register:·file_exists5181 ······register:·file_exists
5182 ······when:5182 ······when:
5183 ······-·'"grub2-common"·in·ansible_facts.packages' 
5184 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5183 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5184 ······-·'"grub2-common"·in·ansible_facts.packages'
5185 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5185 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5186 ······tags:5186 ······tags:
5187 ······-·CJIS-5.5.2.25187 ······-·CJIS-5.5.2.2
5188 ······-·NIST-800-171-3.4.55188 ······-·NIST-800-171-3.4.5
5189 ······-·NIST-800-53-AC-6(1)5189 ······-·NIST-800-53-AC-6(1)
5190 ······-·NIST-800-53-CM-6(a)5190 ······-·NIST-800-53-CM-6(a)
5191 ······-·PCI-DSS-Req-7.15191 ······-·PCI-DSS-Req-7.1
Offset 5198, 16 lines modifiedOffset 5198, 16 lines modified
5198 ······-·no_reboot_needed5198 ······-·no_reboot_needed
  
5199 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg5199 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
5200 ······file:5200 ······file:
5201 ········path:·/boot/grub2/grub.cfg5201 ········path:·/boot/grub2/grub.cfg
5202 ········owner:·'0'5202 ········owner:·'0'
5203 ······when:5203 ······when:
5204 ······-·'"grub2-common"·in·ansible_facts.packages' 
5205 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5204 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5205 ······-·'"grub2-common"·in·ansible_facts.packages'
5206 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5206 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5207 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5207 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5208 ······tags:5208 ······tags:
5209 ······-·CJIS-5.5.2.25209 ······-·CJIS-5.5.2.2
5210 ······-·NIST-800-171-3.4.55210 ······-·NIST-800-171-3.4.5
5211 ······-·NIST-800-53-AC-6(1)5211 ······-·NIST-800-53-AC-6(1)
5212 ······-·NIST-800-53-CM-6(a)5212 ······-·NIST-800-53-CM-6(a)
Offset 5237, 16 lines modifiedOffset 5237, 16 lines modified
5237 ······-·no_reboot_needed5237 ······-·no_reboot_needed
  
5238 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5238 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5239 ······stat:5239 ······stat:
5240 ········path:·/boot/grub2/user.cfg5240 ········path:·/boot/grub2/user.cfg
5241 ······register:·file_exists5241 ······register:·file_exists
5242 ······when:5242 ······when:
5243 ······-·'"grub2-common"·in·ansible_facts.packages' 
5244 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5243 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5244 ······-·'"grub2-common"·in·ansible_facts.packages'
5245 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5245 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5246 ······tags:5246 ······tags:
5247 ······-·CJIS-5.5.2.25247 ······-·CJIS-5.5.2.2
5248 ······-·NIST-800-171-3.4.55248 ······-·NIST-800-171-3.4.5
5249 ······-·NIST-800-53-AC-6(1)5249 ······-·NIST-800-53-AC-6(1)
5250 ······-·NIST-800-53-CM-6(a)5250 ······-·NIST-800-53-CM-6(a)
5251 ······-·PCI-DSS-Req-7.15251 ······-·PCI-DSS-Req-7.1
Offset 5258, 16 lines modifiedOffset 5258, 16 lines modified
5258 ······-·no_reboot_needed5258 ······-·no_reboot_needed
Max diff block lines reached; 3245/7725 bytes (42.01%) of diff not shown.
7.71 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-cis_workstation_l1.yml
Ordering differences only
    
Offset 5057, 16 lines modifiedOffset 5057, 16 lines modified
5057 ······-·no_reboot_needed5057 ······-·no_reboot_needed
  
5058 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5058 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5059 ······stat:5059 ······stat:
5060 ········path:·/boot/grub2/grub.cfg5060 ········path:·/boot/grub2/grub.cfg
5061 ······register:·file_exists5061 ······register:·file_exists
5062 ······when:5062 ······when:
5063 ······-·'"grub2-common"·in·ansible_facts.packages' 
5064 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5063 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5064 ······-·'"grub2-common"·in·ansible_facts.packages'
5065 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5065 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5066 ······tags:5066 ······tags:
5067 ······-·CJIS-5.5.2.25067 ······-·CJIS-5.5.2.2
5068 ······-·NIST-800-171-3.4.55068 ······-·NIST-800-171-3.4.5
5069 ······-·NIST-800-53-AC-6(1)5069 ······-·NIST-800-53-AC-6(1)
5070 ······-·NIST-800-53-CM-6(a)5070 ······-·NIST-800-53-CM-6(a)
5071 ······-·PCI-DSS-Req-7.15071 ······-·PCI-DSS-Req-7.1
Offset 5078, 16 lines modifiedOffset 5078, 16 lines modified
5078 ······-·no_reboot_needed5078 ······-·no_reboot_needed
  
5079 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg5079 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
5080 ······file:5080 ······file:
5081 ········path:·/boot/grub2/grub.cfg5081 ········path:·/boot/grub2/grub.cfg
5082 ········group:·'0'5082 ········group:·'0'
5083 ······when:5083 ······when:
5084 ······-·'"grub2-common"·in·ansible_facts.packages' 
5085 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5084 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5085 ······-·'"grub2-common"·in·ansible_facts.packages'
5086 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5086 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5087 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5087 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5088 ······tags:5088 ······tags:
5089 ······-·CJIS-5.5.2.25089 ······-·CJIS-5.5.2.2
5090 ······-·NIST-800-171-3.4.55090 ······-·NIST-800-171-3.4.5
5091 ······-·NIST-800-53-AC-6(1)5091 ······-·NIST-800-53-AC-6(1)
5092 ······-·NIST-800-53-CM-6(a)5092 ······-·NIST-800-53-CM-6(a)
Offset 5117, 16 lines modifiedOffset 5117, 16 lines modified
5117 ······-·no_reboot_needed5117 ······-·no_reboot_needed
  
5118 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5118 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5119 ······stat:5119 ······stat:
5120 ········path:·/boot/grub2/user.cfg5120 ········path:·/boot/grub2/user.cfg
5121 ······register:·file_exists5121 ······register:·file_exists
5122 ······when:5122 ······when:
5123 ······-·'"grub2-common"·in·ansible_facts.packages' 
5124 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5123 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5124 ······-·'"grub2-common"·in·ansible_facts.packages'
5125 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5125 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5126 ······tags:5126 ······tags:
5127 ······-·CJIS-5.5.2.25127 ······-·CJIS-5.5.2.2
5128 ······-·NIST-800-171-3.4.55128 ······-·NIST-800-171-3.4.5
5129 ······-·NIST-800-53-AC-6(1)5129 ······-·NIST-800-53-AC-6(1)
5130 ······-·NIST-800-53-CM-6(a)5130 ······-·NIST-800-53-CM-6(a)
5131 ······-·PCI-DSS-Req-7.15131 ······-·PCI-DSS-Req-7.1
Offset 5138, 16 lines modifiedOffset 5138, 16 lines modified
5138 ······-·no_reboot_needed5138 ······-·no_reboot_needed
  
5139 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg5139 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
5140 ······file:5140 ······file:
5141 ········path:·/boot/grub2/user.cfg5141 ········path:·/boot/grub2/user.cfg
5142 ········group:·'0'5142 ········group:·'0'
5143 ······when:5143 ······when:
5144 ······-·'"grub2-common"·in·ansible_facts.packages' 
5145 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5144 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5145 ······-·'"grub2-common"·in·ansible_facts.packages'
5146 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5146 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5147 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5147 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5148 ······tags:5148 ······tags:
5149 ······-·CJIS-5.5.2.25149 ······-·CJIS-5.5.2.2
5150 ······-·NIST-800-171-3.4.55150 ······-·NIST-800-171-3.4.5
5151 ······-·NIST-800-53-AC-6(1)5151 ······-·NIST-800-53-AC-6(1)
5152 ······-·NIST-800-53-CM-6(a)5152 ······-·NIST-800-53-CM-6(a)
Offset 5177, 16 lines modifiedOffset 5177, 16 lines modified
5177 ······-·no_reboot_needed5177 ······-·no_reboot_needed
  
5178 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5178 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5179 ······stat:5179 ······stat:
5180 ········path:·/boot/grub2/grub.cfg5180 ········path:·/boot/grub2/grub.cfg
5181 ······register:·file_exists5181 ······register:·file_exists
5182 ······when:5182 ······when:
5183 ······-·'"grub2-common"·in·ansible_facts.packages' 
5184 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5183 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5184 ······-·'"grub2-common"·in·ansible_facts.packages'
5185 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5185 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5186 ······tags:5186 ······tags:
5187 ······-·CJIS-5.5.2.25187 ······-·CJIS-5.5.2.2
5188 ······-·NIST-800-171-3.4.55188 ······-·NIST-800-171-3.4.5
5189 ······-·NIST-800-53-AC-6(1)5189 ······-·NIST-800-53-AC-6(1)
5190 ······-·NIST-800-53-CM-6(a)5190 ······-·NIST-800-53-CM-6(a)
5191 ······-·PCI-DSS-Req-7.15191 ······-·PCI-DSS-Req-7.1
Offset 5198, 16 lines modifiedOffset 5198, 16 lines modified
5198 ······-·no_reboot_needed5198 ······-·no_reboot_needed
  
5199 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg5199 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
5200 ······file:5200 ······file:
5201 ········path:·/boot/grub2/grub.cfg5201 ········path:·/boot/grub2/grub.cfg
5202 ········owner:·'0'5202 ········owner:·'0'
5203 ······when:5203 ······when:
5204 ······-·'"grub2-common"·in·ansible_facts.packages' 
5205 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5204 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5205 ······-·'"grub2-common"·in·ansible_facts.packages'
5206 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5206 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5207 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5207 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5208 ······tags:5208 ······tags:
5209 ······-·CJIS-5.5.2.25209 ······-·CJIS-5.5.2.2
5210 ······-·NIST-800-171-3.4.55210 ······-·NIST-800-171-3.4.5
5211 ······-·NIST-800-53-AC-6(1)5211 ······-·NIST-800-53-AC-6(1)
5212 ······-·NIST-800-53-CM-6(a)5212 ······-·NIST-800-53-CM-6(a)
Offset 5237, 16 lines modifiedOffset 5237, 16 lines modified
5237 ······-·no_reboot_needed5237 ······-·no_reboot_needed
  
5238 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5238 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5239 ······stat:5239 ······stat:
5240 ········path:·/boot/grub2/user.cfg5240 ········path:·/boot/grub2/user.cfg
5241 ······register:·file_exists5241 ······register:·file_exists
5242 ······when:5242 ······when:
5243 ······-·'"grub2-common"·in·ansible_facts.packages' 
5244 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5243 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5244 ······-·'"grub2-common"·in·ansible_facts.packages'
5245 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5245 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5246 ······tags:5246 ······tags:
5247 ······-·CJIS-5.5.2.25247 ······-·CJIS-5.5.2.2
5248 ······-·NIST-800-171-3.4.55248 ······-·NIST-800-171-3.4.5
5249 ······-·NIST-800-53-AC-6(1)5249 ······-·NIST-800-53-AC-6(1)
5250 ······-·NIST-800-53-CM-6(a)5250 ······-·NIST-800-53-CM-6(a)
5251 ······-·PCI-DSS-Req-7.15251 ······-·PCI-DSS-Req-7.1
Offset 5258, 16 lines modifiedOffset 5258, 16 lines modified
5258 ······-·no_reboot_needed5258 ······-·no_reboot_needed
Max diff block lines reached; 3245/7725 bytes (42.01%) of diff not shown.
160 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-cis_workstation_l2.yml
Ordering differences only
    
Offset 5222, 16 lines modifiedOffset 5222, 16 lines modified
  
5222 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5222 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5223 ······find:5223 ······find:
5224 ········paths:·/etc/audit/rules.d/5224 ········paths:·/etc/audit/rules.d/
5225 ········patterns:·'*.rules'5225 ········patterns:·'*.rules'
5226 ······register:·find_rules_d5226 ······register:·find_rules_d
5227 ······when:5227 ······when:
5228 ······-·'"audit"·in·ansible_facts.packages' 
5229 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5228 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5229 ······-·'"audit"·in·ansible_facts.packages'
5230 ······tags:5230 ······tags:
5231 ······-·CJIS-5.4.1.15231 ······-·CJIS-5.4.1.1
5232 ······-·NIST-800-171-3.3.15232 ······-·NIST-800-171-3.3.1
5233 ······-·NIST-800-171-3.4.35233 ······-·NIST-800-171-3.4.3
5234 ······-·NIST-800-53-AC-6(9)5234 ······-·NIST-800-53-AC-6(9)
5235 ······-·NIST-800-53-CM-6(a)5235 ······-·NIST-800-53-CM-6(a)
5236 ······-·PCI-DSS-Req-10.5.25236 ······-·PCI-DSS-Req-10.5.2
Offset 5246, 16 lines modifiedOffset 5246, 16 lines modified
5246 ······lineinfile:5246 ······lineinfile:
5247 ········path:·'{{·item·}}'5247 ········path:·'{{·item·}}'
5248 ········regexp:·^\s*(?:-e)\s+.*$5248 ········regexp:·^\s*(?:-e)\s+.*$
5249 ········state:·absent5249 ········state:·absent
5250 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5250 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5251 ········}}'5251 ········}}'
5252 ······when:5252 ······when:
5253 ······-·'"audit"·in·ansible_facts.packages' 
5254 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5253 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5254 ······-·'"audit"·in·ansible_facts.packages'
5255 ······tags:5255 ······tags:
5256 ······-·CJIS-5.4.1.15256 ······-·CJIS-5.4.1.1
5257 ······-·NIST-800-171-3.3.15257 ······-·NIST-800-171-3.3.1
5258 ······-·NIST-800-171-3.4.35258 ······-·NIST-800-171-3.4.3
5259 ······-·NIST-800-53-AC-6(9)5259 ······-·NIST-800-53-AC-6(9)
5260 ······-·NIST-800-53-CM-6(a)5260 ······-·NIST-800-53-CM-6(a)
5261 ······-·PCI-DSS-Req-10.5.25261 ······-·PCI-DSS-Req-10.5.2
Offset 5272, 16 lines modifiedOffset 5272, 16 lines modified
5272 ········create:·true5272 ········create:·true
5273 ········line:·-e·25273 ········line:·-e·2
5274 ········mode:·o-rwx5274 ········mode:·o-rwx
5275 ······loop:5275 ······loop:
5276 ······-·/etc/audit/audit.rules5276 ······-·/etc/audit/audit.rules
5277 ······-·/etc/audit/rules.d/immutable.rules5277 ······-·/etc/audit/rules.d/immutable.rules
5278 ······when:5278 ······when:
5279 ······-·'"audit"·in·ansible_facts.packages' 
5280 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5279 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5280 ······-·'"audit"·in·ansible_facts.packages'
5281 ······tags:5281 ······tags:
5282 ······-·CJIS-5.4.1.15282 ······-·CJIS-5.4.1.1
5283 ······-·NIST-800-171-3.3.15283 ······-·NIST-800-171-3.3.1
5284 ······-·NIST-800-171-3.4.35284 ······-·NIST-800-171-3.4.3
5285 ······-·NIST-800-53-AC-6(9)5285 ······-·NIST-800-53-AC-6(9)
5286 ······-·NIST-800-53-CM-6(a)5286 ······-·NIST-800-53-CM-6(a)
5287 ······-·PCI-DSS-Req-10.5.25287 ······-·PCI-DSS-Req-10.5.2
Offset 5313, 16 lines modifiedOffset 5313, 16 lines modified
5313 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5313 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5314 ······find:5314 ······find:
5315 ········paths:·/etc/audit/rules.d5315 ········paths:·/etc/audit/rules.d
5316 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5316 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5317 ········patterns:·'*.rules'5317 ········patterns:·'*.rules'
5318 ······register:·find_existing_watch_rules_d5318 ······register:·find_existing_watch_rules_d
5319 ······when:5319 ······when:
5320 ······-·'"audit"·in·ansible_facts.packages' 
5321 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5320 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5321 ······-·'"audit"·in·ansible_facts.packages'
5322 ······tags:5322 ······tags:
5323 ······-·CJIS-5.4.1.15323 ······-·CJIS-5.4.1.1
5324 ······-·NIST-800-171-3.1.85324 ······-·NIST-800-171-3.1.8
5325 ······-·NIST-800-53-AU-12(c)5325 ······-·NIST-800-53-AU-12(c)
5326 ······-·NIST-800-53-AU-2(d)5326 ······-·NIST-800-53-AU-2(d)
5327 ······-·NIST-800-53-CM-6(a)5327 ······-·NIST-800-53-CM-6(a)
5328 ······-·PCI-DSS-Req-10.5.55328 ······-·PCI-DSS-Req-10.5.5
Offset 5336, 16 lines modifiedOffset 5336, 16 lines modified
5336 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5336 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5337 ······find:5337 ······find:
5338 ········paths:·/etc/audit/rules.d5338 ········paths:·/etc/audit/rules.d
5339 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5339 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5340 ········patterns:·'*.rules'5340 ········patterns:·'*.rules'
5341 ······register:·find_watch_key5341 ······register:·find_watch_key
5342 ······when:5342 ······when:
5343 ······-·'"audit"·in·ansible_facts.packages' 
5344 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5343 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5344 ······-·'"audit"·in·ansible_facts.packages'
5345 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5345 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5346 ········==·05346 ········==·0
5347 ······tags:5347 ······tags:
5348 ······-·CJIS-5.4.1.15348 ······-·CJIS-5.4.1.1
5349 ······-·NIST-800-171-3.1.85349 ······-·NIST-800-171-3.1.8
5350 ······-·NIST-800-53-AU-12(c)5350 ······-·NIST-800-53-AU-12(c)
5351 ······-·NIST-800-53-AU-2(d)5351 ······-·NIST-800-53-AU-2(d)
Offset 5359, 16 lines modifiedOffset 5359, 16 lines modified
5359 ······-·restrict_strategy5359 ······-·restrict_strategy
  
5360 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5360 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5361 ······set_fact:5361 ······set_fact:
5362 ········all_files:5362 ········all_files:
5363 ········-·/etc/audit/rules.d/MAC-policy.rules5363 ········-·/etc/audit/rules.d/MAC-policy.rules
5364 ······when:5364 ······when:
5365 ······-·'"audit"·in·ansible_facts.packages' 
5366 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5365 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5366 ······-·'"audit"·in·ansible_facts.packages'
5367 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5367 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5368 ········is·defined·and·find_existing_watch_rules_d.matched·==·05368 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5369 ······tags:5369 ······tags:
5370 ······-·CJIS-5.4.1.15370 ······-·CJIS-5.4.1.1
5371 ······-·NIST-800-171-3.1.85371 ······-·NIST-800-171-3.1.8
5372 ······-·NIST-800-53-AU-12(c)5372 ······-·NIST-800-53-AU-12(c)
5373 ······-·NIST-800-53-AU-2(d)5373 ······-·NIST-800-53-AU-2(d)
Offset 5382, 16 lines modifiedOffset 5382, 16 lines modified
5382 ······-·restrict_strategy5382 ······-·restrict_strategy
  
5383 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5383 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5384 ······set_fact:5384 ······set_fact:
5385 ········all_files:5385 ········all_files:
5386 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5386 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5387 ······when:5387 ······when:
5388 ······-·'"audit"·in·ansible_facts.packages' 
5389 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5388 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5389 ······-·'"audit"·in·ansible_facts.packages'
5390 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5390 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5391 ········is·defined·and·find_existing_watch_rules_d.matched·==·05391 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5392 ······tags:5392 ······tags:
5393 ······-·CJIS-5.4.1.15393 ······-·CJIS-5.4.1.1
5394 ······-·NIST-800-171-3.1.85394 ······-·NIST-800-171-3.1.8
5395 ······-·NIST-800-53-AU-12(c)5395 ······-·NIST-800-53-AU-12(c)
5396 ······-·NIST-800-53-AU-2(d)5396 ······-·NIST-800-53-AU-2(d)
Offset 5407, 16 lines modifiedOffset 5407, 16 lines modified
5407 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5407 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 159331/164016 bytes (97.14%) of diff not shown.
2.4 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-cui.yml
Ordering differences only
    
Offset 3365, 16 lines modifiedOffset 3365, 16 lines modified
3365 ······lineinfile:3365 ······lineinfile:
3366 ········dest:·/etc/audit/auditd.conf3366 ········dest:·/etc/audit/auditd.conf
3367 ········regexp:·^\s*flush\s*=\s*.*$3367 ········regexp:·^\s*flush\s*=\s*.*$
3368 ········line:·flush·=·{{·var_auditd_flush·}}3368 ········line:·flush·=·{{·var_auditd_flush·}}
3369 ········state:·present3369 ········state:·present
3370 ········create:·true3370 ········create:·true
3371 ······when:3371 ······when:
3372 ······-·'"audit"·in·ansible_facts.packages' 
3373 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3372 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3373 ······-·'"audit"·in·ansible_facts.packages'
3374 ······tags:3374 ······tags:
3375 ······-·NIST-800-171-3.3.13375 ······-·NIST-800-171-3.3.1
3376 ······-·NIST-800-53-AU-113376 ······-·NIST-800-53-AU-11
3377 ······-·NIST-800-53-CM-6(a)3377 ······-·NIST-800-53-CM-6(a)
3378 ······-·auditd_data_retention_flush3378 ······-·auditd_data_retention_flush
3379 ······-·low_complexity3379 ······-·low_complexity
3380 ······-·low_disruption3380 ······-·low_disruption
Offset 3420, 16 lines modifiedOffset 3420, 16 lines modified
3420 ········lineinfile:3420 ········lineinfile:
3421 ··········path:·/etc/audit/auditd.conf3421 ··········path:·/etc/audit/auditd.conf
3422 ··········create:·true3422 ··········create:·true
3423 ··········regexp:·(?i)^\s*freq\s*=\s*3423 ··········regexp:·(?i)^\s*freq\s*=\s*
3424 ··········line:·freq·=·503424 ··········line:·freq·=·50
3425 ··········state:·present3425 ··········state:·present
3426 ······when:3426 ······when:
3427 ······-·'"audit"·in·ansible_facts.packages' 
3428 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3427 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3428 ······-·'"audit"·in·ansible_facts.packages'
3429 ······tags:3429 ······tags:
3430 ······-·NIST-800-53-CM-63430 ······-·NIST-800-53-CM-6
3431 ······-·auditd_freq3431 ······-·auditd_freq
3432 ······-·low_complexity3432 ······-·low_complexity
3433 ······-·low_disruption3433 ······-·low_disruption
3434 ······-·medium_severity3434 ······-·medium_severity
3435 ······-·no_reboot_needed3435 ······-·no_reboot_needed
Offset 3474, 16 lines modifiedOffset 3474, 16 lines modified
3474 ········lineinfile:3474 ········lineinfile:
3475 ··········path:·/etc/audit/auditd.conf3475 ··········path:·/etc/audit/auditd.conf
3476 ··········create:·true3476 ··········create:·true
3477 ··········regexp:·(?i)^\s*log_format\s*=\s*3477 ··········regexp:·(?i)^\s*log_format\s*=\s*
3478 ··········line:·log_format·=·ENRICHED3478 ··········line:·log_format·=·ENRICHED
3479 ··········state:·present3479 ··········state:·present
3480 ······when:3480 ······when:
3481 ······-·'"audit"·in·ansible_facts.packages' 
3482 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3481 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3482 ······-·'"audit"·in·ansible_facts.packages'
3483 ······tags:3483 ······tags:
3484 ······-·NIST-800-53-AU-33484 ······-·NIST-800-53-AU-3
3485 ······-·NIST-800-53-CM-63485 ······-·NIST-800-53-CM-6
3486 ······-·auditd_log_format3486 ······-·auditd_log_format
3487 ······-·low_complexity3487 ······-·low_complexity
3488 ······-·low_disruption3488 ······-·low_disruption
3489 ······-·low_severity3489 ······-·low_severity
Offset 3529, 16 lines modifiedOffset 3529, 16 lines modified
3529 ········lineinfile:3529 ········lineinfile:
3530 ··········path:·/etc/audit/auditd.conf3530 ··········path:·/etc/audit/auditd.conf
3531 ··········create:·true3531 ··········create:·true
3532 ··········regexp:·(?i)^\s*name_format\s*=\s*3532 ··········regexp:·(?i)^\s*name_format\s*=\s*
3533 ··········line:·name_format·=·hostname3533 ··········line:·name_format·=·hostname
3534 ··········state:·present3534 ··········state:·present
3535 ······when:3535 ······when:
3536 ······-·'"audit"·in·ansible_facts.packages' 
3537 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3536 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3537 ······-·'"audit"·in·ansible_facts.packages'
3538 ······tags:3538 ······tags:
3539 ······-·NIST-800-53-AU-33539 ······-·NIST-800-53-AU-3
3540 ······-·NIST-800-53-CM-63540 ······-·NIST-800-53-CM-6
3541 ······-·auditd_name_format3541 ······-·auditd_name_format
3542 ······-·low_complexity3542 ······-·low_complexity
3543 ······-·low_disruption3543 ······-·low_disruption
3544 ······-·medium_severity3544 ······-·medium_severity
69.5 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-e8.yml
Ordering differences only
    
Offset 1117, 16 lines modifiedOffset 1117, 16 lines modified
1117 ······-·no_reboot_needed1117 ······-·no_reboot_needed
1118 ······-·restrict_strategy1118 ······-·restrict_strategy
  
1119 ····-·name:·Set·architecture·for·audit·tasks1119 ····-·name:·Set·architecture·for·audit·tasks
1120 ······set_fact:1120 ······set_fact:
1121 ········audit_arch:·b641121 ········audit_arch:·b64
1122 ······when:1122 ······when:
1123 ······-·'"audit"·in·ansible_facts.packages' 
1124 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1123 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1124 ······-·'"audit"·in·ansible_facts.packages'
1125 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1125 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1126 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1126 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1127 ······tags:1127 ······tags:
1128 ······-·CJIS-5.4.1.11128 ······-·CJIS-5.4.1.1
1129 ······-·NIST-800-171-3.1.71129 ······-·NIST-800-171-3.1.7
1130 ······-·NIST-800-53-AC-6(9)1130 ······-·NIST-800-53-AC-6(9)
1131 ······-·NIST-800-53-AU-12(c)1131 ······-·NIST-800-53-AU-12(c)
Offset 1259, 16 lines modifiedOffset 1259, 16 lines modified
1259 ··········path:·'{{·audit_file·}}'1259 ··········path:·'{{·audit_file·}}'
1260 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1260 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1261 ··········create:·true1261 ··········create:·true
1262 ··········mode:·o-rwx1262 ··········mode:·o-rwx
1263 ··········state:·present1263 ··········state:·present
1264 ········when:·syscalls_found·|·length·==·01264 ········when:·syscalls_found·|·length·==·0
1265 ······when:1265 ······when:
1266 ······-·'"audit"·in·ansible_facts.packages' 
1267 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1266 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1267 ······-·'"audit"·in·ansible_facts.packages'
1268 ······tags:1268 ······tags:
1269 ······-·CJIS-5.4.1.11269 ······-·CJIS-5.4.1.1
1270 ······-·NIST-800-171-3.1.71270 ······-·NIST-800-171-3.1.7
1271 ······-·NIST-800-53-AC-6(9)1271 ······-·NIST-800-53-AC-6(9)
1272 ······-·NIST-800-53-AU-12(c)1272 ······-·NIST-800-53-AU-12(c)
1273 ······-·NIST-800-53-AU-2(d)1273 ······-·NIST-800-53-AU-2(d)
1274 ······-·NIST-800-53-CM-6(a)1274 ······-·NIST-800-53-CM-6(a)
Offset 1399, 16 lines modifiedOffset 1399, 16 lines modified
1399 ··········path:·'{{·audit_file·}}'1399 ··········path:·'{{·audit_file·}}'
1400 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1400 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1401 ··········create:·true1401 ··········create:·true
1402 ··········mode:·o-rwx1402 ··········mode:·o-rwx
1403 ··········state:·present1403 ··········state:·present
1404 ········when:·syscalls_found·|·length·==·01404 ········when:·syscalls_found·|·length·==·0
1405 ······when:1405 ······when:
1406 ······-·'"audit"·in·ansible_facts.packages' 
1407 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1406 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1407 ······-·'"audit"·in·ansible_facts.packages'
1408 ······-·audit_arch·==·"b64"1408 ······-·audit_arch·==·"b64"
1409 ······tags:1409 ······tags:
1410 ······-·CJIS-5.4.1.11410 ······-·CJIS-5.4.1.1
1411 ······-·NIST-800-171-3.1.71411 ······-·NIST-800-171-3.1.7
1412 ······-·NIST-800-53-AC-6(9)1412 ······-·NIST-800-53-AC-6(9)
1413 ······-·NIST-800-53-AU-12(c)1413 ······-·NIST-800-53-AU-12(c)
1414 ······-·NIST-800-53-AU-2(d)1414 ······-·NIST-800-53-AU-2(d)
Offset 1424, 16 lines modifiedOffset 1424, 16 lines modified
1424 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/1424 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
1425 ······find:1425 ······find:
1426 ········paths:·/etc/audit/rules.d1426 ········paths:·/etc/audit/rules.d
1427 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+1427 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
1428 ········patterns:·'*.rules'1428 ········patterns:·'*.rules'
1429 ······register:·find_existing_watch_rules_d1429 ······register:·find_existing_watch_rules_d
1430 ······when:1430 ······when:
1431 ······-·'"audit"·in·ansible_facts.packages' 
1432 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1431 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1432 ······-·'"audit"·in·ansible_facts.packages'
1433 ······tags:1433 ······tags:
1434 ······-·CJIS-5.4.1.11434 ······-·CJIS-5.4.1.1
1435 ······-·NIST-800-171-3.1.71435 ······-·NIST-800-171-3.1.7
1436 ······-·NIST-800-53-AC-6(9)1436 ······-·NIST-800-53-AC-6(9)
1437 ······-·NIST-800-53-AU-12(c)1437 ······-·NIST-800-53-AU-12(c)
1438 ······-·NIST-800-53-AU-2(d)1438 ······-·NIST-800-53-AU-2(d)
1439 ······-·NIST-800-53-CM-6(a)1439 ······-·NIST-800-53-CM-6(a)
Offset 1448, 16 lines modifiedOffset 1448, 16 lines modified
1448 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification1448 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
1449 ······find:1449 ······find:
1450 ········paths:·/etc/audit/rules.d1450 ········paths:·/etc/audit/rules.d
1451 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$1451 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
1452 ········patterns:·'*.rules'1452 ········patterns:·'*.rules'
1453 ······register:·find_watch_key1453 ······register:·find_watch_key
1454 ······when:1454 ······when:
1455 ······-·'"audit"·in·ansible_facts.packages' 
1456 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1455 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1456 ······-·'"audit"·in·ansible_facts.packages'
1457 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1457 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1458 ········==·01458 ········==·0
1459 ······tags:1459 ······tags:
1460 ······-·CJIS-5.4.1.11460 ······-·CJIS-5.4.1.1
1461 ······-·NIST-800-171-3.1.71461 ······-·NIST-800-171-3.1.7
1462 ······-·NIST-800-53-AC-6(9)1462 ······-·NIST-800-53-AC-6(9)
1463 ······-·NIST-800-53-AU-12(c)1463 ······-·NIST-800-53-AU-12(c)
Offset 1473, 16 lines modifiedOffset 1473, 16 lines modified
  
1473 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the1473 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
1474 ········recipient·for·the·rule1474 ········recipient·for·the·rule
1475 ······set_fact:1475 ······set_fact:
1476 ········all_files:1476 ········all_files:
1477 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules1477 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
1478 ······when:1478 ······when:
1479 ······-·'"audit"·in·ansible_facts.packages' 
1480 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1479 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1480 ······-·'"audit"·in·ansible_facts.packages'
1481 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1481 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1482 ········is·defined·and·find_existing_watch_rules_d.matched·==·01482 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1483 ······tags:1483 ······tags:
1484 ······-·CJIS-5.4.1.11484 ······-·CJIS-5.4.1.1
1485 ······-·NIST-800-171-3.1.71485 ······-·NIST-800-171-3.1.7
1486 ······-·NIST-800-53-AC-6(9)1486 ······-·NIST-800-53-AC-6(9)
1487 ······-·NIST-800-53-AU-12(c)1487 ······-·NIST-800-53-AU-12(c)
Offset 1497, 16 lines modifiedOffset 1497, 16 lines modified
1497 ······-·restrict_strategy1497 ······-·restrict_strategy
  
1498 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1498 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1499 ······set_fact:1499 ······set_fact:
1500 ········all_files:1500 ········all_files:
1501 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1501 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1502 ······when:1502 ······when:
1503 ······-·'"audit"·in·ansible_facts.packages' 
1504 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1503 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1504 ······-·'"audit"·in·ansible_facts.packages'
1505 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1505 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1506 ········is·defined·and·find_existing_watch_rules_d.matched·==·01506 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1507 ······tags:1507 ······tags:
1508 ······-·CJIS-5.4.1.11508 ······-·CJIS-5.4.1.1
1509 ······-·NIST-800-171-3.1.71509 ······-·NIST-800-171-3.1.7
1510 ······-·NIST-800-53-AC-6(9)1510 ······-·NIST-800-53-AC-6(9)
1511 ······-·NIST-800-53-AU-12(c)1511 ······-·NIST-800-53-AU-12(c)
Offset 1523, 16 lines modifiedOffset 1523, 16 lines modified
1523 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/1523 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 66026/71076 bytes (92.89%) of diff not shown.
181 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-hipaa.yml
Ordering differences only
    
Offset 1279, 16 lines modifiedOffset 1279, 16 lines modified
  
1279 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1279 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1280 ······find:1280 ······find:
1281 ········paths:·/etc/audit/rules.d/1281 ········paths:·/etc/audit/rules.d/
1282 ········patterns:·'*.rules'1282 ········patterns:·'*.rules'
1283 ······register:·find_rules_d1283 ······register:·find_rules_d
1284 ······when:1284 ······when:
1285 ······-·'"audit"·in·ansible_facts.packages' 
1286 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1285 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1286 ······-·'"audit"·in·ansible_facts.packages'
1287 ······tags:1287 ······tags:
1288 ······-·CJIS-5.4.1.11288 ······-·CJIS-5.4.1.1
1289 ······-·NIST-800-171-3.3.11289 ······-·NIST-800-171-3.3.1
1290 ······-·NIST-800-171-3.4.31290 ······-·NIST-800-171-3.4.3
1291 ······-·NIST-800-53-AC-6(9)1291 ······-·NIST-800-53-AC-6(9)
1292 ······-·NIST-800-53-CM-6(a)1292 ······-·NIST-800-53-CM-6(a)
1293 ······-·PCI-DSS-Req-10.5.21293 ······-·PCI-DSS-Req-10.5.2
Offset 1303, 16 lines modifiedOffset 1303, 16 lines modified
1303 ······lineinfile:1303 ······lineinfile:
1304 ········path:·'{{·item·}}'1304 ········path:·'{{·item·}}'
1305 ········regexp:·^\s*(?:-e)\s+.*$1305 ········regexp:·^\s*(?:-e)\s+.*$
1306 ········state:·absent1306 ········state:·absent
1307 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1307 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1308 ········}}'1308 ········}}'
1309 ······when:1309 ······when:
1310 ······-·'"audit"·in·ansible_facts.packages' 
1311 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1310 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1311 ······-·'"audit"·in·ansible_facts.packages'
1312 ······tags:1312 ······tags:
1313 ······-·CJIS-5.4.1.11313 ······-·CJIS-5.4.1.1
1314 ······-·NIST-800-171-3.3.11314 ······-·NIST-800-171-3.3.1
1315 ······-·NIST-800-171-3.4.31315 ······-·NIST-800-171-3.4.3
1316 ······-·NIST-800-53-AC-6(9)1316 ······-·NIST-800-53-AC-6(9)
1317 ······-·NIST-800-53-CM-6(a)1317 ······-·NIST-800-53-CM-6(a)
1318 ······-·PCI-DSS-Req-10.5.21318 ······-·PCI-DSS-Req-10.5.2
Offset 1329, 16 lines modifiedOffset 1329, 16 lines modified
1329 ········create:·true1329 ········create:·true
1330 ········line:·-e·21330 ········line:·-e·2
1331 ········mode:·o-rwx1331 ········mode:·o-rwx
1332 ······loop:1332 ······loop:
1333 ······-·/etc/audit/audit.rules1333 ······-·/etc/audit/audit.rules
1334 ······-·/etc/audit/rules.d/immutable.rules1334 ······-·/etc/audit/rules.d/immutable.rules
1335 ······when:1335 ······when:
1336 ······-·'"audit"·in·ansible_facts.packages' 
1337 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1336 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1337 ······-·'"audit"·in·ansible_facts.packages'
1338 ······tags:1338 ······tags:
1339 ······-·CJIS-5.4.1.11339 ······-·CJIS-5.4.1.1
1340 ······-·NIST-800-171-3.3.11340 ······-·NIST-800-171-3.3.1
1341 ······-·NIST-800-171-3.4.31341 ······-·NIST-800-171-3.4.3
1342 ······-·NIST-800-53-AC-6(9)1342 ······-·NIST-800-53-AC-6(9)
1343 ······-·NIST-800-53-CM-6(a)1343 ······-·NIST-800-53-CM-6(a)
1344 ······-·PCI-DSS-Req-10.5.21344 ······-·PCI-DSS-Req-10.5.2
Offset 1370, 16 lines modifiedOffset 1370, 16 lines modified
1370 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1370 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1371 ······find:1371 ······find:
1372 ········paths:·/etc/audit/rules.d1372 ········paths:·/etc/audit/rules.d
1373 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1373 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1374 ········patterns:·'*.rules'1374 ········patterns:·'*.rules'
1375 ······register:·find_existing_watch_rules_d1375 ······register:·find_existing_watch_rules_d
1376 ······when:1376 ······when:
1377 ······-·'"audit"·in·ansible_facts.packages' 
1378 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1377 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1378 ······-·'"audit"·in·ansible_facts.packages'
1379 ······tags:1379 ······tags:
1380 ······-·CJIS-5.4.1.11380 ······-·CJIS-5.4.1.1
1381 ······-·NIST-800-171-3.1.81381 ······-·NIST-800-171-3.1.8
1382 ······-·NIST-800-53-AU-12(c)1382 ······-·NIST-800-53-AU-12(c)
1383 ······-·NIST-800-53-AU-2(d)1383 ······-·NIST-800-53-AU-2(d)
1384 ······-·NIST-800-53-CM-6(a)1384 ······-·NIST-800-53-CM-6(a)
1385 ······-·PCI-DSS-Req-10.5.51385 ······-·PCI-DSS-Req-10.5.5
Offset 1393, 16 lines modifiedOffset 1393, 16 lines modified
1393 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1393 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1394 ······find:1394 ······find:
1395 ········paths:·/etc/audit/rules.d1395 ········paths:·/etc/audit/rules.d
1396 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1396 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1397 ········patterns:·'*.rules'1397 ········patterns:·'*.rules'
1398 ······register:·find_watch_key1398 ······register:·find_watch_key
1399 ······when:1399 ······when:
1400 ······-·'"audit"·in·ansible_facts.packages' 
1401 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1400 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1401 ······-·'"audit"·in·ansible_facts.packages'
1402 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1402 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1403 ········==·01403 ········==·0
1404 ······tags:1404 ······tags:
1405 ······-·CJIS-5.4.1.11405 ······-·CJIS-5.4.1.1
1406 ······-·NIST-800-171-3.1.81406 ······-·NIST-800-171-3.1.8
1407 ······-·NIST-800-53-AU-12(c)1407 ······-·NIST-800-53-AU-12(c)
1408 ······-·NIST-800-53-AU-2(d)1408 ······-·NIST-800-53-AU-2(d)
Offset 1416, 16 lines modifiedOffset 1416, 16 lines modified
1416 ······-·restrict_strategy1416 ······-·restrict_strategy
  
1417 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1417 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1418 ······set_fact:1418 ······set_fact:
1419 ········all_files:1419 ········all_files:
1420 ········-·/etc/audit/rules.d/MAC-policy.rules1420 ········-·/etc/audit/rules.d/MAC-policy.rules
1421 ······when:1421 ······when:
1422 ······-·'"audit"·in·ansible_facts.packages' 
1423 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1422 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1423 ······-·'"audit"·in·ansible_facts.packages'
1424 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1424 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1425 ········is·defined·and·find_existing_watch_rules_d.matched·==·01425 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1426 ······tags:1426 ······tags:
1427 ······-·CJIS-5.4.1.11427 ······-·CJIS-5.4.1.1
1428 ······-·NIST-800-171-3.1.81428 ······-·NIST-800-171-3.1.8
1429 ······-·NIST-800-53-AU-12(c)1429 ······-·NIST-800-53-AU-12(c)
1430 ······-·NIST-800-53-AU-2(d)1430 ······-·NIST-800-53-AU-2(d)
Offset 1439, 16 lines modifiedOffset 1439, 16 lines modified
1439 ······-·restrict_strategy1439 ······-·restrict_strategy
  
1440 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1440 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1441 ······set_fact:1441 ······set_fact:
1442 ········all_files:1442 ········all_files:
1443 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1443 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1444 ······when:1444 ······when:
1445 ······-·'"audit"·in·ansible_facts.packages' 
1446 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1445 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1446 ······-·'"audit"·in·ansible_facts.packages'
1447 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1447 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1448 ········is·defined·and·find_existing_watch_rules_d.matched·==·01448 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1449 ······tags:1449 ······tags:
1450 ······-·CJIS-5.4.1.11450 ······-·CJIS-5.4.1.1
1451 ······-·NIST-800-171-3.1.81451 ······-·NIST-800-171-3.1.8
1452 ······-·NIST-800-53-AU-12(c)1452 ······-·NIST-800-53-AU-12(c)
1453 ······-·NIST-800-53-AU-2(d)1453 ······-·NIST-800-53-AU-2(d)
Offset 1464, 16 lines modifiedOffset 1464, 16 lines modified
1464 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1464 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 180115/184800 bytes (97.46%) of diff not shown.
86.6 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-ism_o.yml
Ordering differences only
    
Offset 4432, 16 lines modifiedOffset 4432, 16 lines modified
4432 ······-·no_reboot_needed4432 ······-·no_reboot_needed
4433 ······-·restrict_strategy4433 ······-·restrict_strategy
  
4434 ····-·name:·Set·architecture·for·audit·tasks4434 ····-·name:·Set·architecture·for·audit·tasks
4435 ······set_fact:4435 ······set_fact:
4436 ········audit_arch:·b644436 ········audit_arch:·b64
4437 ······when:4437 ······when:
4438 ······-·'"audit"·in·ansible_facts.packages' 
4439 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4438 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4439 ······-·'"audit"·in·ansible_facts.packages'
4440 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4440 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4441 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4441 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4442 ······tags:4442 ······tags:
4443 ······-·CJIS-5.4.1.14443 ······-·CJIS-5.4.1.1
4444 ······-·NIST-800-171-3.1.74444 ······-·NIST-800-171-3.1.7
4445 ······-·NIST-800-53-AC-6(9)4445 ······-·NIST-800-53-AC-6(9)
4446 ······-·NIST-800-53-AU-12(c)4446 ······-·NIST-800-53-AU-12(c)
Offset 4574, 16 lines modifiedOffset 4574, 16 lines modified
4574 ··········path:·'{{·audit_file·}}'4574 ··········path:·'{{·audit_file·}}'
4575 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification4575 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
4576 ··········create:·true4576 ··········create:·true
4577 ··········mode:·o-rwx4577 ··········mode:·o-rwx
4578 ··········state:·present4578 ··········state:·present
4579 ········when:·syscalls_found·|·length·==·04579 ········when:·syscalls_found·|·length·==·0
4580 ······when:4580 ······when:
4581 ······-·'"audit"·in·ansible_facts.packages' 
4582 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4581 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4582 ······-·'"audit"·in·ansible_facts.packages'
4583 ······tags:4583 ······tags:
4584 ······-·CJIS-5.4.1.14584 ······-·CJIS-5.4.1.1
4585 ······-·NIST-800-171-3.1.74585 ······-·NIST-800-171-3.1.7
4586 ······-·NIST-800-53-AC-6(9)4586 ······-·NIST-800-53-AC-6(9)
4587 ······-·NIST-800-53-AU-12(c)4587 ······-·NIST-800-53-AU-12(c)
4588 ······-·NIST-800-53-AU-2(d)4588 ······-·NIST-800-53-AU-2(d)
4589 ······-·NIST-800-53-CM-6(a)4589 ······-·NIST-800-53-CM-6(a)
Offset 4714, 16 lines modifiedOffset 4714, 16 lines modified
4714 ··········path:·'{{·audit_file·}}'4714 ··········path:·'{{·audit_file·}}'
4715 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification4715 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
4716 ··········create:·true4716 ··········create:·true
4717 ··········mode:·o-rwx4717 ··········mode:·o-rwx
4718 ··········state:·present4718 ··········state:·present
4719 ········when:·syscalls_found·|·length·==·04719 ········when:·syscalls_found·|·length·==·0
4720 ······when:4720 ······when:
4721 ······-·'"audit"·in·ansible_facts.packages' 
4722 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4721 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4722 ······-·'"audit"·in·ansible_facts.packages'
4723 ······-·audit_arch·==·"b64"4723 ······-·audit_arch·==·"b64"
4724 ······tags:4724 ······tags:
4725 ······-·CJIS-5.4.1.14725 ······-·CJIS-5.4.1.1
4726 ······-·NIST-800-171-3.1.74726 ······-·NIST-800-171-3.1.7
4727 ······-·NIST-800-53-AC-6(9)4727 ······-·NIST-800-53-AC-6(9)
4728 ······-·NIST-800-53-AU-12(c)4728 ······-·NIST-800-53-AU-12(c)
4729 ······-·NIST-800-53-AU-2(d)4729 ······-·NIST-800-53-AU-2(d)
Offset 4739, 16 lines modifiedOffset 4739, 16 lines modified
4739 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/4739 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
4740 ······find:4740 ······find:
4741 ········paths:·/etc/audit/rules.d4741 ········paths:·/etc/audit/rules.d
4742 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+4742 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
4743 ········patterns:·'*.rules'4743 ········patterns:·'*.rules'
4744 ······register:·find_existing_watch_rules_d4744 ······register:·find_existing_watch_rules_d
4745 ······when:4745 ······when:
4746 ······-·'"audit"·in·ansible_facts.packages' 
4747 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4746 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4747 ······-·'"audit"·in·ansible_facts.packages'
4748 ······tags:4748 ······tags:
4749 ······-·CJIS-5.4.1.14749 ······-·CJIS-5.4.1.1
4750 ······-·NIST-800-171-3.1.74750 ······-·NIST-800-171-3.1.7
4751 ······-·NIST-800-53-AC-6(9)4751 ······-·NIST-800-53-AC-6(9)
4752 ······-·NIST-800-53-AU-12(c)4752 ······-·NIST-800-53-AU-12(c)
4753 ······-·NIST-800-53-AU-2(d)4753 ······-·NIST-800-53-AU-2(d)
4754 ······-·NIST-800-53-CM-6(a)4754 ······-·NIST-800-53-CM-6(a)
Offset 4763, 16 lines modifiedOffset 4763, 16 lines modified
4763 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification4763 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
4764 ······find:4764 ······find:
4765 ········paths:·/etc/audit/rules.d4765 ········paths:·/etc/audit/rules.d
4766 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$4766 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
4767 ········patterns:·'*.rules'4767 ········patterns:·'*.rules'
4768 ······register:·find_watch_key4768 ······register:·find_watch_key
4769 ······when:4769 ······when:
4770 ······-·'"audit"·in·ansible_facts.packages' 
4771 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4770 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4771 ······-·'"audit"·in·ansible_facts.packages'
4772 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4772 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4773 ········==·04773 ········==·0
4774 ······tags:4774 ······tags:
4775 ······-·CJIS-5.4.1.14775 ······-·CJIS-5.4.1.1
4776 ······-·NIST-800-171-3.1.74776 ······-·NIST-800-171-3.1.7
4777 ······-·NIST-800-53-AC-6(9)4777 ······-·NIST-800-53-AC-6(9)
4778 ······-·NIST-800-53-AU-12(c)4778 ······-·NIST-800-53-AU-12(c)
Offset 4788, 16 lines modifiedOffset 4788, 16 lines modified
  
4788 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the4788 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
4789 ········recipient·for·the·rule4789 ········recipient·for·the·rule
4790 ······set_fact:4790 ······set_fact:
4791 ········all_files:4791 ········all_files:
4792 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules4792 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
4793 ······when:4793 ······when:
4794 ······-·'"audit"·in·ansible_facts.packages' 
4795 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4794 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4795 ······-·'"audit"·in·ansible_facts.packages'
4796 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched4796 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
4797 ········is·defined·and·find_existing_watch_rules_d.matched·==·04797 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4798 ······tags:4798 ······tags:
4799 ······-·CJIS-5.4.1.14799 ······-·CJIS-5.4.1.1
4800 ······-·NIST-800-171-3.1.74800 ······-·NIST-800-171-3.1.7
4801 ······-·NIST-800-53-AC-6(9)4801 ······-·NIST-800-53-AC-6(9)
4802 ······-·NIST-800-53-AU-12(c)4802 ······-·NIST-800-53-AU-12(c)
Offset 4812, 16 lines modifiedOffset 4812, 16 lines modified
4812 ······-·restrict_strategy4812 ······-·restrict_strategy
  
4813 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule4813 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
4814 ······set_fact:4814 ······set_fact:
4815 ········all_files:4815 ········all_files:
4816 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'4816 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
4817 ······when:4817 ······when:
4818 ······-·'"audit"·in·ansible_facts.packages' 
4819 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4818 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4819 ······-·'"audit"·in·ansible_facts.packages'
4820 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched4820 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
4821 ········is·defined·and·find_existing_watch_rules_d.matched·==·04821 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4822 ······tags:4822 ······tags:
4823 ······-·CJIS-5.4.1.14823 ······-·CJIS-5.4.1.1
4824 ······-·NIST-800-171-3.1.74824 ······-·NIST-800-171-3.1.7
4825 ······-·NIST-800-53-AC-6(9)4825 ······-·NIST-800-53-AC-6(9)
4826 ······-·NIST-800-53-AU-12(c)4826 ······-·NIST-800-53-AU-12(c)
Offset 4838, 16 lines modifiedOffset 4838, 16 lines modified
4838 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/4838 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 83486/88536 bytes (94.30%) of diff not shown.
2.4 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-ospp.yml
Ordering differences only
    
Offset 3357, 16 lines modifiedOffset 3357, 16 lines modified
3357 ······lineinfile:3357 ······lineinfile:
3358 ········dest:·/etc/audit/auditd.conf3358 ········dest:·/etc/audit/auditd.conf
3359 ········regexp:·^\s*flush\s*=\s*.*$3359 ········regexp:·^\s*flush\s*=\s*.*$
3360 ········line:·flush·=·{{·var_auditd_flush·}}3360 ········line:·flush·=·{{·var_auditd_flush·}}
3361 ········state:·present3361 ········state:·present
3362 ········create:·true3362 ········create:·true
3363 ······when:3363 ······when:
3364 ······-·'"audit"·in·ansible_facts.packages' 
3365 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3364 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3365 ······-·'"audit"·in·ansible_facts.packages'
3366 ······tags:3366 ······tags:
3367 ······-·NIST-800-171-3.3.13367 ······-·NIST-800-171-3.3.1
3368 ······-·NIST-800-53-AU-113368 ······-·NIST-800-53-AU-11
3369 ······-·NIST-800-53-CM-6(a)3369 ······-·NIST-800-53-CM-6(a)
3370 ······-·auditd_data_retention_flush3370 ······-·auditd_data_retention_flush
3371 ······-·low_complexity3371 ······-·low_complexity
3372 ······-·low_disruption3372 ······-·low_disruption
Offset 3412, 16 lines modifiedOffset 3412, 16 lines modified
3412 ········lineinfile:3412 ········lineinfile:
3413 ··········path:·/etc/audit/auditd.conf3413 ··········path:·/etc/audit/auditd.conf
3414 ··········create:·true3414 ··········create:·true
3415 ··········regexp:·(?i)^\s*freq\s*=\s*3415 ··········regexp:·(?i)^\s*freq\s*=\s*
3416 ··········line:·freq·=·503416 ··········line:·freq·=·50
3417 ··········state:·present3417 ··········state:·present
3418 ······when:3418 ······when:
3419 ······-·'"audit"·in·ansible_facts.packages' 
3420 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3419 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3420 ······-·'"audit"·in·ansible_facts.packages'
3421 ······tags:3421 ······tags:
3422 ······-·NIST-800-53-CM-63422 ······-·NIST-800-53-CM-6
3423 ······-·auditd_freq3423 ······-·auditd_freq
3424 ······-·low_complexity3424 ······-·low_complexity
3425 ······-·low_disruption3425 ······-·low_disruption
3426 ······-·medium_severity3426 ······-·medium_severity
3427 ······-·no_reboot_needed3427 ······-·no_reboot_needed
Offset 3466, 16 lines modifiedOffset 3466, 16 lines modified
3466 ········lineinfile:3466 ········lineinfile:
3467 ··········path:·/etc/audit/auditd.conf3467 ··········path:·/etc/audit/auditd.conf
3468 ··········create:·true3468 ··········create:·true
3469 ··········regexp:·(?i)^\s*log_format\s*=\s*3469 ··········regexp:·(?i)^\s*log_format\s*=\s*
3470 ··········line:·log_format·=·ENRICHED3470 ··········line:·log_format·=·ENRICHED
3471 ··········state:·present3471 ··········state:·present
3472 ······when:3472 ······when:
3473 ······-·'"audit"·in·ansible_facts.packages' 
3474 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3473 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3474 ······-·'"audit"·in·ansible_facts.packages'
3475 ······tags:3475 ······tags:
3476 ······-·NIST-800-53-AU-33476 ······-·NIST-800-53-AU-3
3477 ······-·NIST-800-53-CM-63477 ······-·NIST-800-53-CM-6
3478 ······-·auditd_log_format3478 ······-·auditd_log_format
3479 ······-·low_complexity3479 ······-·low_complexity
3480 ······-·low_disruption3480 ······-·low_disruption
3481 ······-·low_severity3481 ······-·low_severity
Offset 3521, 16 lines modifiedOffset 3521, 16 lines modified
3521 ········lineinfile:3521 ········lineinfile:
3522 ··········path:·/etc/audit/auditd.conf3522 ··········path:·/etc/audit/auditd.conf
3523 ··········create:·true3523 ··········create:·true
3524 ··········regexp:·(?i)^\s*name_format\s*=\s*3524 ··········regexp:·(?i)^\s*name_format\s*=\s*
3525 ··········line:·name_format·=·hostname3525 ··········line:·name_format·=·hostname
3526 ··········state:·present3526 ··········state:·present
3527 ······when:3527 ······when:
3528 ······-·'"audit"·in·ansible_facts.packages' 
3529 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3528 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3529 ······-·'"audit"·in·ansible_facts.packages'
3530 ······tags:3530 ······tags:
3531 ······-·NIST-800-53-AU-33531 ······-·NIST-800-53-AU-3
3532 ······-·NIST-800-53-CM-63532 ······-·NIST-800-53-CM-6
3533 ······-·auditd_name_format3533 ······-·auditd_name_format
3534 ······-·low_complexity3534 ······-·low_complexity
3535 ······-·low_disruption3535 ······-·low_disruption
3536 ······-·medium_severity3536 ······-·medium_severity
159 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-pci-dss.yml
Ordering differences only
    
Offset 4963, 16 lines modifiedOffset 4963, 16 lines modified
  
4963 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension4963 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
4964 ······find:4964 ······find:
4965 ········paths:·/etc/audit/rules.d/4965 ········paths:·/etc/audit/rules.d/
4966 ········patterns:·'*.rules'4966 ········patterns:·'*.rules'
4967 ······register:·find_rules_d4967 ······register:·find_rules_d
4968 ······when:4968 ······when:
4969 ······-·'"audit"·in·ansible_facts.packages' 
4970 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4969 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4970 ······-·'"audit"·in·ansible_facts.packages'
4971 ······tags:4971 ······tags:
4972 ······-·CJIS-5.4.1.14972 ······-·CJIS-5.4.1.1
4973 ······-·NIST-800-171-3.3.14973 ······-·NIST-800-171-3.3.1
4974 ······-·NIST-800-171-3.4.34974 ······-·NIST-800-171-3.4.3
4975 ······-·NIST-800-53-AC-6(9)4975 ······-·NIST-800-53-AC-6(9)
4976 ······-·NIST-800-53-CM-6(a)4976 ······-·NIST-800-53-CM-6(a)
4977 ······-·PCI-DSS-Req-10.5.24977 ······-·PCI-DSS-Req-10.5.2
Offset 4987, 16 lines modifiedOffset 4987, 16 lines modified
4987 ······lineinfile:4987 ······lineinfile:
4988 ········path:·'{{·item·}}'4988 ········path:·'{{·item·}}'
4989 ········regexp:·^\s*(?:-e)\s+.*$4989 ········regexp:·^\s*(?:-e)\s+.*$
4990 ········state:·absent4990 ········state:·absent
4991 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']4991 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
4992 ········}}'4992 ········}}'
4993 ······when:4993 ······when:
4994 ······-·'"audit"·in·ansible_facts.packages' 
4995 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4994 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4995 ······-·'"audit"·in·ansible_facts.packages'
4996 ······tags:4996 ······tags:
4997 ······-·CJIS-5.4.1.14997 ······-·CJIS-5.4.1.1
4998 ······-·NIST-800-171-3.3.14998 ······-·NIST-800-171-3.3.1
4999 ······-·NIST-800-171-3.4.34999 ······-·NIST-800-171-3.4.3
5000 ······-·NIST-800-53-AC-6(9)5000 ······-·NIST-800-53-AC-6(9)
5001 ······-·NIST-800-53-CM-6(a)5001 ······-·NIST-800-53-CM-6(a)
5002 ······-·PCI-DSS-Req-10.5.25002 ······-·PCI-DSS-Req-10.5.2
Offset 5013, 16 lines modifiedOffset 5013, 16 lines modified
5013 ········create:·true5013 ········create:·true
5014 ········line:·-e·25014 ········line:·-e·2
5015 ········mode:·o-rwx5015 ········mode:·o-rwx
5016 ······loop:5016 ······loop:
5017 ······-·/etc/audit/audit.rules5017 ······-·/etc/audit/audit.rules
5018 ······-·/etc/audit/rules.d/immutable.rules5018 ······-·/etc/audit/rules.d/immutable.rules
5019 ······when:5019 ······when:
5020 ······-·'"audit"·in·ansible_facts.packages' 
5021 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5020 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5021 ······-·'"audit"·in·ansible_facts.packages'
5022 ······tags:5022 ······tags:
5023 ······-·CJIS-5.4.1.15023 ······-·CJIS-5.4.1.1
5024 ······-·NIST-800-171-3.3.15024 ······-·NIST-800-171-3.3.1
5025 ······-·NIST-800-171-3.4.35025 ······-·NIST-800-171-3.4.3
5026 ······-·NIST-800-53-AC-6(9)5026 ······-·NIST-800-53-AC-6(9)
5027 ······-·NIST-800-53-CM-6(a)5027 ······-·NIST-800-53-CM-6(a)
5028 ······-·PCI-DSS-Req-10.5.25028 ······-·PCI-DSS-Req-10.5.2
Offset 5054, 16 lines modifiedOffset 5054, 16 lines modified
5054 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5054 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5055 ······find:5055 ······find:
5056 ········paths:·/etc/audit/rules.d5056 ········paths:·/etc/audit/rules.d
5057 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5057 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5058 ········patterns:·'*.rules'5058 ········patterns:·'*.rules'
5059 ······register:·find_existing_watch_rules_d5059 ······register:·find_existing_watch_rules_d
5060 ······when:5060 ······when:
5061 ······-·'"audit"·in·ansible_facts.packages' 
5062 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5061 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5062 ······-·'"audit"·in·ansible_facts.packages'
5063 ······tags:5063 ······tags:
5064 ······-·CJIS-5.4.1.15064 ······-·CJIS-5.4.1.1
5065 ······-·NIST-800-171-3.1.85065 ······-·NIST-800-171-3.1.8
5066 ······-·NIST-800-53-AU-12(c)5066 ······-·NIST-800-53-AU-12(c)
5067 ······-·NIST-800-53-AU-2(d)5067 ······-·NIST-800-53-AU-2(d)
5068 ······-·NIST-800-53-CM-6(a)5068 ······-·NIST-800-53-CM-6(a)
5069 ······-·PCI-DSS-Req-10.5.55069 ······-·PCI-DSS-Req-10.5.5
Offset 5077, 16 lines modifiedOffset 5077, 16 lines modified
5077 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5077 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5078 ······find:5078 ······find:
5079 ········paths:·/etc/audit/rules.d5079 ········paths:·/etc/audit/rules.d
5080 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5080 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5081 ········patterns:·'*.rules'5081 ········patterns:·'*.rules'
5082 ······register:·find_watch_key5082 ······register:·find_watch_key
5083 ······when:5083 ······when:
5084 ······-·'"audit"·in·ansible_facts.packages' 
5085 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5084 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5085 ······-·'"audit"·in·ansible_facts.packages'
5086 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5086 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5087 ········==·05087 ········==·0
5088 ······tags:5088 ······tags:
5089 ······-·CJIS-5.4.1.15089 ······-·CJIS-5.4.1.1
5090 ······-·NIST-800-171-3.1.85090 ······-·NIST-800-171-3.1.8
5091 ······-·NIST-800-53-AU-12(c)5091 ······-·NIST-800-53-AU-12(c)
5092 ······-·NIST-800-53-AU-2(d)5092 ······-·NIST-800-53-AU-2(d)
Offset 5100, 16 lines modifiedOffset 5100, 16 lines modified
5100 ······-·restrict_strategy5100 ······-·restrict_strategy
  
5101 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5101 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5102 ······set_fact:5102 ······set_fact:
5103 ········all_files:5103 ········all_files:
5104 ········-·/etc/audit/rules.d/MAC-policy.rules5104 ········-·/etc/audit/rules.d/MAC-policy.rules
5105 ······when:5105 ······when:
5106 ······-·'"audit"·in·ansible_facts.packages' 
5107 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5106 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5107 ······-·'"audit"·in·ansible_facts.packages'
5108 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5108 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5109 ········is·defined·and·find_existing_watch_rules_d.matched·==·05109 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5110 ······tags:5110 ······tags:
5111 ······-·CJIS-5.4.1.15111 ······-·CJIS-5.4.1.1
5112 ······-·NIST-800-171-3.1.85112 ······-·NIST-800-171-3.1.8
5113 ······-·NIST-800-53-AU-12(c)5113 ······-·NIST-800-53-AU-12(c)
5114 ······-·NIST-800-53-AU-2(d)5114 ······-·NIST-800-53-AU-2(d)
Offset 5123, 16 lines modifiedOffset 5123, 16 lines modified
5123 ······-·restrict_strategy5123 ······-·restrict_strategy
  
5124 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5124 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5125 ······set_fact:5125 ······set_fact:
5126 ········all_files:5126 ········all_files:
5127 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5127 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5128 ······when:5128 ······when:
5129 ······-·'"audit"·in·ansible_facts.packages' 
5130 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5129 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5130 ······-·'"audit"·in·ansible_facts.packages'
5131 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5131 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5132 ········is·defined·and·find_existing_watch_rules_d.matched·==·05132 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5133 ······tags:5133 ······tags:
5134 ······-·CJIS-5.4.1.15134 ······-·CJIS-5.4.1.1
5135 ······-·NIST-800-171-3.1.85135 ······-·NIST-800-171-3.1.8
5136 ······-·NIST-800-53-AU-12(c)5136 ······-·NIST-800-53-AU-12(c)
5137 ······-·NIST-800-53-AU-2(d)5137 ······-·NIST-800-53-AU-2(d)
Offset 5148, 16 lines modifiedOffset 5148, 16 lines modified
5148 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5148 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 158112/162797 bytes (97.12%) of diff not shown.
166 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-stig.yml
Ordering differences only
    
Offset 11695, 16 lines modifiedOffset 11695, 16 lines modified
  
11695 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension11695 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
11696 ······find:11696 ······find:
11697 ········paths:·/etc/audit/rules.d/11697 ········paths:·/etc/audit/rules.d/
11698 ········patterns:·'*.rules'11698 ········patterns:·'*.rules'
11699 ······register:·find_rules_d11699 ······register:·find_rules_d
11700 ······when:11700 ······when:
11701 ······-·'"audit"·in·ansible_facts.packages' 
11702 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11701 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11702 ······-·'"audit"·in·ansible_facts.packages'
11703 ······tags:11703 ······tags:
11704 ······-·CJIS-5.4.1.111704 ······-·CJIS-5.4.1.1
11705 ······-·NIST-800-171-3.3.111705 ······-·NIST-800-171-3.3.1
11706 ······-·NIST-800-171-3.4.311706 ······-·NIST-800-171-3.4.3
11707 ······-·NIST-800-53-AC-6(9)11707 ······-·NIST-800-53-AC-6(9)
11708 ······-·NIST-800-53-CM-6(a)11708 ······-·NIST-800-53-CM-6(a)
11709 ······-·PCI-DSS-Req-10.5.211709 ······-·PCI-DSS-Req-10.5.2
Offset 11719, 16 lines modifiedOffset 11719, 16 lines modified
11719 ······lineinfile:11719 ······lineinfile:
11720 ········path:·'{{·item·}}'11720 ········path:·'{{·item·}}'
11721 ········regexp:·^\s*(?:-e)\s+.*$11721 ········regexp:·^\s*(?:-e)\s+.*$
11722 ········state:·absent11722 ········state:·absent
11723 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']11723 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
11724 ········}}'11724 ········}}'
11725 ······when:11725 ······when:
11726 ······-·'"audit"·in·ansible_facts.packages' 
11727 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11726 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11727 ······-·'"audit"·in·ansible_facts.packages'
11728 ······tags:11728 ······tags:
11729 ······-·CJIS-5.4.1.111729 ······-·CJIS-5.4.1.1
11730 ······-·NIST-800-171-3.3.111730 ······-·NIST-800-171-3.3.1
11731 ······-·NIST-800-171-3.4.311731 ······-·NIST-800-171-3.4.3
11732 ······-·NIST-800-53-AC-6(9)11732 ······-·NIST-800-53-AC-6(9)
11733 ······-·NIST-800-53-CM-6(a)11733 ······-·NIST-800-53-CM-6(a)
11734 ······-·PCI-DSS-Req-10.5.211734 ······-·PCI-DSS-Req-10.5.2
Offset 11745, 16 lines modifiedOffset 11745, 16 lines modified
11745 ········create:·true11745 ········create:·true
11746 ········line:·-e·211746 ········line:·-e·2
11747 ········mode:·o-rwx11747 ········mode:·o-rwx
11748 ······loop:11748 ······loop:
11749 ······-·/etc/audit/audit.rules11749 ······-·/etc/audit/audit.rules
11750 ······-·/etc/audit/rules.d/immutable.rules11750 ······-·/etc/audit/rules.d/immutable.rules
11751 ······when:11751 ······when:
11752 ······-·'"audit"·in·ansible_facts.packages' 
11753 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11752 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11753 ······-·'"audit"·in·ansible_facts.packages'
11754 ······tags:11754 ······tags:
11755 ······-·CJIS-5.4.1.111755 ······-·CJIS-5.4.1.1
11756 ······-·NIST-800-171-3.3.111756 ······-·NIST-800-171-3.3.1
11757 ······-·NIST-800-171-3.4.311757 ······-·NIST-800-171-3.4.3
11758 ······-·NIST-800-53-AC-6(9)11758 ······-·NIST-800-53-AC-6(9)
11759 ······-·NIST-800-53-CM-6(a)11759 ······-·NIST-800-53-CM-6(a)
11760 ······-·PCI-DSS-Req-10.5.211760 ······-·PCI-DSS-Req-10.5.2
Offset 11784, 16 lines modifiedOffset 11784, 16 lines modified
11784 ······-·reboot_required11784 ······-·reboot_required
11785 ······-·restrict_strategy11785 ······-·restrict_strategy
  
11786 ····-·name:·Set·architecture·for·audit·mount·tasks11786 ····-·name:·Set·architecture·for·audit·mount·tasks
11787 ······set_fact:11787 ······set_fact:
11788 ········audit_arch:·b6411788 ········audit_arch:·b64
11789 ······when:11789 ······when:
11790 ······-·'"audit"·in·ansible_facts.packages' 
11791 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11790 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11791 ······-·'"audit"·in·ansible_facts.packages'
11792 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture11792 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
11793 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"11793 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
11794 ······tags:11794 ······tags:
11795 ······-·CJIS-5.4.1.111795 ······-·CJIS-5.4.1.1
11796 ······-·NIST-800-171-3.1.711796 ······-·NIST-800-171-3.1.7
11797 ······-·NIST-800-53-AC-6(9)11797 ······-·NIST-800-53-AC-6(9)
11798 ······-·NIST-800-53-AU-12(c)11798 ······-·NIST-800-53-AU-12(c)
Offset 11924, 16 lines modifiedOffset 11924, 16 lines modified
11924 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011924 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11925 ············-F·auid!=unset·-F·key=perm_mod11925 ············-F·auid!=unset·-F·key=perm_mod
11926 ··········create:·true11926 ··········create:·true
11927 ··········mode:·o-rwx11927 ··········mode:·o-rwx
11928 ··········state:·present11928 ··········state:·present
11929 ········when:·syscalls_found·|·length·==·011929 ········when:·syscalls_found·|·length·==·0
11930 ······when:11930 ······when:
11931 ······-·'"audit"·in·ansible_facts.packages' 
11932 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11931 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11932 ······-·'"audit"·in·ansible_facts.packages'
11933 ······tags:11933 ······tags:
11934 ······-·CJIS-5.4.1.111934 ······-·CJIS-5.4.1.1
11935 ······-·NIST-800-171-3.1.711935 ······-·NIST-800-171-3.1.7
11936 ······-·NIST-800-53-AC-6(9)11936 ······-·NIST-800-53-AC-6(9)
11937 ······-·NIST-800-53-AU-12(c)11937 ······-·NIST-800-53-AU-12(c)
11938 ······-·NIST-800-53-AU-2(d)11938 ······-·NIST-800-53-AU-2(d)
11939 ······-·NIST-800-53-CM-6(a)11939 ······-·NIST-800-53-CM-6(a)
Offset 12062, 16 lines modifiedOffset 12062, 16 lines modified
12062 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012062 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12063 ············-F·auid!=unset·-F·key=perm_mod12063 ············-F·auid!=unset·-F·key=perm_mod
12064 ··········create:·true12064 ··········create:·true
12065 ··········mode:·o-rwx12065 ··········mode:·o-rwx
12066 ··········state:·present12066 ··········state:·present
12067 ········when:·syscalls_found·|·length·==·012067 ········when:·syscalls_found·|·length·==·0
12068 ······when:12068 ······when:
12069 ······-·'"audit"·in·ansible_facts.packages' 
12070 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12069 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12070 ······-·'"audit"·in·ansible_facts.packages'
12071 ······-·audit_arch·==·"b64"12071 ······-·audit_arch·==·"b64"
12072 ······tags:12072 ······tags:
12073 ······-·CJIS-5.4.1.112073 ······-·CJIS-5.4.1.1
12074 ······-·NIST-800-171-3.1.712074 ······-·NIST-800-171-3.1.7
12075 ······-·NIST-800-53-AC-6(9)12075 ······-·NIST-800-53-AC-6(9)
12076 ······-·NIST-800-53-AU-12(c)12076 ······-·NIST-800-53-AU-12(c)
12077 ······-·NIST-800-53-AU-2(d)12077 ······-·NIST-800-53-AU-2(d)
Offset 12099, 16 lines modifiedOffset 12099, 16 lines modified
12099 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/12099 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
12100 ······find:12100 ······find:
12101 ········paths:·/etc/audit/rules.d12101 ········paths:·/etc/audit/rules.d
12102 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+12102 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
12103 ········patterns:·'*.rules'12103 ········patterns:·'*.rules'
12104 ······register:·find_existing_watch_rules_d12104 ······register:·find_existing_watch_rules_d
12105 ······when:12105 ······when:
12106 ······-·'"audit"·in·ansible_facts.packages' 
12107 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12106 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12107 ······-·'"audit"·in·ansible_facts.packages'
12108 ······tags:12108 ······tags:
12109 ······-·audit_rules_sudoers12109 ······-·audit_rules_sudoers
12110 ······-·low_complexity12110 ······-·low_complexity
12111 ······-·low_disruption12111 ······-·low_disruption
12112 ······-·medium_severity12112 ······-·medium_severity
12113 ······-·no_reboot_needed12113 ······-·no_reboot_needed
12114 ······-·restrict_strategy12114 ······-·restrict_strategy
Offset 12116, 16 lines modifiedOffset 12116, 16 lines modified
12116 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions12116 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 165197/169732 bytes (97.33%) of diff not shown.
166 KB
./usr/share/scap-security-guide/ansible/cs9-playbook-stig_gui.yml
Ordering differences only
    
Offset 11669, 16 lines modifiedOffset 11669, 16 lines modified
  
11669 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension11669 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
11670 ······find:11670 ······find:
11671 ········paths:·/etc/audit/rules.d/11671 ········paths:·/etc/audit/rules.d/
11672 ········patterns:·'*.rules'11672 ········patterns:·'*.rules'
11673 ······register:·find_rules_d11673 ······register:·find_rules_d
11674 ······when:11674 ······when:
11675 ······-·'"audit"·in·ansible_facts.packages' 
11676 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11675 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11676 ······-·'"audit"·in·ansible_facts.packages'
11677 ······tags:11677 ······tags:
11678 ······-·CJIS-5.4.1.111678 ······-·CJIS-5.4.1.1
11679 ······-·NIST-800-171-3.3.111679 ······-·NIST-800-171-3.3.1
11680 ······-·NIST-800-171-3.4.311680 ······-·NIST-800-171-3.4.3
11681 ······-·NIST-800-53-AC-6(9)11681 ······-·NIST-800-53-AC-6(9)
11682 ······-·NIST-800-53-CM-6(a)11682 ······-·NIST-800-53-CM-6(a)
11683 ······-·PCI-DSS-Req-10.5.211683 ······-·PCI-DSS-Req-10.5.2
Offset 11693, 16 lines modifiedOffset 11693, 16 lines modified
11693 ······lineinfile:11693 ······lineinfile:
11694 ········path:·'{{·item·}}'11694 ········path:·'{{·item·}}'
11695 ········regexp:·^\s*(?:-e)\s+.*$11695 ········regexp:·^\s*(?:-e)\s+.*$
11696 ········state:·absent11696 ········state:·absent
11697 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']11697 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
11698 ········}}'11698 ········}}'
11699 ······when:11699 ······when:
11700 ······-·'"audit"·in·ansible_facts.packages' 
11701 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11700 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11701 ······-·'"audit"·in·ansible_facts.packages'
11702 ······tags:11702 ······tags:
11703 ······-·CJIS-5.4.1.111703 ······-·CJIS-5.4.1.1
11704 ······-·NIST-800-171-3.3.111704 ······-·NIST-800-171-3.3.1
11705 ······-·NIST-800-171-3.4.311705 ······-·NIST-800-171-3.4.3
11706 ······-·NIST-800-53-AC-6(9)11706 ······-·NIST-800-53-AC-6(9)
11707 ······-·NIST-800-53-CM-6(a)11707 ······-·NIST-800-53-CM-6(a)
11708 ······-·PCI-DSS-Req-10.5.211708 ······-·PCI-DSS-Req-10.5.2
Offset 11719, 16 lines modifiedOffset 11719, 16 lines modified
11719 ········create:·true11719 ········create:·true
11720 ········line:·-e·211720 ········line:·-e·2
11721 ········mode:·o-rwx11721 ········mode:·o-rwx
11722 ······loop:11722 ······loop:
11723 ······-·/etc/audit/audit.rules11723 ······-·/etc/audit/audit.rules
11724 ······-·/etc/audit/rules.d/immutable.rules11724 ······-·/etc/audit/rules.d/immutable.rules
11725 ······when:11725 ······when:
11726 ······-·'"audit"·in·ansible_facts.packages' 
11727 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11726 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11727 ······-·'"audit"·in·ansible_facts.packages'
11728 ······tags:11728 ······tags:
11729 ······-·CJIS-5.4.1.111729 ······-·CJIS-5.4.1.1
11730 ······-·NIST-800-171-3.3.111730 ······-·NIST-800-171-3.3.1
11731 ······-·NIST-800-171-3.4.311731 ······-·NIST-800-171-3.4.3
11732 ······-·NIST-800-53-AC-6(9)11732 ······-·NIST-800-53-AC-6(9)
11733 ······-·NIST-800-53-CM-6(a)11733 ······-·NIST-800-53-CM-6(a)
11734 ······-·PCI-DSS-Req-10.5.211734 ······-·PCI-DSS-Req-10.5.2
Offset 11758, 16 lines modifiedOffset 11758, 16 lines modified
11758 ······-·reboot_required11758 ······-·reboot_required
11759 ······-·restrict_strategy11759 ······-·restrict_strategy
  
11760 ····-·name:·Set·architecture·for·audit·mount·tasks11760 ····-·name:·Set·architecture·for·audit·mount·tasks
11761 ······set_fact:11761 ······set_fact:
11762 ········audit_arch:·b6411762 ········audit_arch:·b64
11763 ······when:11763 ······when:
11764 ······-·'"audit"·in·ansible_facts.packages' 
11765 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11764 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11765 ······-·'"audit"·in·ansible_facts.packages'
11766 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture11766 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
11767 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"11767 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
11768 ······tags:11768 ······tags:
11769 ······-·CJIS-5.4.1.111769 ······-·CJIS-5.4.1.1
11770 ······-·NIST-800-171-3.1.711770 ······-·NIST-800-171-3.1.7
11771 ······-·NIST-800-53-AC-6(9)11771 ······-·NIST-800-53-AC-6(9)
11772 ······-·NIST-800-53-AU-12(c)11772 ······-·NIST-800-53-AU-12(c)
Offset 11898, 16 lines modifiedOffset 11898, 16 lines modified
11898 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100011898 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
11899 ············-F·auid!=unset·-F·key=perm_mod11899 ············-F·auid!=unset·-F·key=perm_mod
11900 ··········create:·true11900 ··········create:·true
11901 ··········mode:·o-rwx11901 ··········mode:·o-rwx
11902 ··········state:·present11902 ··········state:·present
11903 ········when:·syscalls_found·|·length·==·011903 ········when:·syscalls_found·|·length·==·0
11904 ······when:11904 ······when:
11905 ······-·'"audit"·in·ansible_facts.packages' 
11906 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11905 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11906 ······-·'"audit"·in·ansible_facts.packages'
11907 ······tags:11907 ······tags:
11908 ······-·CJIS-5.4.1.111908 ······-·CJIS-5.4.1.1
11909 ······-·NIST-800-171-3.1.711909 ······-·NIST-800-171-3.1.7
11910 ······-·NIST-800-53-AC-6(9)11910 ······-·NIST-800-53-AC-6(9)
11911 ······-·NIST-800-53-AU-12(c)11911 ······-·NIST-800-53-AU-12(c)
11912 ······-·NIST-800-53-AU-2(d)11912 ······-·NIST-800-53-AU-2(d)
11913 ······-·NIST-800-53-CM-6(a)11913 ······-·NIST-800-53-CM-6(a)
Offset 12036, 16 lines modifiedOffset 12036, 16 lines modified
12036 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012036 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12037 ············-F·auid!=unset·-F·key=perm_mod12037 ············-F·auid!=unset·-F·key=perm_mod
12038 ··········create:·true12038 ··········create:·true
12039 ··········mode:·o-rwx12039 ··········mode:·o-rwx
12040 ··········state:·present12040 ··········state:·present
12041 ········when:·syscalls_found·|·length·==·012041 ········when:·syscalls_found·|·length·==·0
12042 ······when:12042 ······when:
12043 ······-·'"audit"·in·ansible_facts.packages' 
12044 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12043 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12044 ······-·'"audit"·in·ansible_facts.packages'
12045 ······-·audit_arch·==·"b64"12045 ······-·audit_arch·==·"b64"
12046 ······tags:12046 ······tags:
12047 ······-·CJIS-5.4.1.112047 ······-·CJIS-5.4.1.1
12048 ······-·NIST-800-171-3.1.712048 ······-·NIST-800-171-3.1.7
12049 ······-·NIST-800-53-AC-6(9)12049 ······-·NIST-800-53-AC-6(9)
12050 ······-·NIST-800-53-AU-12(c)12050 ······-·NIST-800-53-AU-12(c)
12051 ······-·NIST-800-53-AU-2(d)12051 ······-·NIST-800-53-AU-2(d)
Offset 12073, 16 lines modifiedOffset 12073, 16 lines modified
12073 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/12073 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
12074 ······find:12074 ······find:
12075 ········paths:·/etc/audit/rules.d12075 ········paths:·/etc/audit/rules.d
12076 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+12076 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
12077 ········patterns:·'*.rules'12077 ········patterns:·'*.rules'
12078 ······register:·find_existing_watch_rules_d12078 ······register:·find_existing_watch_rules_d
12079 ······when:12079 ······when:
12080 ······-·'"audit"·in·ansible_facts.packages' 
12081 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12080 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12081 ······-·'"audit"·in·ansible_facts.packages'
12082 ······tags:12082 ······tags:
12083 ······-·audit_rules_sudoers12083 ······-·audit_rules_sudoers
12084 ······-·low_complexity12084 ······-·low_complexity
12085 ······-·low_disruption12085 ······-·low_disruption
12086 ······-·medium_severity12086 ······-·medium_severity
12087 ······-·no_reboot_needed12087 ······-·no_reboot_needed
12088 ······-·restrict_strategy12088 ······-·restrict_strategy
Offset 12090, 16 lines modifiedOffset 12090, 16 lines modified
12090 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions12090 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 165197/169732 bytes (97.33%) of diff not shown.
250 KB
./usr/share/scap-security-guide/ansible/fedora-playbook-ospp.yml
Ordering differences only
    
Offset 5154, 16 lines modifiedOffset 5154, 16 lines modified
5154 ······-·reboot_required5154 ······-·reboot_required
5155 ······-·restrict_strategy5155 ······-·restrict_strategy
  
5156 ····-·name:·Set·architecture·for·audit·open·tasks5156 ····-·name:·Set·architecture·for·audit·open·tasks
5157 ······set_fact:5157 ······set_fact:
5158 ········audit_arch:·b645158 ········audit_arch:·b64
5159 ······when:5159 ······when:
5160 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5161 ······-·'"audit"·in·ansible_facts.packages'5160 ······-·'"audit"·in·ansible_facts.packages'
 5161 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5162 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5162 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5163 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5163 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5164 ······tags:5164 ······tags:
5165 ······-·NIST-800-53-AC-2(4)5165 ······-·NIST-800-53-AC-2(4)
5166 ······-·NIST-800-53-AC-6(9)5166 ······-·NIST-800-53-AC-6(9)
5167 ······-·NIST-800-53-AU-12(c)5167 ······-·NIST-800-53-AU-12(c)
5168 ······-·NIST-800-53-AU-2(d)5168 ······-·NIST-800-53-AU-2(d)
Offset 5292, 16 lines modifiedOffset 5292, 16 lines modified
5292 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a1&03·-F·path=/etc/group5292 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a1&03·-F·path=/etc/group
5293 ············-F·auid>=1000·-F·auid!=unset·-F·key=modify5293 ············-F·auid>=1000·-F·auid!=unset·-F·key=modify
5294 ··········create:·true5294 ··········create:·true
5295 ··········mode:·o-rwx5295 ··········mode:·o-rwx
5296 ··········state:·present5296 ··········state:·present
5297 ········when:·syscalls_found·|·length·==·05297 ········when:·syscalls_found·|·length·==·0
5298 ······when:5298 ······when:
5299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5300 ······-·'"audit"·in·ansible_facts.packages'5299 ······-·'"audit"·in·ansible_facts.packages'
 5300 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5301 ······tags:5301 ······tags:
5302 ······-·NIST-800-53-AC-2(4)5302 ······-·NIST-800-53-AC-2(4)
5303 ······-·NIST-800-53-AC-6(9)5303 ······-·NIST-800-53-AC-6(9)
5304 ······-·NIST-800-53-AU-12(c)5304 ······-·NIST-800-53-AU-12(c)
5305 ······-·NIST-800-53-AU-2(d)5305 ······-·NIST-800-53-AU-2(d)
5306 ······-·NIST-800-53-CM-6(a)5306 ······-·NIST-800-53-CM-6(a)
5307 ······-·audit_rules_etc_group_open5307 ······-·audit_rules_etc_group_open
Offset 5428, 16 lines modifiedOffset 5428, 16 lines modified
5428 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·a1&03·-F·path=/etc/group5428 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·a1&03·-F·path=/etc/group
5429 ············-F·auid>=1000·-F·auid!=unset·-F·key=modify5429 ············-F·auid>=1000·-F·auid!=unset·-F·key=modify
5430 ··········create:·true5430 ··········create:·true
5431 ··········mode:·o-rwx5431 ··········mode:·o-rwx
5432 ··········state:·present5432 ··········state:·present
5433 ········when:·syscalls_found·|·length·==·05433 ········when:·syscalls_found·|·length·==·0
5434 ······when:5434 ······when:
5435 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5436 ······-·'"audit"·in·ansible_facts.packages'5435 ······-·'"audit"·in·ansible_facts.packages'
 5436 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5437 ······-·audit_arch·==·"b64"5437 ······-·audit_arch·==·"b64"
5438 ······tags:5438 ······tags:
5439 ······-·NIST-800-53-AC-2(4)5439 ······-·NIST-800-53-AC-2(4)
5440 ······-·NIST-800-53-AC-6(9)5440 ······-·NIST-800-53-AC-6(9)
5441 ······-·NIST-800-53-AU-12(c)5441 ······-·NIST-800-53-AU-12(c)
5442 ······-·NIST-800-53-AU-2(d)5442 ······-·NIST-800-53-AU-2(d)
5443 ······-·NIST-800-53-CM-6(a)5443 ······-·NIST-800-53-CM-6(a)
Offset 5465, 16 lines modifiedOffset 5465, 16 lines modified
5465 ······-·reboot_required5465 ······-·reboot_required
5466 ······-·restrict_strategy5466 ······-·restrict_strategy
  
5467 ····-·name:·Set·architecture·for·audit·open_by_handle_at·tasks5467 ····-·name:·Set·architecture·for·audit·open_by_handle_at·tasks
5468 ······set_fact:5468 ······set_fact:
5469 ········audit_arch:·b645469 ········audit_arch:·b64
5470 ······when:5470 ······when:
5471 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5472 ······-·'"audit"·in·ansible_facts.packages'5471 ······-·'"audit"·in·ansible_facts.packages'
 5472 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5473 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5473 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5474 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5474 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5475 ······tags:5475 ······tags:
5476 ······-·NIST-800-53-AC-2(4)5476 ······-·NIST-800-53-AC-2(4)
5477 ······-·NIST-800-53-AC-6(9)5477 ······-·NIST-800-53-AC-6(9)
5478 ······-·NIST-800-53-AU-12(c)5478 ······-·NIST-800-53-AU-12(c)
5479 ······-·NIST-800-53-AU-2(d)5479 ······-·NIST-800-53-AU-2(d)
Offset 5603, 16 lines modifiedOffset 5603, 16 lines modified
5603 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a2&03·-F·path=/etc/group5603 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a2&03·-F·path=/etc/group
5604 ············-F·auid>=1000·-F·auid!=unset·-F·key=modify5604 ············-F·auid>=1000·-F·auid!=unset·-F·key=modify
5605 ··········create:·true5605 ··········create:·true
5606 ··········mode:·o-rwx5606 ··········mode:·o-rwx
5607 ··········state:·present5607 ··········state:·present
5608 ········when:·syscalls_found·|·length·==·05608 ········when:·syscalls_found·|·length·==·0
5609 ······when:5609 ······when:
5610 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5611 ······-·'"audit"·in·ansible_facts.packages'5610 ······-·'"audit"·in·ansible_facts.packages'
 5611 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5612 ······tags:5612 ······tags:
5613 ······-·NIST-800-53-AC-2(4)5613 ······-·NIST-800-53-AC-2(4)
5614 ······-·NIST-800-53-AC-6(9)5614 ······-·NIST-800-53-AC-6(9)
5615 ······-·NIST-800-53-AU-12(c)5615 ······-·NIST-800-53-AU-12(c)
5616 ······-·NIST-800-53-AU-2(d)5616 ······-·NIST-800-53-AU-2(d)
5617 ······-·NIST-800-53-CM-6(a)5617 ······-·NIST-800-53-CM-6(a)
5618 ······-·audit_rules_etc_group_open_by_handle_at5618 ······-·audit_rules_etc_group_open_by_handle_at
Offset 5739, 16 lines modifiedOffset 5739, 16 lines modified
5739 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·a2&03·-F·path=/etc/group5739 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·a2&03·-F·path=/etc/group
5740 ············-F·auid>=1000·-F·auid!=unset·-F·key=modify5740 ············-F·auid>=1000·-F·auid!=unset·-F·key=modify
5741 ··········create:·true5741 ··········create:·true
5742 ··········mode:·o-rwx5742 ··········mode:·o-rwx
5743 ··········state:·present5743 ··········state:·present
5744 ········when:·syscalls_found·|·length·==·05744 ········when:·syscalls_found·|·length·==·0
5745 ······when:5745 ······when:
5746 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5747 ······-·'"audit"·in·ansible_facts.packages'5746 ······-·'"audit"·in·ansible_facts.packages'
 5747 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5748 ······-·audit_arch·==·"b64"5748 ······-·audit_arch·==·"b64"
5749 ······tags:5749 ······tags:
5750 ······-·NIST-800-53-AC-2(4)5750 ······-·NIST-800-53-AC-2(4)
5751 ······-·NIST-800-53-AC-6(9)5751 ······-·NIST-800-53-AC-6(9)
5752 ······-·NIST-800-53-AU-12(c)5752 ······-·NIST-800-53-AU-12(c)
5753 ······-·NIST-800-53-AU-2(d)5753 ······-·NIST-800-53-AU-2(d)
5754 ······-·NIST-800-53-CM-6(a)5754 ······-·NIST-800-53-CM-6(a)
Offset 5776, 16 lines modifiedOffset 5776, 16 lines modified
5776 ······-·reboot_required5776 ······-·reboot_required
5777 ······-·restrict_strategy5777 ······-·restrict_strategy
  
5778 ····-·name:·Set·architecture·for·audit·openat·tasks5778 ····-·name:·Set·architecture·for·audit·openat·tasks
5779 ······set_fact:5779 ······set_fact:
5780 ········audit_arch:·b645780 ········audit_arch:·b64
5781 ······when:5781 ······when:
5782 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5783 ······-·'"audit"·in·ansible_facts.packages'5782 ······-·'"audit"·in·ansible_facts.packages'
 5783 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5784 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture5784 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
5785 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"5785 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
5786 ······tags:5786 ······tags:
5787 ······-·NIST-800-53-AC-2(4)5787 ······-·NIST-800-53-AC-2(4)
5788 ······-·NIST-800-53-AC-6(9)5788 ······-·NIST-800-53-AC-6(9)
5789 ······-·NIST-800-53-AU-12(c)5789 ······-·NIST-800-53-AU-12(c)
5790 ······-·NIST-800-53-AU-2(d)5790 ······-·NIST-800-53-AU-2(d)
Offset 5914, 16 lines modifiedOffset 5914, 16 lines modified
5914 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a2&03·-F·path=/etc/group5914 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·a2&03·-F·path=/etc/group
Max diff block lines reached; 250199/255595 bytes (97.89%) of diff not shown.
165 KB
./usr/share/scap-security-guide/ansible/fedora-playbook-pci-dss.yml
Ordering differences only
    
Offset 4622, 16 lines modifiedOffset 4622, 16 lines modified
  
4622 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension4622 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
4623 ······find:4623 ······find:
4624 ········paths:·/etc/audit/rules.d/4624 ········paths:·/etc/audit/rules.d/
4625 ········patterns:·'*.rules'4625 ········patterns:·'*.rules'
4626 ······register:·find_rules_d4626 ······register:·find_rules_d
4627 ······when:4627 ······when:
4628 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4629 ······-·'"audit"·in·ansible_facts.packages'4628 ······-·'"audit"·in·ansible_facts.packages'
 4629 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4630 ······tags:4630 ······tags:
4631 ······-·CJIS-5.4.1.14631 ······-·CJIS-5.4.1.1
4632 ······-·NIST-800-171-3.3.14632 ······-·NIST-800-171-3.3.1
4633 ······-·NIST-800-171-3.4.34633 ······-·NIST-800-171-3.4.3
4634 ······-·NIST-800-53-AC-6(9)4634 ······-·NIST-800-53-AC-6(9)
4635 ······-·NIST-800-53-CM-6(a)4635 ······-·NIST-800-53-CM-6(a)
4636 ······-·PCI-DSS-Req-10.5.24636 ······-·PCI-DSS-Req-10.5.2
Offset 4646, 16 lines modifiedOffset 4646, 16 lines modified
4646 ······lineinfile:4646 ······lineinfile:
4647 ········path:·'{{·item·}}'4647 ········path:·'{{·item·}}'
4648 ········regexp:·^\s*(?:-e)\s+.*$4648 ········regexp:·^\s*(?:-e)\s+.*$
4649 ········state:·absent4649 ········state:·absent
4650 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']4650 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
4651 ········}}'4651 ········}}'
4652 ······when:4652 ······when:
4653 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4654 ······-·'"audit"·in·ansible_facts.packages'4653 ······-·'"audit"·in·ansible_facts.packages'
 4654 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4655 ······tags:4655 ······tags:
4656 ······-·CJIS-5.4.1.14656 ······-·CJIS-5.4.1.1
4657 ······-·NIST-800-171-3.3.14657 ······-·NIST-800-171-3.3.1
4658 ······-·NIST-800-171-3.4.34658 ······-·NIST-800-171-3.4.3
4659 ······-·NIST-800-53-AC-6(9)4659 ······-·NIST-800-53-AC-6(9)
4660 ······-·NIST-800-53-CM-6(a)4660 ······-·NIST-800-53-CM-6(a)
4661 ······-·PCI-DSS-Req-10.5.24661 ······-·PCI-DSS-Req-10.5.2
Offset 4672, 16 lines modifiedOffset 4672, 16 lines modified
4672 ········create:·true4672 ········create:·true
4673 ········line:·-e·24673 ········line:·-e·2
4674 ········mode:·o-rwx4674 ········mode:·o-rwx
4675 ······loop:4675 ······loop:
4676 ······-·/etc/audit/audit.rules4676 ······-·/etc/audit/audit.rules
4677 ······-·/etc/audit/rules.d/immutable.rules4677 ······-·/etc/audit/rules.d/immutable.rules
4678 ······when:4678 ······when:
4679 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4680 ······-·'"audit"·in·ansible_facts.packages'4679 ······-·'"audit"·in·ansible_facts.packages'
 4680 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4681 ······tags:4681 ······tags:
4682 ······-·CJIS-5.4.1.14682 ······-·CJIS-5.4.1.1
4683 ······-·NIST-800-171-3.3.14683 ······-·NIST-800-171-3.3.1
4684 ······-·NIST-800-171-3.4.34684 ······-·NIST-800-171-3.4.3
4685 ······-·NIST-800-53-AC-6(9)4685 ······-·NIST-800-53-AC-6(9)
4686 ······-·NIST-800-53-CM-6(a)4686 ······-·NIST-800-53-CM-6(a)
4687 ······-·PCI-DSS-Req-10.5.24687 ······-·PCI-DSS-Req-10.5.2
Offset 4713, 16 lines modifiedOffset 4713, 16 lines modified
4713 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/4713 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
4714 ······find:4714 ······find:
4715 ········paths:·/etc/audit/rules.d4715 ········paths:·/etc/audit/rules.d
4716 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+4716 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
4717 ········patterns:·'*.rules'4717 ········patterns:·'*.rules'
4718 ······register:·find_existing_watch_rules_d4718 ······register:·find_existing_watch_rules_d
4719 ······when:4719 ······when:
4720 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4721 ······-·'"audit"·in·ansible_facts.packages'4720 ······-·'"audit"·in·ansible_facts.packages'
 4721 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4722 ······tags:4722 ······tags:
4723 ······-·CJIS-5.4.1.14723 ······-·CJIS-5.4.1.1
4724 ······-·NIST-800-171-3.1.84724 ······-·NIST-800-171-3.1.8
4725 ······-·NIST-800-53-AU-12(c)4725 ······-·NIST-800-53-AU-12(c)
4726 ······-·NIST-800-53-AU-2(d)4726 ······-·NIST-800-53-AU-2(d)
4727 ······-·NIST-800-53-CM-6(a)4727 ······-·NIST-800-53-CM-6(a)
4728 ······-·PCI-DSS-Req-10.5.54728 ······-·PCI-DSS-Req-10.5.5
Offset 4736, 16 lines modifiedOffset 4736, 16 lines modified
4736 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy4736 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
4737 ······find:4737 ······find:
4738 ········paths:·/etc/audit/rules.d4738 ········paths:·/etc/audit/rules.d
4739 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$4739 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
4740 ········patterns:·'*.rules'4740 ········patterns:·'*.rules'
4741 ······register:·find_watch_key4741 ······register:·find_watch_key
4742 ······when:4742 ······when:
4743 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4744 ······-·'"audit"·in·ansible_facts.packages'4743 ······-·'"audit"·in·ansible_facts.packages'
 4744 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4745 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4745 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4746 ········==·04746 ········==·0
4747 ······tags:4747 ······tags:
4748 ······-·CJIS-5.4.1.14748 ······-·CJIS-5.4.1.1
4749 ······-·NIST-800-171-3.1.84749 ······-·NIST-800-171-3.1.8
4750 ······-·NIST-800-53-AU-12(c)4750 ······-·NIST-800-53-AU-12(c)
4751 ······-·NIST-800-53-AU-2(d)4751 ······-·NIST-800-53-AU-2(d)
Offset 4759, 16 lines modifiedOffset 4759, 16 lines modified
4759 ······-·restrict_strategy4759 ······-·restrict_strategy
  
4760 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule4760 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
4761 ······set_fact:4761 ······set_fact:
4762 ········all_files:4762 ········all_files:
4763 ········-·/etc/audit/rules.d/MAC-policy.rules4763 ········-·/etc/audit/rules.d/MAC-policy.rules
4764 ······when:4764 ······when:
4765 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4766 ······-·'"audit"·in·ansible_facts.packages'4765 ······-·'"audit"·in·ansible_facts.packages'
 4766 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4767 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched4767 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
4768 ········is·defined·and·find_existing_watch_rules_d.matched·==·04768 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4769 ······tags:4769 ······tags:
4770 ······-·CJIS-5.4.1.14770 ······-·CJIS-5.4.1.1
4771 ······-·NIST-800-171-3.1.84771 ······-·NIST-800-171-3.1.8
4772 ······-·NIST-800-53-AU-12(c)4772 ······-·NIST-800-53-AU-12(c)
4773 ······-·NIST-800-53-AU-2(d)4773 ······-·NIST-800-53-AU-2(d)
Offset 4782, 16 lines modifiedOffset 4782, 16 lines modified
4782 ······-·restrict_strategy4782 ······-·restrict_strategy
  
4783 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule4783 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
4784 ······set_fact:4784 ······set_fact:
4785 ········all_files:4785 ········all_files:
4786 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'4786 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
4787 ······when:4787 ······when:
4788 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4789 ······-·'"audit"·in·ansible_facts.packages'4788 ······-·'"audit"·in·ansible_facts.packages'
 4789 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4790 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched4790 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
4791 ········is·defined·and·find_existing_watch_rules_d.matched·==·04791 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4792 ······tags:4792 ······tags:
4793 ······-·CJIS-5.4.1.14793 ······-·CJIS-5.4.1.1
4794 ······-·NIST-800-171-3.1.84794 ······-·NIST-800-171-3.1.8
4795 ······-·NIST-800-53-AU-12(c)4795 ······-·NIST-800-53-AU-12(c)
4796 ······-·NIST-800-53-AU-2(d)4796 ······-·NIST-800-53-AU-2(d)
Offset 4807, 16 lines modifiedOffset 4807, 16 lines modified
4807 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/4807 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 163341/168376 bytes (97.01%) of diff not shown.
106 KB
./usr/share/scap-security-guide/ansible/fedora-playbook-standard.yml
Ordering differences only
    
Offset 1570, 16 lines modifiedOffset 1570, 16 lines modified
  
1570 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1570 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1571 ······find:1571 ······find:
1572 ········paths:·/etc/audit/rules.d/1572 ········paths:·/etc/audit/rules.d/
1573 ········patterns:·'*.rules'1573 ········patterns:·'*.rules'
1574 ······register:·find_rules_d1574 ······register:·find_rules_d
1575 ······when:1575 ······when:
1576 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1577 ······-·'"audit"·in·ansible_facts.packages'1576 ······-·'"audit"·in·ansible_facts.packages'
 1577 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1578 ······tags:1578 ······tags:
1579 ······-·CJIS-5.4.1.11579 ······-·CJIS-5.4.1.1
1580 ······-·NIST-800-171-3.3.11580 ······-·NIST-800-171-3.3.1
1581 ······-·NIST-800-171-3.4.31581 ······-·NIST-800-171-3.4.3
1582 ······-·NIST-800-53-AC-6(9)1582 ······-·NIST-800-53-AC-6(9)
1583 ······-·NIST-800-53-CM-6(a)1583 ······-·NIST-800-53-CM-6(a)
1584 ······-·PCI-DSS-Req-10.5.21584 ······-·PCI-DSS-Req-10.5.2
Offset 1594, 16 lines modifiedOffset 1594, 16 lines modified
1594 ······lineinfile:1594 ······lineinfile:
1595 ········path:·'{{·item·}}'1595 ········path:·'{{·item·}}'
1596 ········regexp:·^\s*(?:-e)\s+.*$1596 ········regexp:·^\s*(?:-e)\s+.*$
1597 ········state:·absent1597 ········state:·absent
1598 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1598 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1599 ········}}'1599 ········}}'
1600 ······when:1600 ······when:
1601 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1602 ······-·'"audit"·in·ansible_facts.packages'1601 ······-·'"audit"·in·ansible_facts.packages'
 1602 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1603 ······tags:1603 ······tags:
1604 ······-·CJIS-5.4.1.11604 ······-·CJIS-5.4.1.1
1605 ······-·NIST-800-171-3.3.11605 ······-·NIST-800-171-3.3.1
1606 ······-·NIST-800-171-3.4.31606 ······-·NIST-800-171-3.4.3
1607 ······-·NIST-800-53-AC-6(9)1607 ······-·NIST-800-53-AC-6(9)
1608 ······-·NIST-800-53-CM-6(a)1608 ······-·NIST-800-53-CM-6(a)
1609 ······-·PCI-DSS-Req-10.5.21609 ······-·PCI-DSS-Req-10.5.2
Offset 1620, 16 lines modifiedOffset 1620, 16 lines modified
1620 ········create:·true1620 ········create:·true
1621 ········line:·-e·21621 ········line:·-e·2
1622 ········mode:·o-rwx1622 ········mode:·o-rwx
1623 ······loop:1623 ······loop:
1624 ······-·/etc/audit/audit.rules1624 ······-·/etc/audit/audit.rules
1625 ······-·/etc/audit/rules.d/immutable.rules1625 ······-·/etc/audit/rules.d/immutable.rules
1626 ······when:1626 ······when:
1627 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1628 ······-·'"audit"·in·ansible_facts.packages'1627 ······-·'"audit"·in·ansible_facts.packages'
 1628 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1629 ······tags:1629 ······tags:
1630 ······-·CJIS-5.4.1.11630 ······-·CJIS-5.4.1.1
1631 ······-·NIST-800-171-3.3.11631 ······-·NIST-800-171-3.3.1
1632 ······-·NIST-800-171-3.4.31632 ······-·NIST-800-171-3.4.3
1633 ······-·NIST-800-53-AC-6(9)1633 ······-·NIST-800-53-AC-6(9)
1634 ······-·NIST-800-53-CM-6(a)1634 ······-·NIST-800-53-CM-6(a)
1635 ······-·PCI-DSS-Req-10.5.21635 ······-·PCI-DSS-Req-10.5.2
Offset 1661, 16 lines modifiedOffset 1661, 16 lines modified
1661 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1661 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1662 ······find:1662 ······find:
1663 ········paths:·/etc/audit/rules.d1663 ········paths:·/etc/audit/rules.d
1664 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1664 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1665 ········patterns:·'*.rules'1665 ········patterns:·'*.rules'
1666 ······register:·find_existing_watch_rules_d1666 ······register:·find_existing_watch_rules_d
1667 ······when:1667 ······when:
1668 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1669 ······-·'"audit"·in·ansible_facts.packages'1668 ······-·'"audit"·in·ansible_facts.packages'
 1669 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1670 ······tags:1670 ······tags:
1671 ······-·CJIS-5.4.1.11671 ······-·CJIS-5.4.1.1
1672 ······-·NIST-800-171-3.1.81672 ······-·NIST-800-171-3.1.8
1673 ······-·NIST-800-53-AU-12(c)1673 ······-·NIST-800-53-AU-12(c)
1674 ······-·NIST-800-53-AU-2(d)1674 ······-·NIST-800-53-AU-2(d)
1675 ······-·NIST-800-53-CM-6(a)1675 ······-·NIST-800-53-CM-6(a)
1676 ······-·PCI-DSS-Req-10.5.51676 ······-·PCI-DSS-Req-10.5.5
Offset 1684, 16 lines modifiedOffset 1684, 16 lines modified
1684 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1684 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1685 ······find:1685 ······find:
1686 ········paths:·/etc/audit/rules.d1686 ········paths:·/etc/audit/rules.d
1687 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1687 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1688 ········patterns:·'*.rules'1688 ········patterns:·'*.rules'
1689 ······register:·find_watch_key1689 ······register:·find_watch_key
1690 ······when:1690 ······when:
1691 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1692 ······-·'"audit"·in·ansible_facts.packages'1691 ······-·'"audit"·in·ansible_facts.packages'
 1692 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1693 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1693 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1694 ········==·01694 ········==·0
1695 ······tags:1695 ······tags:
1696 ······-·CJIS-5.4.1.11696 ······-·CJIS-5.4.1.1
1697 ······-·NIST-800-171-3.1.81697 ······-·NIST-800-171-3.1.8
1698 ······-·NIST-800-53-AU-12(c)1698 ······-·NIST-800-53-AU-12(c)
1699 ······-·NIST-800-53-AU-2(d)1699 ······-·NIST-800-53-AU-2(d)
Offset 1707, 16 lines modifiedOffset 1707, 16 lines modified
1707 ······-·restrict_strategy1707 ······-·restrict_strategy
  
1708 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1708 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1709 ······set_fact:1709 ······set_fact:
1710 ········all_files:1710 ········all_files:
1711 ········-·/etc/audit/rules.d/MAC-policy.rules1711 ········-·/etc/audit/rules.d/MAC-policy.rules
1712 ······when:1712 ······when:
1713 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1714 ······-·'"audit"·in·ansible_facts.packages'1713 ······-·'"audit"·in·ansible_facts.packages'
 1714 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1715 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1715 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1716 ········is·defined·and·find_existing_watch_rules_d.matched·==·01716 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1717 ······tags:1717 ······tags:
1718 ······-·CJIS-5.4.1.11718 ······-·CJIS-5.4.1.1
1719 ······-·NIST-800-171-3.1.81719 ······-·NIST-800-171-3.1.8
1720 ······-·NIST-800-53-AU-12(c)1720 ······-·NIST-800-53-AU-12(c)
1721 ······-·NIST-800-53-AU-2(d)1721 ······-·NIST-800-53-AU-2(d)
Offset 1730, 16 lines modifiedOffset 1730, 16 lines modified
1730 ······-·restrict_strategy1730 ······-·restrict_strategy
  
1731 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1731 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1732 ······set_fact:1732 ······set_fact:
1733 ········all_files:1733 ········all_files:
1734 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1734 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1735 ······when:1735 ······when:
1736 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1737 ······-·'"audit"·in·ansible_facts.packages'1736 ······-·'"audit"·in·ansible_facts.packages'
 1737 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1738 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1738 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1739 ········is·defined·and·find_existing_watch_rules_d.matched·==·01739 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1740 ······tags:1740 ······tags:
1741 ······-·CJIS-5.4.1.11741 ······-·CJIS-5.4.1.1
1742 ······-·NIST-800-171-3.1.81742 ······-·NIST-800-171-3.1.8
1743 ······-·NIST-800-53-AU-12(c)1743 ······-·NIST-800-53-AU-12(c)
1744 ······-·NIST-800-53-AU-2(d)1744 ······-·NIST-800-53-AU-2(d)
Offset 1755, 16 lines modifiedOffset 1755, 16 lines modified
1755 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1755 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 103613/108648 bytes (95.37%) of diff not shown.
908 B
./usr/share/scap-security-guide/ansible/ol7-playbook-anssi_nt28_enhanced.yml
Ordering differences only
    
Offset 5306, 16 lines modifiedOffset 5306, 16 lines modified
5306 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5306 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5307 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5307 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5308 ··········create:·true5308 ··········create:·true
5309 ··········mode:·o-rwx5309 ··········mode:·o-rwx
5310 ··········state:·present5310 ··········state:·present
5311 ········when:·syscalls_found·|·length·==·05311 ········when:·syscalls_found·|·length·==·0
5312 ······when:5312 ······when:
5313 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5314 ······-·'"audit"·in·ansible_facts.packages'5313 ······-·'"audit"·in·ansible_facts.packages'
 5314 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5315 ······tags:5315 ······tags:
5316 ······-·DISA-STIG-OL07-00-0306905316 ······-·DISA-STIG-OL07-00-030690
5317 ······-·NIST-800-171-3.1.75317 ······-·NIST-800-171-3.1.7
5318 ······-·NIST-800-53-AC-6(9)5318 ······-·NIST-800-53-AC-6(9)
5319 ······-·NIST-800-53-AU-12(c)5319 ······-·NIST-800-53-AU-12(c)
5320 ······-·NIST-800-53-AU-2(d)5320 ······-·NIST-800-53-AU-2(d)
5321 ······-·NIST-800-53-CM-6(a)5321 ······-·NIST-800-53-CM-6(a)
900 B
./usr/share/scap-security-guide/ansible/ol7-playbook-anssi_nt28_high.yml
Ordering differences only
    
Offset 5459, 16 lines modifiedOffset 5459, 16 lines modified
5459 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5459 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5460 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5460 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5461 ··········create:·true5461 ··········create:·true
5462 ··········mode:·o-rwx5462 ··········mode:·o-rwx
5463 ··········state:·present5463 ··········state:·present
5464 ········when:·syscalls_found·|·length·==·05464 ········when:·syscalls_found·|·length·==·0
5465 ······when:5465 ······when:
5466 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5467 ······-·'"audit"·in·ansible_facts.packages'5466 ······-·'"audit"·in·ansible_facts.packages'
 5467 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5468 ······tags:5468 ······tags:
5469 ······-·DISA-STIG-OL07-00-0306905469 ······-·DISA-STIG-OL07-00-030690
5470 ······-·NIST-800-171-3.1.75470 ······-·NIST-800-171-3.1.7
5471 ······-·NIST-800-53-AC-6(9)5471 ······-·NIST-800-53-AC-6(9)
5472 ······-·NIST-800-53-AU-12(c)5472 ······-·NIST-800-53-AU-12(c)
5473 ······-·NIST-800-53-AU-2(d)5473 ······-·NIST-800-53-AU-2(d)
5474 ······-·NIST-800-53-CM-6(a)5474 ······-·NIST-800-53-CM-6(a)
916 B
./usr/share/scap-security-guide/ansible/ol7-playbook-anssi_nt28_intermediary.yml
Ordering differences only
    
Offset 5034, 16 lines modifiedOffset 5034, 16 lines modified
5034 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5034 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5035 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5035 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5036 ··········create:·true5036 ··········create:·true
5037 ··········mode:·o-rwx5037 ··········mode:·o-rwx
5038 ··········state:·present5038 ··········state:·present
5039 ········when:·syscalls_found·|·length·==·05039 ········when:·syscalls_found·|·length·==·0
5040 ······when:5040 ······when:
5041 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5042 ······-·'"audit"·in·ansible_facts.packages'5041 ······-·'"audit"·in·ansible_facts.packages'
 5042 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5043 ······tags:5043 ······tags:
5044 ······-·DISA-STIG-OL07-00-0306905044 ······-·DISA-STIG-OL07-00-030690
5045 ······-·NIST-800-171-3.1.75045 ······-·NIST-800-171-3.1.7
5046 ······-·NIST-800-53-AC-6(9)5046 ······-·NIST-800-53-AC-6(9)
5047 ······-·NIST-800-53-AU-12(c)5047 ······-·NIST-800-53-AU-12(c)
5048 ······-·NIST-800-53-AU-2(d)5048 ······-·NIST-800-53-AU-2(d)
5049 ······-·NIST-800-53-CM-6(a)5049 ······-·NIST-800-53-CM-6(a)
107 KB
./usr/share/scap-security-guide/ansible/ol7-playbook-cjis.yml
Ordering differences only
    
Offset 2552, 16 lines modifiedOffset 2552, 16 lines modified
  
2552 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension2552 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
2553 ······find:2553 ······find:
2554 ········paths:·/etc/audit/rules.d/2554 ········paths:·/etc/audit/rules.d/
2555 ········patterns:·'*.rules'2555 ········patterns:·'*.rules'
2556 ······register:·find_rules_d2556 ······register:·find_rules_d
2557 ······when:2557 ······when:
2558 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2559 ······-·'"audit"·in·ansible_facts.packages'2558 ······-·'"audit"·in·ansible_facts.packages'
 2559 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2560 ······tags:2560 ······tags:
2561 ······-·CJIS-5.4.1.12561 ······-·CJIS-5.4.1.1
2562 ······-·NIST-800-171-3.3.12562 ······-·NIST-800-171-3.3.1
2563 ······-·NIST-800-171-3.4.32563 ······-·NIST-800-171-3.4.3
2564 ······-·NIST-800-53-AC-6(9)2564 ······-·NIST-800-53-AC-6(9)
2565 ······-·NIST-800-53-CM-6(a)2565 ······-·NIST-800-53-CM-6(a)
2566 ······-·PCI-DSS-Req-10.5.22566 ······-·PCI-DSS-Req-10.5.2
Offset 2576, 16 lines modifiedOffset 2576, 16 lines modified
2576 ······lineinfile:2576 ······lineinfile:
2577 ········path:·'{{·item·}}'2577 ········path:·'{{·item·}}'
2578 ········regexp:·^\s*(?:-e)\s+.*$2578 ········regexp:·^\s*(?:-e)\s+.*$
2579 ········state:·absent2579 ········state:·absent
2580 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']2580 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
2581 ········}}'2581 ········}}'
2582 ······when:2582 ······when:
2583 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2584 ······-·'"audit"·in·ansible_facts.packages'2583 ······-·'"audit"·in·ansible_facts.packages'
 2584 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2585 ······tags:2585 ······tags:
2586 ······-·CJIS-5.4.1.12586 ······-·CJIS-5.4.1.1
2587 ······-·NIST-800-171-3.3.12587 ······-·NIST-800-171-3.3.1
2588 ······-·NIST-800-171-3.4.32588 ······-·NIST-800-171-3.4.3
2589 ······-·NIST-800-53-AC-6(9)2589 ······-·NIST-800-53-AC-6(9)
2590 ······-·NIST-800-53-CM-6(a)2590 ······-·NIST-800-53-CM-6(a)
2591 ······-·PCI-DSS-Req-10.5.22591 ······-·PCI-DSS-Req-10.5.2
Offset 2602, 16 lines modifiedOffset 2602, 16 lines modified
2602 ········create:·true2602 ········create:·true
2603 ········line:·-e·22603 ········line:·-e·2
2604 ········mode:·o-rwx2604 ········mode:·o-rwx
2605 ······loop:2605 ······loop:
2606 ······-·/etc/audit/audit.rules2606 ······-·/etc/audit/audit.rules
2607 ······-·/etc/audit/rules.d/immutable.rules2607 ······-·/etc/audit/rules.d/immutable.rules
2608 ······when:2608 ······when:
2609 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2610 ······-·'"audit"·in·ansible_facts.packages'2609 ······-·'"audit"·in·ansible_facts.packages'
 2610 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2611 ······tags:2611 ······tags:
2612 ······-·CJIS-5.4.1.12612 ······-·CJIS-5.4.1.1
2613 ······-·NIST-800-171-3.3.12613 ······-·NIST-800-171-3.3.1
2614 ······-·NIST-800-171-3.4.32614 ······-·NIST-800-171-3.4.3
2615 ······-·NIST-800-53-AC-6(9)2615 ······-·NIST-800-53-AC-6(9)
2616 ······-·NIST-800-53-CM-6(a)2616 ······-·NIST-800-53-CM-6(a)
2617 ······-·PCI-DSS-Req-10.5.22617 ······-·PCI-DSS-Req-10.5.2
Offset 2643, 16 lines modifiedOffset 2643, 16 lines modified
2643 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/2643 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
2644 ······find:2644 ······find:
2645 ········paths:·/etc/audit/rules.d2645 ········paths:·/etc/audit/rules.d
2646 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+2646 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
2647 ········patterns:·'*.rules'2647 ········patterns:·'*.rules'
2648 ······register:·find_existing_watch_rules_d2648 ······register:·find_existing_watch_rules_d
2649 ······when:2649 ······when:
2650 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2651 ······-·'"audit"·in·ansible_facts.packages'2650 ······-·'"audit"·in·ansible_facts.packages'
 2651 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2652 ······tags:2652 ······tags:
2653 ······-·CJIS-5.4.1.12653 ······-·CJIS-5.4.1.1
2654 ······-·NIST-800-171-3.1.82654 ······-·NIST-800-171-3.1.8
2655 ······-·NIST-800-53-AU-12(c)2655 ······-·NIST-800-53-AU-12(c)
2656 ······-·NIST-800-53-AU-2(d)2656 ······-·NIST-800-53-AU-2(d)
2657 ······-·NIST-800-53-CM-6(a)2657 ······-·NIST-800-53-CM-6(a)
2658 ······-·PCI-DSS-Req-10.5.52658 ······-·PCI-DSS-Req-10.5.5
Offset 2666, 16 lines modifiedOffset 2666, 16 lines modified
2666 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy2666 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
2667 ······find:2667 ······find:
2668 ········paths:·/etc/audit/rules.d2668 ········paths:·/etc/audit/rules.d
2669 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$2669 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
2670 ········patterns:·'*.rules'2670 ········patterns:·'*.rules'
2671 ······register:·find_watch_key2671 ······register:·find_watch_key
2672 ······when:2672 ······when:
2673 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2674 ······-·'"audit"·in·ansible_facts.packages'2673 ······-·'"audit"·in·ansible_facts.packages'
 2674 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2675 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched2675 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
2676 ········==·02676 ········==·0
2677 ······tags:2677 ······tags:
2678 ······-·CJIS-5.4.1.12678 ······-·CJIS-5.4.1.1
2679 ······-·NIST-800-171-3.1.82679 ······-·NIST-800-171-3.1.8
2680 ······-·NIST-800-53-AU-12(c)2680 ······-·NIST-800-53-AU-12(c)
2681 ······-·NIST-800-53-AU-2(d)2681 ······-·NIST-800-53-AU-2(d)
Offset 2689, 16 lines modifiedOffset 2689, 16 lines modified
2689 ······-·restrict_strategy2689 ······-·restrict_strategy
  
2690 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule2690 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
2691 ······set_fact:2691 ······set_fact:
2692 ········all_files:2692 ········all_files:
2693 ········-·/etc/audit/rules.d/MAC-policy.rules2693 ········-·/etc/audit/rules.d/MAC-policy.rules
2694 ······when:2694 ······when:
2695 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2696 ······-·'"audit"·in·ansible_facts.packages'2695 ······-·'"audit"·in·ansible_facts.packages'
 2696 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2697 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched2697 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
2698 ········is·defined·and·find_existing_watch_rules_d.matched·==·02698 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
2699 ······tags:2699 ······tags:
2700 ······-·CJIS-5.4.1.12700 ······-·CJIS-5.4.1.1
2701 ······-·NIST-800-171-3.1.82701 ······-·NIST-800-171-3.1.8
2702 ······-·NIST-800-53-AU-12(c)2702 ······-·NIST-800-53-AU-12(c)
2703 ······-·NIST-800-53-AU-2(d)2703 ······-·NIST-800-53-AU-2(d)
Offset 2712, 16 lines modifiedOffset 2712, 16 lines modified
2712 ······-·restrict_strategy2712 ······-·restrict_strategy
  
2713 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule2713 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
2714 ······set_fact:2714 ······set_fact:
2715 ········all_files:2715 ········all_files:
2716 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'2716 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
2717 ······when:2717 ······when:
2718 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2719 ······-·'"audit"·in·ansible_facts.packages'2718 ······-·'"audit"·in·ansible_facts.packages'
 2719 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2720 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched2720 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
2721 ········is·defined·and·find_existing_watch_rules_d.matched·==·02721 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
2722 ······tags:2722 ······tags:
2723 ······-·CJIS-5.4.1.12723 ······-·CJIS-5.4.1.1
2724 ······-·NIST-800-171-3.1.82724 ······-·NIST-800-171-3.1.8
2725 ······-·NIST-800-53-AU-12(c)2725 ······-·NIST-800-53-AU-12(c)
2726 ······-·NIST-800-53-AU-2(d)2726 ······-·NIST-800-53-AU-2(d)
Offset 2737, 16 lines modifiedOffset 2737, 16 lines modified
2737 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/2737 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 103937/108972 bytes (95.38%) of diff not shown.
785 B
./usr/share/scap-security-guide/ansible/ol7-playbook-cui.yml
Ordering differences only
    
Offset 4498, 16 lines modifiedOffset 4498, 16 lines modified
4498 ······lineinfile:4498 ······lineinfile:
4499 ········dest:·/etc/audit/auditd.conf4499 ········dest:·/etc/audit/auditd.conf
4500 ········regexp:·^\s*flush\s*=\s*.*$4500 ········regexp:·^\s*flush\s*=\s*.*$
4501 ········line:·flush·=·{{·var_auditd_flush·}}4501 ········line:·flush·=·{{·var_auditd_flush·}}
4502 ········state:·present4502 ········state:·present
4503 ········create:·true4503 ········create:·true
4504 ······when:4504 ······when:
4505 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4506 ······-·'"audit"·in·ansible_facts.packages'4505 ······-·'"audit"·in·ansible_facts.packages'
 4506 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4507 ······tags:4507 ······tags:
4508 ······-·NIST-800-171-3.3.14508 ······-·NIST-800-171-3.3.1
4509 ······-·NIST-800-53-AU-114509 ······-·NIST-800-53-AU-11
4510 ······-·NIST-800-53-CM-6(a)4510 ······-·NIST-800-53-CM-6(a)
4511 ······-·auditd_data_retention_flush4511 ······-·auditd_data_retention_flush
4512 ······-·low_complexity4512 ······-·low_complexity
4513 ······-·low_disruption4513 ······-·low_disruption
74.8 KB
./usr/share/scap-security-guide/ansible/ol7-playbook-e8.yml
Ordering differences only
    
Offset 905, 16 lines modifiedOffset 905, 16 lines modified
905 ······-·no_reboot_needed905 ······-·no_reboot_needed
906 ······-·restrict_strategy906 ······-·restrict_strategy
  
907 ····-·name:·Set·architecture·for·audit·tasks907 ····-·name:·Set·architecture·for·audit·tasks
908 ······set_fact:908 ······set_fact:
909 ········audit_arch:·b64909 ········audit_arch:·b64
910 ······when:910 ······when:
911 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
912 ······-·'"audit"·in·ansible_facts.packages'911 ······-·'"audit"·in·ansible_facts.packages'
 912 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
913 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture913 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
914 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"914 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
915 ······tags:915 ······tags:
916 ······-·CJIS-5.4.1.1916 ······-·CJIS-5.4.1.1
917 ······-·NIST-800-171-3.1.7917 ······-·NIST-800-171-3.1.7
918 ······-·NIST-800-53-AC-6(9)918 ······-·NIST-800-53-AC-6(9)
919 ······-·NIST-800-53-AU-12(c)919 ······-·NIST-800-53-AU-12(c)
Offset 1047, 16 lines modifiedOffset 1047, 16 lines modified
1047 ··········path:·'{{·audit_file·}}'1047 ··········path:·'{{·audit_file·}}'
1048 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1048 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1049 ··········create:·true1049 ··········create:·true
1050 ··········mode:·o-rwx1050 ··········mode:·o-rwx
1051 ··········state:·present1051 ··········state:·present
1052 ········when:·syscalls_found·|·length·==·01052 ········when:·syscalls_found·|·length·==·0
1053 ······when:1053 ······when:
1054 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1055 ······-·'"audit"·in·ansible_facts.packages'1054 ······-·'"audit"·in·ansible_facts.packages'
 1055 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1056 ······tags:1056 ······tags:
1057 ······-·CJIS-5.4.1.11057 ······-·CJIS-5.4.1.1
1058 ······-·NIST-800-171-3.1.71058 ······-·NIST-800-171-3.1.7
1059 ······-·NIST-800-53-AC-6(9)1059 ······-·NIST-800-53-AC-6(9)
1060 ······-·NIST-800-53-AU-12(c)1060 ······-·NIST-800-53-AU-12(c)
1061 ······-·NIST-800-53-AU-2(d)1061 ······-·NIST-800-53-AU-2(d)
1062 ······-·NIST-800-53-CM-6(a)1062 ······-·NIST-800-53-CM-6(a)
Offset 1187, 16 lines modifiedOffset 1187, 16 lines modified
1187 ··········path:·'{{·audit_file·}}'1187 ··········path:·'{{·audit_file·}}'
1188 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1188 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1189 ··········create:·true1189 ··········create:·true
1190 ··········mode:·o-rwx1190 ··········mode:·o-rwx
1191 ··········state:·present1191 ··········state:·present
1192 ········when:·syscalls_found·|·length·==·01192 ········when:·syscalls_found·|·length·==·0
1193 ······when:1193 ······when:
1194 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1195 ······-·'"audit"·in·ansible_facts.packages'1194 ······-·'"audit"·in·ansible_facts.packages'
 1195 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1196 ······-·audit_arch·==·"b64"1196 ······-·audit_arch·==·"b64"
1197 ······tags:1197 ······tags:
1198 ······-·CJIS-5.4.1.11198 ······-·CJIS-5.4.1.1
1199 ······-·NIST-800-171-3.1.71199 ······-·NIST-800-171-3.1.7
1200 ······-·NIST-800-53-AC-6(9)1200 ······-·NIST-800-53-AC-6(9)
1201 ······-·NIST-800-53-AU-12(c)1201 ······-·NIST-800-53-AU-12(c)
1202 ······-·NIST-800-53-AU-2(d)1202 ······-·NIST-800-53-AU-2(d)
Offset 1212, 16 lines modifiedOffset 1212, 16 lines modified
1212 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/1212 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
1213 ······find:1213 ······find:
1214 ········paths:·/etc/audit/rules.d1214 ········paths:·/etc/audit/rules.d
1215 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+1215 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
1216 ········patterns:·'*.rules'1216 ········patterns:·'*.rules'
1217 ······register:·find_existing_watch_rules_d1217 ······register:·find_existing_watch_rules_d
1218 ······when:1218 ······when:
1219 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1220 ······-·'"audit"·in·ansible_facts.packages'1219 ······-·'"audit"·in·ansible_facts.packages'
 1220 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1221 ······tags:1221 ······tags:
1222 ······-·CJIS-5.4.1.11222 ······-·CJIS-5.4.1.1
1223 ······-·NIST-800-171-3.1.71223 ······-·NIST-800-171-3.1.7
1224 ······-·NIST-800-53-AC-6(9)1224 ······-·NIST-800-53-AC-6(9)
1225 ······-·NIST-800-53-AU-12(c)1225 ······-·NIST-800-53-AU-12(c)
1226 ······-·NIST-800-53-AU-2(d)1226 ······-·NIST-800-53-AU-2(d)
1227 ······-·NIST-800-53-CM-6(a)1227 ······-·NIST-800-53-CM-6(a)
Offset 1236, 16 lines modifiedOffset 1236, 16 lines modified
1236 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification1236 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
1237 ······find:1237 ······find:
1238 ········paths:·/etc/audit/rules.d1238 ········paths:·/etc/audit/rules.d
1239 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$1239 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
1240 ········patterns:·'*.rules'1240 ········patterns:·'*.rules'
1241 ······register:·find_watch_key1241 ······register:·find_watch_key
1242 ······when:1242 ······when:
1243 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1244 ······-·'"audit"·in·ansible_facts.packages'1243 ······-·'"audit"·in·ansible_facts.packages'
 1244 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1245 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1245 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1246 ········==·01246 ········==·0
1247 ······tags:1247 ······tags:
1248 ······-·CJIS-5.4.1.11248 ······-·CJIS-5.4.1.1
1249 ······-·NIST-800-171-3.1.71249 ······-·NIST-800-171-3.1.7
1250 ······-·NIST-800-53-AC-6(9)1250 ······-·NIST-800-53-AC-6(9)
1251 ······-·NIST-800-53-AU-12(c)1251 ······-·NIST-800-53-AU-12(c)
Offset 1261, 16 lines modifiedOffset 1261, 16 lines modified
  
1261 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the1261 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
1262 ········recipient·for·the·rule1262 ········recipient·for·the·rule
1263 ······set_fact:1263 ······set_fact:
1264 ········all_files:1264 ········all_files:
1265 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules1265 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
1266 ······when:1266 ······when:
1267 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1268 ······-·'"audit"·in·ansible_facts.packages'1267 ······-·'"audit"·in·ansible_facts.packages'
 1268 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1269 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1269 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1270 ········is·defined·and·find_existing_watch_rules_d.matched·==·01270 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1271 ······tags:1271 ······tags:
1272 ······-·CJIS-5.4.1.11272 ······-·CJIS-5.4.1.1
1273 ······-·NIST-800-171-3.1.71273 ······-·NIST-800-171-3.1.7
1274 ······-·NIST-800-53-AC-6(9)1274 ······-·NIST-800-53-AC-6(9)
1275 ······-·NIST-800-53-AU-12(c)1275 ······-·NIST-800-53-AU-12(c)
Offset 1285, 16 lines modifiedOffset 1285, 16 lines modified
1285 ······-·restrict_strategy1285 ······-·restrict_strategy
  
1286 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1286 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1287 ······set_fact:1287 ······set_fact:
1288 ········all_files:1288 ········all_files:
1289 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1289 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1290 ······when:1290 ······when:
1291 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1292 ······-·'"audit"·in·ansible_facts.packages'1291 ······-·'"audit"·in·ansible_facts.packages'
 1292 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1293 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1293 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1294 ········is·defined·and·find_existing_watch_rules_d.matched·==·01294 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1295 ······tags:1295 ······tags:
1296 ······-·CJIS-5.4.1.11296 ······-·CJIS-5.4.1.1
1297 ······-·NIST-800-171-3.1.71297 ······-·NIST-800-171-3.1.7
1298 ······-·NIST-800-53-AC-6(9)1298 ······-·NIST-800-53-AC-6(9)
1299 ······-·NIST-800-53-AU-12(c)1299 ······-·NIST-800-53-AU-12(c)
Offset 1311, 16 lines modifiedOffset 1311, 16 lines modified
1311 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/1311 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 71056/76454 bytes (92.94%) of diff not shown.
192 KB
./usr/share/scap-security-guide/ansible/ol7-playbook-hipaa.yml
Ordering differences only
    
Offset 1193, 16 lines modifiedOffset 1193, 16 lines modified
  
1193 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1193 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1194 ······find:1194 ······find:
1195 ········paths:·/etc/audit/rules.d/1195 ········paths:·/etc/audit/rules.d/
1196 ········patterns:·'*.rules'1196 ········patterns:·'*.rules'
1197 ······register:·find_rules_d1197 ······register:·find_rules_d
1198 ······when:1198 ······when:
1199 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1200 ······-·'"audit"·in·ansible_facts.packages'1199 ······-·'"audit"·in·ansible_facts.packages'
 1200 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1201 ······tags:1201 ······tags:
1202 ······-·CJIS-5.4.1.11202 ······-·CJIS-5.4.1.1
1203 ······-·NIST-800-171-3.3.11203 ······-·NIST-800-171-3.3.1
1204 ······-·NIST-800-171-3.4.31204 ······-·NIST-800-171-3.4.3
1205 ······-·NIST-800-53-AC-6(9)1205 ······-·NIST-800-53-AC-6(9)
1206 ······-·NIST-800-53-CM-6(a)1206 ······-·NIST-800-53-CM-6(a)
1207 ······-·PCI-DSS-Req-10.5.21207 ······-·PCI-DSS-Req-10.5.2
Offset 1217, 16 lines modifiedOffset 1217, 16 lines modified
1217 ······lineinfile:1217 ······lineinfile:
1218 ········path:·'{{·item·}}'1218 ········path:·'{{·item·}}'
1219 ········regexp:·^\s*(?:-e)\s+.*$1219 ········regexp:·^\s*(?:-e)\s+.*$
1220 ········state:·absent1220 ········state:·absent
1221 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1221 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1222 ········}}'1222 ········}}'
1223 ······when:1223 ······when:
1224 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1225 ······-·'"audit"·in·ansible_facts.packages'1224 ······-·'"audit"·in·ansible_facts.packages'
 1225 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1226 ······tags:1226 ······tags:
1227 ······-·CJIS-5.4.1.11227 ······-·CJIS-5.4.1.1
1228 ······-·NIST-800-171-3.3.11228 ······-·NIST-800-171-3.3.1
1229 ······-·NIST-800-171-3.4.31229 ······-·NIST-800-171-3.4.3
1230 ······-·NIST-800-53-AC-6(9)1230 ······-·NIST-800-53-AC-6(9)
1231 ······-·NIST-800-53-CM-6(a)1231 ······-·NIST-800-53-CM-6(a)
1232 ······-·PCI-DSS-Req-10.5.21232 ······-·PCI-DSS-Req-10.5.2
Offset 1243, 16 lines modifiedOffset 1243, 16 lines modified
1243 ········create:·true1243 ········create:·true
1244 ········line:·-e·21244 ········line:·-e·2
1245 ········mode:·o-rwx1245 ········mode:·o-rwx
1246 ······loop:1246 ······loop:
1247 ······-·/etc/audit/audit.rules1247 ······-·/etc/audit/audit.rules
1248 ······-·/etc/audit/rules.d/immutable.rules1248 ······-·/etc/audit/rules.d/immutable.rules
1249 ······when:1249 ······when:
1250 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1251 ······-·'"audit"·in·ansible_facts.packages'1250 ······-·'"audit"·in·ansible_facts.packages'
 1251 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1252 ······tags:1252 ······tags:
1253 ······-·CJIS-5.4.1.11253 ······-·CJIS-5.4.1.1
1254 ······-·NIST-800-171-3.3.11254 ······-·NIST-800-171-3.3.1
1255 ······-·NIST-800-171-3.4.31255 ······-·NIST-800-171-3.4.3
1256 ······-·NIST-800-53-AC-6(9)1256 ······-·NIST-800-53-AC-6(9)
1257 ······-·NIST-800-53-CM-6(a)1257 ······-·NIST-800-53-CM-6(a)
1258 ······-·PCI-DSS-Req-10.5.21258 ······-·PCI-DSS-Req-10.5.2
Offset 1284, 16 lines modifiedOffset 1284, 16 lines modified
1284 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1284 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1285 ······find:1285 ······find:
1286 ········paths:·/etc/audit/rules.d1286 ········paths:·/etc/audit/rules.d
1287 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1287 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1288 ········patterns:·'*.rules'1288 ········patterns:·'*.rules'
1289 ······register:·find_existing_watch_rules_d1289 ······register:·find_existing_watch_rules_d
1290 ······when:1290 ······when:
1291 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1292 ······-·'"audit"·in·ansible_facts.packages'1291 ······-·'"audit"·in·ansible_facts.packages'
 1292 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1293 ······tags:1293 ······tags:
1294 ······-·CJIS-5.4.1.11294 ······-·CJIS-5.4.1.1
1295 ······-·NIST-800-171-3.1.81295 ······-·NIST-800-171-3.1.8
1296 ······-·NIST-800-53-AU-12(c)1296 ······-·NIST-800-53-AU-12(c)
1297 ······-·NIST-800-53-AU-2(d)1297 ······-·NIST-800-53-AU-2(d)
1298 ······-·NIST-800-53-CM-6(a)1298 ······-·NIST-800-53-CM-6(a)
1299 ······-·PCI-DSS-Req-10.5.51299 ······-·PCI-DSS-Req-10.5.5
Offset 1307, 16 lines modifiedOffset 1307, 16 lines modified
1307 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1307 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1308 ······find:1308 ······find:
1309 ········paths:·/etc/audit/rules.d1309 ········paths:·/etc/audit/rules.d
1310 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1310 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1311 ········patterns:·'*.rules'1311 ········patterns:·'*.rules'
1312 ······register:·find_watch_key1312 ······register:·find_watch_key
1313 ······when:1313 ······when:
1314 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1315 ······-·'"audit"·in·ansible_facts.packages'1314 ······-·'"audit"·in·ansible_facts.packages'
 1315 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1316 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1316 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1317 ········==·01317 ········==·0
1318 ······tags:1318 ······tags:
1319 ······-·CJIS-5.4.1.11319 ······-·CJIS-5.4.1.1
1320 ······-·NIST-800-171-3.1.81320 ······-·NIST-800-171-3.1.8
1321 ······-·NIST-800-53-AU-12(c)1321 ······-·NIST-800-53-AU-12(c)
1322 ······-·NIST-800-53-AU-2(d)1322 ······-·NIST-800-53-AU-2(d)
Offset 1330, 16 lines modifiedOffset 1330, 16 lines modified
1330 ······-·restrict_strategy1330 ······-·restrict_strategy
  
1331 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1331 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1332 ······set_fact:1332 ······set_fact:
1333 ········all_files:1333 ········all_files:
1334 ········-·/etc/audit/rules.d/MAC-policy.rules1334 ········-·/etc/audit/rules.d/MAC-policy.rules
1335 ······when:1335 ······when:
1336 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1337 ······-·'"audit"·in·ansible_facts.packages'1336 ······-·'"audit"·in·ansible_facts.packages'
 1337 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1338 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1338 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1339 ········is·defined·and·find_existing_watch_rules_d.matched·==·01339 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1340 ······tags:1340 ······tags:
1341 ······-·CJIS-5.4.1.11341 ······-·CJIS-5.4.1.1
1342 ······-·NIST-800-171-3.1.81342 ······-·NIST-800-171-3.1.8
1343 ······-·NIST-800-53-AU-12(c)1343 ······-·NIST-800-53-AU-12(c)
1344 ······-·NIST-800-53-AU-2(d)1344 ······-·NIST-800-53-AU-2(d)
Offset 1353, 16 lines modifiedOffset 1353, 16 lines modified
1353 ······-·restrict_strategy1353 ······-·restrict_strategy
  
1354 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1354 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1355 ······set_fact:1355 ······set_fact:
1356 ········all_files:1356 ········all_files:
1357 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1357 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1358 ······when:1358 ······when:
1359 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1360 ······-·'"audit"·in·ansible_facts.packages'1359 ······-·'"audit"·in·ansible_facts.packages'
 1360 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1361 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1361 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1362 ········is·defined·and·find_existing_watch_rules_d.matched·==·01362 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1363 ······tags:1363 ······tags:
1364 ······-·CJIS-5.4.1.11364 ······-·CJIS-5.4.1.1
1365 ······-·NIST-800-171-3.1.81365 ······-·NIST-800-171-3.1.8
1366 ······-·NIST-800-53-AU-12(c)1366 ······-·NIST-800-53-AU-12(c)
1367 ······-·NIST-800-53-AU-2(d)1367 ······-·NIST-800-53-AU-2(d)
Offset 1378, 16 lines modifiedOffset 1378, 16 lines modified
1378 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1378 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 191368/196403 bytes (97.44%) of diff not shown.
199 KB
./usr/share/scap-security-guide/ansible/ol7-playbook-ncp.yml
Ordering differences only
    
Offset 9673, 16 lines modifiedOffset 9673, 16 lines modified
  
9673 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension9673 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
9674 ······find:9674 ······find:
9675 ········paths:·/etc/audit/rules.d/9675 ········paths:·/etc/audit/rules.d/
9676 ········patterns:·'*.rules'9676 ········patterns:·'*.rules'
9677 ······register:·find_rules_d9677 ······register:·find_rules_d
9678 ······when:9678 ······when:
9679 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9680 ······-·'"audit"·in·ansible_facts.packages'9679 ······-·'"audit"·in·ansible_facts.packages'
 9680 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9681 ······tags:9681 ······tags:
9682 ······-·CJIS-5.4.1.19682 ······-·CJIS-5.4.1.1
9683 ······-·NIST-800-171-3.3.19683 ······-·NIST-800-171-3.3.1
9684 ······-·NIST-800-171-3.4.39684 ······-·NIST-800-171-3.4.3
9685 ······-·NIST-800-53-AC-6(9)9685 ······-·NIST-800-53-AC-6(9)
9686 ······-·NIST-800-53-CM-6(a)9686 ······-·NIST-800-53-CM-6(a)
9687 ······-·PCI-DSS-Req-10.5.29687 ······-·PCI-DSS-Req-10.5.2
Offset 9697, 16 lines modifiedOffset 9697, 16 lines modified
9697 ······lineinfile:9697 ······lineinfile:
9698 ········path:·'{{·item·}}'9698 ········path:·'{{·item·}}'
9699 ········regexp:·^\s*(?:-e)\s+.*$9699 ········regexp:·^\s*(?:-e)\s+.*$
9700 ········state:·absent9700 ········state:·absent
9701 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']9701 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
9702 ········}}'9702 ········}}'
9703 ······when:9703 ······when:
9704 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9705 ······-·'"audit"·in·ansible_facts.packages'9704 ······-·'"audit"·in·ansible_facts.packages'
 9705 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9706 ······tags:9706 ······tags:
9707 ······-·CJIS-5.4.1.19707 ······-·CJIS-5.4.1.1
9708 ······-·NIST-800-171-3.3.19708 ······-·NIST-800-171-3.3.1
9709 ······-·NIST-800-171-3.4.39709 ······-·NIST-800-171-3.4.3
9710 ······-·NIST-800-53-AC-6(9)9710 ······-·NIST-800-53-AC-6(9)
9711 ······-·NIST-800-53-CM-6(a)9711 ······-·NIST-800-53-CM-6(a)
9712 ······-·PCI-DSS-Req-10.5.29712 ······-·PCI-DSS-Req-10.5.2
Offset 9723, 16 lines modifiedOffset 9723, 16 lines modified
9723 ········create:·true9723 ········create:·true
9724 ········line:·-e·29724 ········line:·-e·2
9725 ········mode:·o-rwx9725 ········mode:·o-rwx
9726 ······loop:9726 ······loop:
9727 ······-·/etc/audit/audit.rules9727 ······-·/etc/audit/audit.rules
9728 ······-·/etc/audit/rules.d/immutable.rules9728 ······-·/etc/audit/rules.d/immutable.rules
9729 ······when:9729 ······when:
9730 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9731 ······-·'"audit"·in·ansible_facts.packages'9730 ······-·'"audit"·in·ansible_facts.packages'
 9731 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9732 ······tags:9732 ······tags:
9733 ······-·CJIS-5.4.1.19733 ······-·CJIS-5.4.1.1
9734 ······-·NIST-800-171-3.3.19734 ······-·NIST-800-171-3.3.1
9735 ······-·NIST-800-171-3.4.39735 ······-·NIST-800-171-3.4.3
9736 ······-·NIST-800-53-AC-6(9)9736 ······-·NIST-800-53-AC-6(9)
9737 ······-·NIST-800-53-CM-6(a)9737 ······-·NIST-800-53-CM-6(a)
9738 ······-·PCI-DSS-Req-10.5.29738 ······-·PCI-DSS-Req-10.5.2
Offset 9764, 16 lines modifiedOffset 9764, 16 lines modified
9764 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/9764 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
9765 ······find:9765 ······find:
9766 ········paths:·/etc/audit/rules.d9766 ········paths:·/etc/audit/rules.d
9767 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+9767 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
9768 ········patterns:·'*.rules'9768 ········patterns:·'*.rules'
9769 ······register:·find_existing_watch_rules_d9769 ······register:·find_existing_watch_rules_d
9770 ······when:9770 ······when:
9771 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9772 ······-·'"audit"·in·ansible_facts.packages'9771 ······-·'"audit"·in·ansible_facts.packages'
 9772 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9773 ······tags:9773 ······tags:
9774 ······-·CJIS-5.4.1.19774 ······-·CJIS-5.4.1.1
9775 ······-·NIST-800-171-3.1.89775 ······-·NIST-800-171-3.1.8
9776 ······-·NIST-800-53-AU-12(c)9776 ······-·NIST-800-53-AU-12(c)
9777 ······-·NIST-800-53-AU-2(d)9777 ······-·NIST-800-53-AU-2(d)
9778 ······-·NIST-800-53-CM-6(a)9778 ······-·NIST-800-53-CM-6(a)
9779 ······-·PCI-DSS-Req-10.5.59779 ······-·PCI-DSS-Req-10.5.5
Offset 9787, 16 lines modifiedOffset 9787, 16 lines modified
9787 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy9787 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
9788 ······find:9788 ······find:
9789 ········paths:·/etc/audit/rules.d9789 ········paths:·/etc/audit/rules.d
9790 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$9790 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
9791 ········patterns:·'*.rules'9791 ········patterns:·'*.rules'
9792 ······register:·find_watch_key9792 ······register:·find_watch_key
9793 ······when:9793 ······when:
9794 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9795 ······-·'"audit"·in·ansible_facts.packages'9794 ······-·'"audit"·in·ansible_facts.packages'
 9795 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9796 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched9796 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
9797 ········==·09797 ········==·0
9798 ······tags:9798 ······tags:
9799 ······-·CJIS-5.4.1.19799 ······-·CJIS-5.4.1.1
9800 ······-·NIST-800-171-3.1.89800 ······-·NIST-800-171-3.1.8
9801 ······-·NIST-800-53-AU-12(c)9801 ······-·NIST-800-53-AU-12(c)
9802 ······-·NIST-800-53-AU-2(d)9802 ······-·NIST-800-53-AU-2(d)
Offset 9810, 16 lines modifiedOffset 9810, 16 lines modified
9810 ······-·restrict_strategy9810 ······-·restrict_strategy
  
9811 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule9811 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
9812 ······set_fact:9812 ······set_fact:
9813 ········all_files:9813 ········all_files:
9814 ········-·/etc/audit/rules.d/MAC-policy.rules9814 ········-·/etc/audit/rules.d/MAC-policy.rules
9815 ······when:9815 ······when:
9816 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9817 ······-·'"audit"·in·ansible_facts.packages'9816 ······-·'"audit"·in·ansible_facts.packages'
 9817 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9818 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched9818 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
9819 ········is·defined·and·find_existing_watch_rules_d.matched·==·09819 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
9820 ······tags:9820 ······tags:
9821 ······-·CJIS-5.4.1.19821 ······-·CJIS-5.4.1.1
9822 ······-·NIST-800-171-3.1.89822 ······-·NIST-800-171-3.1.8
9823 ······-·NIST-800-53-AU-12(c)9823 ······-·NIST-800-53-AU-12(c)
9824 ······-·NIST-800-53-AU-2(d)9824 ······-·NIST-800-53-AU-2(d)
Offset 9833, 16 lines modifiedOffset 9833, 16 lines modified
9833 ······-·restrict_strategy9833 ······-·restrict_strategy
  
9834 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule9834 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
9835 ······set_fact:9835 ······set_fact:
9836 ········all_files:9836 ········all_files:
9837 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'9837 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
9838 ······when:9838 ······when:
9839 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9840 ······-·'"audit"·in·ansible_facts.packages'9839 ······-·'"audit"·in·ansible_facts.packages'
 9840 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9841 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched9841 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
9842 ········is·defined·and·find_existing_watch_rules_d.matched·==·09842 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
9843 ······tags:9843 ······tags:
9844 ······-·CJIS-5.4.1.19844 ······-·CJIS-5.4.1.1
9845 ······-·NIST-800-171-3.1.89845 ······-·NIST-800-171-3.1.8
9846 ······-·NIST-800-53-AU-12(c)9846 ······-·NIST-800-53-AU-12(c)
9847 ······-·NIST-800-53-AU-2(d)9847 ······-·NIST-800-53-AU-2(d)
Offset 9858, 16 lines modifiedOffset 9858, 16 lines modified
9858 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/9858 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 199070/204105 bytes (97.53%) of diff not shown.
787 B
./usr/share/scap-security-guide/ansible/ol7-playbook-ospp.yml
Ordering differences only
    
Offset 4491, 16 lines modifiedOffset 4491, 16 lines modified
4491 ······lineinfile:4491 ······lineinfile:
4492 ········dest:·/etc/audit/auditd.conf4492 ········dest:·/etc/audit/auditd.conf
4493 ········regexp:·^\s*flush\s*=\s*.*$4493 ········regexp:·^\s*flush\s*=\s*.*$
4494 ········line:·flush·=·{{·var_auditd_flush·}}4494 ········line:·flush·=·{{·var_auditd_flush·}}
4495 ········state:·present4495 ········state:·present
4496 ········create:·true4496 ········create:·true
4497 ······when:4497 ······when:
4498 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4499 ······-·'"audit"·in·ansible_facts.packages'4498 ······-·'"audit"·in·ansible_facts.packages'
 4499 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4500 ······tags:4500 ······tags:
4501 ······-·NIST-800-171-3.3.14501 ······-·NIST-800-171-3.3.1
4502 ······-·NIST-800-53-AU-114502 ······-·NIST-800-53-AU-11
4503 ······-·NIST-800-53-CM-6(a)4503 ······-·NIST-800-53-CM-6(a)
4504 ······-·auditd_data_retention_flush4504 ······-·auditd_data_retention_flush
4505 ······-·low_complexity4505 ······-·low_complexity
4506 ······-·low_disruption4506 ······-·low_disruption
107 KB
./usr/share/scap-security-guide/ansible/ol7-playbook-pci-dss.yml
Ordering differences only
    
Offset 4439, 16 lines modifiedOffset 4439, 16 lines modified
  
4439 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension4439 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
4440 ······find:4440 ······find:
4441 ········paths:·/etc/audit/rules.d/4441 ········paths:·/etc/audit/rules.d/
4442 ········patterns:·'*.rules'4442 ········patterns:·'*.rules'
4443 ······register:·find_rules_d4443 ······register:·find_rules_d
4444 ······when:4444 ······when:
4445 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4446 ······-·'"audit"·in·ansible_facts.packages'4445 ······-·'"audit"·in·ansible_facts.packages'
 4446 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4447 ······tags:4447 ······tags:
4448 ······-·CJIS-5.4.1.14448 ······-·CJIS-5.4.1.1
4449 ······-·NIST-800-171-3.3.14449 ······-·NIST-800-171-3.3.1
4450 ······-·NIST-800-171-3.4.34450 ······-·NIST-800-171-3.4.3
4451 ······-·NIST-800-53-AC-6(9)4451 ······-·NIST-800-53-AC-6(9)
4452 ······-·NIST-800-53-CM-6(a)4452 ······-·NIST-800-53-CM-6(a)
4453 ······-·PCI-DSS-Req-10.5.24453 ······-·PCI-DSS-Req-10.5.2
Offset 4463, 16 lines modifiedOffset 4463, 16 lines modified
4463 ······lineinfile:4463 ······lineinfile:
4464 ········path:·'{{·item·}}'4464 ········path:·'{{·item·}}'
4465 ········regexp:·^\s*(?:-e)\s+.*$4465 ········regexp:·^\s*(?:-e)\s+.*$
4466 ········state:·absent4466 ········state:·absent
4467 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']4467 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
4468 ········}}'4468 ········}}'
4469 ······when:4469 ······when:
4470 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4471 ······-·'"audit"·in·ansible_facts.packages'4470 ······-·'"audit"·in·ansible_facts.packages'
 4471 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4472 ······tags:4472 ······tags:
4473 ······-·CJIS-5.4.1.14473 ······-·CJIS-5.4.1.1
4474 ······-·NIST-800-171-3.3.14474 ······-·NIST-800-171-3.3.1
4475 ······-·NIST-800-171-3.4.34475 ······-·NIST-800-171-3.4.3
4476 ······-·NIST-800-53-AC-6(9)4476 ······-·NIST-800-53-AC-6(9)
4477 ······-·NIST-800-53-CM-6(a)4477 ······-·NIST-800-53-CM-6(a)
4478 ······-·PCI-DSS-Req-10.5.24478 ······-·PCI-DSS-Req-10.5.2
Offset 4489, 16 lines modifiedOffset 4489, 16 lines modified
4489 ········create:·true4489 ········create:·true
4490 ········line:·-e·24490 ········line:·-e·2
4491 ········mode:·o-rwx4491 ········mode:·o-rwx
4492 ······loop:4492 ······loop:
4493 ······-·/etc/audit/audit.rules4493 ······-·/etc/audit/audit.rules
4494 ······-·/etc/audit/rules.d/immutable.rules4494 ······-·/etc/audit/rules.d/immutable.rules
4495 ······when:4495 ······when:
4496 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4497 ······-·'"audit"·in·ansible_facts.packages'4496 ······-·'"audit"·in·ansible_facts.packages'
 4497 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4498 ······tags:4498 ······tags:
4499 ······-·CJIS-5.4.1.14499 ······-·CJIS-5.4.1.1
4500 ······-·NIST-800-171-3.3.14500 ······-·NIST-800-171-3.3.1
4501 ······-·NIST-800-171-3.4.34501 ······-·NIST-800-171-3.4.3
4502 ······-·NIST-800-53-AC-6(9)4502 ······-·NIST-800-53-AC-6(9)
4503 ······-·NIST-800-53-CM-6(a)4503 ······-·NIST-800-53-CM-6(a)
4504 ······-·PCI-DSS-Req-10.5.24504 ······-·PCI-DSS-Req-10.5.2
Offset 4530, 16 lines modifiedOffset 4530, 16 lines modified
4530 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/4530 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
4531 ······find:4531 ······find:
4532 ········paths:·/etc/audit/rules.d4532 ········paths:·/etc/audit/rules.d
4533 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+4533 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
4534 ········patterns:·'*.rules'4534 ········patterns:·'*.rules'
4535 ······register:·find_existing_watch_rules_d4535 ······register:·find_existing_watch_rules_d
4536 ······when:4536 ······when:
4537 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4538 ······-·'"audit"·in·ansible_facts.packages'4537 ······-·'"audit"·in·ansible_facts.packages'
 4538 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4539 ······tags:4539 ······tags:
4540 ······-·CJIS-5.4.1.14540 ······-·CJIS-5.4.1.1
4541 ······-·NIST-800-171-3.1.84541 ······-·NIST-800-171-3.1.8
4542 ······-·NIST-800-53-AU-12(c)4542 ······-·NIST-800-53-AU-12(c)
4543 ······-·NIST-800-53-AU-2(d)4543 ······-·NIST-800-53-AU-2(d)
4544 ······-·NIST-800-53-CM-6(a)4544 ······-·NIST-800-53-CM-6(a)
4545 ······-·PCI-DSS-Req-10.5.54545 ······-·PCI-DSS-Req-10.5.5
Offset 4553, 16 lines modifiedOffset 4553, 16 lines modified
4553 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy4553 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
4554 ······find:4554 ······find:
4555 ········paths:·/etc/audit/rules.d4555 ········paths:·/etc/audit/rules.d
4556 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$4556 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
4557 ········patterns:·'*.rules'4557 ········patterns:·'*.rules'
4558 ······register:·find_watch_key4558 ······register:·find_watch_key
4559 ······when:4559 ······when:
4560 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4561 ······-·'"audit"·in·ansible_facts.packages'4560 ······-·'"audit"·in·ansible_facts.packages'
 4561 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4562 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4562 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4563 ········==·04563 ········==·0
4564 ······tags:4564 ······tags:
4565 ······-·CJIS-5.4.1.14565 ······-·CJIS-5.4.1.1
4566 ······-·NIST-800-171-3.1.84566 ······-·NIST-800-171-3.1.8
4567 ······-·NIST-800-53-AU-12(c)4567 ······-·NIST-800-53-AU-12(c)
4568 ······-·NIST-800-53-AU-2(d)4568 ······-·NIST-800-53-AU-2(d)
Offset 4576, 16 lines modifiedOffset 4576, 16 lines modified
4576 ······-·restrict_strategy4576 ······-·restrict_strategy
  
4577 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule4577 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
4578 ······set_fact:4578 ······set_fact:
4579 ········all_files:4579 ········all_files:
4580 ········-·/etc/audit/rules.d/MAC-policy.rules4580 ········-·/etc/audit/rules.d/MAC-policy.rules
4581 ······when:4581 ······when:
4582 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4583 ······-·'"audit"·in·ansible_facts.packages'4582 ······-·'"audit"·in·ansible_facts.packages'
 4583 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4584 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched4584 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
4585 ········is·defined·and·find_existing_watch_rules_d.matched·==·04585 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4586 ······tags:4586 ······tags:
4587 ······-·CJIS-5.4.1.14587 ······-·CJIS-5.4.1.1
4588 ······-·NIST-800-171-3.1.84588 ······-·NIST-800-171-3.1.8
4589 ······-·NIST-800-53-AU-12(c)4589 ······-·NIST-800-53-AU-12(c)
4590 ······-·NIST-800-53-AU-2(d)4590 ······-·NIST-800-53-AU-2(d)
Offset 4599, 16 lines modifiedOffset 4599, 16 lines modified
4599 ······-·restrict_strategy4599 ······-·restrict_strategy
  
4600 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule4600 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
4601 ······set_fact:4601 ······set_fact:
4602 ········all_files:4602 ········all_files:
4603 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'4603 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
4604 ······when:4604 ······when:
4605 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4606 ······-·'"audit"·in·ansible_facts.packages'4605 ······-·'"audit"·in·ansible_facts.packages'
 4606 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4607 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched4607 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
4608 ········is·defined·and·find_existing_watch_rules_d.matched·==·04608 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4609 ······tags:4609 ······tags:
4610 ······-·CJIS-5.4.1.14610 ······-·CJIS-5.4.1.1
4611 ······-·NIST-800-171-3.1.84611 ······-·NIST-800-171-3.1.8
4612 ······-·NIST-800-53-AU-12(c)4612 ······-·NIST-800-53-AU-12(c)
4613 ······-·NIST-800-53-AU-2(d)4613 ······-·NIST-800-53-AU-2(d)
Offset 4624, 16 lines modifiedOffset 4624, 16 lines modified
4624 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/4624 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 103979/109014 bytes (95.38%) of diff not shown.
98.7 KB
./usr/share/scap-security-guide/ansible/ol7-playbook-standard.yml
Ordering differences only
    
Offset 535, 16 lines modifiedOffset 535, 16 lines modified
535 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/535 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
536 ······find:536 ······find:
537 ········paths:·/etc/audit/rules.d537 ········paths:·/etc/audit/rules.d
538 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+538 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
539 ········patterns:·'*.rules'539 ········patterns:·'*.rules'
540 ······register:·find_existing_watch_rules_d540 ······register:·find_existing_watch_rules_d
541 ······when:541 ······when:
542 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
543 ······-·'"audit"·in·ansible_facts.packages'542 ······-·'"audit"·in·ansible_facts.packages'
 543 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
544 ······tags:544 ······tags:
545 ······-·CJIS-5.4.1.1545 ······-·CJIS-5.4.1.1
546 ······-·NIST-800-171-3.1.8546 ······-·NIST-800-171-3.1.8
547 ······-·NIST-800-53-AU-12(c)547 ······-·NIST-800-53-AU-12(c)
548 ······-·NIST-800-53-AU-2(d)548 ······-·NIST-800-53-AU-2(d)
549 ······-·NIST-800-53-CM-6(a)549 ······-·NIST-800-53-CM-6(a)
550 ······-·PCI-DSS-Req-10.5.5550 ······-·PCI-DSS-Req-10.5.5
Offset 558, 16 lines modifiedOffset 558, 16 lines modified
558 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy558 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
559 ······find:559 ······find:
560 ········paths:·/etc/audit/rules.d560 ········paths:·/etc/audit/rules.d
561 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$561 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
562 ········patterns:·'*.rules'562 ········patterns:·'*.rules'
563 ······register:·find_watch_key563 ······register:·find_watch_key
564 ······when:564 ······when:
565 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
566 ······-·'"audit"·in·ansible_facts.packages'565 ······-·'"audit"·in·ansible_facts.packages'
 566 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
567 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched567 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
568 ········==·0568 ········==·0
569 ······tags:569 ······tags:
570 ······-·CJIS-5.4.1.1570 ······-·CJIS-5.4.1.1
571 ······-·NIST-800-171-3.1.8571 ······-·NIST-800-171-3.1.8
572 ······-·NIST-800-53-AU-12(c)572 ······-·NIST-800-53-AU-12(c)
573 ······-·NIST-800-53-AU-2(d)573 ······-·NIST-800-53-AU-2(d)
Offset 581, 16 lines modifiedOffset 581, 16 lines modified
581 ······-·restrict_strategy581 ······-·restrict_strategy
  
582 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule582 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
583 ······set_fact:583 ······set_fact:
584 ········all_files:584 ········all_files:
585 ········-·/etc/audit/rules.d/MAC-policy.rules585 ········-·/etc/audit/rules.d/MAC-policy.rules
586 ······when:586 ······when:
587 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
588 ······-·'"audit"·in·ansible_facts.packages'587 ······-·'"audit"·in·ansible_facts.packages'
 588 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
589 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched589 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
590 ········is·defined·and·find_existing_watch_rules_d.matched·==·0590 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
591 ······tags:591 ······tags:
592 ······-·CJIS-5.4.1.1592 ······-·CJIS-5.4.1.1
593 ······-·NIST-800-171-3.1.8593 ······-·NIST-800-171-3.1.8
594 ······-·NIST-800-53-AU-12(c)594 ······-·NIST-800-53-AU-12(c)
595 ······-·NIST-800-53-AU-2(d)595 ······-·NIST-800-53-AU-2(d)
Offset 604, 16 lines modifiedOffset 604, 16 lines modified
604 ······-·restrict_strategy604 ······-·restrict_strategy
  
605 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule605 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
606 ······set_fact:606 ······set_fact:
607 ········all_files:607 ········all_files:
608 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'608 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
609 ······when:609 ······when:
610 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
611 ······-·'"audit"·in·ansible_facts.packages'610 ······-·'"audit"·in·ansible_facts.packages'
 611 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
612 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched612 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
613 ········is·defined·and·find_existing_watch_rules_d.matched·==·0613 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
614 ······tags:614 ······tags:
615 ······-·CJIS-5.4.1.1615 ······-·CJIS-5.4.1.1
616 ······-·NIST-800-171-3.1.8616 ······-·NIST-800-171-3.1.8
617 ······-·NIST-800-53-AU-12(c)617 ······-·NIST-800-53-AU-12(c)
618 ······-·NIST-800-53-AU-2(d)618 ······-·NIST-800-53-AU-2(d)
Offset 629, 16 lines modifiedOffset 629, 16 lines modified
629 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/629 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
630 ······lineinfile:630 ······lineinfile:
631 ········path:·'{{·all_files[0]·}}'631 ········path:·'{{·all_files[0]·}}'
632 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy632 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
633 ········create:·true633 ········create:·true
634 ········mode:·'0640'634 ········mode:·'0640'
635 ······when:635 ······when:
636 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
637 ······-·'"audit"·in·ansible_facts.packages'636 ······-·'"audit"·in·ansible_facts.packages'
 637 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
638 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched638 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
639 ········==·0639 ········==·0
640 ······tags:640 ······tags:
641 ······-·CJIS-5.4.1.1641 ······-·CJIS-5.4.1.1
642 ······-·NIST-800-171-3.1.8642 ······-·NIST-800-171-3.1.8
643 ······-·NIST-800-53-AU-12(c)643 ······-·NIST-800-53-AU-12(c)
644 ······-·NIST-800-53-AU-2(d)644 ······-·NIST-800-53-AU-2(d)
Offset 654, 16 lines modifiedOffset 654, 16 lines modified
654 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules654 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules
655 ······find:655 ······find:
656 ········paths:·/etc/audit/656 ········paths:·/etc/audit/
657 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+657 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
658 ········patterns:·audit.rules658 ········patterns:·audit.rules
659 ······register:·find_existing_watch_audit_rules659 ······register:·find_existing_watch_audit_rules
660 ······when:660 ······when:
661 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
662 ······-·'"audit"·in·ansible_facts.packages'661 ······-·'"audit"·in·ansible_facts.packages'
 662 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
663 ······tags:663 ······tags:
664 ······-·CJIS-5.4.1.1664 ······-·CJIS-5.4.1.1
665 ······-·NIST-800-171-3.1.8665 ······-·NIST-800-171-3.1.8
666 ······-·NIST-800-53-AU-12(c)666 ······-·NIST-800-53-AU-12(c)
667 ······-·NIST-800-53-AU-2(d)667 ······-·NIST-800-53-AU-2(d)
668 ······-·NIST-800-53-CM-6(a)668 ······-·NIST-800-53-CM-6(a)
669 ······-·PCI-DSS-Req-10.5.5669 ······-·PCI-DSS-Req-10.5.5
Offset 678, 16 lines modifiedOffset 678, 16 lines modified
678 ······lineinfile:678 ······lineinfile:
679 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy679 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
680 ········state:·present680 ········state:·present
681 ········dest:·/etc/audit/audit.rules681 ········dest:·/etc/audit/audit.rules
682 ········create:·true682 ········create:·true
683 ········mode:·'0640'683 ········mode:·'0640'
684 ······when:684 ······when:
685 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
686 ······-·'"audit"·in·ansible_facts.packages'685 ······-·'"audit"·in·ansible_facts.packages'
 686 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
687 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched687 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
688 ········==·0688 ········==·0
689 ······tags:689 ······tags:
690 ······-·CJIS-5.4.1.1690 ······-·CJIS-5.4.1.1
691 ······-·NIST-800-171-3.1.8691 ······-·NIST-800-171-3.1.8
692 ······-·NIST-800-53-AU-12(c)692 ······-·NIST-800-53-AU-12(c)
693 ······-·NIST-800-53-AU-2(d)693 ······-·NIST-800-53-AU-2(d)
Offset 720, 16 lines modifiedOffset 720, 16 lines modified
720 ······-·reboot_required720 ······-·reboot_required
Max diff block lines reached; 95737/100953 bytes (94.83%) of diff not shown.
151 KB
./usr/share/scap-security-guide/ansible/ol7-playbook-stig.yml
Ordering differences only
    
Offset 8951, 16 lines modifiedOffset 8951, 16 lines modified
8951 ······-·reboot_required8951 ······-·reboot_required
8952 ······-·restrict_strategy8952 ······-·restrict_strategy
  
8953 ····-·name:·Set·architecture·for·audit·mount·tasks8953 ····-·name:·Set·architecture·for·audit·mount·tasks
8954 ······set_fact:8954 ······set_fact:
8955 ········audit_arch:·b648955 ········audit_arch:·b64
8956 ······when:8956 ······when:
8957 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8958 ······-·'"audit"·in·ansible_facts.packages'8957 ······-·'"audit"·in·ansible_facts.packages'
 8958 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8959 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8959 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8960 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8960 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8961 ······tags:8961 ······tags:
8962 ······-·CJIS-5.4.1.18962 ······-·CJIS-5.4.1.1
8963 ······-·DISA-STIG-OL07-00-0307408963 ······-·DISA-STIG-OL07-00-030740
8964 ······-·NIST-800-171-3.1.78964 ······-·NIST-800-171-3.1.7
8965 ······-·NIST-800-53-AC-6(9)8965 ······-·NIST-800-53-AC-6(9)
Offset 9092, 16 lines modifiedOffset 9092, 16 lines modified
9092 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009092 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9093 ············-F·auid!=unset·-F·key=perm_mod9093 ············-F·auid!=unset·-F·key=perm_mod
9094 ··········create:·true9094 ··········create:·true
9095 ··········mode:·o-rwx9095 ··········mode:·o-rwx
9096 ··········state:·present9096 ··········state:·present
9097 ········when:·syscalls_found·|·length·==·09097 ········when:·syscalls_found·|·length·==·0
9098 ······when:9098 ······when:
9099 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9100 ······-·'"audit"·in·ansible_facts.packages'9099 ······-·'"audit"·in·ansible_facts.packages'
 9100 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9101 ······tags:9101 ······tags:
9102 ······-·CJIS-5.4.1.19102 ······-·CJIS-5.4.1.1
9103 ······-·DISA-STIG-OL07-00-0307409103 ······-·DISA-STIG-OL07-00-030740
9104 ······-·NIST-800-171-3.1.79104 ······-·NIST-800-171-3.1.7
9105 ······-·NIST-800-53-AC-6(9)9105 ······-·NIST-800-53-AC-6(9)
9106 ······-·NIST-800-53-AU-12(c)9106 ······-·NIST-800-53-AU-12(c)
9107 ······-·NIST-800-53-AU-2(d)9107 ······-·NIST-800-53-AU-2(d)
Offset 9231, 16 lines modifiedOffset 9231, 16 lines modified
9231 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009231 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9232 ············-F·auid!=unset·-F·key=perm_mod9232 ············-F·auid!=unset·-F·key=perm_mod
9233 ··········create:·true9233 ··········create:·true
9234 ··········mode:·o-rwx9234 ··········mode:·o-rwx
9235 ··········state:·present9235 ··········state:·present
9236 ········when:·syscalls_found·|·length·==·09236 ········when:·syscalls_found·|·length·==·0
9237 ······when:9237 ······when:
9238 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9239 ······-·'"audit"·in·ansible_facts.packages'9238 ······-·'"audit"·in·ansible_facts.packages'
 9239 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9240 ······-·audit_arch·==·"b64"9240 ······-·audit_arch·==·"b64"
9241 ······tags:9241 ······tags:
9242 ······-·CJIS-5.4.1.19242 ······-·CJIS-5.4.1.1
9243 ······-·DISA-STIG-OL07-00-0307409243 ······-·DISA-STIG-OL07-00-030740
9244 ······-·NIST-800-171-3.1.79244 ······-·NIST-800-171-3.1.7
9245 ······-·NIST-800-53-AC-6(9)9245 ······-·NIST-800-53-AC-6(9)
9246 ······-·NIST-800-53-AU-12(c)9246 ······-·NIST-800-53-AU-12(c)
Offset 9272, 16 lines modifiedOffset 9272, 16 lines modified
9272 ······-·medium_severity9272 ······-·medium_severity
9273 ······-·no_reboot_needed9273 ······-·no_reboot_needed
9274 ······-·restrict_strategy9274 ······-·restrict_strategy
  
9275 ····-·name:·Service·facts9275 ····-·name:·Service·facts
9276 ······service_facts:·null9276 ······service_facts:·null
9277 ······when:9277 ······when:
9278 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9279 ······-·'"audit"·in·ansible_facts.packages'9278 ······-·'"audit"·in·ansible_facts.packages'
 9279 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9280 ······tags:9280 ······tags:
9281 ······-·DISA-STIG-OL07-00-0303609281 ······-·DISA-STIG-OL07-00-030360
9282 ······-·NIST-800-53-AC-6(9)9282 ······-·NIST-800-53-AC-6(9)
9283 ······-·NIST-800-53-AU-12(3)9283 ······-·NIST-800-53-AU-12(3)
9284 ······-·NIST-800-53-AU-7(a)9284 ······-·NIST-800-53-AU-7(a)
9285 ······-·NIST-800-53-AU-7(b)9285 ······-·NIST-800-53-AU-7(b)
9286 ······-·NIST-800-53-AU-8(b)9286 ······-·NIST-800-53-AU-8(b)
Offset 9293, 16 lines modifiedOffset 9293, 16 lines modified
9293 ······-·no_reboot_needed9293 ······-·no_reboot_needed
9294 ······-·restrict_strategy9294 ······-·restrict_strategy
  
9295 ····-·name:·Check·the·rules·script·being·used9295 ····-·name:·Check·the·rules·script·being·used
9296 ······command:·grep·'^ExecStartPost'·/usr/lib/systemd/system/auditd.service9296 ······command:·grep·'^ExecStartPost'·/usr/lib/systemd/system/auditd.service
9297 ······register:·check_rules_scripts_result9297 ······register:·check_rules_scripts_result
9298 ······when:9298 ······when:
9299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9300 ······-·'"audit"·in·ansible_facts.packages'9299 ······-·'"audit"·in·ansible_facts.packages'
 9300 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9301 ······tags:9301 ······tags:
9302 ······-·DISA-STIG-OL07-00-0303609302 ······-·DISA-STIG-OL07-00-030360
9303 ······-·NIST-800-53-AC-6(9)9303 ······-·NIST-800-53-AC-6(9)
9304 ······-·NIST-800-53-AU-12(3)9304 ······-·NIST-800-53-AU-12(3)
9305 ······-·NIST-800-53-AU-7(a)9305 ······-·NIST-800-53-AU-7(a)
9306 ······-·NIST-800-53-AU-7(b)9306 ······-·NIST-800-53-AU-7(b)
9307 ······-·NIST-800-53-AU-8(b)9307 ······-·NIST-800-53-AU-8(b)
Offset 9318, 16 lines modifiedOffset 9318, 16 lines modified
9318 ······set_fact:9318 ······set_fact:
9319 ········suid_audit_rules:9319 ········suid_audit_rules:
9320 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid9320 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid
9321 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid9321 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid
9322 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid9322 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid
9323 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid9323 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid
9324 ······when:9324 ······when:
9325 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9326 ······-·'"audit"·in·ansible_facts.packages'9325 ······-·'"audit"·in·ansible_facts.packages'
 9326 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9327 ······tags:9327 ······tags:
9328 ······-·DISA-STIG-OL07-00-0303609328 ······-·DISA-STIG-OL07-00-030360
9329 ······-·NIST-800-53-AC-6(9)9329 ······-·NIST-800-53-AC-6(9)
9330 ······-·NIST-800-53-AU-12(3)9330 ······-·NIST-800-53-AU-12(3)
9331 ······-·NIST-800-53-AU-7(a)9331 ······-·NIST-800-53-AU-7(a)
9332 ······-·NIST-800-53-AU-7(b)9332 ······-·NIST-800-53-AU-7(b)
9333 ······-·NIST-800-53-AU-8(b)9333 ······-·NIST-800-53-AU-8(b)
Offset 9341, 16 lines modifiedOffset 9341, 16 lines modified
  
9341 ····-·name:·Update·/etc/audit/rules.d/privileged.rules·to·audit·privileged·functions9341 ····-·name:·Update·/etc/audit/rules.d/privileged.rules·to·audit·privileged·functions
9342 ······lineinfile:9342 ······lineinfile:
9343 ········path:·/etc/audit/rules.d/privileged.rules9343 ········path:·/etc/audit/rules.d/privileged.rules
9344 ········line:·'{{··item··}}'9344 ········line:·'{{··item··}}'
9345 ········create:·true9345 ········create:·true
9346 ······when:9346 ······when:
9347 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9348 ······-·'"audit"·in·ansible_facts.packages'9347 ······-·'"audit"·in·ansible_facts.packages'
 9348 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9349 ······-·'"auditd.service"·in·ansible_facts.services'9349 ······-·'"auditd.service"·in·ansible_facts.services'
9350 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'9350 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
9351 ······register:·augenrules_audit_rules_privilege_function_update_result9351 ······register:·augenrules_audit_rules_privilege_function_update_result
9352 ······with_items:·'{{·suid_audit_rules·}}'9352 ······with_items:·'{{·suid_audit_rules·}}'
9353 ······tags:9353 ······tags:
9354 ······-·DISA-STIG-OL07-00-0303609354 ······-·DISA-STIG-OL07-00-030360
9355 ······-·NIST-800-53-AC-6(9)9355 ······-·NIST-800-53-AC-6(9)
Offset 9368, 16 lines modifiedOffset 9368, 16 lines modified
  
Max diff block lines reached; 149634/154803 bytes (96.66%) of diff not shown.
151 KB
./usr/share/scap-security-guide/ansible/ol7-playbook-stig_gui.yml
Ordering differences only
    
Offset 8956, 16 lines modifiedOffset 8956, 16 lines modified
8956 ······-·reboot_required8956 ······-·reboot_required
8957 ······-·restrict_strategy8957 ······-·restrict_strategy
  
8958 ····-·name:·Set·architecture·for·audit·mount·tasks8958 ····-·name:·Set·architecture·for·audit·mount·tasks
8959 ······set_fact:8959 ······set_fact:
8960 ········audit_arch:·b648960 ········audit_arch:·b64
8961 ······when:8961 ······when:
8962 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8963 ······-·'"audit"·in·ansible_facts.packages'8962 ······-·'"audit"·in·ansible_facts.packages'
 8963 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8964 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture8964 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
8965 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"8965 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
8966 ······tags:8966 ······tags:
8967 ······-·CJIS-5.4.1.18967 ······-·CJIS-5.4.1.1
8968 ······-·DISA-STIG-OL07-00-0307408968 ······-·DISA-STIG-OL07-00-030740
8969 ······-·NIST-800-171-3.1.78969 ······-·NIST-800-171-3.1.7
8970 ······-·NIST-800-53-AC-6(9)8970 ······-·NIST-800-53-AC-6(9)
Offset 9097, 16 lines modifiedOffset 9097, 16 lines modified
9097 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009097 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9098 ············-F·auid!=unset·-F·key=perm_mod9098 ············-F·auid!=unset·-F·key=perm_mod
9099 ··········create:·true9099 ··········create:·true
9100 ··········mode:·o-rwx9100 ··········mode:·o-rwx
9101 ··········state:·present9101 ··········state:·present
9102 ········when:·syscalls_found·|·length·==·09102 ········when:·syscalls_found·|·length·==·0
9103 ······when:9103 ······when:
9104 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9105 ······-·'"audit"·in·ansible_facts.packages'9104 ······-·'"audit"·in·ansible_facts.packages'
 9105 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9106 ······tags:9106 ······tags:
9107 ······-·CJIS-5.4.1.19107 ······-·CJIS-5.4.1.1
9108 ······-·DISA-STIG-OL07-00-0307409108 ······-·DISA-STIG-OL07-00-030740
9109 ······-·NIST-800-171-3.1.79109 ······-·NIST-800-171-3.1.7
9110 ······-·NIST-800-53-AC-6(9)9110 ······-·NIST-800-53-AC-6(9)
9111 ······-·NIST-800-53-AU-12(c)9111 ······-·NIST-800-53-AU-12(c)
9112 ······-·NIST-800-53-AU-2(d)9112 ······-·NIST-800-53-AU-2(d)
Offset 9236, 16 lines modifiedOffset 9236, 16 lines modified
9236 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009236 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9237 ············-F·auid!=unset·-F·key=perm_mod9237 ············-F·auid!=unset·-F·key=perm_mod
9238 ··········create:·true9238 ··········create:·true
9239 ··········mode:·o-rwx9239 ··········mode:·o-rwx
9240 ··········state:·present9240 ··········state:·present
9241 ········when:·syscalls_found·|·length·==·09241 ········when:·syscalls_found·|·length·==·0
9242 ······when:9242 ······when:
9243 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9244 ······-·'"audit"·in·ansible_facts.packages'9243 ······-·'"audit"·in·ansible_facts.packages'
 9244 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9245 ······-·audit_arch·==·"b64"9245 ······-·audit_arch·==·"b64"
9246 ······tags:9246 ······tags:
9247 ······-·CJIS-5.4.1.19247 ······-·CJIS-5.4.1.1
9248 ······-·DISA-STIG-OL07-00-0307409248 ······-·DISA-STIG-OL07-00-030740
9249 ······-·NIST-800-171-3.1.79249 ······-·NIST-800-171-3.1.7
9250 ······-·NIST-800-53-AC-6(9)9250 ······-·NIST-800-53-AC-6(9)
9251 ······-·NIST-800-53-AU-12(c)9251 ······-·NIST-800-53-AU-12(c)
Offset 9277, 16 lines modifiedOffset 9277, 16 lines modified
9277 ······-·medium_severity9277 ······-·medium_severity
9278 ······-·no_reboot_needed9278 ······-·no_reboot_needed
9279 ······-·restrict_strategy9279 ······-·restrict_strategy
  
9280 ····-·name:·Service·facts9280 ····-·name:·Service·facts
9281 ······service_facts:·null9281 ······service_facts:·null
9282 ······when:9282 ······when:
9283 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9284 ······-·'"audit"·in·ansible_facts.packages'9283 ······-·'"audit"·in·ansible_facts.packages'
 9284 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9285 ······tags:9285 ······tags:
9286 ······-·DISA-STIG-OL07-00-0303609286 ······-·DISA-STIG-OL07-00-030360
9287 ······-·NIST-800-53-AC-6(9)9287 ······-·NIST-800-53-AC-6(9)
9288 ······-·NIST-800-53-AU-12(3)9288 ······-·NIST-800-53-AU-12(3)
9289 ······-·NIST-800-53-AU-7(a)9289 ······-·NIST-800-53-AU-7(a)
9290 ······-·NIST-800-53-AU-7(b)9290 ······-·NIST-800-53-AU-7(b)
9291 ······-·NIST-800-53-AU-8(b)9291 ······-·NIST-800-53-AU-8(b)
Offset 9298, 16 lines modifiedOffset 9298, 16 lines modified
9298 ······-·no_reboot_needed9298 ······-·no_reboot_needed
9299 ······-·restrict_strategy9299 ······-·restrict_strategy
  
9300 ····-·name:·Check·the·rules·script·being·used9300 ····-·name:·Check·the·rules·script·being·used
9301 ······command:·grep·'^ExecStartPost'·/usr/lib/systemd/system/auditd.service9301 ······command:·grep·'^ExecStartPost'·/usr/lib/systemd/system/auditd.service
9302 ······register:·check_rules_scripts_result9302 ······register:·check_rules_scripts_result
9303 ······when:9303 ······when:
9304 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9305 ······-·'"audit"·in·ansible_facts.packages'9304 ······-·'"audit"·in·ansible_facts.packages'
 9305 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9306 ······tags:9306 ······tags:
9307 ······-·DISA-STIG-OL07-00-0303609307 ······-·DISA-STIG-OL07-00-030360
9308 ······-·NIST-800-53-AC-6(9)9308 ······-·NIST-800-53-AC-6(9)
9309 ······-·NIST-800-53-AU-12(3)9309 ······-·NIST-800-53-AU-12(3)
9310 ······-·NIST-800-53-AU-7(a)9310 ······-·NIST-800-53-AU-7(a)
9311 ······-·NIST-800-53-AU-7(b)9311 ······-·NIST-800-53-AU-7(b)
9312 ······-·NIST-800-53-AU-8(b)9312 ······-·NIST-800-53-AU-8(b)
Offset 9323, 16 lines modifiedOffset 9323, 16 lines modified
9323 ······set_fact:9323 ······set_fact:
9324 ········suid_audit_rules:9324 ········suid_audit_rules:
9325 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid9325 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid
9326 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid9326 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid
9327 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid9327 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid
9328 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid9328 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid
9329 ······when:9329 ······when:
9330 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9331 ······-·'"audit"·in·ansible_facts.packages'9330 ······-·'"audit"·in·ansible_facts.packages'
 9331 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9332 ······tags:9332 ······tags:
9333 ······-·DISA-STIG-OL07-00-0303609333 ······-·DISA-STIG-OL07-00-030360
9334 ······-·NIST-800-53-AC-6(9)9334 ······-·NIST-800-53-AC-6(9)
9335 ······-·NIST-800-53-AU-12(3)9335 ······-·NIST-800-53-AU-12(3)
9336 ······-·NIST-800-53-AU-7(a)9336 ······-·NIST-800-53-AU-7(a)
9337 ······-·NIST-800-53-AU-7(b)9337 ······-·NIST-800-53-AU-7(b)
9338 ······-·NIST-800-53-AU-8(b)9338 ······-·NIST-800-53-AU-8(b)
Offset 9346, 16 lines modifiedOffset 9346, 16 lines modified
  
9346 ····-·name:·Update·/etc/audit/rules.d/privileged.rules·to·audit·privileged·functions9346 ····-·name:·Update·/etc/audit/rules.d/privileged.rules·to·audit·privileged·functions
9347 ······lineinfile:9347 ······lineinfile:
9348 ········path:·/etc/audit/rules.d/privileged.rules9348 ········path:·/etc/audit/rules.d/privileged.rules
9349 ········line:·'{{··item··}}'9349 ········line:·'{{··item··}}'
9350 ········create:·true9350 ········create:·true
9351 ······when:9351 ······when:
9352 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9353 ······-·'"audit"·in·ansible_facts.packages'9352 ······-·'"audit"·in·ansible_facts.packages'
 9353 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9354 ······-·'"auditd.service"·in·ansible_facts.services'9354 ······-·'"auditd.service"·in·ansible_facts.services'
9355 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'9355 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
9356 ······register:·augenrules_audit_rules_privilege_function_update_result9356 ······register:·augenrules_audit_rules_privilege_function_update_result
9357 ······with_items:·'{{·suid_audit_rules·}}'9357 ······with_items:·'{{·suid_audit_rules·}}'
9358 ······tags:9358 ······tags:
9359 ······-·DISA-STIG-OL07-00-0303609359 ······-·DISA-STIG-OL07-00-030360
9360 ······-·NIST-800-53-AC-6(9)9360 ······-·NIST-800-53-AC-6(9)
Offset 9373, 16 lines modifiedOffset 9373, 16 lines modified
  
Max diff block lines reached; 149636/154805 bytes (96.66%) of diff not shown.
858 B
./usr/share/scap-security-guide/ansible/ol8-playbook-anssi_bp28_enhanced.yml
Ordering differences only
    
Offset 5459, 16 lines modifiedOffset 5459, 16 lines modified
5459 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5459 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5460 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5460 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5461 ··········create:·true5461 ··········create:·true
5462 ··········mode:·o-rwx5462 ··········mode:·o-rwx
5463 ··········state:·present5463 ··········state:·present
5464 ········when:·syscalls_found·|·length·==·05464 ········when:·syscalls_found·|·length·==·0
5465 ······when:5465 ······when:
5466 ······-·'"audit"·in·ansible_facts.packages' 
5467 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5466 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5467 ······-·'"audit"·in·ansible_facts.packages'
5468 ······tags:5468 ······tags:
5469 ······-·DISA-STIG-OL08-00-0305505469 ······-·DISA-STIG-OL08-00-030550
5470 ······-·NIST-800-171-3.1.75470 ······-·NIST-800-171-3.1.7
5471 ······-·NIST-800-53-AC-6(9)5471 ······-·NIST-800-53-AC-6(9)
5472 ······-·NIST-800-53-AU-12(c)5472 ······-·NIST-800-53-AU-12(c)
5473 ······-·NIST-800-53-AU-2(d)5473 ······-·NIST-800-53-AU-2(d)
5474 ······-·NIST-800-53-CM-6(a)5474 ······-·NIST-800-53-CM-6(a)
850 B
./usr/share/scap-security-guide/ansible/ol8-playbook-anssi_bp28_high.yml
Ordering differences only
    
Offset 5607, 16 lines modifiedOffset 5607, 16 lines modified
5607 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5607 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5608 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5608 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5609 ··········create:·true5609 ··········create:·true
5610 ··········mode:·o-rwx5610 ··········mode:·o-rwx
5611 ··········state:·present5611 ··········state:·present
5612 ········when:·syscalls_found·|·length·==·05612 ········when:·syscalls_found·|·length·==·0
5613 ······when:5613 ······when:
5614 ······-·'"audit"·in·ansible_facts.packages' 
5615 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5614 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5615 ······-·'"audit"·in·ansible_facts.packages'
5616 ······tags:5616 ······tags:
5617 ······-·DISA-STIG-OL08-00-0305505617 ······-·DISA-STIG-OL08-00-030550
5618 ······-·NIST-800-171-3.1.75618 ······-·NIST-800-171-3.1.7
5619 ······-·NIST-800-53-AC-6(9)5619 ······-·NIST-800-53-AC-6(9)
5620 ······-·NIST-800-53-AU-12(c)5620 ······-·NIST-800-53-AU-12(c)
5621 ······-·NIST-800-53-AU-2(d)5621 ······-·NIST-800-53-AU-2(d)
5622 ······-·NIST-800-53-CM-6(a)5622 ······-·NIST-800-53-CM-6(a)
866 B
./usr/share/scap-security-guide/ansible/ol8-playbook-anssi_bp28_intermediary.yml
Ordering differences only
    
Offset 5184, 16 lines modifiedOffset 5184, 16 lines modified
5184 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5184 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5185 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5185 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5186 ··········create:·true5186 ··········create:·true
5187 ··········mode:·o-rwx5187 ··········mode:·o-rwx
5188 ··········state:·present5188 ··········state:·present
5189 ········when:·syscalls_found·|·length·==·05189 ········when:·syscalls_found·|·length·==·0
5190 ······when:5190 ······when:
5191 ······-·'"audit"·in·ansible_facts.packages' 
5192 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5191 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5192 ······-·'"audit"·in·ansible_facts.packages'
5193 ······tags:5193 ······tags:
5194 ······-·DISA-STIG-OL08-00-0305505194 ······-·DISA-STIG-OL08-00-030550
5195 ······-·NIST-800-171-3.1.75195 ······-·NIST-800-171-3.1.7
5196 ······-·NIST-800-53-AC-6(9)5196 ······-·NIST-800-53-AC-6(9)
5197 ······-·NIST-800-53-AU-12(c)5197 ······-·NIST-800-53-AU-12(c)
5198 ······-·NIST-800-53-AU-2(d)5198 ······-·NIST-800-53-AU-2(d)
5199 ······-·NIST-800-53-CM-6(a)5199 ······-·NIST-800-53-CM-6(a)
99.0 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-cjis.yml
Ordering differences only
    
Offset 2492, 16 lines modifiedOffset 2492, 16 lines modified
  
2492 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension2492 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
2493 ······find:2493 ······find:
2494 ········paths:·/etc/audit/rules.d/2494 ········paths:·/etc/audit/rules.d/
2495 ········patterns:·'*.rules'2495 ········patterns:·'*.rules'
2496 ······register:·find_rules_d2496 ······register:·find_rules_d
2497 ······when:2497 ······when:
2498 ······-·'"audit"·in·ansible_facts.packages' 
2499 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2498 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2499 ······-·'"audit"·in·ansible_facts.packages'
2500 ······tags:2500 ······tags:
2501 ······-·CJIS-5.4.1.12501 ······-·CJIS-5.4.1.1
2502 ······-·DISA-STIG-OL08-00-0301212502 ······-·DISA-STIG-OL08-00-030121
2503 ······-·NIST-800-171-3.3.12503 ······-·NIST-800-171-3.3.1
2504 ······-·NIST-800-171-3.4.32504 ······-·NIST-800-171-3.4.3
2505 ······-·NIST-800-53-AC-6(9)2505 ······-·NIST-800-53-AC-6(9)
2506 ······-·NIST-800-53-CM-6(a)2506 ······-·NIST-800-53-CM-6(a)
Offset 2517, 16 lines modifiedOffset 2517, 16 lines modified
2517 ······lineinfile:2517 ······lineinfile:
2518 ········path:·'{{·item·}}'2518 ········path:·'{{·item·}}'
2519 ········regexp:·^\s*(?:-e)\s+.*$2519 ········regexp:·^\s*(?:-e)\s+.*$
2520 ········state:·absent2520 ········state:·absent
2521 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']2521 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
2522 ········}}'2522 ········}}'
2523 ······when:2523 ······when:
2524 ······-·'"audit"·in·ansible_facts.packages' 
2525 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2524 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2525 ······-·'"audit"·in·ansible_facts.packages'
2526 ······tags:2526 ······tags:
2527 ······-·CJIS-5.4.1.12527 ······-·CJIS-5.4.1.1
2528 ······-·DISA-STIG-OL08-00-0301212528 ······-·DISA-STIG-OL08-00-030121
2529 ······-·NIST-800-171-3.3.12529 ······-·NIST-800-171-3.3.1
2530 ······-·NIST-800-171-3.4.32530 ······-·NIST-800-171-3.4.3
2531 ······-·NIST-800-53-AC-6(9)2531 ······-·NIST-800-53-AC-6(9)
2532 ······-·NIST-800-53-CM-6(a)2532 ······-·NIST-800-53-CM-6(a)
Offset 2544, 16 lines modifiedOffset 2544, 16 lines modified
2544 ········create:·true2544 ········create:·true
2545 ········line:·-e·22545 ········line:·-e·2
2546 ········mode:·o-rwx2546 ········mode:·o-rwx
2547 ······loop:2547 ······loop:
2548 ······-·/etc/audit/audit.rules2548 ······-·/etc/audit/audit.rules
2549 ······-·/etc/audit/rules.d/immutable.rules2549 ······-·/etc/audit/rules.d/immutable.rules
2550 ······when:2550 ······when:
2551 ······-·'"audit"·in·ansible_facts.packages' 
2552 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2551 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2552 ······-·'"audit"·in·ansible_facts.packages'
2553 ······tags:2553 ······tags:
2554 ······-·CJIS-5.4.1.12554 ······-·CJIS-5.4.1.1
2555 ······-·DISA-STIG-OL08-00-0301212555 ······-·DISA-STIG-OL08-00-030121
2556 ······-·NIST-800-171-3.3.12556 ······-·NIST-800-171-3.3.1
2557 ······-·NIST-800-171-3.4.32557 ······-·NIST-800-171-3.4.3
2558 ······-·NIST-800-53-AC-6(9)2558 ······-·NIST-800-53-AC-6(9)
2559 ······-·NIST-800-53-CM-6(a)2559 ······-·NIST-800-53-CM-6(a)
Offset 2586, 16 lines modifiedOffset 2586, 16 lines modified
2586 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/2586 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
2587 ······find:2587 ······find:
2588 ········paths:·/etc/audit/rules.d2588 ········paths:·/etc/audit/rules.d
2589 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+2589 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
2590 ········patterns:·'*.rules'2590 ········patterns:·'*.rules'
2591 ······register:·find_existing_watch_rules_d2591 ······register:·find_existing_watch_rules_d
2592 ······when:2592 ······when:
2593 ······-·'"audit"·in·ansible_facts.packages' 
2594 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2593 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2594 ······-·'"audit"·in·ansible_facts.packages'
2595 ······tags:2595 ······tags:
2596 ······-·CJIS-5.4.1.12596 ······-·CJIS-5.4.1.1
2597 ······-·NIST-800-171-3.1.82597 ······-·NIST-800-171-3.1.8
2598 ······-·NIST-800-53-AU-12(c)2598 ······-·NIST-800-53-AU-12(c)
2599 ······-·NIST-800-53-AU-2(d)2599 ······-·NIST-800-53-AU-2(d)
2600 ······-·NIST-800-53-CM-6(a)2600 ······-·NIST-800-53-CM-6(a)
2601 ······-·PCI-DSS-Req-10.5.52601 ······-·PCI-DSS-Req-10.5.5
Offset 2609, 16 lines modifiedOffset 2609, 16 lines modified
2609 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy2609 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
2610 ······find:2610 ······find:
2611 ········paths:·/etc/audit/rules.d2611 ········paths:·/etc/audit/rules.d
2612 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$2612 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
2613 ········patterns:·'*.rules'2613 ········patterns:·'*.rules'
2614 ······register:·find_watch_key2614 ······register:·find_watch_key
2615 ······when:2615 ······when:
2616 ······-·'"audit"·in·ansible_facts.packages' 
2617 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2616 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2617 ······-·'"audit"·in·ansible_facts.packages'
2618 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched2618 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
2619 ········==·02619 ········==·0
2620 ······tags:2620 ······tags:
2621 ······-·CJIS-5.4.1.12621 ······-·CJIS-5.4.1.1
2622 ······-·NIST-800-171-3.1.82622 ······-·NIST-800-171-3.1.8
2623 ······-·NIST-800-53-AU-12(c)2623 ······-·NIST-800-53-AU-12(c)
2624 ······-·NIST-800-53-AU-2(d)2624 ······-·NIST-800-53-AU-2(d)
Offset 2632, 16 lines modifiedOffset 2632, 16 lines modified
2632 ······-·restrict_strategy2632 ······-·restrict_strategy
  
2633 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule2633 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
2634 ······set_fact:2634 ······set_fact:
2635 ········all_files:2635 ········all_files:
2636 ········-·/etc/audit/rules.d/MAC-policy.rules2636 ········-·/etc/audit/rules.d/MAC-policy.rules
2637 ······when:2637 ······when:
2638 ······-·'"audit"·in·ansible_facts.packages' 
2639 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2638 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2639 ······-·'"audit"·in·ansible_facts.packages'
2640 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched2640 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
2641 ········is·defined·and·find_existing_watch_rules_d.matched·==·02641 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
2642 ······tags:2642 ······tags:
2643 ······-·CJIS-5.4.1.12643 ······-·CJIS-5.4.1.1
2644 ······-·NIST-800-171-3.1.82644 ······-·NIST-800-171-3.1.8
2645 ······-·NIST-800-53-AU-12(c)2645 ······-·NIST-800-53-AU-12(c)
2646 ······-·NIST-800-53-AU-2(d)2646 ······-·NIST-800-53-AU-2(d)
Offset 2655, 16 lines modifiedOffset 2655, 16 lines modified
2655 ······-·restrict_strategy2655 ······-·restrict_strategy
  
2656 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule2656 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
2657 ······set_fact:2657 ······set_fact:
2658 ········all_files:2658 ········all_files:
2659 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'2659 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
2660 ······when:2660 ······when:
2661 ······-·'"audit"·in·ansible_facts.packages' 
2662 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2661 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 2662 ······-·'"audit"·in·ansible_facts.packages'
2663 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched2663 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
2664 ········is·defined·and·find_existing_watch_rules_d.matched·==·02664 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
2665 ······tags:2665 ······tags:
2666 ······-·CJIS-5.4.1.12666 ······-·CJIS-5.4.1.1
2667 ······-·NIST-800-171-3.1.82667 ······-·NIST-800-171-3.1.8
2668 ······-·NIST-800-53-AU-12(c)2668 ······-·NIST-800-53-AU-12(c)
2669 ······-·NIST-800-53-AU-2(d)2669 ······-·NIST-800-53-AU-2(d)
Offset 2680, 16 lines modifiedOffset 2680, 16 lines modified
2680 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/2680 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 96528/101231 bytes (95.35%) of diff not shown.
3.56 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-cui.yml
Ordering differences only
    
Offset 4761, 16 lines modifiedOffset 4761, 16 lines modified
4761 ······lineinfile:4761 ······lineinfile:
4762 ········dest:·/etc/audit/auditd.conf4762 ········dest:·/etc/audit/auditd.conf
4763 ········regexp:·^\s*flush\s*=\s*.*$4763 ········regexp:·^\s*flush\s*=\s*.*$
4764 ········line:·flush·=·{{·var_auditd_flush·}}4764 ········line:·flush·=·{{·var_auditd_flush·}}
4765 ········state:·present4765 ········state:·present
4766 ········create:·true4766 ········create:·true
4767 ······when:4767 ······when:
4768 ······-·'"audit"·in·ansible_facts.packages' 
4769 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4768 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4769 ······-·'"audit"·in·ansible_facts.packages'
4770 ······tags:4770 ······tags:
4771 ······-·NIST-800-171-3.3.14771 ······-·NIST-800-171-3.3.1
4772 ······-·NIST-800-53-AU-114772 ······-·NIST-800-53-AU-11
4773 ······-·NIST-800-53-CM-6(a)4773 ······-·NIST-800-53-CM-6(a)
4774 ······-·auditd_data_retention_flush4774 ······-·auditd_data_retention_flush
4775 ······-·low_complexity4775 ······-·low_complexity
4776 ······-·low_disruption4776 ······-·low_disruption
Offset 4816, 16 lines modifiedOffset 4816, 16 lines modified
4816 ········lineinfile:4816 ········lineinfile:
4817 ··········path:·/etc/audit/auditd.conf4817 ··········path:·/etc/audit/auditd.conf
4818 ··········create:·true4818 ··········create:·true
4819 ··········regexp:·(?i)^\s*freq\s*=\s*4819 ··········regexp:·(?i)^\s*freq\s*=\s*
4820 ··········line:·freq·=·504820 ··········line:·freq·=·50
4821 ··········state:·present4821 ··········state:·present
4822 ······when:4822 ······when:
4823 ······-·'"audit"·in·ansible_facts.packages' 
4824 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4823 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4824 ······-·'"audit"·in·ansible_facts.packages'
4825 ······tags:4825 ······tags:
4826 ······-·NIST-800-53-CM-64826 ······-·NIST-800-53-CM-6
4827 ······-·auditd_freq4827 ······-·auditd_freq
4828 ······-·low_complexity4828 ······-·low_complexity
4829 ······-·low_disruption4829 ······-·low_disruption
4830 ······-·medium_severity4830 ······-·medium_severity
4831 ······-·no_reboot_needed4831 ······-·no_reboot_needed
Offset 4870, 16 lines modifiedOffset 4870, 16 lines modified
4870 ········lineinfile:4870 ········lineinfile:
4871 ··········path:·/etc/audit/auditd.conf4871 ··········path:·/etc/audit/auditd.conf
4872 ··········create:·true4872 ··········create:·true
4873 ··········regexp:·(?i)^\s*local_events\s*=\s*4873 ··········regexp:·(?i)^\s*local_events\s*=\s*
4874 ··········line:·local_events·=·yes4874 ··········line:·local_events·=·yes
4875 ··········state:·present4875 ··········state:·present
4876 ······when:4876 ······when:
4877 ······-·'"audit"·in·ansible_facts.packages' 
4878 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4877 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4878 ······-·'"audit"·in·ansible_facts.packages'
4879 ······tags:4879 ······tags:
4880 ······-·DISA-STIG-OL08-00-0300614880 ······-·DISA-STIG-OL08-00-030061
4881 ······-·NIST-800-53-CM-64881 ······-·NIST-800-53-CM-6
4882 ······-·auditd_local_events4882 ······-·auditd_local_events
4883 ······-·low_complexity4883 ······-·low_complexity
4884 ······-·low_disruption4884 ······-·low_disruption
4885 ······-·medium_severity4885 ······-·medium_severity
Offset 4926, 16 lines modifiedOffset 4926, 16 lines modified
4926 ········lineinfile:4926 ········lineinfile:
4927 ··········path:·/etc/audit/auditd.conf4927 ··········path:·/etc/audit/auditd.conf
4928 ··········create:·true4928 ··········create:·true
4929 ··········regexp:·(?i)^\s*log_format\s*=\s*4929 ··········regexp:·(?i)^\s*log_format\s*=\s*
4930 ··········line:·log_format·=·ENRICHED4930 ··········line:·log_format·=·ENRICHED
4931 ··········state:·present4931 ··········state:·present
4932 ······when:4932 ······when:
4933 ······-·'"audit"·in·ansible_facts.packages' 
4934 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4933 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4934 ······-·'"audit"·in·ansible_facts.packages'
4935 ······tags:4935 ······tags:
4936 ······-·DISA-STIG-OL08-00-0300634936 ······-·DISA-STIG-OL08-00-030063
4937 ······-·NIST-800-53-AU-34937 ······-·NIST-800-53-AU-3
4938 ······-·NIST-800-53-CM-64938 ······-·NIST-800-53-CM-6
4939 ······-·auditd_log_format4939 ······-·auditd_log_format
4940 ······-·low_complexity4940 ······-·low_complexity
4941 ······-·low_disruption4941 ······-·low_disruption
Offset 4983, 16 lines modifiedOffset 4983, 16 lines modified
4983 ········lineinfile:4983 ········lineinfile:
4984 ··········path:·/etc/audit/auditd.conf4984 ··········path:·/etc/audit/auditd.conf
4985 ··········create:·true4985 ··········create:·true
4986 ··········regexp:·(?i)^\s*name_format\s*=\s*4986 ··········regexp:·(?i)^\s*name_format\s*=\s*
4987 ··········line:·name_format·=·hostname4987 ··········line:·name_format·=·hostname
4988 ··········state:·present4988 ··········state:·present
4989 ······when:4989 ······when:
4990 ······-·'"audit"·in·ansible_facts.packages' 
4991 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4990 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4991 ······-·'"audit"·in·ansible_facts.packages'
4992 ······tags:4992 ······tags:
4993 ······-·DISA-STIG-OL08-00-0300624993 ······-·DISA-STIG-OL08-00-030062
4994 ······-·NIST-800-53-AU-34994 ······-·NIST-800-53-AU-3
4995 ······-·NIST-800-53-CM-64995 ······-·NIST-800-53-CM-6
4996 ······-·auditd_name_format4996 ······-·auditd_name_format
4997 ······-·low_complexity4997 ······-·low_complexity
4998 ······-·low_disruption4998 ······-·low_disruption
Offset 5038, 16 lines modifiedOffset 5038, 16 lines modified
5038 ········lineinfile:5038 ········lineinfile:
5039 ··········path:·/etc/audit/auditd.conf5039 ··········path:·/etc/audit/auditd.conf
5040 ··········create:·true5040 ··········create:·true
5041 ··········regexp:·(?i)^\s*write_logs\s*=\s*5041 ··········regexp:·(?i)^\s*write_logs\s*=\s*
5042 ··········line:·write_logs·=·yes5042 ··········line:·write_logs·=·yes
5043 ··········state:·present5043 ··········state:·present
5044 ······when:5044 ······when:
5045 ······-·'"audit"·in·ansible_facts.packages' 
5046 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5045 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5046 ······-·'"audit"·in·ansible_facts.packages'
5047 ······tags:5047 ······tags:
5048 ······-·NIST-800-53-CM-65048 ······-·NIST-800-53-CM-6
5049 ······-·auditd_write_logs5049 ······-·auditd_write_logs
5050 ······-·low_complexity5050 ······-·low_complexity
5051 ······-·low_disruption5051 ······-·low_disruption
5052 ······-·medium_severity5052 ······-·medium_severity
5053 ······-·no_reboot_needed5053 ······-·no_reboot_needed
69.7 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-e8.yml
Ordering differences only
    
Offset 980, 16 lines modifiedOffset 980, 16 lines modified
980 ······-·no_reboot_needed980 ······-·no_reboot_needed
981 ······-·restrict_strategy981 ······-·restrict_strategy
  
982 ····-·name:·Set·architecture·for·audit·tasks982 ····-·name:·Set·architecture·for·audit·tasks
983 ······set_fact:983 ······set_fact:
984 ········audit_arch:·b64984 ········audit_arch:·b64
985 ······when:985 ······when:
986 ······-·'"audit"·in·ansible_facts.packages' 
987 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]986 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 987 ······-·'"audit"·in·ansible_facts.packages'
988 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture988 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
989 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"989 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
990 ······tags:990 ······tags:
991 ······-·CJIS-5.4.1.1991 ······-·CJIS-5.4.1.1
992 ······-·NIST-800-171-3.1.7992 ······-·NIST-800-171-3.1.7
993 ······-·NIST-800-53-AC-6(9)993 ······-·NIST-800-53-AC-6(9)
994 ······-·NIST-800-53-AU-12(c)994 ······-·NIST-800-53-AU-12(c)
Offset 1122, 16 lines modifiedOffset 1122, 16 lines modified
1122 ··········path:·'{{·audit_file·}}'1122 ··········path:·'{{·audit_file·}}'
1123 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1123 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1124 ··········create:·true1124 ··········create:·true
1125 ··········mode:·o-rwx1125 ··········mode:·o-rwx
1126 ··········state:·present1126 ··········state:·present
1127 ········when:·syscalls_found·|·length·==·01127 ········when:·syscalls_found·|·length·==·0
1128 ······when:1128 ······when:
1129 ······-·'"audit"·in·ansible_facts.packages' 
1130 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1129 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1130 ······-·'"audit"·in·ansible_facts.packages'
1131 ······tags:1131 ······tags:
1132 ······-·CJIS-5.4.1.11132 ······-·CJIS-5.4.1.1
1133 ······-·NIST-800-171-3.1.71133 ······-·NIST-800-171-3.1.7
1134 ······-·NIST-800-53-AC-6(9)1134 ······-·NIST-800-53-AC-6(9)
1135 ······-·NIST-800-53-AU-12(c)1135 ······-·NIST-800-53-AU-12(c)
1136 ······-·NIST-800-53-AU-2(d)1136 ······-·NIST-800-53-AU-2(d)
1137 ······-·NIST-800-53-CM-6(a)1137 ······-·NIST-800-53-CM-6(a)
Offset 1262, 16 lines modifiedOffset 1262, 16 lines modified
1262 ··········path:·'{{·audit_file·}}'1262 ··········path:·'{{·audit_file·}}'
1263 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1263 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1264 ··········create:·true1264 ··········create:·true
1265 ··········mode:·o-rwx1265 ··········mode:·o-rwx
1266 ··········state:·present1266 ··········state:·present
1267 ········when:·syscalls_found·|·length·==·01267 ········when:·syscalls_found·|·length·==·0
1268 ······when:1268 ······when:
1269 ······-·'"audit"·in·ansible_facts.packages' 
1270 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1269 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1270 ······-·'"audit"·in·ansible_facts.packages'
1271 ······-·audit_arch·==·"b64"1271 ······-·audit_arch·==·"b64"
1272 ······tags:1272 ······tags:
1273 ······-·CJIS-5.4.1.11273 ······-·CJIS-5.4.1.1
1274 ······-·NIST-800-171-3.1.71274 ······-·NIST-800-171-3.1.7
1275 ······-·NIST-800-53-AC-6(9)1275 ······-·NIST-800-53-AC-6(9)
1276 ······-·NIST-800-53-AU-12(c)1276 ······-·NIST-800-53-AU-12(c)
1277 ······-·NIST-800-53-AU-2(d)1277 ······-·NIST-800-53-AU-2(d)
Offset 1287, 16 lines modifiedOffset 1287, 16 lines modified
1287 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/1287 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
1288 ······find:1288 ······find:
1289 ········paths:·/etc/audit/rules.d1289 ········paths:·/etc/audit/rules.d
1290 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+1290 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
1291 ········patterns:·'*.rules'1291 ········patterns:·'*.rules'
1292 ······register:·find_existing_watch_rules_d1292 ······register:·find_existing_watch_rules_d
1293 ······when:1293 ······when:
1294 ······-·'"audit"·in·ansible_facts.packages' 
1295 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1294 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1295 ······-·'"audit"·in·ansible_facts.packages'
1296 ······tags:1296 ······tags:
1297 ······-·CJIS-5.4.1.11297 ······-·CJIS-5.4.1.1
1298 ······-·NIST-800-171-3.1.71298 ······-·NIST-800-171-3.1.7
1299 ······-·NIST-800-53-AC-6(9)1299 ······-·NIST-800-53-AC-6(9)
1300 ······-·NIST-800-53-AU-12(c)1300 ······-·NIST-800-53-AU-12(c)
1301 ······-·NIST-800-53-AU-2(d)1301 ······-·NIST-800-53-AU-2(d)
1302 ······-·NIST-800-53-CM-6(a)1302 ······-·NIST-800-53-CM-6(a)
Offset 1311, 16 lines modifiedOffset 1311, 16 lines modified
1311 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification1311 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
1312 ······find:1312 ······find:
1313 ········paths:·/etc/audit/rules.d1313 ········paths:·/etc/audit/rules.d
1314 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$1314 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
1315 ········patterns:·'*.rules'1315 ········patterns:·'*.rules'
1316 ······register:·find_watch_key1316 ······register:·find_watch_key
1317 ······when:1317 ······when:
1318 ······-·'"audit"·in·ansible_facts.packages' 
1319 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1318 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1319 ······-·'"audit"·in·ansible_facts.packages'
1320 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1320 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1321 ········==·01321 ········==·0
1322 ······tags:1322 ······tags:
1323 ······-·CJIS-5.4.1.11323 ······-·CJIS-5.4.1.1
1324 ······-·NIST-800-171-3.1.71324 ······-·NIST-800-171-3.1.7
1325 ······-·NIST-800-53-AC-6(9)1325 ······-·NIST-800-53-AC-6(9)
1326 ······-·NIST-800-53-AU-12(c)1326 ······-·NIST-800-53-AU-12(c)
Offset 1336, 16 lines modifiedOffset 1336, 16 lines modified
  
1336 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the1336 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
1337 ········recipient·for·the·rule1337 ········recipient·for·the·rule
1338 ······set_fact:1338 ······set_fact:
1339 ········all_files:1339 ········all_files:
1340 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules1340 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
1341 ······when:1341 ······when:
1342 ······-·'"audit"·in·ansible_facts.packages' 
1343 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1342 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1343 ······-·'"audit"·in·ansible_facts.packages'
1344 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1344 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1345 ········is·defined·and·find_existing_watch_rules_d.matched·==·01345 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1346 ······tags:1346 ······tags:
1347 ······-·CJIS-5.4.1.11347 ······-·CJIS-5.4.1.1
1348 ······-·NIST-800-171-3.1.71348 ······-·NIST-800-171-3.1.7
1349 ······-·NIST-800-53-AC-6(9)1349 ······-·NIST-800-53-AC-6(9)
1350 ······-·NIST-800-53-AU-12(c)1350 ······-·NIST-800-53-AU-12(c)
Offset 1360, 16 lines modifiedOffset 1360, 16 lines modified
1360 ······-·restrict_strategy1360 ······-·restrict_strategy
  
1361 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1361 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1362 ······set_fact:1362 ······set_fact:
1363 ········all_files:1363 ········all_files:
1364 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1364 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1365 ······when:1365 ······when:
1366 ······-·'"audit"·in·ansible_facts.packages' 
1367 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1366 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1367 ······-·'"audit"·in·ansible_facts.packages'
1368 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1368 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1369 ········is·defined·and·find_existing_watch_rules_d.matched·==·01369 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1370 ······tags:1370 ······tags:
1371 ······-·CJIS-5.4.1.11371 ······-·CJIS-5.4.1.1
1372 ······-·NIST-800-171-3.1.71372 ······-·NIST-800-171-3.1.7
1373 ······-·NIST-800-53-AC-6(9)1373 ······-·NIST-800-53-AC-6(9)
1374 ······-·NIST-800-53-AU-12(c)1374 ······-·NIST-800-53-AU-12(c)
Offset 1386, 16 lines modifiedOffset 1386, 16 lines modified
1386 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/1386 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 66166/71214 bytes (92.91%) of diff not shown.
179 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-hipaa.yml
Ordering differences only
    
Offset 1185, 16 lines modifiedOffset 1185, 16 lines modified
  
1185 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1185 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1186 ······find:1186 ······find:
1187 ········paths:·/etc/audit/rules.d/1187 ········paths:·/etc/audit/rules.d/
1188 ········patterns:·'*.rules'1188 ········patterns:·'*.rules'
1189 ······register:·find_rules_d1189 ······register:·find_rules_d
1190 ······when:1190 ······when:
1191 ······-·'"audit"·in·ansible_facts.packages' 
1192 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1191 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1192 ······-·'"audit"·in·ansible_facts.packages'
1193 ······tags:1193 ······tags:
1194 ······-·CJIS-5.4.1.11194 ······-·CJIS-5.4.1.1
1195 ······-·DISA-STIG-OL08-00-0301211195 ······-·DISA-STIG-OL08-00-030121
1196 ······-·NIST-800-171-3.3.11196 ······-·NIST-800-171-3.3.1
1197 ······-·NIST-800-171-3.4.31197 ······-·NIST-800-171-3.4.3
1198 ······-·NIST-800-53-AC-6(9)1198 ······-·NIST-800-53-AC-6(9)
1199 ······-·NIST-800-53-CM-6(a)1199 ······-·NIST-800-53-CM-6(a)
Offset 1210, 16 lines modifiedOffset 1210, 16 lines modified
1210 ······lineinfile:1210 ······lineinfile:
1211 ········path:·'{{·item·}}'1211 ········path:·'{{·item·}}'
1212 ········regexp:·^\s*(?:-e)\s+.*$1212 ········regexp:·^\s*(?:-e)\s+.*$
1213 ········state:·absent1213 ········state:·absent
1214 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1214 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1215 ········}}'1215 ········}}'
1216 ······when:1216 ······when:
1217 ······-·'"audit"·in·ansible_facts.packages' 
1218 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1217 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1218 ······-·'"audit"·in·ansible_facts.packages'
1219 ······tags:1219 ······tags:
1220 ······-·CJIS-5.4.1.11220 ······-·CJIS-5.4.1.1
1221 ······-·DISA-STIG-OL08-00-0301211221 ······-·DISA-STIG-OL08-00-030121
1222 ······-·NIST-800-171-3.3.11222 ······-·NIST-800-171-3.3.1
1223 ······-·NIST-800-171-3.4.31223 ······-·NIST-800-171-3.4.3
1224 ······-·NIST-800-53-AC-6(9)1224 ······-·NIST-800-53-AC-6(9)
1225 ······-·NIST-800-53-CM-6(a)1225 ······-·NIST-800-53-CM-6(a)
Offset 1237, 16 lines modifiedOffset 1237, 16 lines modified
1237 ········create:·true1237 ········create:·true
1238 ········line:·-e·21238 ········line:·-e·2
1239 ········mode:·o-rwx1239 ········mode:·o-rwx
1240 ······loop:1240 ······loop:
1241 ······-·/etc/audit/audit.rules1241 ······-·/etc/audit/audit.rules
1242 ······-·/etc/audit/rules.d/immutable.rules1242 ······-·/etc/audit/rules.d/immutable.rules
1243 ······when:1243 ······when:
1244 ······-·'"audit"·in·ansible_facts.packages' 
1245 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1244 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1245 ······-·'"audit"·in·ansible_facts.packages'
1246 ······tags:1246 ······tags:
1247 ······-·CJIS-5.4.1.11247 ······-·CJIS-5.4.1.1
1248 ······-·DISA-STIG-OL08-00-0301211248 ······-·DISA-STIG-OL08-00-030121
1249 ······-·NIST-800-171-3.3.11249 ······-·NIST-800-171-3.3.1
1250 ······-·NIST-800-171-3.4.31250 ······-·NIST-800-171-3.4.3
1251 ······-·NIST-800-53-AC-6(9)1251 ······-·NIST-800-53-AC-6(9)
1252 ······-·NIST-800-53-CM-6(a)1252 ······-·NIST-800-53-CM-6(a)
Offset 1279, 16 lines modifiedOffset 1279, 16 lines modified
1279 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1279 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1280 ······find:1280 ······find:
1281 ········paths:·/etc/audit/rules.d1281 ········paths:·/etc/audit/rules.d
1282 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1282 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1283 ········patterns:·'*.rules'1283 ········patterns:·'*.rules'
1284 ······register:·find_existing_watch_rules_d1284 ······register:·find_existing_watch_rules_d
1285 ······when:1285 ······when:
1286 ······-·'"audit"·in·ansible_facts.packages' 
1287 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1286 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1287 ······-·'"audit"·in·ansible_facts.packages'
1288 ······tags:1288 ······tags:
1289 ······-·CJIS-5.4.1.11289 ······-·CJIS-5.4.1.1
1290 ······-·NIST-800-171-3.1.81290 ······-·NIST-800-171-3.1.8
1291 ······-·NIST-800-53-AU-12(c)1291 ······-·NIST-800-53-AU-12(c)
1292 ······-·NIST-800-53-AU-2(d)1292 ······-·NIST-800-53-AU-2(d)
1293 ······-·NIST-800-53-CM-6(a)1293 ······-·NIST-800-53-CM-6(a)
1294 ······-·PCI-DSS-Req-10.5.51294 ······-·PCI-DSS-Req-10.5.5
Offset 1302, 16 lines modifiedOffset 1302, 16 lines modified
1302 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1302 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1303 ······find:1303 ······find:
1304 ········paths:·/etc/audit/rules.d1304 ········paths:·/etc/audit/rules.d
1305 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1305 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1306 ········patterns:·'*.rules'1306 ········patterns:·'*.rules'
1307 ······register:·find_watch_key1307 ······register:·find_watch_key
1308 ······when:1308 ······when:
1309 ······-·'"audit"·in·ansible_facts.packages' 
1310 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1309 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1310 ······-·'"audit"·in·ansible_facts.packages'
1311 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1311 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1312 ········==·01312 ········==·0
1313 ······tags:1313 ······tags:
1314 ······-·CJIS-5.4.1.11314 ······-·CJIS-5.4.1.1
1315 ······-·NIST-800-171-3.1.81315 ······-·NIST-800-171-3.1.8
1316 ······-·NIST-800-53-AU-12(c)1316 ······-·NIST-800-53-AU-12(c)
1317 ······-·NIST-800-53-AU-2(d)1317 ······-·NIST-800-53-AU-2(d)
Offset 1325, 16 lines modifiedOffset 1325, 16 lines modified
1325 ······-·restrict_strategy1325 ······-·restrict_strategy
  
1326 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1326 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1327 ······set_fact:1327 ······set_fact:
1328 ········all_files:1328 ········all_files:
1329 ········-·/etc/audit/rules.d/MAC-policy.rules1329 ········-·/etc/audit/rules.d/MAC-policy.rules
1330 ······when:1330 ······when:
1331 ······-·'"audit"·in·ansible_facts.packages' 
1332 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1331 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1332 ······-·'"audit"·in·ansible_facts.packages'
1333 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1333 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1334 ········is·defined·and·find_existing_watch_rules_d.matched·==·01334 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1335 ······tags:1335 ······tags:
1336 ······-·CJIS-5.4.1.11336 ······-·CJIS-5.4.1.1
1337 ······-·NIST-800-171-3.1.81337 ······-·NIST-800-171-3.1.8
1338 ······-·NIST-800-53-AU-12(c)1338 ······-·NIST-800-53-AU-12(c)
1339 ······-·NIST-800-53-AU-2(d)1339 ······-·NIST-800-53-AU-2(d)
Offset 1348, 16 lines modifiedOffset 1348, 16 lines modified
1348 ······-·restrict_strategy1348 ······-·restrict_strategy
  
1349 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1349 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1350 ······set_fact:1350 ······set_fact:
1351 ········all_files:1351 ········all_files:
1352 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1352 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1353 ······when:1353 ······when:
1354 ······-·'"audit"·in·ansible_facts.packages' 
1355 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1354 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1355 ······-·'"audit"·in·ansible_facts.packages'
1356 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1356 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1357 ········is·defined·and·find_existing_watch_rules_d.matched·==·01357 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1358 ······tags:1358 ······tags:
1359 ······-·CJIS-5.4.1.11359 ······-·CJIS-5.4.1.1
1360 ······-·NIST-800-171-3.1.81360 ······-·NIST-800-171-3.1.8
1361 ······-·NIST-800-53-AU-12(c)1361 ······-·NIST-800-53-AU-12(c)
1362 ······-·NIST-800-53-AU-2(d)1362 ······-·NIST-800-53-AU-2(d)
Offset 1373, 16 lines modifiedOffset 1373, 16 lines modified
1373 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1373 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 178096/182799 bytes (97.43%) of diff not shown.
3.56 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-ospp.yml
Ordering differences only
    
Offset 4754, 16 lines modifiedOffset 4754, 16 lines modified
4754 ······lineinfile:4754 ······lineinfile:
4755 ········dest:·/etc/audit/auditd.conf4755 ········dest:·/etc/audit/auditd.conf
4756 ········regexp:·^\s*flush\s*=\s*.*$4756 ········regexp:·^\s*flush\s*=\s*.*$
4757 ········line:·flush·=·{{·var_auditd_flush·}}4757 ········line:·flush·=·{{·var_auditd_flush·}}
4758 ········state:·present4758 ········state:·present
4759 ········create:·true4759 ········create:·true
4760 ······when:4760 ······when:
4761 ······-·'"audit"·in·ansible_facts.packages' 
4762 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4761 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4762 ······-·'"audit"·in·ansible_facts.packages'
4763 ······tags:4763 ······tags:
4764 ······-·NIST-800-171-3.3.14764 ······-·NIST-800-171-3.3.1
4765 ······-·NIST-800-53-AU-114765 ······-·NIST-800-53-AU-11
4766 ······-·NIST-800-53-CM-6(a)4766 ······-·NIST-800-53-CM-6(a)
4767 ······-·auditd_data_retention_flush4767 ······-·auditd_data_retention_flush
4768 ······-·low_complexity4768 ······-·low_complexity
4769 ······-·low_disruption4769 ······-·low_disruption
Offset 4809, 16 lines modifiedOffset 4809, 16 lines modified
4809 ········lineinfile:4809 ········lineinfile:
4810 ··········path:·/etc/audit/auditd.conf4810 ··········path:·/etc/audit/auditd.conf
4811 ··········create:·true4811 ··········create:·true
4812 ··········regexp:·(?i)^\s*freq\s*=\s*4812 ··········regexp:·(?i)^\s*freq\s*=\s*
4813 ··········line:·freq·=·504813 ··········line:·freq·=·50
4814 ··········state:·present4814 ··········state:·present
4815 ······when:4815 ······when:
4816 ······-·'"audit"·in·ansible_facts.packages' 
4817 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4816 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4817 ······-·'"audit"·in·ansible_facts.packages'
4818 ······tags:4818 ······tags:
4819 ······-·NIST-800-53-CM-64819 ······-·NIST-800-53-CM-6
4820 ······-·auditd_freq4820 ······-·auditd_freq
4821 ······-·low_complexity4821 ······-·low_complexity
4822 ······-·low_disruption4822 ······-·low_disruption
4823 ······-·medium_severity4823 ······-·medium_severity
4824 ······-·no_reboot_needed4824 ······-·no_reboot_needed
Offset 4863, 16 lines modifiedOffset 4863, 16 lines modified
4863 ········lineinfile:4863 ········lineinfile:
4864 ··········path:·/etc/audit/auditd.conf4864 ··········path:·/etc/audit/auditd.conf
4865 ··········create:·true4865 ··········create:·true
4866 ··········regexp:·(?i)^\s*local_events\s*=\s*4866 ··········regexp:·(?i)^\s*local_events\s*=\s*
4867 ··········line:·local_events·=·yes4867 ··········line:·local_events·=·yes
4868 ··········state:·present4868 ··········state:·present
4869 ······when:4869 ······when:
4870 ······-·'"audit"·in·ansible_facts.packages' 
4871 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4870 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4871 ······-·'"audit"·in·ansible_facts.packages'
4872 ······tags:4872 ······tags:
4873 ······-·DISA-STIG-OL08-00-0300614873 ······-·DISA-STIG-OL08-00-030061
4874 ······-·NIST-800-53-CM-64874 ······-·NIST-800-53-CM-6
4875 ······-·auditd_local_events4875 ······-·auditd_local_events
4876 ······-·low_complexity4876 ······-·low_complexity
4877 ······-·low_disruption4877 ······-·low_disruption
4878 ······-·medium_severity4878 ······-·medium_severity
Offset 4919, 16 lines modifiedOffset 4919, 16 lines modified
4919 ········lineinfile:4919 ········lineinfile:
4920 ··········path:·/etc/audit/auditd.conf4920 ··········path:·/etc/audit/auditd.conf
4921 ··········create:·true4921 ··········create:·true
4922 ··········regexp:·(?i)^\s*log_format\s*=\s*4922 ··········regexp:·(?i)^\s*log_format\s*=\s*
4923 ··········line:·log_format·=·ENRICHED4923 ··········line:·log_format·=·ENRICHED
4924 ··········state:·present4924 ··········state:·present
4925 ······when:4925 ······when:
4926 ······-·'"audit"·in·ansible_facts.packages' 
4927 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4926 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4927 ······-·'"audit"·in·ansible_facts.packages'
4928 ······tags:4928 ······tags:
4929 ······-·DISA-STIG-OL08-00-0300634929 ······-·DISA-STIG-OL08-00-030063
4930 ······-·NIST-800-53-AU-34930 ······-·NIST-800-53-AU-3
4931 ······-·NIST-800-53-CM-64931 ······-·NIST-800-53-CM-6
4932 ······-·auditd_log_format4932 ······-·auditd_log_format
4933 ······-·low_complexity4933 ······-·low_complexity
4934 ······-·low_disruption4934 ······-·low_disruption
Offset 4976, 16 lines modifiedOffset 4976, 16 lines modified
4976 ········lineinfile:4976 ········lineinfile:
4977 ··········path:·/etc/audit/auditd.conf4977 ··········path:·/etc/audit/auditd.conf
4978 ··········create:·true4978 ··········create:·true
4979 ··········regexp:·(?i)^\s*name_format\s*=\s*4979 ··········regexp:·(?i)^\s*name_format\s*=\s*
4980 ··········line:·name_format·=·hostname4980 ··········line:·name_format·=·hostname
4981 ··········state:·present4981 ··········state:·present
4982 ······when:4982 ······when:
4983 ······-·'"audit"·in·ansible_facts.packages' 
4984 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4983 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4984 ······-·'"audit"·in·ansible_facts.packages'
4985 ······tags:4985 ······tags:
4986 ······-·DISA-STIG-OL08-00-0300624986 ······-·DISA-STIG-OL08-00-030062
4987 ······-·NIST-800-53-AU-34987 ······-·NIST-800-53-AU-3
4988 ······-·NIST-800-53-CM-64988 ······-·NIST-800-53-CM-6
4989 ······-·auditd_name_format4989 ······-·auditd_name_format
4990 ······-·low_complexity4990 ······-·low_complexity
4991 ······-·low_disruption4991 ······-·low_disruption
Offset 5031, 16 lines modifiedOffset 5031, 16 lines modified
5031 ········lineinfile:5031 ········lineinfile:
5032 ··········path:·/etc/audit/auditd.conf5032 ··········path:·/etc/audit/auditd.conf
5033 ··········create:·true5033 ··········create:·true
5034 ··········regexp:·(?i)^\s*write_logs\s*=\s*5034 ··········regexp:·(?i)^\s*write_logs\s*=\s*
5035 ··········line:·write_logs·=·yes5035 ··········line:·write_logs·=·yes
5036 ··········state:·present5036 ··········state:·present
5037 ······when:5037 ······when:
5038 ······-·'"audit"·in·ansible_facts.packages' 
5039 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5038 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5039 ······-·'"audit"·in·ansible_facts.packages'
5040 ······tags:5040 ······tags:
5041 ······-·NIST-800-53-CM-65041 ······-·NIST-800-53-CM-6
5042 ······-·auditd_write_logs5042 ······-·auditd_write_logs
5043 ······-·low_complexity5043 ······-·low_complexity
5044 ······-·low_disruption5044 ······-·low_disruption
5045 ······-·medium_severity5045 ······-·medium_severity
5046 ······-·no_reboot_needed5046 ······-·no_reboot_needed
157 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-pci-dss.yml
Ordering differences only
    
Offset 4699, 16 lines modifiedOffset 4699, 16 lines modified
  
4699 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension4699 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
4700 ······find:4700 ······find:
4701 ········paths:·/etc/audit/rules.d/4701 ········paths:·/etc/audit/rules.d/
4702 ········patterns:·'*.rules'4702 ········patterns:·'*.rules'
4703 ······register:·find_rules_d4703 ······register:·find_rules_d
4704 ······when:4704 ······when:
4705 ······-·'"audit"·in·ansible_facts.packages' 
4706 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4705 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4706 ······-·'"audit"·in·ansible_facts.packages'
4707 ······tags:4707 ······tags:
4708 ······-·CJIS-5.4.1.14708 ······-·CJIS-5.4.1.1
4709 ······-·DISA-STIG-OL08-00-0301214709 ······-·DISA-STIG-OL08-00-030121
4710 ······-·NIST-800-171-3.3.14710 ······-·NIST-800-171-3.3.1
4711 ······-·NIST-800-171-3.4.34711 ······-·NIST-800-171-3.4.3
4712 ······-·NIST-800-53-AC-6(9)4712 ······-·NIST-800-53-AC-6(9)
4713 ······-·NIST-800-53-CM-6(a)4713 ······-·NIST-800-53-CM-6(a)
Offset 4724, 16 lines modifiedOffset 4724, 16 lines modified
4724 ······lineinfile:4724 ······lineinfile:
4725 ········path:·'{{·item·}}'4725 ········path:·'{{·item·}}'
4726 ········regexp:·^\s*(?:-e)\s+.*$4726 ········regexp:·^\s*(?:-e)\s+.*$
4727 ········state:·absent4727 ········state:·absent
4728 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']4728 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
4729 ········}}'4729 ········}}'
4730 ······when:4730 ······when:
4731 ······-·'"audit"·in·ansible_facts.packages' 
4732 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4731 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4732 ······-·'"audit"·in·ansible_facts.packages'
4733 ······tags:4733 ······tags:
4734 ······-·CJIS-5.4.1.14734 ······-·CJIS-5.4.1.1
4735 ······-·DISA-STIG-OL08-00-0301214735 ······-·DISA-STIG-OL08-00-030121
4736 ······-·NIST-800-171-3.3.14736 ······-·NIST-800-171-3.3.1
4737 ······-·NIST-800-171-3.4.34737 ······-·NIST-800-171-3.4.3
4738 ······-·NIST-800-53-AC-6(9)4738 ······-·NIST-800-53-AC-6(9)
4739 ······-·NIST-800-53-CM-6(a)4739 ······-·NIST-800-53-CM-6(a)
Offset 4751, 16 lines modifiedOffset 4751, 16 lines modified
4751 ········create:·true4751 ········create:·true
4752 ········line:·-e·24752 ········line:·-e·2
4753 ········mode:·o-rwx4753 ········mode:·o-rwx
4754 ······loop:4754 ······loop:
4755 ······-·/etc/audit/audit.rules4755 ······-·/etc/audit/audit.rules
4756 ······-·/etc/audit/rules.d/immutable.rules4756 ······-·/etc/audit/rules.d/immutable.rules
4757 ······when:4757 ······when:
4758 ······-·'"audit"·in·ansible_facts.packages' 
4759 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4758 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4759 ······-·'"audit"·in·ansible_facts.packages'
4760 ······tags:4760 ······tags:
4761 ······-·CJIS-5.4.1.14761 ······-·CJIS-5.4.1.1
4762 ······-·DISA-STIG-OL08-00-0301214762 ······-·DISA-STIG-OL08-00-030121
4763 ······-·NIST-800-171-3.3.14763 ······-·NIST-800-171-3.3.1
4764 ······-·NIST-800-171-3.4.34764 ······-·NIST-800-171-3.4.3
4765 ······-·NIST-800-53-AC-6(9)4765 ······-·NIST-800-53-AC-6(9)
4766 ······-·NIST-800-53-CM-6(a)4766 ······-·NIST-800-53-CM-6(a)
Offset 4793, 16 lines modifiedOffset 4793, 16 lines modified
4793 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/4793 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
4794 ······find:4794 ······find:
4795 ········paths:·/etc/audit/rules.d4795 ········paths:·/etc/audit/rules.d
4796 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+4796 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
4797 ········patterns:·'*.rules'4797 ········patterns:·'*.rules'
4798 ······register:·find_existing_watch_rules_d4798 ······register:·find_existing_watch_rules_d
4799 ······when:4799 ······when:
4800 ······-·'"audit"·in·ansible_facts.packages' 
4801 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4800 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4801 ······-·'"audit"·in·ansible_facts.packages'
4802 ······tags:4802 ······tags:
4803 ······-·CJIS-5.4.1.14803 ······-·CJIS-5.4.1.1
4804 ······-·NIST-800-171-3.1.84804 ······-·NIST-800-171-3.1.8
4805 ······-·NIST-800-53-AU-12(c)4805 ······-·NIST-800-53-AU-12(c)
4806 ······-·NIST-800-53-AU-2(d)4806 ······-·NIST-800-53-AU-2(d)
4807 ······-·NIST-800-53-CM-6(a)4807 ······-·NIST-800-53-CM-6(a)
4808 ······-·PCI-DSS-Req-10.5.54808 ······-·PCI-DSS-Req-10.5.5
Offset 4816, 16 lines modifiedOffset 4816, 16 lines modified
4816 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy4816 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
4817 ······find:4817 ······find:
4818 ········paths:·/etc/audit/rules.d4818 ········paths:·/etc/audit/rules.d
4819 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$4819 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
4820 ········patterns:·'*.rules'4820 ········patterns:·'*.rules'
4821 ······register:·find_watch_key4821 ······register:·find_watch_key
4822 ······when:4822 ······when:
4823 ······-·'"audit"·in·ansible_facts.packages' 
4824 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4823 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4824 ······-·'"audit"·in·ansible_facts.packages'
4825 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4825 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4826 ········==·04826 ········==·0
4827 ······tags:4827 ······tags:
4828 ······-·CJIS-5.4.1.14828 ······-·CJIS-5.4.1.1
4829 ······-·NIST-800-171-3.1.84829 ······-·NIST-800-171-3.1.8
4830 ······-·NIST-800-53-AU-12(c)4830 ······-·NIST-800-53-AU-12(c)
4831 ······-·NIST-800-53-AU-2(d)4831 ······-·NIST-800-53-AU-2(d)
Offset 4839, 16 lines modifiedOffset 4839, 16 lines modified
4839 ······-·restrict_strategy4839 ······-·restrict_strategy
  
4840 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule4840 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
4841 ······set_fact:4841 ······set_fact:
4842 ········all_files:4842 ········all_files:
4843 ········-·/etc/audit/rules.d/MAC-policy.rules4843 ········-·/etc/audit/rules.d/MAC-policy.rules
4844 ······when:4844 ······when:
4845 ······-·'"audit"·in·ansible_facts.packages' 
4846 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4845 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4846 ······-·'"audit"·in·ansible_facts.packages'
4847 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched4847 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
4848 ········is·defined·and·find_existing_watch_rules_d.matched·==·04848 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4849 ······tags:4849 ······tags:
4850 ······-·CJIS-5.4.1.14850 ······-·CJIS-5.4.1.1
4851 ······-·NIST-800-171-3.1.84851 ······-·NIST-800-171-3.1.8
4852 ······-·NIST-800-53-AU-12(c)4852 ······-·NIST-800-53-AU-12(c)
4853 ······-·NIST-800-53-AU-2(d)4853 ······-·NIST-800-53-AU-2(d)
Offset 4862, 16 lines modifiedOffset 4862, 16 lines modified
4862 ······-·restrict_strategy4862 ······-·restrict_strategy
  
4863 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule4863 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
4864 ······set_fact:4864 ······set_fact:
4865 ········all_files:4865 ········all_files:
4866 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'4866 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
4867 ······when:4867 ······when:
4868 ······-·'"audit"·in·ansible_facts.packages' 
4869 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4868 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4869 ······-·'"audit"·in·ansible_facts.packages'
4870 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched4870 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
4871 ········is·defined·and·find_existing_watch_rules_d.matched·==·04871 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4872 ······tags:4872 ······tags:
4873 ······-·CJIS-5.4.1.14873 ······-·CJIS-5.4.1.1
4874 ······-·NIST-800-171-3.1.84874 ······-·NIST-800-171-3.1.8
4875 ······-·NIST-800-53-AU-12(c)4875 ······-·NIST-800-53-AU-12(c)
4876 ······-·NIST-800-53-AU-2(d)4876 ······-·NIST-800-53-AU-2(d)
Offset 4887, 16 lines modifiedOffset 4887, 16 lines modified
4887 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/4887 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 156173/160876 bytes (97.08%) of diff not shown.
91.7 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-standard.yml
Ordering differences only
    
Offset 708, 16 lines modifiedOffset 708, 16 lines modified
708 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/708 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
709 ······find:709 ······find:
710 ········paths:·/etc/audit/rules.d710 ········paths:·/etc/audit/rules.d
711 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+711 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
712 ········patterns:·'*.rules'712 ········patterns:·'*.rules'
713 ······register:·find_existing_watch_rules_d713 ······register:·find_existing_watch_rules_d
714 ······when:714 ······when:
715 ······-·'"audit"·in·ansible_facts.packages' 
716 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]715 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 716 ······-·'"audit"·in·ansible_facts.packages'
717 ······tags:717 ······tags:
718 ······-·CJIS-5.4.1.1718 ······-·CJIS-5.4.1.1
719 ······-·NIST-800-171-3.1.8719 ······-·NIST-800-171-3.1.8
720 ······-·NIST-800-53-AU-12(c)720 ······-·NIST-800-53-AU-12(c)
721 ······-·NIST-800-53-AU-2(d)721 ······-·NIST-800-53-AU-2(d)
722 ······-·NIST-800-53-CM-6(a)722 ······-·NIST-800-53-CM-6(a)
723 ······-·PCI-DSS-Req-10.5.5723 ······-·PCI-DSS-Req-10.5.5
Offset 731, 16 lines modifiedOffset 731, 16 lines modified
731 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy731 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
732 ······find:732 ······find:
733 ········paths:·/etc/audit/rules.d733 ········paths:·/etc/audit/rules.d
734 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$734 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
735 ········patterns:·'*.rules'735 ········patterns:·'*.rules'
736 ······register:·find_watch_key736 ······register:·find_watch_key
737 ······when:737 ······when:
738 ······-·'"audit"·in·ansible_facts.packages' 
739 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]738 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 739 ······-·'"audit"·in·ansible_facts.packages'
740 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched740 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
741 ········==·0741 ········==·0
742 ······tags:742 ······tags:
743 ······-·CJIS-5.4.1.1743 ······-·CJIS-5.4.1.1
744 ······-·NIST-800-171-3.1.8744 ······-·NIST-800-171-3.1.8
745 ······-·NIST-800-53-AU-12(c)745 ······-·NIST-800-53-AU-12(c)
746 ······-·NIST-800-53-AU-2(d)746 ······-·NIST-800-53-AU-2(d)
Offset 754, 16 lines modifiedOffset 754, 16 lines modified
754 ······-·restrict_strategy754 ······-·restrict_strategy
  
755 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule755 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
756 ······set_fact:756 ······set_fact:
757 ········all_files:757 ········all_files:
758 ········-·/etc/audit/rules.d/MAC-policy.rules758 ········-·/etc/audit/rules.d/MAC-policy.rules
759 ······when:759 ······when:
760 ······-·'"audit"·in·ansible_facts.packages' 
761 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]760 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 761 ······-·'"audit"·in·ansible_facts.packages'
762 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched762 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
763 ········is·defined·and·find_existing_watch_rules_d.matched·==·0763 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
764 ······tags:764 ······tags:
765 ······-·CJIS-5.4.1.1765 ······-·CJIS-5.4.1.1
766 ······-·NIST-800-171-3.1.8766 ······-·NIST-800-171-3.1.8
767 ······-·NIST-800-53-AU-12(c)767 ······-·NIST-800-53-AU-12(c)
768 ······-·NIST-800-53-AU-2(d)768 ······-·NIST-800-53-AU-2(d)
Offset 777, 16 lines modifiedOffset 777, 16 lines modified
777 ······-·restrict_strategy777 ······-·restrict_strategy
  
778 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule778 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
779 ······set_fact:779 ······set_fact:
780 ········all_files:780 ········all_files:
781 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'781 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
782 ······when:782 ······when:
783 ······-·'"audit"·in·ansible_facts.packages' 
784 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]783 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 784 ······-·'"audit"·in·ansible_facts.packages'
785 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched785 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
786 ········is·defined·and·find_existing_watch_rules_d.matched·==·0786 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
787 ······tags:787 ······tags:
788 ······-·CJIS-5.4.1.1788 ······-·CJIS-5.4.1.1
789 ······-·NIST-800-171-3.1.8789 ······-·NIST-800-171-3.1.8
790 ······-·NIST-800-53-AU-12(c)790 ······-·NIST-800-53-AU-12(c)
791 ······-·NIST-800-53-AU-2(d)791 ······-·NIST-800-53-AU-2(d)
Offset 802, 16 lines modifiedOffset 802, 16 lines modified
802 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/802 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
803 ······lineinfile:803 ······lineinfile:
804 ········path:·'{{·all_files[0]·}}'804 ········path:·'{{·all_files[0]·}}'
805 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy805 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
806 ········create:·true806 ········create:·true
807 ········mode:·'0640'807 ········mode:·'0640'
808 ······when:808 ······when:
809 ······-·'"audit"·in·ansible_facts.packages' 
810 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]809 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 810 ······-·'"audit"·in·ansible_facts.packages'
811 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched811 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
812 ········==·0812 ········==·0
813 ······tags:813 ······tags:
814 ······-·CJIS-5.4.1.1814 ······-·CJIS-5.4.1.1
815 ······-·NIST-800-171-3.1.8815 ······-·NIST-800-171-3.1.8
816 ······-·NIST-800-53-AU-12(c)816 ······-·NIST-800-53-AU-12(c)
817 ······-·NIST-800-53-AU-2(d)817 ······-·NIST-800-53-AU-2(d)
Offset 827, 16 lines modifiedOffset 827, 16 lines modified
827 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules827 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules
828 ······find:828 ······find:
829 ········paths:·/etc/audit/829 ········paths:·/etc/audit/
830 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+830 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
831 ········patterns:·audit.rules831 ········patterns:·audit.rules
832 ······register:·find_existing_watch_audit_rules832 ······register:·find_existing_watch_audit_rules
833 ······when:833 ······when:
834 ······-·'"audit"·in·ansible_facts.packages' 
835 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]834 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 835 ······-·'"audit"·in·ansible_facts.packages'
836 ······tags:836 ······tags:
837 ······-·CJIS-5.4.1.1837 ······-·CJIS-5.4.1.1
838 ······-·NIST-800-171-3.1.8838 ······-·NIST-800-171-3.1.8
839 ······-·NIST-800-53-AU-12(c)839 ······-·NIST-800-53-AU-12(c)
840 ······-·NIST-800-53-AU-2(d)840 ······-·NIST-800-53-AU-2(d)
841 ······-·NIST-800-53-CM-6(a)841 ······-·NIST-800-53-CM-6(a)
842 ······-·PCI-DSS-Req-10.5.5842 ······-·PCI-DSS-Req-10.5.5
Offset 851, 16 lines modifiedOffset 851, 16 lines modified
851 ······lineinfile:851 ······lineinfile:
852 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy852 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
853 ········state:·present853 ········state:·present
854 ········dest:·/etc/audit/audit.rules854 ········dest:·/etc/audit/audit.rules
855 ········create:·true855 ········create:·true
856 ········mode:·'0640'856 ········mode:·'0640'
857 ······when:857 ······when:
858 ······-·'"audit"·in·ansible_facts.packages' 
859 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]858 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 859 ······-·'"audit"·in·ansible_facts.packages'
860 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched860 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
861 ········==·0861 ········==·0
862 ······tags:862 ······tags:
863 ······-·CJIS-5.4.1.1863 ······-·CJIS-5.4.1.1
864 ······-·NIST-800-171-3.1.8864 ······-·NIST-800-171-3.1.8
865 ······-·NIST-800-53-AU-12(c)865 ······-·NIST-800-53-AU-12(c)
866 ······-·NIST-800-53-AU-2(d)866 ······-·NIST-800-53-AU-2(d)
Offset 893, 16 lines modifiedOffset 893, 16 lines modified
893 ······-·reboot_required893 ······-·reboot_required
Max diff block lines reached; 88925/93791 bytes (94.81%) of diff not shown.
136 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-stig.yml
Ordering differences only
    
Offset 12670, 16 lines modifiedOffset 12670, 16 lines modified
  
12670 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension12670 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
12671 ······find:12671 ······find:
12672 ········paths:·/etc/audit/rules.d/12672 ········paths:·/etc/audit/rules.d/
12673 ········patterns:·'*.rules'12673 ········patterns:·'*.rules'
12674 ······register:·find_rules_d12674 ······register:·find_rules_d
12675 ······when:12675 ······when:
12676 ······-·'"audit"·in·ansible_facts.packages' 
12677 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12676 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12677 ······-·'"audit"·in·ansible_facts.packages'
12678 ······tags:12678 ······tags:
12679 ······-·CJIS-5.4.1.112679 ······-·CJIS-5.4.1.1
12680 ······-·DISA-STIG-OL08-00-03012112680 ······-·DISA-STIG-OL08-00-030121
12681 ······-·NIST-800-171-3.3.112681 ······-·NIST-800-171-3.3.1
12682 ······-·NIST-800-171-3.4.312682 ······-·NIST-800-171-3.4.3
12683 ······-·NIST-800-53-AC-6(9)12683 ······-·NIST-800-53-AC-6(9)
12684 ······-·NIST-800-53-CM-6(a)12684 ······-·NIST-800-53-CM-6(a)
Offset 12695, 16 lines modifiedOffset 12695, 16 lines modified
12695 ······lineinfile:12695 ······lineinfile:
12696 ········path:·'{{·item·}}'12696 ········path:·'{{·item·}}'
12697 ········regexp:·^\s*(?:-e)\s+.*$12697 ········regexp:·^\s*(?:-e)\s+.*$
12698 ········state:·absent12698 ········state:·absent
12699 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']12699 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
12700 ········}}'12700 ········}}'
12701 ······when:12701 ······when:
12702 ······-·'"audit"·in·ansible_facts.packages' 
12703 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12702 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12703 ······-·'"audit"·in·ansible_facts.packages'
12704 ······tags:12704 ······tags:
12705 ······-·CJIS-5.4.1.112705 ······-·CJIS-5.4.1.1
12706 ······-·DISA-STIG-OL08-00-03012112706 ······-·DISA-STIG-OL08-00-030121
12707 ······-·NIST-800-171-3.3.112707 ······-·NIST-800-171-3.3.1
12708 ······-·NIST-800-171-3.4.312708 ······-·NIST-800-171-3.4.3
12709 ······-·NIST-800-53-AC-6(9)12709 ······-·NIST-800-53-AC-6(9)
12710 ······-·NIST-800-53-CM-6(a)12710 ······-·NIST-800-53-CM-6(a)
Offset 12722, 16 lines modifiedOffset 12722, 16 lines modified
12722 ········create:·true12722 ········create:·true
12723 ········line:·-e·212723 ········line:·-e·2
12724 ········mode:·o-rwx12724 ········mode:·o-rwx
12725 ······loop:12725 ······loop:
12726 ······-·/etc/audit/audit.rules12726 ······-·/etc/audit/audit.rules
12727 ······-·/etc/audit/rules.d/immutable.rules12727 ······-·/etc/audit/rules.d/immutable.rules
12728 ······when:12728 ······when:
12729 ······-·'"audit"·in·ansible_facts.packages' 
12730 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12729 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12730 ······-·'"audit"·in·ansible_facts.packages'
12731 ······tags:12731 ······tags:
12732 ······-·CJIS-5.4.1.112732 ······-·CJIS-5.4.1.1
12733 ······-·DISA-STIG-OL08-00-03012112733 ······-·DISA-STIG-OL08-00-030121
12734 ······-·NIST-800-171-3.3.112734 ······-·NIST-800-171-3.3.1
12735 ······-·NIST-800-171-3.4.312735 ······-·NIST-800-171-3.4.3
12736 ······-·NIST-800-53-AC-6(9)12736 ······-·NIST-800-53-AC-6(9)
12737 ······-·NIST-800-53-CM-6(a)12737 ······-·NIST-800-53-CM-6(a)
Offset 12763, 16 lines modifiedOffset 12763, 16 lines modified
12763 ······-·reboot_required12763 ······-·reboot_required
12764 ······-·restrict_strategy12764 ······-·restrict_strategy
  
12765 ····-·name:·Set·architecture·for·audit·mount·tasks12765 ····-·name:·Set·architecture·for·audit·mount·tasks
12766 ······set_fact:12766 ······set_fact:
12767 ········audit_arch:·b6412767 ········audit_arch:·b64
12768 ······when:12768 ······when:
12769 ······-·'"audit"·in·ansible_facts.packages' 
12770 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12769 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12770 ······-·'"audit"·in·ansible_facts.packages'
12771 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture12771 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
12772 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"12772 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
12773 ······tags:12773 ······tags:
12774 ······-·CJIS-5.4.1.112774 ······-·CJIS-5.4.1.1
12775 ······-·DISA-STIG-OL08-00-03030212775 ······-·DISA-STIG-OL08-00-030302
12776 ······-·NIST-800-171-3.1.712776 ······-·NIST-800-171-3.1.7
12777 ······-·NIST-800-53-AC-6(9)12777 ······-·NIST-800-53-AC-6(9)
Offset 12904, 16 lines modifiedOffset 12904, 16 lines modified
12904 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012904 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12905 ············-F·auid!=unset·-F·key=perm_mod12905 ············-F·auid!=unset·-F·key=perm_mod
12906 ··········create:·true12906 ··········create:·true
12907 ··········mode:·o-rwx12907 ··········mode:·o-rwx
12908 ··········state:·present12908 ··········state:·present
12909 ········when:·syscalls_found·|·length·==·012909 ········when:·syscalls_found·|·length·==·0
12910 ······when:12910 ······when:
12911 ······-·'"audit"·in·ansible_facts.packages' 
12912 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12911 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12912 ······-·'"audit"·in·ansible_facts.packages'
12913 ······tags:12913 ······tags:
12914 ······-·CJIS-5.4.1.112914 ······-·CJIS-5.4.1.1
12915 ······-·DISA-STIG-OL08-00-03030212915 ······-·DISA-STIG-OL08-00-030302
12916 ······-·NIST-800-171-3.1.712916 ······-·NIST-800-171-3.1.7
12917 ······-·NIST-800-53-AC-6(9)12917 ······-·NIST-800-53-AC-6(9)
12918 ······-·NIST-800-53-AU-12(c)12918 ······-·NIST-800-53-AU-12(c)
12919 ······-·NIST-800-53-AU-2(d)12919 ······-·NIST-800-53-AU-2(d)
Offset 13043, 16 lines modifiedOffset 13043, 16 lines modified
13043 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100013043 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
13044 ············-F·auid!=unset·-F·key=perm_mod13044 ············-F·auid!=unset·-F·key=perm_mod
13045 ··········create:·true13045 ··········create:·true
13046 ··········mode:·o-rwx13046 ··········mode:·o-rwx
13047 ··········state:·present13047 ··········state:·present
13048 ········when:·syscalls_found·|·length·==·013048 ········when:·syscalls_found·|·length·==·0
13049 ······when:13049 ······when:
13050 ······-·'"audit"·in·ansible_facts.packages' 
13051 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]13050 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 13051 ······-·'"audit"·in·ansible_facts.packages'
13052 ······-·audit_arch·==·"b64"13052 ······-·audit_arch·==·"b64"
13053 ······tags:13053 ······tags:
13054 ······-·CJIS-5.4.1.113054 ······-·CJIS-5.4.1.1
13055 ······-·DISA-STIG-OL08-00-03030213055 ······-·DISA-STIG-OL08-00-030302
13056 ······-·NIST-800-171-3.1.713056 ······-·NIST-800-171-3.1.7
13057 ······-·NIST-800-53-AC-6(9)13057 ······-·NIST-800-53-AC-6(9)
13058 ······-·NIST-800-53-AU-12(c)13058 ······-·NIST-800-53-AU-12(c)
Offset 13082, 16 lines modifiedOffset 13082, 16 lines modified
13082 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/13082 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
13083 ······find:13083 ······find:
13084 ········paths:·/etc/audit/rules.d13084 ········paths:·/etc/audit/rules.d
13085 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+13085 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
13086 ········patterns:·'*.rules'13086 ········patterns:·'*.rules'
13087 ······register:·find_existing_watch_rules_d13087 ······register:·find_existing_watch_rules_d
13088 ······when:13088 ······when:
13089 ······-·'"audit"·in·ansible_facts.packages' 
13090 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]13089 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 13090 ······-·'"audit"·in·ansible_facts.packages'
13091 ······tags:13091 ······tags:
13092 ······-·DISA-STIG-OL08-00-03017113092 ······-·DISA-STIG-OL08-00-030171
13093 ······-·audit_rules_sudoers13093 ······-·audit_rules_sudoers
13094 ······-·low_complexity13094 ······-·low_complexity
13095 ······-·low_disruption13095 ······-·low_disruption
13096 ······-·medium_severity13096 ······-·medium_severity
13097 ······-·no_reboot_needed13097 ······-·no_reboot_needed
Offset 13100, 16 lines modifiedOffset 13100, 16 lines modified
13100 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions13100 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 134587/139161 bytes (96.71%) of diff not shown.
136 KB
./usr/share/scap-security-guide/ansible/ol8-playbook-stig_gui.yml
Ordering differences only
    
Offset 12675, 16 lines modifiedOffset 12675, 16 lines modified
  
12675 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension12675 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
12676 ······find:12676 ······find:
12677 ········paths:·/etc/audit/rules.d/12677 ········paths:·/etc/audit/rules.d/
12678 ········patterns:·'*.rules'12678 ········patterns:·'*.rules'
12679 ······register:·find_rules_d12679 ······register:·find_rules_d
12680 ······when:12680 ······when:
12681 ······-·'"audit"·in·ansible_facts.packages' 
12682 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12681 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12682 ······-·'"audit"·in·ansible_facts.packages'
12683 ······tags:12683 ······tags:
12684 ······-·CJIS-5.4.1.112684 ······-·CJIS-5.4.1.1
12685 ······-·DISA-STIG-OL08-00-03012112685 ······-·DISA-STIG-OL08-00-030121
12686 ······-·NIST-800-171-3.3.112686 ······-·NIST-800-171-3.3.1
12687 ······-·NIST-800-171-3.4.312687 ······-·NIST-800-171-3.4.3
12688 ······-·NIST-800-53-AC-6(9)12688 ······-·NIST-800-53-AC-6(9)
12689 ······-·NIST-800-53-CM-6(a)12689 ······-·NIST-800-53-CM-6(a)
Offset 12700, 16 lines modifiedOffset 12700, 16 lines modified
12700 ······lineinfile:12700 ······lineinfile:
12701 ········path:·'{{·item·}}'12701 ········path:·'{{·item·}}'
12702 ········regexp:·^\s*(?:-e)\s+.*$12702 ········regexp:·^\s*(?:-e)\s+.*$
12703 ········state:·absent12703 ········state:·absent
12704 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']12704 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
12705 ········}}'12705 ········}}'
12706 ······when:12706 ······when:
12707 ······-·'"audit"·in·ansible_facts.packages' 
12708 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12707 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12708 ······-·'"audit"·in·ansible_facts.packages'
12709 ······tags:12709 ······tags:
12710 ······-·CJIS-5.4.1.112710 ······-·CJIS-5.4.1.1
12711 ······-·DISA-STIG-OL08-00-03012112711 ······-·DISA-STIG-OL08-00-030121
12712 ······-·NIST-800-171-3.3.112712 ······-·NIST-800-171-3.3.1
12713 ······-·NIST-800-171-3.4.312713 ······-·NIST-800-171-3.4.3
12714 ······-·NIST-800-53-AC-6(9)12714 ······-·NIST-800-53-AC-6(9)
12715 ······-·NIST-800-53-CM-6(a)12715 ······-·NIST-800-53-CM-6(a)
Offset 12727, 16 lines modifiedOffset 12727, 16 lines modified
12727 ········create:·true12727 ········create:·true
12728 ········line:·-e·212728 ········line:·-e·2
12729 ········mode:·o-rwx12729 ········mode:·o-rwx
12730 ······loop:12730 ······loop:
12731 ······-·/etc/audit/audit.rules12731 ······-·/etc/audit/audit.rules
12732 ······-·/etc/audit/rules.d/immutable.rules12732 ······-·/etc/audit/rules.d/immutable.rules
12733 ······when:12733 ······when:
12734 ······-·'"audit"·in·ansible_facts.packages' 
12735 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12734 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12735 ······-·'"audit"·in·ansible_facts.packages'
12736 ······tags:12736 ······tags:
12737 ······-·CJIS-5.4.1.112737 ······-·CJIS-5.4.1.1
12738 ······-·DISA-STIG-OL08-00-03012112738 ······-·DISA-STIG-OL08-00-030121
12739 ······-·NIST-800-171-3.3.112739 ······-·NIST-800-171-3.3.1
12740 ······-·NIST-800-171-3.4.312740 ······-·NIST-800-171-3.4.3
12741 ······-·NIST-800-53-AC-6(9)12741 ······-·NIST-800-53-AC-6(9)
12742 ······-·NIST-800-53-CM-6(a)12742 ······-·NIST-800-53-CM-6(a)
Offset 12768, 16 lines modifiedOffset 12768, 16 lines modified
12768 ······-·reboot_required12768 ······-·reboot_required
12769 ······-·restrict_strategy12769 ······-·restrict_strategy
  
12770 ····-·name:·Set·architecture·for·audit·mount·tasks12770 ····-·name:·Set·architecture·for·audit·mount·tasks
12771 ······set_fact:12771 ······set_fact:
12772 ········audit_arch:·b6412772 ········audit_arch:·b64
12773 ······when:12773 ······when:
12774 ······-·'"audit"·in·ansible_facts.packages' 
12775 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12774 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12775 ······-·'"audit"·in·ansible_facts.packages'
12776 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture12776 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
12777 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"12777 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
12778 ······tags:12778 ······tags:
12779 ······-·CJIS-5.4.1.112779 ······-·CJIS-5.4.1.1
12780 ······-·DISA-STIG-OL08-00-03030212780 ······-·DISA-STIG-OL08-00-030302
12781 ······-·NIST-800-171-3.1.712781 ······-·NIST-800-171-3.1.7
12782 ······-·NIST-800-53-AC-6(9)12782 ······-·NIST-800-53-AC-6(9)
Offset 12909, 16 lines modifiedOffset 12909, 16 lines modified
12909 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012909 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12910 ············-F·auid!=unset·-F·key=perm_mod12910 ············-F·auid!=unset·-F·key=perm_mod
12911 ··········create:·true12911 ··········create:·true
12912 ··········mode:·o-rwx12912 ··········mode:·o-rwx
12913 ··········state:·present12913 ··········state:·present
12914 ········when:·syscalls_found·|·length·==·012914 ········when:·syscalls_found·|·length·==·0
12915 ······when:12915 ······when:
12916 ······-·'"audit"·in·ansible_facts.packages' 
12917 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12916 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12917 ······-·'"audit"·in·ansible_facts.packages'
12918 ······tags:12918 ······tags:
12919 ······-·CJIS-5.4.1.112919 ······-·CJIS-5.4.1.1
12920 ······-·DISA-STIG-OL08-00-03030212920 ······-·DISA-STIG-OL08-00-030302
12921 ······-·NIST-800-171-3.1.712921 ······-·NIST-800-171-3.1.7
12922 ······-·NIST-800-53-AC-6(9)12922 ······-·NIST-800-53-AC-6(9)
12923 ······-·NIST-800-53-AU-12(c)12923 ······-·NIST-800-53-AU-12(c)
12924 ······-·NIST-800-53-AU-2(d)12924 ······-·NIST-800-53-AU-2(d)
Offset 13048, 16 lines modifiedOffset 13048, 16 lines modified
13048 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100013048 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
13049 ············-F·auid!=unset·-F·key=perm_mod13049 ············-F·auid!=unset·-F·key=perm_mod
13050 ··········create:·true13050 ··········create:·true
13051 ··········mode:·o-rwx13051 ··········mode:·o-rwx
13052 ··········state:·present13052 ··········state:·present
13053 ········when:·syscalls_found·|·length·==·013053 ········when:·syscalls_found·|·length·==·0
13054 ······when:13054 ······when:
13055 ······-·'"audit"·in·ansible_facts.packages' 
13056 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]13055 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 13056 ······-·'"audit"·in·ansible_facts.packages'
13057 ······-·audit_arch·==·"b64"13057 ······-·audit_arch·==·"b64"
13058 ······tags:13058 ······tags:
13059 ······-·CJIS-5.4.1.113059 ······-·CJIS-5.4.1.1
13060 ······-·DISA-STIG-OL08-00-03030213060 ······-·DISA-STIG-OL08-00-030302
13061 ······-·NIST-800-171-3.1.713061 ······-·NIST-800-171-3.1.7
13062 ······-·NIST-800-53-AC-6(9)13062 ······-·NIST-800-53-AC-6(9)
13063 ······-·NIST-800-53-AU-12(c)13063 ······-·NIST-800-53-AU-12(c)
Offset 13087, 16 lines modifiedOffset 13087, 16 lines modified
13087 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/13087 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
13088 ······find:13088 ······find:
13089 ········paths:·/etc/audit/rules.d13089 ········paths:·/etc/audit/rules.d
13090 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+13090 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
13091 ········patterns:·'*.rules'13091 ········patterns:·'*.rules'
13092 ······register:·find_existing_watch_rules_d13092 ······register:·find_existing_watch_rules_d
13093 ······when:13093 ······when:
13094 ······-·'"audit"·in·ansible_facts.packages' 
13095 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]13094 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 13095 ······-·'"audit"·in·ansible_facts.packages'
13096 ······tags:13096 ······tags:
13097 ······-·DISA-STIG-OL08-00-03017113097 ······-·DISA-STIG-OL08-00-030171
13098 ······-·audit_rules_sudoers13098 ······-·audit_rules_sudoers
13099 ······-·low_complexity13099 ······-·low_complexity
13100 ······-·low_disruption13100 ······-·low_disruption
13101 ······-·medium_severity13101 ······-·medium_severity
13102 ······-·no_reboot_needed13102 ······-·no_reboot_needed
Offset 13105, 16 lines modifiedOffset 13105, 16 lines modified
13105 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions13105 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 134587/139161 bytes (96.71%) of diff not shown.
796 B
./usr/share/scap-security-guide/ansible/ol9-playbook-stig.yml
Ordering differences only
    
Offset 32428, 16 lines modifiedOffset 32428, 16 lines modified
32428 ········lineinfile:32428 ········lineinfile:
32429 ··········path:·/etc/postfix/main.cf32429 ··········path:·/etc/postfix/main.cf
32430 ··········create:·true32430 ··········create:·true
32431 ··········regexp:·^[·\t]*smtpd_client_restrictions\s*=\s*32431 ··········regexp:·^[·\t]*smtpd_client_restrictions\s*=\s*
32432 ··········line:·smtpd_client_restrictions·=·permit_mynetworks,reject32432 ··········line:·smtpd_client_restrictions·=·permit_mynetworks,reject
32433 ··········state:·present32433 ··········state:·present
32434 ······when:32434 ······when:
32435 ······-·'"postfix"·in·ansible_facts.packages' 
32436 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]32435 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 32436 ······-·'"postfix"·in·ansible_facts.packages'
32437 ······tags:32437 ······tags:
32438 ······-·low_complexity32438 ······-·low_complexity
32439 ······-·low_disruption32439 ······-·low_disruption
32440 ······-·medium_severity32440 ······-·medium_severity
32441 ······-·no_reboot_needed32441 ······-·no_reboot_needed
32442 ······-·postfix_prevent_unrestricted_relay32442 ······-·postfix_prevent_unrestricted_relay
32443 ······-·restrict_strategy32443 ······-·restrict_strategy
804 B
./usr/share/scap-security-guide/ansible/ol9-playbook-stig_gui.yml
Ordering differences only
    
Offset 32433, 16 lines modifiedOffset 32433, 16 lines modified
32433 ········lineinfile:32433 ········lineinfile:
32434 ··········path:·/etc/postfix/main.cf32434 ··········path:·/etc/postfix/main.cf
32435 ··········create:·true32435 ··········create:·true
32436 ··········regexp:·^[·\t]*smtpd_client_restrictions\s*=\s*32436 ··········regexp:·^[·\t]*smtpd_client_restrictions\s*=\s*
32437 ··········line:·smtpd_client_restrictions·=·permit_mynetworks,reject32437 ··········line:·smtpd_client_restrictions·=·permit_mynetworks,reject
32438 ··········state:·present32438 ··········state:·present
32439 ······when:32439 ······when:
32440 ······-·'"postfix"·in·ansible_facts.packages' 
32441 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]32440 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 32441 ······-·'"postfix"·in·ansible_facts.packages'
32442 ······tags:32442 ······tags:
32443 ······-·low_complexity32443 ······-·low_complexity
32444 ······-·low_disruption32444 ······-·low_disruption
32445 ······-·medium_severity32445 ······-·medium_severity
32446 ······-·no_reboot_needed32446 ······-·no_reboot_needed
32447 ······-·postfix_prevent_unrestricted_relay32447 ······-·postfix_prevent_unrestricted_relay
32448 ······-·restrict_strategy32448 ······-·restrict_strategy
165 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-C2S.yml
Ordering differences only
    
Offset 3817, 16 lines modifiedOffset 3817, 16 lines modified
  
3817 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension3817 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
3818 ······find:3818 ······find:
3819 ········paths:·/etc/audit/rules.d/3819 ········paths:·/etc/audit/rules.d/
3820 ········patterns:·'*.rules'3820 ········patterns:·'*.rules'
3821 ······register:·find_rules_d3821 ······register:·find_rules_d
3822 ······when:3822 ······when:
3823 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3824 ······-·'"audit"·in·ansible_facts.packages'3823 ······-·'"audit"·in·ansible_facts.packages'
 3824 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3825 ······tags:3825 ······tags:
3826 ······-·CCE-27097-53826 ······-·CCE-27097-5
3827 ······-·CJIS-5.4.1.13827 ······-·CJIS-5.4.1.1
3828 ······-·NIST-800-171-3.3.13828 ······-·NIST-800-171-3.3.1
3829 ······-·NIST-800-171-3.4.33829 ······-·NIST-800-171-3.4.3
3830 ······-·NIST-800-53-AC-6(9)3830 ······-·NIST-800-53-AC-6(9)
3831 ······-·NIST-800-53-CM-6(a)3831 ······-·NIST-800-53-CM-6(a)
Offset 3842, 16 lines modifiedOffset 3842, 16 lines modified
3842 ······lineinfile:3842 ······lineinfile:
3843 ········path:·'{{·item·}}'3843 ········path:·'{{·item·}}'
3844 ········regexp:·^\s*(?:-e)\s+.*$3844 ········regexp:·^\s*(?:-e)\s+.*$
3845 ········state:·absent3845 ········state:·absent
3846 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']3846 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
3847 ········}}'3847 ········}}'
3848 ······when:3848 ······when:
3849 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3850 ······-·'"audit"·in·ansible_facts.packages'3849 ······-·'"audit"·in·ansible_facts.packages'
 3850 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3851 ······tags:3851 ······tags:
3852 ······-·CCE-27097-53852 ······-·CCE-27097-5
3853 ······-·CJIS-5.4.1.13853 ······-·CJIS-5.4.1.1
3854 ······-·NIST-800-171-3.3.13854 ······-·NIST-800-171-3.3.1
3855 ······-·NIST-800-171-3.4.33855 ······-·NIST-800-171-3.4.3
3856 ······-·NIST-800-53-AC-6(9)3856 ······-·NIST-800-53-AC-6(9)
3857 ······-·NIST-800-53-CM-6(a)3857 ······-·NIST-800-53-CM-6(a)
Offset 3869, 16 lines modifiedOffset 3869, 16 lines modified
3869 ········create:·true3869 ········create:·true
3870 ········line:·-e·23870 ········line:·-e·2
3871 ········mode:·o-rwx3871 ········mode:·o-rwx
3872 ······loop:3872 ······loop:
3873 ······-·/etc/audit/audit.rules3873 ······-·/etc/audit/audit.rules
3874 ······-·/etc/audit/rules.d/immutable.rules3874 ······-·/etc/audit/rules.d/immutable.rules
3875 ······when:3875 ······when:
3876 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3877 ······-·'"audit"·in·ansible_facts.packages'3876 ······-·'"audit"·in·ansible_facts.packages'
 3877 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3878 ······tags:3878 ······tags:
3879 ······-·CCE-27097-53879 ······-·CCE-27097-5
3880 ······-·CJIS-5.4.1.13880 ······-·CJIS-5.4.1.1
3881 ······-·NIST-800-171-3.3.13881 ······-·NIST-800-171-3.3.1
3882 ······-·NIST-800-171-3.4.33882 ······-·NIST-800-171-3.4.3
3883 ······-·NIST-800-53-AC-6(9)3883 ······-·NIST-800-53-AC-6(9)
3884 ······-·NIST-800-53-CM-6(a)3884 ······-·NIST-800-53-CM-6(a)
Offset 3912, 16 lines modifiedOffset 3912, 16 lines modified
3912 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/3912 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
3913 ······find:3913 ······find:
3914 ········paths:·/etc/audit/rules.d3914 ········paths:·/etc/audit/rules.d
3915 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+3915 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
3916 ········patterns:·'*.rules'3916 ········patterns:·'*.rules'
3917 ······register:·find_existing_watch_rules_d3917 ······register:·find_existing_watch_rules_d
3918 ······when:3918 ······when:
3919 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3920 ······-·'"audit"·in·ansible_facts.packages'3919 ······-·'"audit"·in·ansible_facts.packages'
 3920 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3921 ······tags:3921 ······tags:
3922 ······-·CCE-27168-43922 ······-·CCE-27168-4
3923 ······-·CJIS-5.4.1.13923 ······-·CJIS-5.4.1.1
3924 ······-·NIST-800-171-3.1.83924 ······-·NIST-800-171-3.1.8
3925 ······-·NIST-800-53-AU-12(c)3925 ······-·NIST-800-53-AU-12(c)
3926 ······-·NIST-800-53-AU-2(d)3926 ······-·NIST-800-53-AU-2(d)
3927 ······-·NIST-800-53-CM-6(a)3927 ······-·NIST-800-53-CM-6(a)
Offset 3936, 16 lines modifiedOffset 3936, 16 lines modified
3936 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy3936 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
3937 ······find:3937 ······find:
3938 ········paths:·/etc/audit/rules.d3938 ········paths:·/etc/audit/rules.d
3939 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$3939 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
3940 ········patterns:·'*.rules'3940 ········patterns:·'*.rules'
3941 ······register:·find_watch_key3941 ······register:·find_watch_key
3942 ······when:3942 ······when:
3943 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3944 ······-·'"audit"·in·ansible_facts.packages'3943 ······-·'"audit"·in·ansible_facts.packages'
 3944 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3945 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3945 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3946 ········==·03946 ········==·0
3947 ······tags:3947 ······tags:
3948 ······-·CCE-27168-43948 ······-·CCE-27168-4
3949 ······-·CJIS-5.4.1.13949 ······-·CJIS-5.4.1.1
3950 ······-·NIST-800-171-3.1.83950 ······-·NIST-800-171-3.1.8
3951 ······-·NIST-800-53-AU-12(c)3951 ······-·NIST-800-53-AU-12(c)
Offset 3960, 16 lines modifiedOffset 3960, 16 lines modified
3960 ······-·restrict_strategy3960 ······-·restrict_strategy
  
3961 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule3961 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
3962 ······set_fact:3962 ······set_fact:
3963 ········all_files:3963 ········all_files:
3964 ········-·/etc/audit/rules.d/MAC-policy.rules3964 ········-·/etc/audit/rules.d/MAC-policy.rules
3965 ······when:3965 ······when:
3966 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3967 ······-·'"audit"·in·ansible_facts.packages'3966 ······-·'"audit"·in·ansible_facts.packages'
 3967 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3968 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched3968 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
3969 ········is·defined·and·find_existing_watch_rules_d.matched·==·03969 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3970 ······tags:3970 ······tags:
3971 ······-·CCE-27168-43971 ······-·CCE-27168-4
3972 ······-·CJIS-5.4.1.13972 ······-·CJIS-5.4.1.1
3973 ······-·NIST-800-171-3.1.83973 ······-·NIST-800-171-3.1.8
3974 ······-·NIST-800-53-AU-12(c)3974 ······-·NIST-800-53-AU-12(c)
Offset 3984, 16 lines modifiedOffset 3984, 16 lines modified
3984 ······-·restrict_strategy3984 ······-·restrict_strategy
  
3985 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule3985 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
3986 ······set_fact:3986 ······set_fact:
3987 ········all_files:3987 ········all_files:
3988 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'3988 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
3989 ······when:3989 ······when:
3990 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3991 ······-·'"audit"·in·ansible_facts.packages'3990 ······-·'"audit"·in·ansible_facts.packages'
 3991 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3992 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched3992 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
3993 ········is·defined·and·find_existing_watch_rules_d.matched·==·03993 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3994 ······tags:3994 ······tags:
3995 ······-·CCE-27168-43995 ······-·CCE-27168-4
3996 ······-·CJIS-5.4.1.13996 ······-·CJIS-5.4.1.1
3997 ······-·NIST-800-171-3.1.83997 ······-·NIST-800-171-3.1.8
3998 ······-·NIST-800-53-AU-12(c)3998 ······-·NIST-800-53-AU-12(c)
Offset 4010, 16 lines modifiedOffset 4010, 16 lines modified
4010 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/4010 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 163628/168611 bytes (97.04%) of diff not shown.
904 B
./usr/share/scap-security-guide/ansible/rhel7-playbook-anssi_nt28_enhanced.yml
Ordering differences only
    
Offset 5590, 16 lines modifiedOffset 5590, 16 lines modified
5590 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5590 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5591 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5591 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5592 ··········create:·true5592 ··········create:·true
5593 ··········mode:·o-rwx5593 ··········mode:·o-rwx
5594 ··········state:·present5594 ··········state:·present
5595 ········when:·syscalls_found·|·length·==·05595 ········when:·syscalls_found·|·length·==·0
5596 ······when:5596 ······when:
5597 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5598 ······-·'"audit"·in·ansible_facts.packages'5597 ······-·'"audit"·in·ansible_facts.packages'
 5598 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5599 ······tags:5599 ······tags:
5600 ······-·CCE-80401-35600 ······-·CCE-80401-3
5601 ······-·DISA-STIG-RHEL-07-0306905601 ······-·DISA-STIG-RHEL-07-030690
5602 ······-·NIST-800-171-3.1.75602 ······-·NIST-800-171-3.1.7
5603 ······-·NIST-800-53-AC-6(9)5603 ······-·NIST-800-53-AC-6(9)
5604 ······-·NIST-800-53-AU-12(c)5604 ······-·NIST-800-53-AU-12(c)
5605 ······-·NIST-800-53-AU-2(d)5605 ······-·NIST-800-53-AU-2(d)
896 B
./usr/share/scap-security-guide/ansible/rhel7-playbook-anssi_nt28_high.yml
Ordering differences only
    
Offset 5750, 16 lines modifiedOffset 5750, 16 lines modified
5750 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5750 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5751 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5751 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5752 ··········create:·true5752 ··········create:·true
5753 ··········mode:·o-rwx5753 ··········mode:·o-rwx
5754 ··········state:·present5754 ··········state:·present
5755 ········when:·syscalls_found·|·length·==·05755 ········when:·syscalls_found·|·length·==·0
5756 ······when:5756 ······when:
5757 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5758 ······-·'"audit"·in·ansible_facts.packages'5757 ······-·'"audit"·in·ansible_facts.packages'
 5758 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5759 ······tags:5759 ······tags:
5760 ······-·CCE-80401-35760 ······-·CCE-80401-3
5761 ······-·DISA-STIG-RHEL-07-0306905761 ······-·DISA-STIG-RHEL-07-030690
5762 ······-·NIST-800-171-3.1.75762 ······-·NIST-800-171-3.1.7
5763 ······-·NIST-800-53-AC-6(9)5763 ······-·NIST-800-53-AC-6(9)
5764 ······-·NIST-800-53-AU-12(c)5764 ······-·NIST-800-53-AU-12(c)
5765 ······-·NIST-800-53-AU-2(d)5765 ······-·NIST-800-53-AU-2(d)
912 B
./usr/share/scap-security-guide/ansible/rhel7-playbook-anssi_nt28_intermediary.yml
Ordering differences only
    
Offset 5305, 16 lines modifiedOffset 5305, 16 lines modified
5305 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5305 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5306 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5306 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5307 ··········create:·true5307 ··········create:·true
5308 ··········mode:·o-rwx5308 ··········mode:·o-rwx
5309 ··········state:·present5309 ··········state:·present
5310 ········when:·syscalls_found·|·length·==·05310 ········when:·syscalls_found·|·length·==·0
5311 ······when:5311 ······when:
5312 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
5313 ······-·'"audit"·in·ansible_facts.packages'5312 ······-·'"audit"·in·ansible_facts.packages'
 5313 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5314 ······tags:5314 ······tags:
5315 ······-·CCE-80401-35315 ······-·CCE-80401-3
5316 ······-·DISA-STIG-RHEL-07-0306905316 ······-·DISA-STIG-RHEL-07-030690
5317 ······-·NIST-800-171-3.1.75317 ······-·NIST-800-171-3.1.7
5318 ······-·NIST-800-53-AC-6(9)5318 ······-·NIST-800-53-AC-6(9)
5319 ······-·NIST-800-53-AU-12(c)5319 ······-·NIST-800-53-AU-12(c)
5320 ······-·NIST-800-53-AU-2(d)5320 ······-·NIST-800-53-AU-2(d)
186 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-cis.yml
Ordering differences only
    
Offset 3189, 16 lines modifiedOffset 3189, 16 lines modified
  
3189 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension3189 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
3190 ······find:3190 ······find:
3191 ········paths:·/etc/audit/rules.d/3191 ········paths:·/etc/audit/rules.d/
3192 ········patterns:·'*.rules'3192 ········patterns:·'*.rules'
3193 ······register:·find_rules_d3193 ······register:·find_rules_d
3194 ······when:3194 ······when:
3195 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3196 ······-·'"audit"·in·ansible_facts.packages'3195 ······-·'"audit"·in·ansible_facts.packages'
 3196 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3197 ······tags:3197 ······tags:
3198 ······-·CCE-27097-53198 ······-·CCE-27097-5
3199 ······-·CJIS-5.4.1.13199 ······-·CJIS-5.4.1.1
3200 ······-·NIST-800-171-3.3.13200 ······-·NIST-800-171-3.3.1
3201 ······-·NIST-800-171-3.4.33201 ······-·NIST-800-171-3.4.3
3202 ······-·NIST-800-53-AC-6(9)3202 ······-·NIST-800-53-AC-6(9)
3203 ······-·NIST-800-53-CM-6(a)3203 ······-·NIST-800-53-CM-6(a)
Offset 3214, 16 lines modifiedOffset 3214, 16 lines modified
3214 ······lineinfile:3214 ······lineinfile:
3215 ········path:·'{{·item·}}'3215 ········path:·'{{·item·}}'
3216 ········regexp:·^\s*(?:-e)\s+.*$3216 ········regexp:·^\s*(?:-e)\s+.*$
3217 ········state:·absent3217 ········state:·absent
3218 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']3218 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
3219 ········}}'3219 ········}}'
3220 ······when:3220 ······when:
3221 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3222 ······-·'"audit"·in·ansible_facts.packages'3221 ······-·'"audit"·in·ansible_facts.packages'
 3222 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3223 ······tags:3223 ······tags:
3224 ······-·CCE-27097-53224 ······-·CCE-27097-5
3225 ······-·CJIS-5.4.1.13225 ······-·CJIS-5.4.1.1
3226 ······-·NIST-800-171-3.3.13226 ······-·NIST-800-171-3.3.1
3227 ······-·NIST-800-171-3.4.33227 ······-·NIST-800-171-3.4.3
3228 ······-·NIST-800-53-AC-6(9)3228 ······-·NIST-800-53-AC-6(9)
3229 ······-·NIST-800-53-CM-6(a)3229 ······-·NIST-800-53-CM-6(a)
Offset 3241, 16 lines modifiedOffset 3241, 16 lines modified
3241 ········create:·true3241 ········create:·true
3242 ········line:·-e·23242 ········line:·-e·2
3243 ········mode:·o-rwx3243 ········mode:·o-rwx
3244 ······loop:3244 ······loop:
3245 ······-·/etc/audit/audit.rules3245 ······-·/etc/audit/audit.rules
3246 ······-·/etc/audit/rules.d/immutable.rules3246 ······-·/etc/audit/rules.d/immutable.rules
3247 ······when:3247 ······when:
3248 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3249 ······-·'"audit"·in·ansible_facts.packages'3248 ······-·'"audit"·in·ansible_facts.packages'
 3249 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3250 ······tags:3250 ······tags:
3251 ······-·CCE-27097-53251 ······-·CCE-27097-5
3252 ······-·CJIS-5.4.1.13252 ······-·CJIS-5.4.1.1
3253 ······-·NIST-800-171-3.3.13253 ······-·NIST-800-171-3.3.1
3254 ······-·NIST-800-171-3.4.33254 ······-·NIST-800-171-3.4.3
3255 ······-·NIST-800-53-AC-6(9)3255 ······-·NIST-800-53-AC-6(9)
3256 ······-·NIST-800-53-CM-6(a)3256 ······-·NIST-800-53-CM-6(a)
Offset 3284, 16 lines modifiedOffset 3284, 16 lines modified
3284 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/3284 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
3285 ······find:3285 ······find:
3286 ········paths:·/etc/audit/rules.d3286 ········paths:·/etc/audit/rules.d
3287 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+3287 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
3288 ········patterns:·'*.rules'3288 ········patterns:·'*.rules'
3289 ······register:·find_existing_watch_rules_d3289 ······register:·find_existing_watch_rules_d
3290 ······when:3290 ······when:
3291 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3292 ······-·'"audit"·in·ansible_facts.packages'3291 ······-·'"audit"·in·ansible_facts.packages'
 3292 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3293 ······tags:3293 ······tags:
3294 ······-·CCE-27168-43294 ······-·CCE-27168-4
3295 ······-·CJIS-5.4.1.13295 ······-·CJIS-5.4.1.1
3296 ······-·NIST-800-171-3.1.83296 ······-·NIST-800-171-3.1.8
3297 ······-·NIST-800-53-AU-12(c)3297 ······-·NIST-800-53-AU-12(c)
3298 ······-·NIST-800-53-AU-2(d)3298 ······-·NIST-800-53-AU-2(d)
3299 ······-·NIST-800-53-CM-6(a)3299 ······-·NIST-800-53-CM-6(a)
Offset 3308, 16 lines modifiedOffset 3308, 16 lines modified
3308 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy3308 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
3309 ······find:3309 ······find:
3310 ········paths:·/etc/audit/rules.d3310 ········paths:·/etc/audit/rules.d
3311 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$3311 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
3312 ········patterns:·'*.rules'3312 ········patterns:·'*.rules'
3313 ······register:·find_watch_key3313 ······register:·find_watch_key
3314 ······when:3314 ······when:
3315 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3316 ······-·'"audit"·in·ansible_facts.packages'3315 ······-·'"audit"·in·ansible_facts.packages'
 3316 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3317 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3317 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3318 ········==·03318 ········==·0
3319 ······tags:3319 ······tags:
3320 ······-·CCE-27168-43320 ······-·CCE-27168-4
3321 ······-·CJIS-5.4.1.13321 ······-·CJIS-5.4.1.1
3322 ······-·NIST-800-171-3.1.83322 ······-·NIST-800-171-3.1.8
3323 ······-·NIST-800-53-AU-12(c)3323 ······-·NIST-800-53-AU-12(c)
Offset 3332, 16 lines modifiedOffset 3332, 16 lines modified
3332 ······-·restrict_strategy3332 ······-·restrict_strategy
  
3333 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule3333 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
3334 ······set_fact:3334 ······set_fact:
3335 ········all_files:3335 ········all_files:
3336 ········-·/etc/audit/rules.d/MAC-policy.rules3336 ········-·/etc/audit/rules.d/MAC-policy.rules
3337 ······when:3337 ······when:
3338 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3339 ······-·'"audit"·in·ansible_facts.packages'3338 ······-·'"audit"·in·ansible_facts.packages'
 3339 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3340 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched3340 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
3341 ········is·defined·and·find_existing_watch_rules_d.matched·==·03341 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3342 ······tags:3342 ······tags:
3343 ······-·CCE-27168-43343 ······-·CCE-27168-4
3344 ······-·CJIS-5.4.1.13344 ······-·CJIS-5.4.1.1
3345 ······-·NIST-800-171-3.1.83345 ······-·NIST-800-171-3.1.8
3346 ······-·NIST-800-53-AU-12(c)3346 ······-·NIST-800-53-AU-12(c)
Offset 3356, 16 lines modifiedOffset 3356, 16 lines modified
3356 ······-·restrict_strategy3356 ······-·restrict_strategy
  
3357 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule3357 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
3358 ······set_fact:3358 ······set_fact:
3359 ········all_files:3359 ········all_files:
3360 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'3360 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
3361 ······when:3361 ······when:
3362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3363 ······-·'"audit"·in·ansible_facts.packages'3362 ······-·'"audit"·in·ansible_facts.packages'
 3363 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3364 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched3364 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
3365 ········is·defined·and·find_existing_watch_rules_d.matched·==·03365 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3366 ······tags:3366 ······tags:
3367 ······-·CCE-27168-43367 ······-·CCE-27168-4
3368 ······-·CJIS-5.4.1.13368 ······-·CJIS-5.4.1.1
3369 ······-·NIST-800-171-3.1.83369 ······-·NIST-800-171-3.1.8
3370 ······-·NIST-800-53-AU-12(c)3370 ······-·NIST-800-53-AU-12(c)
Offset 3382, 16 lines modifiedOffset 3382, 16 lines modified
3382 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/3382 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 185275/190258 bytes (97.38%) of diff not shown.
7.91 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-cis_server_l1.yml
Ordering differences only
    
Offset 2886, 16 lines modifiedOffset 2886, 16 lines modified
2886 ······-·no_reboot_needed2886 ······-·no_reboot_needed
  
2887 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg2887 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
2888 ······stat:2888 ······stat:
2889 ········path:·/boot/grub2/grub.cfg2889 ········path:·/boot/grub2/grub.cfg
2890 ······register:·file_exists2890 ······register:·file_exists
2891 ······when:2891 ······when:
2892 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2893 ······-·'"grub2-common"·in·ansible_facts.packages'2892 ······-·'"grub2-common"·in·ansible_facts.packages'
 2893 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2894 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2894 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2895 ······tags:2895 ······tags:
2896 ······-·CCE-82023-32896 ······-·CCE-82023-3
2897 ······-·CJIS-5.5.2.22897 ······-·CJIS-5.5.2.2
2898 ······-·NIST-800-171-3.4.52898 ······-·NIST-800-171-3.4.5
2899 ······-·NIST-800-53-AC-6(1)2899 ······-·NIST-800-53-AC-6(1)
2900 ······-·NIST-800-53-CM-6(a)2900 ······-·NIST-800-53-CM-6(a)
Offset 2908, 16 lines modifiedOffset 2908, 16 lines modified
2908 ······-·no_reboot_needed2908 ······-·no_reboot_needed
  
2909 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg2909 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
2910 ······file:2910 ······file:
2911 ········path:·/boot/grub2/grub.cfg2911 ········path:·/boot/grub2/grub.cfg
2912 ········group:·'0'2912 ········group:·'0'
2913 ······when:2913 ······when:
2914 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2915 ······-·'"grub2-common"·in·ansible_facts.packages'2914 ······-·'"grub2-common"·in·ansible_facts.packages'
 2915 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2916 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2916 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2917 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists2917 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
2918 ······tags:2918 ······tags:
2919 ······-·CCE-82023-32919 ······-·CCE-82023-3
2920 ······-·CJIS-5.5.2.22920 ······-·CJIS-5.5.2.2
2921 ······-·NIST-800-171-3.4.52921 ······-·NIST-800-171-3.4.5
2922 ······-·NIST-800-53-AC-6(1)2922 ······-·NIST-800-53-AC-6(1)
Offset 2949, 16 lines modifiedOffset 2949, 16 lines modified
2949 ······-·no_reboot_needed2949 ······-·no_reboot_needed
  
2950 ····-·name:·Test·for·existence·/boot/grub2/user.cfg2950 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
2951 ······stat:2951 ······stat:
2952 ········path:·/boot/grub2/user.cfg2952 ········path:·/boot/grub2/user.cfg
2953 ······register:·file_exists2953 ······register:·file_exists
2954 ······when:2954 ······when:
2955 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2956 ······-·'"grub2-common"·in·ansible_facts.packages'2955 ······-·'"grub2-common"·in·ansible_facts.packages'
 2956 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2957 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2957 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2958 ······tags:2958 ······tags:
2959 ······-·CCE-86008-02959 ······-·CCE-86008-0
2960 ······-·CJIS-5.5.2.22960 ······-·CJIS-5.5.2.2
2961 ······-·NIST-800-171-3.4.52961 ······-·NIST-800-171-3.4.5
2962 ······-·NIST-800-53-AC-6(1)2962 ······-·NIST-800-53-AC-6(1)
2963 ······-·NIST-800-53-CM-6(a)2963 ······-·NIST-800-53-CM-6(a)
Offset 2971, 16 lines modifiedOffset 2971, 16 lines modified
2971 ······-·no_reboot_needed2971 ······-·no_reboot_needed
  
2972 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg2972 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
2973 ······file:2973 ······file:
2974 ········path:·/boot/grub2/user.cfg2974 ········path:·/boot/grub2/user.cfg
2975 ········group:·'0'2975 ········group:·'0'
2976 ······when:2976 ······when:
2977 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2978 ······-·'"grub2-common"·in·ansible_facts.packages'2977 ······-·'"grub2-common"·in·ansible_facts.packages'
 2978 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2979 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2979 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2980 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists2980 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
2981 ······tags:2981 ······tags:
2982 ······-·CCE-86008-02982 ······-·CCE-86008-0
2983 ······-·CJIS-5.5.2.22983 ······-·CJIS-5.5.2.2
2984 ······-·NIST-800-171-3.4.52984 ······-·NIST-800-171-3.4.5
2985 ······-·NIST-800-53-AC-6(1)2985 ······-·NIST-800-53-AC-6(1)
Offset 3012, 16 lines modifiedOffset 3012, 16 lines modified
3012 ······-·no_reboot_needed3012 ······-·no_reboot_needed
  
3013 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg3013 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
3014 ······stat:3014 ······stat:
3015 ········path:·/boot/grub2/grub.cfg3015 ········path:·/boot/grub2/grub.cfg
3016 ······register:·file_exists3016 ······register:·file_exists
3017 ······when:3017 ······when:
3018 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3019 ······-·'"grub2-common"·in·ansible_facts.packages'3018 ······-·'"grub2-common"·in·ansible_facts.packages'
 3019 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
3020 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3020 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3021 ······tags:3021 ······tags:
3022 ······-·CCE-82026-63022 ······-·CCE-82026-6
3023 ······-·CJIS-5.5.2.23023 ······-·CJIS-5.5.2.2
3024 ······-·NIST-800-171-3.4.53024 ······-·NIST-800-171-3.4.5
3025 ······-·NIST-800-53-AC-6(1)3025 ······-·NIST-800-53-AC-6(1)
3026 ······-·NIST-800-53-CM-6(a)3026 ······-·NIST-800-53-CM-6(a)
Offset 3034, 16 lines modifiedOffset 3034, 16 lines modified
3034 ······-·no_reboot_needed3034 ······-·no_reboot_needed
  
3035 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg3035 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
3036 ······file:3036 ······file:
3037 ········path:·/boot/grub2/grub.cfg3037 ········path:·/boot/grub2/grub.cfg
3038 ········owner:·'0'3038 ········owner:·'0'
3039 ······when:3039 ······when:
3040 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3041 ······-·'"grub2-common"·in·ansible_facts.packages'3040 ······-·'"grub2-common"·in·ansible_facts.packages'
 3041 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
3042 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3042 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3043 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists3043 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
3044 ······tags:3044 ······tags:
3045 ······-·CCE-82026-63045 ······-·CCE-82026-6
3046 ······-·CJIS-5.5.2.23046 ······-·CJIS-5.5.2.2
3047 ······-·NIST-800-171-3.4.53047 ······-·NIST-800-171-3.4.5
3048 ······-·NIST-800-53-AC-6(1)3048 ······-·NIST-800-53-AC-6(1)
Offset 3075, 16 lines modifiedOffset 3075, 16 lines modified
3075 ······-·no_reboot_needed3075 ······-·no_reboot_needed
  
3076 ····-·name:·Test·for·existence·/boot/grub2/user.cfg3076 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
3077 ······stat:3077 ······stat:
3078 ········path:·/boot/grub2/user.cfg3078 ········path:·/boot/grub2/user.cfg
3079 ······register:·file_exists3079 ······register:·file_exists
3080 ······when:3080 ······when:
3081 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3082 ······-·'"grub2-common"·in·ansible_facts.packages'3081 ······-·'"grub2-common"·in·ansible_facts.packages'
 3082 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
3083 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3083 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3084 ······tags:3084 ······tags:
3085 ······-·CCE-86014-83085 ······-·CCE-86014-8
3086 ······-·CJIS-5.5.2.23086 ······-·CJIS-5.5.2.2
3087 ······-·NIST-800-171-3.4.53087 ······-·NIST-800-171-3.4.5
3088 ······-·NIST-800-53-AC-6(1)3088 ······-·NIST-800-53-AC-6(1)
3089 ······-·NIST-800-53-CM-6(a)3089 ······-·NIST-800-53-CM-6(a)
Offset 3097, 16 lines modifiedOffset 3097, 16 lines modified
3097 ······-·no_reboot_needed3097 ······-·no_reboot_needed
Max diff block lines reached; 3319/7934 bytes (41.83%) of diff not shown.
7.92 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-cis_workstation_l1.yml
Ordering differences only
    
Offset 2886, 16 lines modifiedOffset 2886, 16 lines modified
2886 ······-·no_reboot_needed2886 ······-·no_reboot_needed
  
2887 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg2887 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
2888 ······stat:2888 ······stat:
2889 ········path:·/boot/grub2/grub.cfg2889 ········path:·/boot/grub2/grub.cfg
2890 ······register:·file_exists2890 ······register:·file_exists
2891 ······when:2891 ······when:
2892 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2893 ······-·'"grub2-common"·in·ansible_facts.packages'2892 ······-·'"grub2-common"·in·ansible_facts.packages'
 2893 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2894 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2894 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2895 ······tags:2895 ······tags:
2896 ······-·CCE-82023-32896 ······-·CCE-82023-3
2897 ······-·CJIS-5.5.2.22897 ······-·CJIS-5.5.2.2
2898 ······-·NIST-800-171-3.4.52898 ······-·NIST-800-171-3.4.5
2899 ······-·NIST-800-53-AC-6(1)2899 ······-·NIST-800-53-AC-6(1)
2900 ······-·NIST-800-53-CM-6(a)2900 ······-·NIST-800-53-CM-6(a)
Offset 2908, 16 lines modifiedOffset 2908, 16 lines modified
2908 ······-·no_reboot_needed2908 ······-·no_reboot_needed
  
2909 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg2909 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
2910 ······file:2910 ······file:
2911 ········path:·/boot/grub2/grub.cfg2911 ········path:·/boot/grub2/grub.cfg
2912 ········group:·'0'2912 ········group:·'0'
2913 ······when:2913 ······when:
2914 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2915 ······-·'"grub2-common"·in·ansible_facts.packages'2914 ······-·'"grub2-common"·in·ansible_facts.packages'
 2915 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2916 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2916 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2917 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists2917 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
2918 ······tags:2918 ······tags:
2919 ······-·CCE-82023-32919 ······-·CCE-82023-3
2920 ······-·CJIS-5.5.2.22920 ······-·CJIS-5.5.2.2
2921 ······-·NIST-800-171-3.4.52921 ······-·NIST-800-171-3.4.5
2922 ······-·NIST-800-53-AC-6(1)2922 ······-·NIST-800-53-AC-6(1)
Offset 2949, 16 lines modifiedOffset 2949, 16 lines modified
2949 ······-·no_reboot_needed2949 ······-·no_reboot_needed
  
2950 ····-·name:·Test·for·existence·/boot/grub2/user.cfg2950 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
2951 ······stat:2951 ······stat:
2952 ········path:·/boot/grub2/user.cfg2952 ········path:·/boot/grub2/user.cfg
2953 ······register:·file_exists2953 ······register:·file_exists
2954 ······when:2954 ······when:
2955 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2956 ······-·'"grub2-common"·in·ansible_facts.packages'2955 ······-·'"grub2-common"·in·ansible_facts.packages'
 2956 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2957 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2957 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2958 ······tags:2958 ······tags:
2959 ······-·CCE-86008-02959 ······-·CCE-86008-0
2960 ······-·CJIS-5.5.2.22960 ······-·CJIS-5.5.2.2
2961 ······-·NIST-800-171-3.4.52961 ······-·NIST-800-171-3.4.5
2962 ······-·NIST-800-53-AC-6(1)2962 ······-·NIST-800-53-AC-6(1)
2963 ······-·NIST-800-53-CM-6(a)2963 ······-·NIST-800-53-CM-6(a)
Offset 2971, 16 lines modifiedOffset 2971, 16 lines modified
2971 ······-·no_reboot_needed2971 ······-·no_reboot_needed
  
2972 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg2972 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
2973 ······file:2973 ······file:
2974 ········path:·/boot/grub2/user.cfg2974 ········path:·/boot/grub2/user.cfg
2975 ········group:·'0'2975 ········group:·'0'
2976 ······when:2976 ······when:
2977 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2978 ······-·'"grub2-common"·in·ansible_facts.packages'2977 ······-·'"grub2-common"·in·ansible_facts.packages'
 2978 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2979 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2979 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2980 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists2980 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
2981 ······tags:2981 ······tags:
2982 ······-·CCE-86008-02982 ······-·CCE-86008-0
2983 ······-·CJIS-5.5.2.22983 ······-·CJIS-5.5.2.2
2984 ······-·NIST-800-171-3.4.52984 ······-·NIST-800-171-3.4.5
2985 ······-·NIST-800-53-AC-6(1)2985 ······-·NIST-800-53-AC-6(1)
Offset 3012, 16 lines modifiedOffset 3012, 16 lines modified
3012 ······-·no_reboot_needed3012 ······-·no_reboot_needed
  
3013 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg3013 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
3014 ······stat:3014 ······stat:
3015 ········path:·/boot/grub2/grub.cfg3015 ········path:·/boot/grub2/grub.cfg
3016 ······register:·file_exists3016 ······register:·file_exists
3017 ······when:3017 ······when:
3018 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3019 ······-·'"grub2-common"·in·ansible_facts.packages'3018 ······-·'"grub2-common"·in·ansible_facts.packages'
 3019 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
3020 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3020 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3021 ······tags:3021 ······tags:
3022 ······-·CCE-82026-63022 ······-·CCE-82026-6
3023 ······-·CJIS-5.5.2.23023 ······-·CJIS-5.5.2.2
3024 ······-·NIST-800-171-3.4.53024 ······-·NIST-800-171-3.4.5
3025 ······-·NIST-800-53-AC-6(1)3025 ······-·NIST-800-53-AC-6(1)
3026 ······-·NIST-800-53-CM-6(a)3026 ······-·NIST-800-53-CM-6(a)
Offset 3034, 16 lines modifiedOffset 3034, 16 lines modified
3034 ······-·no_reboot_needed3034 ······-·no_reboot_needed
  
3035 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg3035 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
3036 ······file:3036 ······file:
3037 ········path:·/boot/grub2/grub.cfg3037 ········path:·/boot/grub2/grub.cfg
3038 ········owner:·'0'3038 ········owner:·'0'
3039 ······when:3039 ······when:
3040 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3041 ······-·'"grub2-common"·in·ansible_facts.packages'3040 ······-·'"grub2-common"·in·ansible_facts.packages'
 3041 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
3042 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3042 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3043 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists3043 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
3044 ······tags:3044 ······tags:
3045 ······-·CCE-82026-63045 ······-·CCE-82026-6
3046 ······-·CJIS-5.5.2.23046 ······-·CJIS-5.5.2.2
3047 ······-·NIST-800-171-3.4.53047 ······-·NIST-800-171-3.4.5
3048 ······-·NIST-800-53-AC-6(1)3048 ······-·NIST-800-53-AC-6(1)
Offset 3075, 16 lines modifiedOffset 3075, 16 lines modified
3075 ······-·no_reboot_needed3075 ······-·no_reboot_needed
  
3076 ····-·name:·Test·for·existence·/boot/grub2/user.cfg3076 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
3077 ······stat:3077 ······stat:
3078 ········path:·/boot/grub2/user.cfg3078 ········path:·/boot/grub2/user.cfg
3079 ······register:·file_exists3079 ······register:·file_exists
3080 ······when:3080 ······when:
3081 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
3082 ······-·'"grub2-common"·in·ansible_facts.packages'3081 ······-·'"grub2-common"·in·ansible_facts.packages'
 3082 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
3083 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3083 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3084 ······tags:3084 ······tags:
3085 ······-·CCE-86014-83085 ······-·CCE-86014-8
3086 ······-·CJIS-5.5.2.23086 ······-·CJIS-5.5.2.2
3087 ······-·NIST-800-171-3.4.53087 ······-·NIST-800-171-3.4.5
3088 ······-·NIST-800-53-AC-6(1)3088 ······-·NIST-800-53-AC-6(1)
3089 ······-·NIST-800-53-CM-6(a)3089 ······-·NIST-800-53-CM-6(a)
Offset 3097, 16 lines modifiedOffset 3097, 16 lines modified
3097 ······-·no_reboot_needed3097 ······-·no_reboot_needed
Max diff block lines reached; 3319/7934 bytes (41.83%) of diff not shown.
186 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-cis_workstation_l2.yml
Ordering differences only
    
Offset 3189, 16 lines modifiedOffset 3189, 16 lines modified
  
3189 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension3189 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
3190 ······find:3190 ······find:
3191 ········paths:·/etc/audit/rules.d/3191 ········paths:·/etc/audit/rules.d/
3192 ········patterns:·'*.rules'3192 ········patterns:·'*.rules'
3193 ······register:·find_rules_d3193 ······register:·find_rules_d
3194 ······when:3194 ······when:
3195 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3196 ······-·'"audit"·in·ansible_facts.packages'3195 ······-·'"audit"·in·ansible_facts.packages'
 3196 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3197 ······tags:3197 ······tags:
3198 ······-·CCE-27097-53198 ······-·CCE-27097-5
3199 ······-·CJIS-5.4.1.13199 ······-·CJIS-5.4.1.1
3200 ······-·NIST-800-171-3.3.13200 ······-·NIST-800-171-3.3.1
3201 ······-·NIST-800-171-3.4.33201 ······-·NIST-800-171-3.4.3
3202 ······-·NIST-800-53-AC-6(9)3202 ······-·NIST-800-53-AC-6(9)
3203 ······-·NIST-800-53-CM-6(a)3203 ······-·NIST-800-53-CM-6(a)
Offset 3214, 16 lines modifiedOffset 3214, 16 lines modified
3214 ······lineinfile:3214 ······lineinfile:
3215 ········path:·'{{·item·}}'3215 ········path:·'{{·item·}}'
3216 ········regexp:·^\s*(?:-e)\s+.*$3216 ········regexp:·^\s*(?:-e)\s+.*$
3217 ········state:·absent3217 ········state:·absent
3218 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']3218 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
3219 ········}}'3219 ········}}'
3220 ······when:3220 ······when:
3221 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3222 ······-·'"audit"·in·ansible_facts.packages'3221 ······-·'"audit"·in·ansible_facts.packages'
 3222 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3223 ······tags:3223 ······tags:
3224 ······-·CCE-27097-53224 ······-·CCE-27097-5
3225 ······-·CJIS-5.4.1.13225 ······-·CJIS-5.4.1.1
3226 ······-·NIST-800-171-3.3.13226 ······-·NIST-800-171-3.3.1
3227 ······-·NIST-800-171-3.4.33227 ······-·NIST-800-171-3.4.3
3228 ······-·NIST-800-53-AC-6(9)3228 ······-·NIST-800-53-AC-6(9)
3229 ······-·NIST-800-53-CM-6(a)3229 ······-·NIST-800-53-CM-6(a)
Offset 3241, 16 lines modifiedOffset 3241, 16 lines modified
3241 ········create:·true3241 ········create:·true
3242 ········line:·-e·23242 ········line:·-e·2
3243 ········mode:·o-rwx3243 ········mode:·o-rwx
3244 ······loop:3244 ······loop:
3245 ······-·/etc/audit/audit.rules3245 ······-·/etc/audit/audit.rules
3246 ······-·/etc/audit/rules.d/immutable.rules3246 ······-·/etc/audit/rules.d/immutable.rules
3247 ······when:3247 ······when:
3248 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3249 ······-·'"audit"·in·ansible_facts.packages'3248 ······-·'"audit"·in·ansible_facts.packages'
 3249 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3250 ······tags:3250 ······tags:
3251 ······-·CCE-27097-53251 ······-·CCE-27097-5
3252 ······-·CJIS-5.4.1.13252 ······-·CJIS-5.4.1.1
3253 ······-·NIST-800-171-3.3.13253 ······-·NIST-800-171-3.3.1
3254 ······-·NIST-800-171-3.4.33254 ······-·NIST-800-171-3.4.3
3255 ······-·NIST-800-53-AC-6(9)3255 ······-·NIST-800-53-AC-6(9)
3256 ······-·NIST-800-53-CM-6(a)3256 ······-·NIST-800-53-CM-6(a)
Offset 3284, 16 lines modifiedOffset 3284, 16 lines modified
3284 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/3284 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
3285 ······find:3285 ······find:
3286 ········paths:·/etc/audit/rules.d3286 ········paths:·/etc/audit/rules.d
3287 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+3287 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
3288 ········patterns:·'*.rules'3288 ········patterns:·'*.rules'
3289 ······register:·find_existing_watch_rules_d3289 ······register:·find_existing_watch_rules_d
3290 ······when:3290 ······when:
3291 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3292 ······-·'"audit"·in·ansible_facts.packages'3291 ······-·'"audit"·in·ansible_facts.packages'
 3292 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3293 ······tags:3293 ······tags:
3294 ······-·CCE-27168-43294 ······-·CCE-27168-4
3295 ······-·CJIS-5.4.1.13295 ······-·CJIS-5.4.1.1
3296 ······-·NIST-800-171-3.1.83296 ······-·NIST-800-171-3.1.8
3297 ······-·NIST-800-53-AU-12(c)3297 ······-·NIST-800-53-AU-12(c)
3298 ······-·NIST-800-53-AU-2(d)3298 ······-·NIST-800-53-AU-2(d)
3299 ······-·NIST-800-53-CM-6(a)3299 ······-·NIST-800-53-CM-6(a)
Offset 3308, 16 lines modifiedOffset 3308, 16 lines modified
3308 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy3308 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
3309 ······find:3309 ······find:
3310 ········paths:·/etc/audit/rules.d3310 ········paths:·/etc/audit/rules.d
3311 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$3311 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
3312 ········patterns:·'*.rules'3312 ········patterns:·'*.rules'
3313 ······register:·find_watch_key3313 ······register:·find_watch_key
3314 ······when:3314 ······when:
3315 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3316 ······-·'"audit"·in·ansible_facts.packages'3315 ······-·'"audit"·in·ansible_facts.packages'
 3316 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3317 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3317 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3318 ········==·03318 ········==·0
3319 ······tags:3319 ······tags:
3320 ······-·CCE-27168-43320 ······-·CCE-27168-4
3321 ······-·CJIS-5.4.1.13321 ······-·CJIS-5.4.1.1
3322 ······-·NIST-800-171-3.1.83322 ······-·NIST-800-171-3.1.8
3323 ······-·NIST-800-53-AU-12(c)3323 ······-·NIST-800-53-AU-12(c)
Offset 3332, 16 lines modifiedOffset 3332, 16 lines modified
3332 ······-·restrict_strategy3332 ······-·restrict_strategy
  
3333 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule3333 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
3334 ······set_fact:3334 ······set_fact:
3335 ········all_files:3335 ········all_files:
3336 ········-·/etc/audit/rules.d/MAC-policy.rules3336 ········-·/etc/audit/rules.d/MAC-policy.rules
3337 ······when:3337 ······when:
3338 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3339 ······-·'"audit"·in·ansible_facts.packages'3338 ······-·'"audit"·in·ansible_facts.packages'
 3339 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3340 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched3340 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
3341 ········is·defined·and·find_existing_watch_rules_d.matched·==·03341 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3342 ······tags:3342 ······tags:
3343 ······-·CCE-27168-43343 ······-·CCE-27168-4
3344 ······-·CJIS-5.4.1.13344 ······-·CJIS-5.4.1.1
3345 ······-·NIST-800-171-3.1.83345 ······-·NIST-800-171-3.1.8
3346 ······-·NIST-800-53-AU-12(c)3346 ······-·NIST-800-53-AU-12(c)
Offset 3356, 16 lines modifiedOffset 3356, 16 lines modified
3356 ······-·restrict_strategy3356 ······-·restrict_strategy
  
3357 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule3357 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
3358 ······set_fact:3358 ······set_fact:
3359 ········all_files:3359 ········all_files:
3360 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'3360 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
3361 ······when:3361 ······when:
3362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
3363 ······-·'"audit"·in·ansible_facts.packages'3362 ······-·'"audit"·in·ansible_facts.packages'
 3363 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3364 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched3364 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
3365 ········is·defined·and·find_existing_watch_rules_d.matched·==·03365 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3366 ······tags:3366 ······tags:
3367 ······-·CCE-27168-43367 ······-·CCE-27168-4
3368 ······-·CJIS-5.4.1.13368 ······-·CJIS-5.4.1.1
3369 ······-·NIST-800-171-3.1.83369 ······-·NIST-800-171-3.1.8
3370 ······-·NIST-800-53-AU-12(c)3370 ······-·NIST-800-53-AU-12(c)
Offset 3382, 16 lines modifiedOffset 3382, 16 lines modified
3382 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/3382 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 185275/190258 bytes (97.38%) of diff not shown.
108 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-cjis.yml
Ordering differences only
    
Offset 2750, 16 lines modifiedOffset 2750, 16 lines modified
  
2750 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension2750 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
2751 ······find:2751 ······find:
2752 ········paths:·/etc/audit/rules.d/2752 ········paths:·/etc/audit/rules.d/
2753 ········patterns:·'*.rules'2753 ········patterns:·'*.rules'
2754 ······register:·find_rules_d2754 ······register:·find_rules_d
2755 ······when:2755 ······when:
2756 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2757 ······-·'"audit"·in·ansible_facts.packages'2756 ······-·'"audit"·in·ansible_facts.packages'
 2757 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2758 ······tags:2758 ······tags:
2759 ······-·CCE-27097-52759 ······-·CCE-27097-5
2760 ······-·CJIS-5.4.1.12760 ······-·CJIS-5.4.1.1
2761 ······-·NIST-800-171-3.3.12761 ······-·NIST-800-171-3.3.1
2762 ······-·NIST-800-171-3.4.32762 ······-·NIST-800-171-3.4.3
2763 ······-·NIST-800-53-AC-6(9)2763 ······-·NIST-800-53-AC-6(9)
2764 ······-·NIST-800-53-CM-6(a)2764 ······-·NIST-800-53-CM-6(a)
Offset 2775, 16 lines modifiedOffset 2775, 16 lines modified
2775 ······lineinfile:2775 ······lineinfile:
2776 ········path:·'{{·item·}}'2776 ········path:·'{{·item·}}'
2777 ········regexp:·^\s*(?:-e)\s+.*$2777 ········regexp:·^\s*(?:-e)\s+.*$
2778 ········state:·absent2778 ········state:·absent
2779 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']2779 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
2780 ········}}'2780 ········}}'
2781 ······when:2781 ······when:
2782 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2783 ······-·'"audit"·in·ansible_facts.packages'2782 ······-·'"audit"·in·ansible_facts.packages'
 2783 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2784 ······tags:2784 ······tags:
2785 ······-·CCE-27097-52785 ······-·CCE-27097-5
2786 ······-·CJIS-5.4.1.12786 ······-·CJIS-5.4.1.1
2787 ······-·NIST-800-171-3.3.12787 ······-·NIST-800-171-3.3.1
2788 ······-·NIST-800-171-3.4.32788 ······-·NIST-800-171-3.4.3
2789 ······-·NIST-800-53-AC-6(9)2789 ······-·NIST-800-53-AC-6(9)
2790 ······-·NIST-800-53-CM-6(a)2790 ······-·NIST-800-53-CM-6(a)
Offset 2802, 16 lines modifiedOffset 2802, 16 lines modified
2802 ········create:·true2802 ········create:·true
2803 ········line:·-e·22803 ········line:·-e·2
2804 ········mode:·o-rwx2804 ········mode:·o-rwx
2805 ······loop:2805 ······loop:
2806 ······-·/etc/audit/audit.rules2806 ······-·/etc/audit/audit.rules
2807 ······-·/etc/audit/rules.d/immutable.rules2807 ······-·/etc/audit/rules.d/immutable.rules
2808 ······when:2808 ······when:
2809 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2810 ······-·'"audit"·in·ansible_facts.packages'2809 ······-·'"audit"·in·ansible_facts.packages'
 2810 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2811 ······tags:2811 ······tags:
2812 ······-·CCE-27097-52812 ······-·CCE-27097-5
2813 ······-·CJIS-5.4.1.12813 ······-·CJIS-5.4.1.1
2814 ······-·NIST-800-171-3.3.12814 ······-·NIST-800-171-3.3.1
2815 ······-·NIST-800-171-3.4.32815 ······-·NIST-800-171-3.4.3
2816 ······-·NIST-800-53-AC-6(9)2816 ······-·NIST-800-53-AC-6(9)
2817 ······-·NIST-800-53-CM-6(a)2817 ······-·NIST-800-53-CM-6(a)
Offset 2845, 16 lines modifiedOffset 2845, 16 lines modified
2845 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/2845 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
2846 ······find:2846 ······find:
2847 ········paths:·/etc/audit/rules.d2847 ········paths:·/etc/audit/rules.d
2848 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+2848 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
2849 ········patterns:·'*.rules'2849 ········patterns:·'*.rules'
2850 ······register:·find_existing_watch_rules_d2850 ······register:·find_existing_watch_rules_d
2851 ······when:2851 ······when:
2852 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2853 ······-·'"audit"·in·ansible_facts.packages'2852 ······-·'"audit"·in·ansible_facts.packages'
 2853 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2854 ······tags:2854 ······tags:
2855 ······-·CCE-27168-42855 ······-·CCE-27168-4
2856 ······-·CJIS-5.4.1.12856 ······-·CJIS-5.4.1.1
2857 ······-·NIST-800-171-3.1.82857 ······-·NIST-800-171-3.1.8
2858 ······-·NIST-800-53-AU-12(c)2858 ······-·NIST-800-53-AU-12(c)
2859 ······-·NIST-800-53-AU-2(d)2859 ······-·NIST-800-53-AU-2(d)
2860 ······-·NIST-800-53-CM-6(a)2860 ······-·NIST-800-53-CM-6(a)
Offset 2869, 16 lines modifiedOffset 2869, 16 lines modified
2869 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy2869 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
2870 ······find:2870 ······find:
2871 ········paths:·/etc/audit/rules.d2871 ········paths:·/etc/audit/rules.d
2872 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$2872 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
2873 ········patterns:·'*.rules'2873 ········patterns:·'*.rules'
2874 ······register:·find_watch_key2874 ······register:·find_watch_key
2875 ······when:2875 ······when:
2876 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2877 ······-·'"audit"·in·ansible_facts.packages'2876 ······-·'"audit"·in·ansible_facts.packages'
 2877 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2878 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched2878 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
2879 ········==·02879 ········==·0
2880 ······tags:2880 ······tags:
2881 ······-·CCE-27168-42881 ······-·CCE-27168-4
2882 ······-·CJIS-5.4.1.12882 ······-·CJIS-5.4.1.1
2883 ······-·NIST-800-171-3.1.82883 ······-·NIST-800-171-3.1.8
2884 ······-·NIST-800-53-AU-12(c)2884 ······-·NIST-800-53-AU-12(c)
Offset 2893, 16 lines modifiedOffset 2893, 16 lines modified
2893 ······-·restrict_strategy2893 ······-·restrict_strategy
  
2894 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule2894 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
2895 ······set_fact:2895 ······set_fact:
2896 ········all_files:2896 ········all_files:
2897 ········-·/etc/audit/rules.d/MAC-policy.rules2897 ········-·/etc/audit/rules.d/MAC-policy.rules
2898 ······when:2898 ······when:
2899 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2900 ······-·'"audit"·in·ansible_facts.packages'2899 ······-·'"audit"·in·ansible_facts.packages'
 2900 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2901 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched2901 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
2902 ········is·defined·and·find_existing_watch_rules_d.matched·==·02902 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
2903 ······tags:2903 ······tags:
2904 ······-·CCE-27168-42904 ······-·CCE-27168-4
2905 ······-·CJIS-5.4.1.12905 ······-·CJIS-5.4.1.1
2906 ······-·NIST-800-171-3.1.82906 ······-·NIST-800-171-3.1.8
2907 ······-·NIST-800-53-AU-12(c)2907 ······-·NIST-800-53-AU-12(c)
Offset 2917, 16 lines modifiedOffset 2917, 16 lines modified
2917 ······-·restrict_strategy2917 ······-·restrict_strategy
  
2918 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule2918 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
2919 ······set_fact:2919 ······set_fact:
2920 ········all_files:2920 ········all_files:
2921 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'2921 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
2922 ······when:2922 ······when:
2923 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
2924 ······-·'"audit"·in·ansible_facts.packages'2923 ······-·'"audit"·in·ansible_facts.packages'
 2924 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2925 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched2925 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
2926 ········is·defined·and·find_existing_watch_rules_d.matched·==·02926 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
2927 ······tags:2927 ······tags:
2928 ······-·CCE-27168-42928 ······-·CCE-27168-4
2929 ······-·CJIS-5.4.1.12929 ······-·CJIS-5.4.1.1
2930 ······-·NIST-800-171-3.1.82930 ······-·NIST-800-171-3.1.8
2931 ······-·NIST-800-53-AU-12(c)2931 ······-·NIST-800-53-AU-12(c)
Offset 2943, 16 lines modifiedOffset 2943, 16 lines modified
2943 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/2943 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 105339/110322 bytes (95.48%) of diff not shown.
786 B
./usr/share/scap-security-guide/ansible/rhel7-playbook-cui.yml
Ordering differences only
    
Offset 4681, 16 lines modifiedOffset 4681, 16 lines modified
4681 ······lineinfile:4681 ······lineinfile:
4682 ········dest:·/etc/audit/auditd.conf4682 ········dest:·/etc/audit/auditd.conf
4683 ········regexp:·^\s*flush\s*=\s*.*$4683 ········regexp:·^\s*flush\s*=\s*.*$
4684 ········line:·flush·=·{{·var_auditd_flush·}}4684 ········line:·flush·=·{{·var_auditd_flush·}}
4685 ········state:·present4685 ········state:·present
4686 ········create:·true4686 ········create:·true
4687 ······when:4687 ······when:
4688 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4689 ······-·'"audit"·in·ansible_facts.packages'4688 ······-·'"audit"·in·ansible_facts.packages'
 4689 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4690 ······tags:4690 ······tags:
4691 ······-·CCE-27331-84691 ······-·CCE-27331-8
4692 ······-·NIST-800-171-3.3.14692 ······-·NIST-800-171-3.3.1
4693 ······-·NIST-800-53-AU-114693 ······-·NIST-800-53-AU-11
4694 ······-·NIST-800-53-CM-6(a)4694 ······-·NIST-800-53-CM-6(a)
4695 ······-·auditd_data_retention_flush4695 ······-·auditd_data_retention_flush
4696 ······-·low_complexity4696 ······-·low_complexity
74.0 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-e8.yml
Ordering differences only
    
Offset 1095, 16 lines modifiedOffset 1095, 16 lines modified
1095 ······-·no_reboot_needed1095 ······-·no_reboot_needed
1096 ······-·restrict_strategy1096 ······-·restrict_strategy
  
1097 ····-·name:·Set·architecture·for·audit·tasks1097 ····-·name:·Set·architecture·for·audit·tasks
1098 ······set_fact:1098 ······set_fact:
1099 ········audit_arch:·b641099 ········audit_arch:·b64
1100 ······when:1100 ······when:
1101 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1102 ······-·'"audit"·in·ansible_facts.packages'1101 ······-·'"audit"·in·ansible_facts.packages'
 1102 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1103 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1103 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1104 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1104 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1105 ······tags:1105 ······tags:
1106 ······-·CCE-27076-91106 ······-·CCE-27076-9
1107 ······-·CJIS-5.4.1.11107 ······-·CJIS-5.4.1.1
1108 ······-·NIST-800-171-3.1.71108 ······-·NIST-800-171-3.1.7
1109 ······-·NIST-800-53-AC-6(9)1109 ······-·NIST-800-53-AC-6(9)
Offset 1238, 16 lines modifiedOffset 1238, 16 lines modified
1238 ··········path:·'{{·audit_file·}}'1238 ··········path:·'{{·audit_file·}}'
1239 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1239 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1240 ··········create:·true1240 ··········create:·true
1241 ··········mode:·o-rwx1241 ··········mode:·o-rwx
1242 ··········state:·present1242 ··········state:·present
1243 ········when:·syscalls_found·|·length·==·01243 ········when:·syscalls_found·|·length·==·0
1244 ······when:1244 ······when:
1245 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1246 ······-·'"audit"·in·ansible_facts.packages'1245 ······-·'"audit"·in·ansible_facts.packages'
 1246 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1247 ······tags:1247 ······tags:
1248 ······-·CCE-27076-91248 ······-·CCE-27076-9
1249 ······-·CJIS-5.4.1.11249 ······-·CJIS-5.4.1.1
1250 ······-·NIST-800-171-3.1.71250 ······-·NIST-800-171-3.1.7
1251 ······-·NIST-800-53-AC-6(9)1251 ······-·NIST-800-53-AC-6(9)
1252 ······-·NIST-800-53-AU-12(c)1252 ······-·NIST-800-53-AU-12(c)
1253 ······-·NIST-800-53-AU-2(d)1253 ······-·NIST-800-53-AU-2(d)
Offset 1379, 16 lines modifiedOffset 1379, 16 lines modified
1379 ··········path:·'{{·audit_file·}}'1379 ··········path:·'{{·audit_file·}}'
1380 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1380 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1381 ··········create:·true1381 ··········create:·true
1382 ··········mode:·o-rwx1382 ··········mode:·o-rwx
1383 ··········state:·present1383 ··········state:·present
1384 ········when:·syscalls_found·|·length·==·01384 ········when:·syscalls_found·|·length·==·0
1385 ······when:1385 ······when:
1386 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1387 ······-·'"audit"·in·ansible_facts.packages'1386 ······-·'"audit"·in·ansible_facts.packages'
 1387 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1388 ······-·audit_arch·==·"b64"1388 ······-·audit_arch·==·"b64"
1389 ······tags:1389 ······tags:
1390 ······-·CCE-27076-91390 ······-·CCE-27076-9
1391 ······-·CJIS-5.4.1.11391 ······-·CJIS-5.4.1.1
1392 ······-·NIST-800-171-3.1.71392 ······-·NIST-800-171-3.1.7
1393 ······-·NIST-800-53-AC-6(9)1393 ······-·NIST-800-53-AC-6(9)
1394 ······-·NIST-800-53-AU-12(c)1394 ······-·NIST-800-53-AU-12(c)
Offset 1405, 16 lines modifiedOffset 1405, 16 lines modified
1405 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/1405 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
1406 ······find:1406 ······find:
1407 ········paths:·/etc/audit/rules.d1407 ········paths:·/etc/audit/rules.d
1408 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+1408 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
1409 ········patterns:·'*.rules'1409 ········patterns:·'*.rules'
1410 ······register:·find_existing_watch_rules_d1410 ······register:·find_existing_watch_rules_d
1411 ······when:1411 ······when:
1412 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1413 ······-·'"audit"·in·ansible_facts.packages'1412 ······-·'"audit"·in·ansible_facts.packages'
 1413 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1414 ······tags:1414 ······tags:
1415 ······-·CCE-27076-91415 ······-·CCE-27076-9
1416 ······-·CJIS-5.4.1.11416 ······-·CJIS-5.4.1.1
1417 ······-·NIST-800-171-3.1.71417 ······-·NIST-800-171-3.1.7
1418 ······-·NIST-800-53-AC-6(9)1418 ······-·NIST-800-53-AC-6(9)
1419 ······-·NIST-800-53-AU-12(c)1419 ······-·NIST-800-53-AU-12(c)
1420 ······-·NIST-800-53-AU-2(d)1420 ······-·NIST-800-53-AU-2(d)
Offset 1430, 16 lines modifiedOffset 1430, 16 lines modified
1430 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification1430 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
1431 ······find:1431 ······find:
1432 ········paths:·/etc/audit/rules.d1432 ········paths:·/etc/audit/rules.d
1433 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$1433 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
1434 ········patterns:·'*.rules'1434 ········patterns:·'*.rules'
1435 ······register:·find_watch_key1435 ······register:·find_watch_key
1436 ······when:1436 ······when:
1437 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1438 ······-·'"audit"·in·ansible_facts.packages'1437 ······-·'"audit"·in·ansible_facts.packages'
 1438 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1439 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1439 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1440 ········==·01440 ········==·0
1441 ······tags:1441 ······tags:
1442 ······-·CCE-27076-91442 ······-·CCE-27076-9
1443 ······-·CJIS-5.4.1.11443 ······-·CJIS-5.4.1.1
1444 ······-·NIST-800-171-3.1.71444 ······-·NIST-800-171-3.1.7
1445 ······-·NIST-800-53-AC-6(9)1445 ······-·NIST-800-53-AC-6(9)
Offset 1456, 16 lines modifiedOffset 1456, 16 lines modified
  
1456 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the1456 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
1457 ········recipient·for·the·rule1457 ········recipient·for·the·rule
1458 ······set_fact:1458 ······set_fact:
1459 ········all_files:1459 ········all_files:
1460 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules1460 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
1461 ······when:1461 ······when:
1462 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1463 ······-·'"audit"·in·ansible_facts.packages'1462 ······-·'"audit"·in·ansible_facts.packages'
 1463 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1464 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1464 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1465 ········is·defined·and·find_existing_watch_rules_d.matched·==·01465 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1466 ······tags:1466 ······tags:
1467 ······-·CCE-27076-91467 ······-·CCE-27076-9
1468 ······-·CJIS-5.4.1.11468 ······-·CJIS-5.4.1.1
1469 ······-·NIST-800-171-3.1.71469 ······-·NIST-800-171-3.1.7
1470 ······-·NIST-800-53-AC-6(9)1470 ······-·NIST-800-53-AC-6(9)
Offset 1481, 16 lines modifiedOffset 1481, 16 lines modified
1481 ······-·restrict_strategy1481 ······-·restrict_strategy
  
1482 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1482 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1483 ······set_fact:1483 ······set_fact:
1484 ········all_files:1484 ········all_files:
1485 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1485 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1486 ······when:1486 ······when:
1487 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1488 ······-·'"audit"·in·ansible_facts.packages'1487 ······-·'"audit"·in·ansible_facts.packages'
 1488 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1489 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1489 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1490 ········is·defined·and·find_existing_watch_rules_d.matched·==·01490 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1491 ······tags:1491 ······tags:
1492 ······-·CCE-27076-91492 ······-·CCE-27076-9
1493 ······-·CJIS-5.4.1.11493 ······-·CJIS-5.4.1.1
1494 ······-·NIST-800-171-3.1.71494 ······-·NIST-800-171-3.1.7
1495 ······-·NIST-800-53-AC-6(9)1495 ······-·NIST-800-53-AC-6(9)
Offset 1508, 16 lines modifiedOffset 1508, 16 lines modified
1508 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/1508 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 70259/75599 bytes (92.94%) of diff not shown.
192 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-hipaa.yml
Ordering differences only
    
Offset 1356, 16 lines modifiedOffset 1356, 16 lines modified
  
1356 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1356 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1357 ······find:1357 ······find:
1358 ········paths:·/etc/audit/rules.d/1358 ········paths:·/etc/audit/rules.d/
1359 ········patterns:·'*.rules'1359 ········patterns:·'*.rules'
1360 ······register:·find_rules_d1360 ······register:·find_rules_d
1361 ······when:1361 ······when:
1362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1363 ······-·'"audit"·in·ansible_facts.packages'1362 ······-·'"audit"·in·ansible_facts.packages'
 1363 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1364 ······tags:1364 ······tags:
1365 ······-·CCE-27097-51365 ······-·CCE-27097-5
1366 ······-·CJIS-5.4.1.11366 ······-·CJIS-5.4.1.1
1367 ······-·NIST-800-171-3.3.11367 ······-·NIST-800-171-3.3.1
1368 ······-·NIST-800-171-3.4.31368 ······-·NIST-800-171-3.4.3
1369 ······-·NIST-800-53-AC-6(9)1369 ······-·NIST-800-53-AC-6(9)
1370 ······-·NIST-800-53-CM-6(a)1370 ······-·NIST-800-53-CM-6(a)
Offset 1381, 16 lines modifiedOffset 1381, 16 lines modified
1381 ······lineinfile:1381 ······lineinfile:
1382 ········path:·'{{·item·}}'1382 ········path:·'{{·item·}}'
1383 ········regexp:·^\s*(?:-e)\s+.*$1383 ········regexp:·^\s*(?:-e)\s+.*$
1384 ········state:·absent1384 ········state:·absent
1385 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1385 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1386 ········}}'1386 ········}}'
1387 ······when:1387 ······when:
1388 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1389 ······-·'"audit"·in·ansible_facts.packages'1388 ······-·'"audit"·in·ansible_facts.packages'
 1389 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1390 ······tags:1390 ······tags:
1391 ······-·CCE-27097-51391 ······-·CCE-27097-5
1392 ······-·CJIS-5.4.1.11392 ······-·CJIS-5.4.1.1
1393 ······-·NIST-800-171-3.3.11393 ······-·NIST-800-171-3.3.1
1394 ······-·NIST-800-171-3.4.31394 ······-·NIST-800-171-3.4.3
1395 ······-·NIST-800-53-AC-6(9)1395 ······-·NIST-800-53-AC-6(9)
1396 ······-·NIST-800-53-CM-6(a)1396 ······-·NIST-800-53-CM-6(a)
Offset 1408, 16 lines modifiedOffset 1408, 16 lines modified
1408 ········create:·true1408 ········create:·true
1409 ········line:·-e·21409 ········line:·-e·2
1410 ········mode:·o-rwx1410 ········mode:·o-rwx
1411 ······loop:1411 ······loop:
1412 ······-·/etc/audit/audit.rules1412 ······-·/etc/audit/audit.rules
1413 ······-·/etc/audit/rules.d/immutable.rules1413 ······-·/etc/audit/rules.d/immutable.rules
1414 ······when:1414 ······when:
1415 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1416 ······-·'"audit"·in·ansible_facts.packages'1415 ······-·'"audit"·in·ansible_facts.packages'
 1416 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1417 ······tags:1417 ······tags:
1418 ······-·CCE-27097-51418 ······-·CCE-27097-5
1419 ······-·CJIS-5.4.1.11419 ······-·CJIS-5.4.1.1
1420 ······-·NIST-800-171-3.3.11420 ······-·NIST-800-171-3.3.1
1421 ······-·NIST-800-171-3.4.31421 ······-·NIST-800-171-3.4.3
1422 ······-·NIST-800-53-AC-6(9)1422 ······-·NIST-800-53-AC-6(9)
1423 ······-·NIST-800-53-CM-6(a)1423 ······-·NIST-800-53-CM-6(a)
Offset 1451, 16 lines modifiedOffset 1451, 16 lines modified
1451 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1451 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1452 ······find:1452 ······find:
1453 ········paths:·/etc/audit/rules.d1453 ········paths:·/etc/audit/rules.d
1454 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1454 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1455 ········patterns:·'*.rules'1455 ········patterns:·'*.rules'
1456 ······register:·find_existing_watch_rules_d1456 ······register:·find_existing_watch_rules_d
1457 ······when:1457 ······when:
1458 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1459 ······-·'"audit"·in·ansible_facts.packages'1458 ······-·'"audit"·in·ansible_facts.packages'
 1459 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1460 ······tags:1460 ······tags:
1461 ······-·CCE-27168-41461 ······-·CCE-27168-4
1462 ······-·CJIS-5.4.1.11462 ······-·CJIS-5.4.1.1
1463 ······-·NIST-800-171-3.1.81463 ······-·NIST-800-171-3.1.8
1464 ······-·NIST-800-53-AU-12(c)1464 ······-·NIST-800-53-AU-12(c)
1465 ······-·NIST-800-53-AU-2(d)1465 ······-·NIST-800-53-AU-2(d)
1466 ······-·NIST-800-53-CM-6(a)1466 ······-·NIST-800-53-CM-6(a)
Offset 1475, 16 lines modifiedOffset 1475, 16 lines modified
1475 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1475 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1476 ······find:1476 ······find:
1477 ········paths:·/etc/audit/rules.d1477 ········paths:·/etc/audit/rules.d
1478 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1478 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1479 ········patterns:·'*.rules'1479 ········patterns:·'*.rules'
1480 ······register:·find_watch_key1480 ······register:·find_watch_key
1481 ······when:1481 ······when:
1482 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1483 ······-·'"audit"·in·ansible_facts.packages'1482 ······-·'"audit"·in·ansible_facts.packages'
 1483 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1484 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1484 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1485 ········==·01485 ········==·0
1486 ······tags:1486 ······tags:
1487 ······-·CCE-27168-41487 ······-·CCE-27168-4
1488 ······-·CJIS-5.4.1.11488 ······-·CJIS-5.4.1.1
1489 ······-·NIST-800-171-3.1.81489 ······-·NIST-800-171-3.1.8
1490 ······-·NIST-800-53-AU-12(c)1490 ······-·NIST-800-53-AU-12(c)
Offset 1499, 16 lines modifiedOffset 1499, 16 lines modified
1499 ······-·restrict_strategy1499 ······-·restrict_strategy
  
1500 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1500 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1501 ······set_fact:1501 ······set_fact:
1502 ········all_files:1502 ········all_files:
1503 ········-·/etc/audit/rules.d/MAC-policy.rules1503 ········-·/etc/audit/rules.d/MAC-policy.rules
1504 ······when:1504 ······when:
1505 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1506 ······-·'"audit"·in·ansible_facts.packages'1505 ······-·'"audit"·in·ansible_facts.packages'
 1506 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1507 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1507 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1508 ········is·defined·and·find_existing_watch_rules_d.matched·==·01508 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1509 ······tags:1509 ······tags:
1510 ······-·CCE-27168-41510 ······-·CCE-27168-4
1511 ······-·CJIS-5.4.1.11511 ······-·CJIS-5.4.1.1
1512 ······-·NIST-800-171-3.1.81512 ······-·NIST-800-171-3.1.8
1513 ······-·NIST-800-53-AU-12(c)1513 ······-·NIST-800-53-AU-12(c)
Offset 1523, 16 lines modifiedOffset 1523, 16 lines modified
1523 ······-·restrict_strategy1523 ······-·restrict_strategy
  
1524 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1524 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1525 ······set_fact:1525 ······set_fact:
1526 ········all_files:1526 ········all_files:
1527 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1527 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1528 ······when:1528 ······when:
1529 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
1530 ······-·'"audit"·in·ansible_facts.packages'1529 ······-·'"audit"·in·ansible_facts.packages'
 1530 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
1531 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1531 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1532 ········is·defined·and·find_existing_watch_rules_d.matched·==·01532 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1533 ······tags:1533 ······tags:
1534 ······-·CCE-27168-41534 ······-·CCE-27168-4
1535 ······-·CJIS-5.4.1.11535 ······-·CJIS-5.4.1.1
1536 ······-·NIST-800-171-3.1.81536 ······-·NIST-800-171-3.1.8
1537 ······-·NIST-800-53-AU-12(c)1537 ······-·NIST-800-53-AU-12(c)
Offset 1549, 16 lines modifiedOffset 1549, 16 lines modified
1549 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1549 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 191830/196813 bytes (97.47%) of diff not shown.
201 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-ncp.yml
Ordering differences only
    
Offset 10096, 16 lines modifiedOffset 10096, 16 lines modified
  
10096 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension10096 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
10097 ······find:10097 ······find:
10098 ········paths:·/etc/audit/rules.d/10098 ········paths:·/etc/audit/rules.d/
10099 ········patterns:·'*.rules'10099 ········patterns:·'*.rules'
10100 ······register:·find_rules_d10100 ······register:·find_rules_d
10101 ······when:10101 ······when:
10102 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
10103 ······-·'"audit"·in·ansible_facts.packages'10102 ······-·'"audit"·in·ansible_facts.packages'
 10103 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
10104 ······tags:10104 ······tags:
10105 ······-·CCE-27097-510105 ······-·CCE-27097-5
10106 ······-·CJIS-5.4.1.110106 ······-·CJIS-5.4.1.1
10107 ······-·NIST-800-171-3.3.110107 ······-·NIST-800-171-3.3.1
10108 ······-·NIST-800-171-3.4.310108 ······-·NIST-800-171-3.4.3
10109 ······-·NIST-800-53-AC-6(9)10109 ······-·NIST-800-53-AC-6(9)
10110 ······-·NIST-800-53-CM-6(a)10110 ······-·NIST-800-53-CM-6(a)
Offset 10121, 16 lines modifiedOffset 10121, 16 lines modified
10121 ······lineinfile:10121 ······lineinfile:
10122 ········path:·'{{·item·}}'10122 ········path:·'{{·item·}}'
10123 ········regexp:·^\s*(?:-e)\s+.*$10123 ········regexp:·^\s*(?:-e)\s+.*$
10124 ········state:·absent10124 ········state:·absent
10125 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']10125 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
10126 ········}}'10126 ········}}'
10127 ······when:10127 ······when:
10128 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
10129 ······-·'"audit"·in·ansible_facts.packages'10128 ······-·'"audit"·in·ansible_facts.packages'
 10129 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
10130 ······tags:10130 ······tags:
10131 ······-·CCE-27097-510131 ······-·CCE-27097-5
10132 ······-·CJIS-5.4.1.110132 ······-·CJIS-5.4.1.1
10133 ······-·NIST-800-171-3.3.110133 ······-·NIST-800-171-3.3.1
10134 ······-·NIST-800-171-3.4.310134 ······-·NIST-800-171-3.4.3
10135 ······-·NIST-800-53-AC-6(9)10135 ······-·NIST-800-53-AC-6(9)
10136 ······-·NIST-800-53-CM-6(a)10136 ······-·NIST-800-53-CM-6(a)
Offset 10148, 16 lines modifiedOffset 10148, 16 lines modified
10148 ········create:·true10148 ········create:·true
10149 ········line:·-e·210149 ········line:·-e·2
10150 ········mode:·o-rwx10150 ········mode:·o-rwx
10151 ······loop:10151 ······loop:
10152 ······-·/etc/audit/audit.rules10152 ······-·/etc/audit/audit.rules
10153 ······-·/etc/audit/rules.d/immutable.rules10153 ······-·/etc/audit/rules.d/immutable.rules
10154 ······when:10154 ······when:
10155 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
10156 ······-·'"audit"·in·ansible_facts.packages'10155 ······-·'"audit"·in·ansible_facts.packages'
 10156 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
10157 ······tags:10157 ······tags:
10158 ······-·CCE-27097-510158 ······-·CCE-27097-5
10159 ······-·CJIS-5.4.1.110159 ······-·CJIS-5.4.1.1
10160 ······-·NIST-800-171-3.3.110160 ······-·NIST-800-171-3.3.1
10161 ······-·NIST-800-171-3.4.310161 ······-·NIST-800-171-3.4.3
10162 ······-·NIST-800-53-AC-6(9)10162 ······-·NIST-800-53-AC-6(9)
10163 ······-·NIST-800-53-CM-6(a)10163 ······-·NIST-800-53-CM-6(a)
Offset 10191, 16 lines modifiedOffset 10191, 16 lines modified
10191 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/10191 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
10192 ······find:10192 ······find:
10193 ········paths:·/etc/audit/rules.d10193 ········paths:·/etc/audit/rules.d
10194 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+10194 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
10195 ········patterns:·'*.rules'10195 ········patterns:·'*.rules'
10196 ······register:·find_existing_watch_rules_d10196 ······register:·find_existing_watch_rules_d
10197 ······when:10197 ······when:
10198 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
10199 ······-·'"audit"·in·ansible_facts.packages'10198 ······-·'"audit"·in·ansible_facts.packages'
 10199 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
10200 ······tags:10200 ······tags:
10201 ······-·CCE-27168-410201 ······-·CCE-27168-4
10202 ······-·CJIS-5.4.1.110202 ······-·CJIS-5.4.1.1
10203 ······-·NIST-800-171-3.1.810203 ······-·NIST-800-171-3.1.8
10204 ······-·NIST-800-53-AU-12(c)10204 ······-·NIST-800-53-AU-12(c)
10205 ······-·NIST-800-53-AU-2(d)10205 ······-·NIST-800-53-AU-2(d)
10206 ······-·NIST-800-53-CM-6(a)10206 ······-·NIST-800-53-CM-6(a)
Offset 10215, 16 lines modifiedOffset 10215, 16 lines modified
10215 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy10215 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
10216 ······find:10216 ······find:
10217 ········paths:·/etc/audit/rules.d10217 ········paths:·/etc/audit/rules.d
10218 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$10218 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
10219 ········patterns:·'*.rules'10219 ········patterns:·'*.rules'
10220 ······register:·find_watch_key10220 ······register:·find_watch_key
10221 ······when:10221 ······when:
10222 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
10223 ······-·'"audit"·in·ansible_facts.packages'10222 ······-·'"audit"·in·ansible_facts.packages'
 10223 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
10224 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched10224 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
10225 ········==·010225 ········==·0
10226 ······tags:10226 ······tags:
10227 ······-·CCE-27168-410227 ······-·CCE-27168-4
10228 ······-·CJIS-5.4.1.110228 ······-·CJIS-5.4.1.1
10229 ······-·NIST-800-171-3.1.810229 ······-·NIST-800-171-3.1.8
10230 ······-·NIST-800-53-AU-12(c)10230 ······-·NIST-800-53-AU-12(c)
Offset 10239, 16 lines modifiedOffset 10239, 16 lines modified
10239 ······-·restrict_strategy10239 ······-·restrict_strategy
  
10240 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule10240 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
10241 ······set_fact:10241 ······set_fact:
10242 ········all_files:10242 ········all_files:
10243 ········-·/etc/audit/rules.d/MAC-policy.rules10243 ········-·/etc/audit/rules.d/MAC-policy.rules
10244 ······when:10244 ······when:
10245 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
10246 ······-·'"audit"·in·ansible_facts.packages'10245 ······-·'"audit"·in·ansible_facts.packages'
 10246 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
10247 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched10247 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
10248 ········is·defined·and·find_existing_watch_rules_d.matched·==·010248 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
10249 ······tags:10249 ······tags:
10250 ······-·CCE-27168-410250 ······-·CCE-27168-4
10251 ······-·CJIS-5.4.1.110251 ······-·CJIS-5.4.1.1
10252 ······-·NIST-800-171-3.1.810252 ······-·NIST-800-171-3.1.8
10253 ······-·NIST-800-53-AU-12(c)10253 ······-·NIST-800-53-AU-12(c)
Offset 10263, 16 lines modifiedOffset 10263, 16 lines modified
10263 ······-·restrict_strategy10263 ······-·restrict_strategy
  
10264 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule10264 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
10265 ······set_fact:10265 ······set_fact:
10266 ········all_files:10266 ········all_files:
10267 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'10267 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
10268 ······when:10268 ······when:
10269 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
10270 ······-·'"audit"·in·ansible_facts.packages'10269 ······-·'"audit"·in·ansible_facts.packages'
 10270 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
10271 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched10271 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
10272 ········is·defined·and·find_existing_watch_rules_d.matched·==·010272 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
10273 ······tags:10273 ······tags:
10274 ······-·CCE-27168-410274 ······-·CCE-27168-4
10275 ······-·CJIS-5.4.1.110275 ······-·CJIS-5.4.1.1
10276 ······-·NIST-800-171-3.1.810276 ······-·NIST-800-171-3.1.8
10277 ······-·NIST-800-53-AU-12(c)10277 ······-·NIST-800-53-AU-12(c)
Offset 10289, 16 lines modifiedOffset 10289, 16 lines modified
10289 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/10289 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 200789/205788 bytes (97.57%) of diff not shown.
788 B
./usr/share/scap-security-guide/ansible/rhel7-playbook-ospp.yml
Ordering differences only
    
Offset 4674, 16 lines modifiedOffset 4674, 16 lines modified
4674 ······lineinfile:4674 ······lineinfile:
4675 ········dest:·/etc/audit/auditd.conf4675 ········dest:·/etc/audit/auditd.conf
4676 ········regexp:·^\s*flush\s*=\s*.*$4676 ········regexp:·^\s*flush\s*=\s*.*$
4677 ········line:·flush·=·{{·var_auditd_flush·}}4677 ········line:·flush·=·{{·var_auditd_flush·}}
4678 ········state:·present4678 ········state:·present
4679 ········create:·true4679 ········create:·true
4680 ······when:4680 ······when:
4681 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4682 ······-·'"audit"·in·ansible_facts.packages'4681 ······-·'"audit"·in·ansible_facts.packages'
 4682 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4683 ······tags:4683 ······tags:
4684 ······-·CCE-27331-84684 ······-·CCE-27331-8
4685 ······-·NIST-800-171-3.3.14685 ······-·NIST-800-171-3.3.1
4686 ······-·NIST-800-53-AU-114686 ······-·NIST-800-53-AU-11
4687 ······-·NIST-800-53-CM-6(a)4687 ······-·NIST-800-53-CM-6(a)
4688 ······-·auditd_data_retention_flush4688 ······-·auditd_data_retention_flush
4689 ······-·low_complexity4689 ······-·low_complexity
108 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-pci-dss.yml
Ordering differences only
    
Offset 4601, 16 lines modifiedOffset 4601, 16 lines modified
  
4601 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension4601 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
4602 ······find:4602 ······find:
4603 ········paths:·/etc/audit/rules.d/4603 ········paths:·/etc/audit/rules.d/
4604 ········patterns:·'*.rules'4604 ········patterns:·'*.rules'
4605 ······register:·find_rules_d4605 ······register:·find_rules_d
4606 ······when:4606 ······when:
4607 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4608 ······-·'"audit"·in·ansible_facts.packages'4607 ······-·'"audit"·in·ansible_facts.packages'
 4608 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4609 ······tags:4609 ······tags:
4610 ······-·CCE-27097-54610 ······-·CCE-27097-5
4611 ······-·CJIS-5.4.1.14611 ······-·CJIS-5.4.1.1
4612 ······-·NIST-800-171-3.3.14612 ······-·NIST-800-171-3.3.1
4613 ······-·NIST-800-171-3.4.34613 ······-·NIST-800-171-3.4.3
4614 ······-·NIST-800-53-AC-6(9)4614 ······-·NIST-800-53-AC-6(9)
4615 ······-·NIST-800-53-CM-6(a)4615 ······-·NIST-800-53-CM-6(a)
Offset 4626, 16 lines modifiedOffset 4626, 16 lines modified
4626 ······lineinfile:4626 ······lineinfile:
4627 ········path:·'{{·item·}}'4627 ········path:·'{{·item·}}'
4628 ········regexp:·^\s*(?:-e)\s+.*$4628 ········regexp:·^\s*(?:-e)\s+.*$
4629 ········state:·absent4629 ········state:·absent
4630 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']4630 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
4631 ········}}'4631 ········}}'
4632 ······when:4632 ······when:
4633 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4634 ······-·'"audit"·in·ansible_facts.packages'4633 ······-·'"audit"·in·ansible_facts.packages'
 4634 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4635 ······tags:4635 ······tags:
4636 ······-·CCE-27097-54636 ······-·CCE-27097-5
4637 ······-·CJIS-5.4.1.14637 ······-·CJIS-5.4.1.1
4638 ······-·NIST-800-171-3.3.14638 ······-·NIST-800-171-3.3.1
4639 ······-·NIST-800-171-3.4.34639 ······-·NIST-800-171-3.4.3
4640 ······-·NIST-800-53-AC-6(9)4640 ······-·NIST-800-53-AC-6(9)
4641 ······-·NIST-800-53-CM-6(a)4641 ······-·NIST-800-53-CM-6(a)
Offset 4653, 16 lines modifiedOffset 4653, 16 lines modified
4653 ········create:·true4653 ········create:·true
4654 ········line:·-e·24654 ········line:·-e·2
4655 ········mode:·o-rwx4655 ········mode:·o-rwx
4656 ······loop:4656 ······loop:
4657 ······-·/etc/audit/audit.rules4657 ······-·/etc/audit/audit.rules
4658 ······-·/etc/audit/rules.d/immutable.rules4658 ······-·/etc/audit/rules.d/immutable.rules
4659 ······when:4659 ······when:
4660 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4661 ······-·'"audit"·in·ansible_facts.packages'4660 ······-·'"audit"·in·ansible_facts.packages'
 4661 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4662 ······tags:4662 ······tags:
4663 ······-·CCE-27097-54663 ······-·CCE-27097-5
4664 ······-·CJIS-5.4.1.14664 ······-·CJIS-5.4.1.1
4665 ······-·NIST-800-171-3.3.14665 ······-·NIST-800-171-3.3.1
4666 ······-·NIST-800-171-3.4.34666 ······-·NIST-800-171-3.4.3
4667 ······-·NIST-800-53-AC-6(9)4667 ······-·NIST-800-53-AC-6(9)
4668 ······-·NIST-800-53-CM-6(a)4668 ······-·NIST-800-53-CM-6(a)
Offset 4696, 16 lines modifiedOffset 4696, 16 lines modified
4696 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/4696 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
4697 ······find:4697 ······find:
4698 ········paths:·/etc/audit/rules.d4698 ········paths:·/etc/audit/rules.d
4699 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+4699 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
4700 ········patterns:·'*.rules'4700 ········patterns:·'*.rules'
4701 ······register:·find_existing_watch_rules_d4701 ······register:·find_existing_watch_rules_d
4702 ······when:4702 ······when:
4703 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4704 ······-·'"audit"·in·ansible_facts.packages'4703 ······-·'"audit"·in·ansible_facts.packages'
 4704 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4705 ······tags:4705 ······tags:
4706 ······-·CCE-27168-44706 ······-·CCE-27168-4
4707 ······-·CJIS-5.4.1.14707 ······-·CJIS-5.4.1.1
4708 ······-·NIST-800-171-3.1.84708 ······-·NIST-800-171-3.1.8
4709 ······-·NIST-800-53-AU-12(c)4709 ······-·NIST-800-53-AU-12(c)
4710 ······-·NIST-800-53-AU-2(d)4710 ······-·NIST-800-53-AU-2(d)
4711 ······-·NIST-800-53-CM-6(a)4711 ······-·NIST-800-53-CM-6(a)
Offset 4720, 16 lines modifiedOffset 4720, 16 lines modified
4720 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy4720 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
4721 ······find:4721 ······find:
4722 ········paths:·/etc/audit/rules.d4722 ········paths:·/etc/audit/rules.d
4723 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$4723 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
4724 ········patterns:·'*.rules'4724 ········patterns:·'*.rules'
4725 ······register:·find_watch_key4725 ······register:·find_watch_key
4726 ······when:4726 ······when:
4727 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4728 ······-·'"audit"·in·ansible_facts.packages'4727 ······-·'"audit"·in·ansible_facts.packages'
 4728 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4729 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4729 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4730 ········==·04730 ········==·0
4731 ······tags:4731 ······tags:
4732 ······-·CCE-27168-44732 ······-·CCE-27168-4
4733 ······-·CJIS-5.4.1.14733 ······-·CJIS-5.4.1.1
4734 ······-·NIST-800-171-3.1.84734 ······-·NIST-800-171-3.1.8
4735 ······-·NIST-800-53-AU-12(c)4735 ······-·NIST-800-53-AU-12(c)
Offset 4744, 16 lines modifiedOffset 4744, 16 lines modified
4744 ······-·restrict_strategy4744 ······-·restrict_strategy
  
4745 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule4745 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
4746 ······set_fact:4746 ······set_fact:
4747 ········all_files:4747 ········all_files:
4748 ········-·/etc/audit/rules.d/MAC-policy.rules4748 ········-·/etc/audit/rules.d/MAC-policy.rules
4749 ······when:4749 ······when:
4750 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4751 ······-·'"audit"·in·ansible_facts.packages'4750 ······-·'"audit"·in·ansible_facts.packages'
 4751 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4752 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched4752 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
4753 ········is·defined·and·find_existing_watch_rules_d.matched·==·04753 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4754 ······tags:4754 ······tags:
4755 ······-·CCE-27168-44755 ······-·CCE-27168-4
4756 ······-·CJIS-5.4.1.14756 ······-·CJIS-5.4.1.1
4757 ······-·NIST-800-171-3.1.84757 ······-·NIST-800-171-3.1.8
4758 ······-·NIST-800-53-AU-12(c)4758 ······-·NIST-800-53-AU-12(c)
Offset 4768, 16 lines modifiedOffset 4768, 16 lines modified
4768 ······-·restrict_strategy4768 ······-·restrict_strategy
  
4769 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule4769 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
4770 ······set_fact:4770 ······set_fact:
4771 ········all_files:4771 ········all_files:
4772 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'4772 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
4773 ······when:4773 ······when:
4774 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4775 ······-·'"audit"·in·ansible_facts.packages'4774 ······-·'"audit"·in·ansible_facts.packages'
 4775 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4776 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched4776 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
4777 ········is·defined·and·find_existing_watch_rules_d.matched·==·04777 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4778 ······tags:4778 ······tags:
4779 ······-·CCE-27168-44779 ······-·CCE-27168-4
4780 ······-·CJIS-5.4.1.14780 ······-·CJIS-5.4.1.1
4781 ······-·NIST-800-171-3.1.84781 ······-·NIST-800-171-3.1.8
4782 ······-·NIST-800-53-AU-12(c)4782 ······-·NIST-800-53-AU-12(c)
Offset 4794, 16 lines modifiedOffset 4794, 16 lines modified
4794 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/4794 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 105371/110354 bytes (95.48%) of diff not shown.
207 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-rhelh-stig.yml
Ordering differences only
    
Offset 8342, 16 lines modifiedOffset 8342, 16 lines modified
  
8342 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension8342 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
8343 ······find:8343 ······find:
8344 ········paths:·/etc/audit/rules.d/8344 ········paths:·/etc/audit/rules.d/
8345 ········patterns:·'*.rules'8345 ········patterns:·'*.rules'
8346 ······register:·find_rules_d8346 ······register:·find_rules_d
8347 ······when:8347 ······when:
8348 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8349 ······-·'"audit"·in·ansible_facts.packages'8348 ······-·'"audit"·in·ansible_facts.packages'
 8349 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8350 ······tags:8350 ······tags:
8351 ······-·CCE-27097-58351 ······-·CCE-27097-5
8352 ······-·CJIS-5.4.1.18352 ······-·CJIS-5.4.1.1
8353 ······-·NIST-800-171-3.3.18353 ······-·NIST-800-171-3.3.1
8354 ······-·NIST-800-171-3.4.38354 ······-·NIST-800-171-3.4.3
8355 ······-·NIST-800-53-AC-6(9)8355 ······-·NIST-800-53-AC-6(9)
8356 ······-·NIST-800-53-CM-6(a)8356 ······-·NIST-800-53-CM-6(a)
Offset 8367, 16 lines modifiedOffset 8367, 16 lines modified
8367 ······lineinfile:8367 ······lineinfile:
8368 ········path:·'{{·item·}}'8368 ········path:·'{{·item·}}'
8369 ········regexp:·^\s*(?:-e)\s+.*$8369 ········regexp:·^\s*(?:-e)\s+.*$
8370 ········state:·absent8370 ········state:·absent
8371 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']8371 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
8372 ········}}'8372 ········}}'
8373 ······when:8373 ······when:
8374 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8375 ······-·'"audit"·in·ansible_facts.packages'8374 ······-·'"audit"·in·ansible_facts.packages'
 8375 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8376 ······tags:8376 ······tags:
8377 ······-·CCE-27097-58377 ······-·CCE-27097-5
8378 ······-·CJIS-5.4.1.18378 ······-·CJIS-5.4.1.1
8379 ······-·NIST-800-171-3.3.18379 ······-·NIST-800-171-3.3.1
8380 ······-·NIST-800-171-3.4.38380 ······-·NIST-800-171-3.4.3
8381 ······-·NIST-800-53-AC-6(9)8381 ······-·NIST-800-53-AC-6(9)
8382 ······-·NIST-800-53-CM-6(a)8382 ······-·NIST-800-53-CM-6(a)
Offset 8394, 16 lines modifiedOffset 8394, 16 lines modified
8394 ········create:·true8394 ········create:·true
8395 ········line:·-e·28395 ········line:·-e·2
8396 ········mode:·o-rwx8396 ········mode:·o-rwx
8397 ······loop:8397 ······loop:
8398 ······-·/etc/audit/audit.rules8398 ······-·/etc/audit/audit.rules
8399 ······-·/etc/audit/rules.d/immutable.rules8399 ······-·/etc/audit/rules.d/immutable.rules
8400 ······when:8400 ······when:
8401 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8402 ······-·'"audit"·in·ansible_facts.packages'8401 ······-·'"audit"·in·ansible_facts.packages'
 8402 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8403 ······tags:8403 ······tags:
8404 ······-·CCE-27097-58404 ······-·CCE-27097-5
8405 ······-·CJIS-5.4.1.18405 ······-·CJIS-5.4.1.1
8406 ······-·NIST-800-171-3.3.18406 ······-·NIST-800-171-3.3.1
8407 ······-·NIST-800-171-3.4.38407 ······-·NIST-800-171-3.4.3
8408 ······-·NIST-800-53-AC-6(9)8408 ······-·NIST-800-53-AC-6(9)
8409 ······-·NIST-800-53-CM-6(a)8409 ······-·NIST-800-53-CM-6(a)
Offset 8437, 16 lines modifiedOffset 8437, 16 lines modified
8437 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/8437 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
8438 ······find:8438 ······find:
8439 ········paths:·/etc/audit/rules.d8439 ········paths:·/etc/audit/rules.d
8440 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+8440 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
8441 ········patterns:·'*.rules'8441 ········patterns:·'*.rules'
8442 ······register:·find_existing_watch_rules_d8442 ······register:·find_existing_watch_rules_d
8443 ······when:8443 ······when:
8444 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8445 ······-·'"audit"·in·ansible_facts.packages'8444 ······-·'"audit"·in·ansible_facts.packages'
 8445 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8446 ······tags:8446 ······tags:
8447 ······-·CCE-27168-48447 ······-·CCE-27168-4
8448 ······-·CJIS-5.4.1.18448 ······-·CJIS-5.4.1.1
8449 ······-·NIST-800-171-3.1.88449 ······-·NIST-800-171-3.1.8
8450 ······-·NIST-800-53-AU-12(c)8450 ······-·NIST-800-53-AU-12(c)
8451 ······-·NIST-800-53-AU-2(d)8451 ······-·NIST-800-53-AU-2(d)
8452 ······-·NIST-800-53-CM-6(a)8452 ······-·NIST-800-53-CM-6(a)
Offset 8461, 16 lines modifiedOffset 8461, 16 lines modified
8461 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy8461 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
8462 ······find:8462 ······find:
8463 ········paths:·/etc/audit/rules.d8463 ········paths:·/etc/audit/rules.d
8464 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$8464 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
8465 ········patterns:·'*.rules'8465 ········patterns:·'*.rules'
8466 ······register:·find_watch_key8466 ······register:·find_watch_key
8467 ······when:8467 ······when:
8468 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8469 ······-·'"audit"·in·ansible_facts.packages'8468 ······-·'"audit"·in·ansible_facts.packages'
 8469 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8470 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched8470 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
8471 ········==·08471 ········==·0
8472 ······tags:8472 ······tags:
8473 ······-·CCE-27168-48473 ······-·CCE-27168-4
8474 ······-·CJIS-5.4.1.18474 ······-·CJIS-5.4.1.1
8475 ······-·NIST-800-171-3.1.88475 ······-·NIST-800-171-3.1.8
8476 ······-·NIST-800-53-AU-12(c)8476 ······-·NIST-800-53-AU-12(c)
Offset 8485, 16 lines modifiedOffset 8485, 16 lines modified
8485 ······-·restrict_strategy8485 ······-·restrict_strategy
  
8486 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule8486 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
8487 ······set_fact:8487 ······set_fact:
8488 ········all_files:8488 ········all_files:
8489 ········-·/etc/audit/rules.d/MAC-policy.rules8489 ········-·/etc/audit/rules.d/MAC-policy.rules
8490 ······when:8490 ······when:
8491 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8492 ······-·'"audit"·in·ansible_facts.packages'8491 ······-·'"audit"·in·ansible_facts.packages'
 8492 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8493 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched8493 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
8494 ········is·defined·and·find_existing_watch_rules_d.matched·==·08494 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
8495 ······tags:8495 ······tags:
8496 ······-·CCE-27168-48496 ······-·CCE-27168-4
8497 ······-·CJIS-5.4.1.18497 ······-·CJIS-5.4.1.1
8498 ······-·NIST-800-171-3.1.88498 ······-·NIST-800-171-3.1.8
8499 ······-·NIST-800-53-AU-12(c)8499 ······-·NIST-800-53-AU-12(c)
Offset 8509, 16 lines modifiedOffset 8509, 16 lines modified
8509 ······-·restrict_strategy8509 ······-·restrict_strategy
  
8510 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule8510 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
8511 ······set_fact:8511 ······set_fact:
8512 ········all_files:8512 ········all_files:
8513 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'8513 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
8514 ······when:8514 ······when:
8515 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
8516 ······-·'"audit"·in·ansible_facts.packages'8515 ······-·'"audit"·in·ansible_facts.packages'
 8516 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
8517 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched8517 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
8518 ········is·defined·and·find_existing_watch_rules_d.matched·==·08518 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
8519 ······tags:8519 ······tags:
8520 ······-·CCE-27168-48520 ······-·CCE-27168-4
8521 ······-·CJIS-5.4.1.18521 ······-·CJIS-5.4.1.1
8522 ······-·NIST-800-171-3.1.88522 ······-·NIST-800-171-3.1.8
8523 ······-·NIST-800-53-AU-12(c)8523 ······-·NIST-800-53-AU-12(c)
Offset 8535, 16 lines modifiedOffset 8535, 16 lines modified
8535 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/8535 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 207000/211983 bytes (97.65%) of diff not shown.
138 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-rhelh-vpp.yml
Ordering differences only
    
Offset 6052, 16 lines modifiedOffset 6052, 16 lines modified
6052 ······-·reboot_required6052 ······-·reboot_required
6053 ······-·restrict_strategy6053 ······-·restrict_strategy
  
6054 ····-·name:·Set·architecture·for·audit·mount·tasks6054 ····-·name:·Set·architecture·for·audit·mount·tasks
6055 ······set_fact:6055 ······set_fact:
6056 ········audit_arch:·b646056 ········audit_arch:·b64
6057 ······when:6057 ······when:
6058 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6059 ······-·'"audit"·in·ansible_facts.packages'6058 ······-·'"audit"·in·ansible_facts.packages'
 6059 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6060 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6060 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6061 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6061 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6062 ······tags:6062 ······tags:
6063 ······-·CCE-27447-26063 ······-·CCE-27447-2
6064 ······-·CJIS-5.4.1.16064 ······-·CJIS-5.4.1.1
6065 ······-·DISA-STIG-RHEL-07-0307406065 ······-·DISA-STIG-RHEL-07-030740
6066 ······-·NIST-800-171-3.1.76066 ······-·NIST-800-171-3.1.7
Offset 6194, 16 lines modifiedOffset 6194, 16 lines modified
6194 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006194 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6195 ············-F·auid!=unset·-F·key=perm_mod6195 ············-F·auid!=unset·-F·key=perm_mod
6196 ··········create:·true6196 ··········create:·true
6197 ··········mode:·o-rwx6197 ··········mode:·o-rwx
6198 ··········state:·present6198 ··········state:·present
6199 ········when:·syscalls_found·|·length·==·06199 ········when:·syscalls_found·|·length·==·0
6200 ······when:6200 ······when:
6201 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6202 ······-·'"audit"·in·ansible_facts.packages'6201 ······-·'"audit"·in·ansible_facts.packages'
 6202 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6203 ······tags:6203 ······tags:
6204 ······-·CCE-27447-26204 ······-·CCE-27447-2
6205 ······-·CJIS-5.4.1.16205 ······-·CJIS-5.4.1.1
6206 ······-·DISA-STIG-RHEL-07-0307406206 ······-·DISA-STIG-RHEL-07-030740
6207 ······-·NIST-800-171-3.1.76207 ······-·NIST-800-171-3.1.7
6208 ······-·NIST-800-53-AC-6(9)6208 ······-·NIST-800-53-AC-6(9)
6209 ······-·NIST-800-53-AU-12(c)6209 ······-·NIST-800-53-AU-12(c)
Offset 6334, 16 lines modifiedOffset 6334, 16 lines modified
6334 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006334 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
6335 ············-F·auid!=unset·-F·key=perm_mod6335 ············-F·auid!=unset·-F·key=perm_mod
6336 ··········create:·true6336 ··········create:·true
6337 ··········mode:·o-rwx6337 ··········mode:·o-rwx
6338 ··········state:·present6338 ··········state:·present
6339 ········when:·syscalls_found·|·length·==·06339 ········when:·syscalls_found·|·length·==·0
6340 ······when:6340 ······when:
6341 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6342 ······-·'"audit"·in·ansible_facts.packages'6341 ······-·'"audit"·in·ansible_facts.packages'
 6342 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6343 ······-·audit_arch·==·"b64"6343 ······-·audit_arch·==·"b64"
6344 ······tags:6344 ······tags:
6345 ······-·CCE-27447-26345 ······-·CCE-27447-2
6346 ······-·CJIS-5.4.1.16346 ······-·CJIS-5.4.1.1
6347 ······-·DISA-STIG-RHEL-07-0307406347 ······-·DISA-STIG-RHEL-07-030740
6348 ······-·NIST-800-171-3.1.76348 ······-·NIST-800-171-3.1.7
6349 ······-·NIST-800-53-AC-6(9)6349 ······-·NIST-800-53-AC-6(9)
Offset 6384, 16 lines modifiedOffset 6384, 16 lines modified
6384 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/6384 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
6385 ······find:6385 ······find:
6386 ········paths:·/etc/audit/rules.d6386 ········paths:·/etc/audit/rules.d
6387 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+6387 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
6388 ········patterns:·'*.rules'6388 ········patterns:·'*.rules'
6389 ······register:·find_existing_watch_rules_d6389 ······register:·find_existing_watch_rules_d
6390 ······when:6390 ······when:
6391 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6392 ······-·'"audit"·in·ansible_facts.packages'6391 ······-·'"audit"·in·ansible_facts.packages'
 6392 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6393 ······tags:6393 ······tags:
6394 ······-·CCE-27461-36394 ······-·CCE-27461-3
6395 ······-·CJIS-5.4.1.16395 ······-·CJIS-5.4.1.1
6396 ······-·DISA-STIG-RHEL-07-0307006396 ······-·DISA-STIG-RHEL-07-030700
6397 ······-·NIST-800-171-3.1.76397 ······-·NIST-800-171-3.1.7
6398 ······-·NIST-800-53-AC-2(7)(b)6398 ······-·NIST-800-53-AC-2(7)(b)
6399 ······-·NIST-800-53-AC-6(9)6399 ······-·NIST-800-53-AC-6(9)
Offset 6412, 16 lines modifiedOffset 6412, 16 lines modified
6412 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions6412 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
6413 ······find:6413 ······find:
6414 ········paths:·/etc/audit/rules.d6414 ········paths:·/etc/audit/rules.d
6415 ········contains:·^.*(?:-F·key=|-k\s+)actions$6415 ········contains:·^.*(?:-F·key=|-k\s+)actions$
6416 ········patterns:·'*.rules'6416 ········patterns:·'*.rules'
6417 ······register:·find_watch_key6417 ······register:·find_watch_key
6418 ······when:6418 ······when:
6419 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6420 ······-·'"audit"·in·ansible_facts.packages'6419 ······-·'"audit"·in·ansible_facts.packages'
 6420 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6421 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched6421 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
6422 ········==·06422 ········==·0
6423 ······tags:6423 ······tags:
6424 ······-·CCE-27461-36424 ······-·CCE-27461-3
6425 ······-·CJIS-5.4.1.16425 ······-·CJIS-5.4.1.1
6426 ······-·DISA-STIG-RHEL-07-0307006426 ······-·DISA-STIG-RHEL-07-030700
6427 ······-·NIST-800-171-3.1.76427 ······-·NIST-800-171-3.1.7
Offset 6440, 16 lines modifiedOffset 6440, 16 lines modified
6440 ······-·restrict_strategy6440 ······-·restrict_strategy
  
6441 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule6441 ····-·name:·Use·/etc/audit/rules.d/actions.rules·as·the·recipient·for·the·rule
6442 ······set_fact:6442 ······set_fact:
6443 ········all_files:6443 ········all_files:
6444 ········-·/etc/audit/rules.d/actions.rules6444 ········-·/etc/audit/rules.d/actions.rules
6445 ······when:6445 ······when:
6446 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6447 ······-·'"audit"·in·ansible_facts.packages'6446 ······-·'"audit"·in·ansible_facts.packages'
 6447 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6448 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched6448 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
6449 ········is·defined·and·find_existing_watch_rules_d.matched·==·06449 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
6450 ······tags:6450 ······tags:
6451 ······-·CCE-27461-36451 ······-·CCE-27461-3
6452 ······-·CJIS-5.4.1.16452 ······-·CJIS-5.4.1.1
6453 ······-·DISA-STIG-RHEL-07-0307006453 ······-·DISA-STIG-RHEL-07-030700
6454 ······-·NIST-800-171-3.1.76454 ······-·NIST-800-171-3.1.7
Offset 6468, 16 lines modifiedOffset 6468, 16 lines modified
6468 ······-·restrict_strategy6468 ······-·restrict_strategy
  
6469 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule6469 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
6470 ······set_fact:6470 ······set_fact:
6471 ········all_files:6471 ········all_files:
6472 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'6472 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
6473 ······when:6473 ······when:
6474 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
6475 ······-·'"audit"·in·ansible_facts.packages'6474 ······-·'"audit"·in·ansible_facts.packages'
 6475 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
6476 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched6476 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
6477 ········is·defined·and·find_existing_watch_rules_d.matched·==·06477 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
6478 ······tags:6478 ······tags:
6479 ······-·CCE-27461-36479 ······-·CCE-27461-3
6480 ······-·CJIS-5.4.1.16480 ······-·CJIS-5.4.1.1
6481 ······-·DISA-STIG-RHEL-07-0307006481 ······-·DISA-STIG-RHEL-07-030700
6482 ······-·NIST-800-171-3.1.76482 ······-·NIST-800-171-3.1.7
Offset 6498, 16 lines modifiedOffset 6498, 16 lines modified
6498 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/6498 ····-·name:·Add·watch·rule·for·/etc/sudoers·in·/etc/audit/rules.d/
Max diff block lines reached; 135626/140859 bytes (96.28%) of diff not shown.
4.03 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-rht-ccp.yml
Ordering differences only
    
Offset 2617, 16 lines modifiedOffset 2617, 16 lines modified
2617 ······-·no_reboot_needed2617 ······-·no_reboot_needed
  
2618 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg2618 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
2619 ······stat:2619 ······stat:
2620 ········path:·/boot/grub2/grub.cfg2620 ········path:·/boot/grub2/grub.cfg
2621 ······register:·file_exists2621 ······register:·file_exists
2622 ······when:2622 ······when:
2623 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2624 ······-·'"grub2-common"·in·ansible_facts.packages'2623 ······-·'"grub2-common"·in·ansible_facts.packages'
 2624 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2625 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2625 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2626 ······tags:2626 ······tags:
2627 ······-·CCE-82023-32627 ······-·CCE-82023-3
2628 ······-·CJIS-5.5.2.22628 ······-·CJIS-5.5.2.2
2629 ······-·NIST-800-171-3.4.52629 ······-·NIST-800-171-3.4.5
2630 ······-·NIST-800-53-AC-6(1)2630 ······-·NIST-800-53-AC-6(1)
2631 ······-·NIST-800-53-CM-6(a)2631 ······-·NIST-800-53-CM-6(a)
Offset 2639, 16 lines modifiedOffset 2639, 16 lines modified
2639 ······-·no_reboot_needed2639 ······-·no_reboot_needed
  
2640 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg2640 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
2641 ······file:2641 ······file:
2642 ········path:·/boot/grub2/grub.cfg2642 ········path:·/boot/grub2/grub.cfg
2643 ········group:·'0'2643 ········group:·'0'
2644 ······when:2644 ······when:
2645 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2646 ······-·'"grub2-common"·in·ansible_facts.packages'2645 ······-·'"grub2-common"·in·ansible_facts.packages'
 2646 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2647 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2647 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2648 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists2648 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
2649 ······tags:2649 ······tags:
2650 ······-·CCE-82023-32650 ······-·CCE-82023-3
2651 ······-·CJIS-5.5.2.22651 ······-·CJIS-5.5.2.2
2652 ······-·NIST-800-171-3.4.52652 ······-·NIST-800-171-3.4.5
2653 ······-·NIST-800-53-AC-6(1)2653 ······-·NIST-800-53-AC-6(1)
Offset 2680, 16 lines modifiedOffset 2680, 16 lines modified
2680 ······-·no_reboot_needed2680 ······-·no_reboot_needed
  
2681 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg2681 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
2682 ······stat:2682 ······stat:
2683 ········path:·/boot/grub2/grub.cfg2683 ········path:·/boot/grub2/grub.cfg
2684 ······register:·file_exists2684 ······register:·file_exists
2685 ······when:2685 ······when:
2686 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2687 ······-·'"grub2-common"·in·ansible_facts.packages'2686 ······-·'"grub2-common"·in·ansible_facts.packages'
 2687 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2688 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2688 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2689 ······tags:2689 ······tags:
2690 ······-·CCE-82026-62690 ······-·CCE-82026-6
2691 ······-·CJIS-5.5.2.22691 ······-·CJIS-5.5.2.2
2692 ······-·NIST-800-171-3.4.52692 ······-·NIST-800-171-3.4.5
2693 ······-·NIST-800-53-AC-6(1)2693 ······-·NIST-800-53-AC-6(1)
2694 ······-·NIST-800-53-CM-6(a)2694 ······-·NIST-800-53-CM-6(a)
Offset 2702, 16 lines modifiedOffset 2702, 16 lines modified
2702 ······-·no_reboot_needed2702 ······-·no_reboot_needed
  
2703 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg2703 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
2704 ······file:2704 ······file:
2705 ········path:·/boot/grub2/grub.cfg2705 ········path:·/boot/grub2/grub.cfg
2706 ········owner:·'0'2706 ········owner:·'0'
2707 ······when:2707 ······when:
2708 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2709 ······-·'"grub2-common"·in·ansible_facts.packages'2708 ······-·'"grub2-common"·in·ansible_facts.packages'
 2709 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2710 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2710 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2711 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists2711 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
2712 ······tags:2712 ······tags:
2713 ······-·CCE-82026-62713 ······-·CCE-82026-6
2714 ······-·CJIS-5.5.2.22714 ······-·CJIS-5.5.2.2
2715 ······-·NIST-800-171-3.4.52715 ······-·NIST-800-171-3.4.5
2716 ······-·NIST-800-53-AC-6(1)2716 ······-·NIST-800-53-AC-6(1)
Offset 2741, 16 lines modifiedOffset 2741, 16 lines modified
2741 ······-·no_reboot_needed2741 ······-·no_reboot_needed
  
2742 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg2742 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
2743 ······stat:2743 ······stat:
2744 ········path:·/boot/grub2/grub.cfg2744 ········path:·/boot/grub2/grub.cfg
2745 ······register:·file_exists2745 ······register:·file_exists
2746 ······when:2746 ······when:
2747 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2748 ······-·'"grub2-common"·in·ansible_facts.packages'2747 ······-·'"grub2-common"·in·ansible_facts.packages'
 2748 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2749 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2749 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2750 ······tags:2750 ······tags:
2751 ······-·CCE-82039-92751 ······-·CCE-82039-9
2752 ······-·NIST-800-171-3.4.52752 ······-·NIST-800-171-3.4.5
2753 ······-·NIST-800-53-AC-6(1)2753 ······-·NIST-800-53-AC-6(1)
2754 ······-·NIST-800-53-CM-6(a)2754 ······-·NIST-800-53-CM-6(a)
2755 ······-·configure_strategy2755 ······-·configure_strategy
Offset 2761, 16 lines modifiedOffset 2761, 16 lines modified
2761 ······-·no_reboot_needed2761 ······-·no_reboot_needed
  
2762 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg2762 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg
2763 ······file:2763 ······file:
2764 ········path:·/boot/grub2/grub.cfg2764 ········path:·/boot/grub2/grub.cfg
2765 ········mode:·u-xs,g-xwrs,o-xwrt2765 ········mode:·u-xs,g-xwrs,o-xwrt
2766 ······when:2766 ······when:
2767 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list' 
2768 ······-·'"grub2-common"·in·ansible_facts.packages'2767 ······-·'"grub2-common"·in·ansible_facts.packages'
 2768 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
2769 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]2769 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
2770 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists2770 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
2771 ······tags:2771 ······tags:
2772 ······-·CCE-82039-92772 ······-·CCE-82039-9
2773 ······-·NIST-800-171-3.4.52773 ······-·NIST-800-171-3.4.5
2774 ······-·NIST-800-53-AC-6(1)2774 ······-·NIST-800-53-AC-6(1)
2775 ······-·NIST-800-53-CM-6(a)2775 ······-·NIST-800-53-CM-6(a)
84.0 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-standard.yml
Ordering differences only
    
Offset 668, 16 lines modifiedOffset 668, 16 lines modified
668 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/668 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
669 ······find:669 ······find:
670 ········paths:·/etc/audit/rules.d670 ········paths:·/etc/audit/rules.d
671 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+671 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
672 ········patterns:·'*.rules'672 ········patterns:·'*.rules'
673 ······register:·find_existing_watch_rules_d673 ······register:·find_existing_watch_rules_d
674 ······when:674 ······when:
675 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
676 ······-·'"audit"·in·ansible_facts.packages'675 ······-·'"audit"·in·ansible_facts.packages'
 676 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
677 ······tags:677 ······tags:
678 ······-·CCE-27168-4678 ······-·CCE-27168-4
679 ······-·CJIS-5.4.1.1679 ······-·CJIS-5.4.1.1
680 ······-·NIST-800-171-3.1.8680 ······-·NIST-800-171-3.1.8
681 ······-·NIST-800-53-AU-12(c)681 ······-·NIST-800-53-AU-12(c)
682 ······-·NIST-800-53-AU-2(d)682 ······-·NIST-800-53-AU-2(d)
683 ······-·NIST-800-53-CM-6(a)683 ······-·NIST-800-53-CM-6(a)
Offset 692, 16 lines modifiedOffset 692, 16 lines modified
692 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy692 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
693 ······find:693 ······find:
694 ········paths:·/etc/audit/rules.d694 ········paths:·/etc/audit/rules.d
695 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$695 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
696 ········patterns:·'*.rules'696 ········patterns:·'*.rules'
697 ······register:·find_watch_key697 ······register:·find_watch_key
698 ······when:698 ······when:
699 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
700 ······-·'"audit"·in·ansible_facts.packages'699 ······-·'"audit"·in·ansible_facts.packages'
 700 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
701 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched701 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
702 ········==·0702 ········==·0
703 ······tags:703 ······tags:
704 ······-·CCE-27168-4704 ······-·CCE-27168-4
705 ······-·CJIS-5.4.1.1705 ······-·CJIS-5.4.1.1
706 ······-·NIST-800-171-3.1.8706 ······-·NIST-800-171-3.1.8
707 ······-·NIST-800-53-AU-12(c)707 ······-·NIST-800-53-AU-12(c)
Offset 716, 16 lines modifiedOffset 716, 16 lines modified
716 ······-·restrict_strategy716 ······-·restrict_strategy
  
717 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule717 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
718 ······set_fact:718 ······set_fact:
719 ········all_files:719 ········all_files:
720 ········-·/etc/audit/rules.d/MAC-policy.rules720 ········-·/etc/audit/rules.d/MAC-policy.rules
721 ······when:721 ······when:
722 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
723 ······-·'"audit"·in·ansible_facts.packages'722 ······-·'"audit"·in·ansible_facts.packages'
 723 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
724 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched724 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
725 ········is·defined·and·find_existing_watch_rules_d.matched·==·0725 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
726 ······tags:726 ······tags:
727 ······-·CCE-27168-4727 ······-·CCE-27168-4
728 ······-·CJIS-5.4.1.1728 ······-·CJIS-5.4.1.1
729 ······-·NIST-800-171-3.1.8729 ······-·NIST-800-171-3.1.8
730 ······-·NIST-800-53-AU-12(c)730 ······-·NIST-800-53-AU-12(c)
Offset 740, 16 lines modifiedOffset 740, 16 lines modified
740 ······-·restrict_strategy740 ······-·restrict_strategy
  
741 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule741 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
742 ······set_fact:742 ······set_fact:
743 ········all_files:743 ········all_files:
744 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'744 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
745 ······when:745 ······when:
746 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
747 ······-·'"audit"·in·ansible_facts.packages'746 ······-·'"audit"·in·ansible_facts.packages'
 747 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
748 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched748 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
749 ········is·defined·and·find_existing_watch_rules_d.matched·==·0749 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
750 ······tags:750 ······tags:
751 ······-·CCE-27168-4751 ······-·CCE-27168-4
752 ······-·CJIS-5.4.1.1752 ······-·CJIS-5.4.1.1
753 ······-·NIST-800-171-3.1.8753 ······-·NIST-800-171-3.1.8
754 ······-·NIST-800-53-AU-12(c)754 ······-·NIST-800-53-AU-12(c)
Offset 766, 16 lines modifiedOffset 766, 16 lines modified
766 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/766 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
767 ······lineinfile:767 ······lineinfile:
768 ········path:·'{{·all_files[0]·}}'768 ········path:·'{{·all_files[0]·}}'
769 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy769 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
770 ········create:·true770 ········create:·true
771 ········mode:·'0640'771 ········mode:·'0640'
772 ······when:772 ······when:
773 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
774 ······-·'"audit"·in·ansible_facts.packages'773 ······-·'"audit"·in·ansible_facts.packages'
 774 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
775 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched775 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
776 ········==·0776 ········==·0
777 ······tags:777 ······tags:
778 ······-·CCE-27168-4778 ······-·CCE-27168-4
779 ······-·CJIS-5.4.1.1779 ······-·CJIS-5.4.1.1
780 ······-·NIST-800-171-3.1.8780 ······-·NIST-800-171-3.1.8
781 ······-·NIST-800-53-AU-12(c)781 ······-·NIST-800-53-AU-12(c)
Offset 792, 16 lines modifiedOffset 792, 16 lines modified
792 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules792 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules
793 ······find:793 ······find:
794 ········paths:·/etc/audit/794 ········paths:·/etc/audit/
795 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+795 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
796 ········patterns:·audit.rules796 ········patterns:·audit.rules
797 ······register:·find_existing_watch_audit_rules797 ······register:·find_existing_watch_audit_rules
798 ······when:798 ······when:
799 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
800 ······-·'"audit"·in·ansible_facts.packages'799 ······-·'"audit"·in·ansible_facts.packages'
 800 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
801 ······tags:801 ······tags:
802 ······-·CCE-27168-4802 ······-·CCE-27168-4
803 ······-·CJIS-5.4.1.1803 ······-·CJIS-5.4.1.1
804 ······-·NIST-800-171-3.1.8804 ······-·NIST-800-171-3.1.8
805 ······-·NIST-800-53-AU-12(c)805 ······-·NIST-800-53-AU-12(c)
806 ······-·NIST-800-53-AU-2(d)806 ······-·NIST-800-53-AU-2(d)
807 ······-·NIST-800-53-CM-6(a)807 ······-·NIST-800-53-CM-6(a)
Offset 817, 16 lines modifiedOffset 817, 16 lines modified
817 ······lineinfile:817 ······lineinfile:
818 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy818 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
819 ········state:·present819 ········state:·present
820 ········dest:·/etc/audit/audit.rules820 ········dest:·/etc/audit/audit.rules
821 ········create:·true821 ········create:·true
822 ········mode:·'0640'822 ········mode:·'0640'
823 ······when:823 ······when:
824 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
825 ······-·'"audit"·in·ansible_facts.packages'824 ······-·'"audit"·in·ansible_facts.packages'
 825 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
826 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched826 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
827 ········==·0827 ········==·0
828 ······tags:828 ······tags:
829 ······-·CCE-27168-4829 ······-·CCE-27168-4
830 ······-·CJIS-5.4.1.1830 ······-·CJIS-5.4.1.1
831 ······-·NIST-800-171-3.1.8831 ······-·NIST-800-171-3.1.8
832 ······-·NIST-800-53-AU-12(c)832 ······-·NIST-800-53-AU-12(c)
Offset 861, 16 lines modifiedOffset 861, 16 lines modified
861 ······-·reboot_required861 ······-·reboot_required
Max diff block lines reached; 80706/85868 bytes (93.99%) of diff not shown.
143 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-stig.yml
Ordering differences only
    
Offset 9553, 16 lines modifiedOffset 9553, 16 lines modified
9553 ······-·reboot_required9553 ······-·reboot_required
9554 ······-·restrict_strategy9554 ······-·restrict_strategy
  
9555 ····-·name:·Set·architecture·for·audit·mount·tasks9555 ····-·name:·Set·architecture·for·audit·mount·tasks
9556 ······set_fact:9556 ······set_fact:
9557 ········audit_arch:·b649557 ········audit_arch:·b64
9558 ······when:9558 ······when:
9559 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9560 ······-·'"audit"·in·ansible_facts.packages'9559 ······-·'"audit"·in·ansible_facts.packages'
 9560 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9561 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture9561 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
9562 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"9562 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
9563 ······tags:9563 ······tags:
9564 ······-·CCE-27447-29564 ······-·CCE-27447-2
9565 ······-·CJIS-5.4.1.19565 ······-·CJIS-5.4.1.1
9566 ······-·DISA-STIG-RHEL-07-0307409566 ······-·DISA-STIG-RHEL-07-030740
9567 ······-·NIST-800-171-3.1.79567 ······-·NIST-800-171-3.1.7
Offset 9695, 16 lines modifiedOffset 9695, 16 lines modified
9695 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009695 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9696 ············-F·auid!=unset·-F·key=perm_mod9696 ············-F·auid!=unset·-F·key=perm_mod
9697 ··········create:·true9697 ··········create:·true
9698 ··········mode:·o-rwx9698 ··········mode:·o-rwx
9699 ··········state:·present9699 ··········state:·present
9700 ········when:·syscalls_found·|·length·==·09700 ········when:·syscalls_found·|·length·==·0
9701 ······when:9701 ······when:
9702 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9703 ······-·'"audit"·in·ansible_facts.packages'9702 ······-·'"audit"·in·ansible_facts.packages'
 9703 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9704 ······tags:9704 ······tags:
9705 ······-·CCE-27447-29705 ······-·CCE-27447-2
9706 ······-·CJIS-5.4.1.19706 ······-·CJIS-5.4.1.1
9707 ······-·DISA-STIG-RHEL-07-0307409707 ······-·DISA-STIG-RHEL-07-030740
9708 ······-·NIST-800-171-3.1.79708 ······-·NIST-800-171-3.1.7
9709 ······-·NIST-800-53-AC-6(9)9709 ······-·NIST-800-53-AC-6(9)
9710 ······-·NIST-800-53-AU-12(c)9710 ······-·NIST-800-53-AU-12(c)
Offset 9835, 16 lines modifiedOffset 9835, 16 lines modified
9835 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009835 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9836 ············-F·auid!=unset·-F·key=perm_mod9836 ············-F·auid!=unset·-F·key=perm_mod
9837 ··········create:·true9837 ··········create:·true
9838 ··········mode:·o-rwx9838 ··········mode:·o-rwx
9839 ··········state:·present9839 ··········state:·present
9840 ········when:·syscalls_found·|·length·==·09840 ········when:·syscalls_found·|·length·==·0
9841 ······when:9841 ······when:
9842 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9843 ······-·'"audit"·in·ansible_facts.packages'9842 ······-·'"audit"·in·ansible_facts.packages'
 9843 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9844 ······-·audit_arch·==·"b64"9844 ······-·audit_arch·==·"b64"
9845 ······tags:9845 ······tags:
9846 ······-·CCE-27447-29846 ······-·CCE-27447-2
9847 ······-·CJIS-5.4.1.19847 ······-·CJIS-5.4.1.1
9848 ······-·DISA-STIG-RHEL-07-0307409848 ······-·DISA-STIG-RHEL-07-030740
9849 ······-·NIST-800-171-3.1.79849 ······-·NIST-800-171-3.1.7
9850 ······-·NIST-800-53-AC-6(9)9850 ······-·NIST-800-53-AC-6(9)
Offset 9878, 16 lines modifiedOffset 9878, 16 lines modified
9878 ······-·medium_severity9878 ······-·medium_severity
9879 ······-·no_reboot_needed9879 ······-·no_reboot_needed
9880 ······-·restrict_strategy9880 ······-·restrict_strategy
  
9881 ····-·name:·Service·facts9881 ····-·name:·Service·facts
9882 ······service_facts:·null9882 ······service_facts:·null
9883 ······when:9883 ······when:
9884 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9885 ······-·'"audit"·in·ansible_facts.packages'9884 ······-·'"audit"·in·ansible_facts.packages'
 9885 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9886 ······tags:9886 ······tags:
9887 ······-·CCE-83555-39887 ······-·CCE-83555-3
9888 ······-·DISA-STIG-RHEL-07-0303609888 ······-·DISA-STIG-RHEL-07-030360
9889 ······-·NIST-800-53-AC-6(9)9889 ······-·NIST-800-53-AC-6(9)
9890 ······-·NIST-800-53-AU-12(3)9890 ······-·NIST-800-53-AU-12(3)
9891 ······-·NIST-800-53-AU-7(a)9891 ······-·NIST-800-53-AU-7(a)
9892 ······-·NIST-800-53-AU-7(b)9892 ······-·NIST-800-53-AU-7(b)
Offset 9900, 16 lines modifiedOffset 9900, 16 lines modified
9900 ······-·no_reboot_needed9900 ······-·no_reboot_needed
9901 ······-·restrict_strategy9901 ······-·restrict_strategy
  
9902 ····-·name:·Check·the·rules·script·being·used9902 ····-·name:·Check·the·rules·script·being·used
9903 ······command:·grep·'^ExecStartPost'·/usr/lib/systemd/system/auditd.service9903 ······command:·grep·'^ExecStartPost'·/usr/lib/systemd/system/auditd.service
9904 ······register:·check_rules_scripts_result9904 ······register:·check_rules_scripts_result
9905 ······when:9905 ······when:
9906 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9907 ······-·'"audit"·in·ansible_facts.packages'9906 ······-·'"audit"·in·ansible_facts.packages'
 9907 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9908 ······tags:9908 ······tags:
9909 ······-·CCE-83555-39909 ······-·CCE-83555-3
9910 ······-·DISA-STIG-RHEL-07-0303609910 ······-·DISA-STIG-RHEL-07-030360
9911 ······-·NIST-800-53-AC-6(9)9911 ······-·NIST-800-53-AC-6(9)
9912 ······-·NIST-800-53-AU-12(3)9912 ······-·NIST-800-53-AU-12(3)
9913 ······-·NIST-800-53-AU-7(a)9913 ······-·NIST-800-53-AU-7(a)
9914 ······-·NIST-800-53-AU-7(b)9914 ······-·NIST-800-53-AU-7(b)
Offset 9926, 16 lines modifiedOffset 9926, 16 lines modified
9926 ······set_fact:9926 ······set_fact:
9927 ········suid_audit_rules:9927 ········suid_audit_rules:
9928 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid9928 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid
9929 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid9929 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid
9930 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid9930 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid
9931 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid9931 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid
9932 ······when:9932 ······when:
9933 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9934 ······-·'"audit"·in·ansible_facts.packages'9933 ······-·'"audit"·in·ansible_facts.packages'
 9934 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9935 ······tags:9935 ······tags:
9936 ······-·CCE-83555-39936 ······-·CCE-83555-3
9937 ······-·DISA-STIG-RHEL-07-0303609937 ······-·DISA-STIG-RHEL-07-030360
9938 ······-·NIST-800-53-AC-6(9)9938 ······-·NIST-800-53-AC-6(9)
9939 ······-·NIST-800-53-AU-12(3)9939 ······-·NIST-800-53-AU-12(3)
9940 ······-·NIST-800-53-AU-7(a)9940 ······-·NIST-800-53-AU-7(a)
9941 ······-·NIST-800-53-AU-7(b)9941 ······-·NIST-800-53-AU-7(b)
Offset 9950, 16 lines modifiedOffset 9950, 16 lines modified
  
9950 ····-·name:·Update·/etc/audit/rules.d/privileged.rules·to·audit·privileged·functions9950 ····-·name:·Update·/etc/audit/rules.d/privileged.rules·to·audit·privileged·functions
9951 ······lineinfile:9951 ······lineinfile:
9952 ········path:·/etc/audit/rules.d/privileged.rules9952 ········path:·/etc/audit/rules.d/privileged.rules
9953 ········line:·'{{··item··}}'9953 ········line:·'{{··item··}}'
9954 ········create:·true9954 ········create:·true
9955 ······when:9955 ······when:
9956 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9957 ······-·'"audit"·in·ansible_facts.packages'9956 ······-·'"audit"·in·ansible_facts.packages'
 9957 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9958 ······-·'"auditd.service"·in·ansible_facts.services'9958 ······-·'"auditd.service"·in·ansible_facts.services'
9959 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'9959 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
9960 ······register:·augenrules_audit_rules_privilege_function_update_result9960 ······register:·augenrules_audit_rules_privilege_function_update_result
9961 ······with_items:·'{{·suid_audit_rules·}}'9961 ······with_items:·'{{·suid_audit_rules·}}'
9962 ······tags:9962 ······tags:
9963 ······-·CCE-83555-39963 ······-·CCE-83555-3
9964 ······-·DISA-STIG-RHEL-07-0303609964 ······-·DISA-STIG-RHEL-07-030360
Offset 9978, 16 lines modifiedOffset 9978, 16 lines modified
  
Max diff block lines reached; 141490/146602 bytes (96.51%) of diff not shown.
143 KB
./usr/share/scap-security-guide/ansible/rhel7-playbook-stig_gui.yml
Ordering differences only
    
Offset 9558, 16 lines modifiedOffset 9558, 16 lines modified
9558 ······-·reboot_required9558 ······-·reboot_required
9559 ······-·restrict_strategy9559 ······-·restrict_strategy
  
9560 ····-·name:·Set·architecture·for·audit·mount·tasks9560 ····-·name:·Set·architecture·for·audit·mount·tasks
9561 ······set_fact:9561 ······set_fact:
9562 ········audit_arch:·b649562 ········audit_arch:·b64
9563 ······when:9563 ······when:
9564 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9565 ······-·'"audit"·in·ansible_facts.packages'9564 ······-·'"audit"·in·ansible_facts.packages'
 9565 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9566 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture9566 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
9567 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"9567 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
9568 ······tags:9568 ······tags:
9569 ······-·CCE-27447-29569 ······-·CCE-27447-2
9570 ······-·CJIS-5.4.1.19570 ······-·CJIS-5.4.1.1
9571 ······-·DISA-STIG-RHEL-07-0307409571 ······-·DISA-STIG-RHEL-07-030740
9572 ······-·NIST-800-171-3.1.79572 ······-·NIST-800-171-3.1.7
Offset 9700, 16 lines modifiedOffset 9700, 16 lines modified
9700 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009700 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9701 ············-F·auid!=unset·-F·key=perm_mod9701 ············-F·auid!=unset·-F·key=perm_mod
9702 ··········create:·true9702 ··········create:·true
9703 ··········mode:·o-rwx9703 ··········mode:·o-rwx
9704 ··········state:·present9704 ··········state:·present
9705 ········when:·syscalls_found·|·length·==·09705 ········when:·syscalls_found·|·length·==·0
9706 ······when:9706 ······when:
9707 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9708 ······-·'"audit"·in·ansible_facts.packages'9707 ······-·'"audit"·in·ansible_facts.packages'
 9708 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9709 ······tags:9709 ······tags:
9710 ······-·CCE-27447-29710 ······-·CCE-27447-2
9711 ······-·CJIS-5.4.1.19711 ······-·CJIS-5.4.1.1
9712 ······-·DISA-STIG-RHEL-07-0307409712 ······-·DISA-STIG-RHEL-07-030740
9713 ······-·NIST-800-171-3.1.79713 ······-·NIST-800-171-3.1.7
9714 ······-·NIST-800-53-AC-6(9)9714 ······-·NIST-800-53-AC-6(9)
9715 ······-·NIST-800-53-AU-12(c)9715 ······-·NIST-800-53-AU-12(c)
Offset 9840, 16 lines modifiedOffset 9840, 16 lines modified
9840 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10009840 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
9841 ············-F·auid!=unset·-F·key=perm_mod9841 ············-F·auid!=unset·-F·key=perm_mod
9842 ··········create:·true9842 ··········create:·true
9843 ··········mode:·o-rwx9843 ··········mode:·o-rwx
9844 ··········state:·present9844 ··········state:·present
9845 ········when:·syscalls_found·|·length·==·09845 ········when:·syscalls_found·|·length·==·0
9846 ······when:9846 ······when:
9847 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9848 ······-·'"audit"·in·ansible_facts.packages'9847 ······-·'"audit"·in·ansible_facts.packages'
 9848 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9849 ······-·audit_arch·==·"b64"9849 ······-·audit_arch·==·"b64"
9850 ······tags:9850 ······tags:
9851 ······-·CCE-27447-29851 ······-·CCE-27447-2
9852 ······-·CJIS-5.4.1.19852 ······-·CJIS-5.4.1.1
9853 ······-·DISA-STIG-RHEL-07-0307409853 ······-·DISA-STIG-RHEL-07-030740
9854 ······-·NIST-800-171-3.1.79854 ······-·NIST-800-171-3.1.7
9855 ······-·NIST-800-53-AC-6(9)9855 ······-·NIST-800-53-AC-6(9)
Offset 9883, 16 lines modifiedOffset 9883, 16 lines modified
9883 ······-·medium_severity9883 ······-·medium_severity
9884 ······-·no_reboot_needed9884 ······-·no_reboot_needed
9885 ······-·restrict_strategy9885 ······-·restrict_strategy
  
9886 ····-·name:·Service·facts9886 ····-·name:·Service·facts
9887 ······service_facts:·null9887 ······service_facts:·null
9888 ······when:9888 ······when:
9889 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9890 ······-·'"audit"·in·ansible_facts.packages'9889 ······-·'"audit"·in·ansible_facts.packages'
 9890 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9891 ······tags:9891 ······tags:
9892 ······-·CCE-83555-39892 ······-·CCE-83555-3
9893 ······-·DISA-STIG-RHEL-07-0303609893 ······-·DISA-STIG-RHEL-07-030360
9894 ······-·NIST-800-53-AC-6(9)9894 ······-·NIST-800-53-AC-6(9)
9895 ······-·NIST-800-53-AU-12(3)9895 ······-·NIST-800-53-AU-12(3)
9896 ······-·NIST-800-53-AU-7(a)9896 ······-·NIST-800-53-AU-7(a)
9897 ······-·NIST-800-53-AU-7(b)9897 ······-·NIST-800-53-AU-7(b)
Offset 9905, 16 lines modifiedOffset 9905, 16 lines modified
9905 ······-·no_reboot_needed9905 ······-·no_reboot_needed
9906 ······-·restrict_strategy9906 ······-·restrict_strategy
  
9907 ····-·name:·Check·the·rules·script·being·used9907 ····-·name:·Check·the·rules·script·being·used
9908 ······command:·grep·'^ExecStartPost'·/usr/lib/systemd/system/auditd.service9908 ······command:·grep·'^ExecStartPost'·/usr/lib/systemd/system/auditd.service
9909 ······register:·check_rules_scripts_result9909 ······register:·check_rules_scripts_result
9910 ······when:9910 ······when:
9911 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9912 ······-·'"audit"·in·ansible_facts.packages'9911 ······-·'"audit"·in·ansible_facts.packages'
 9912 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9913 ······tags:9913 ······tags:
9914 ······-·CCE-83555-39914 ······-·CCE-83555-3
9915 ······-·DISA-STIG-RHEL-07-0303609915 ······-·DISA-STIG-RHEL-07-030360
9916 ······-·NIST-800-53-AC-6(9)9916 ······-·NIST-800-53-AC-6(9)
9917 ······-·NIST-800-53-AU-12(3)9917 ······-·NIST-800-53-AU-12(3)
9918 ······-·NIST-800-53-AU-7(a)9918 ······-·NIST-800-53-AU-7(a)
9919 ······-·NIST-800-53-AU-7(b)9919 ······-·NIST-800-53-AU-7(b)
Offset 9931, 16 lines modifiedOffset 9931, 16 lines modified
9931 ······set_fact:9931 ······set_fact:
9932 ········suid_audit_rules:9932 ········suid_audit_rules:
9933 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid9933 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid
9934 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid9934 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·gid!=egid·-F·egid=0·-k·setgid
9935 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid9935 ········-·-a·always,exit·-F·arch=b32·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid
9936 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid9936 ········-·-a·always,exit·-F·arch=b64·-S·execve·-C·uid!=euid·-F·euid=0·-k·setuid
9937 ······when:9937 ······when:
9938 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9939 ······-·'"audit"·in·ansible_facts.packages'9938 ······-·'"audit"·in·ansible_facts.packages'
 9939 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9940 ······tags:9940 ······tags:
9941 ······-·CCE-83555-39941 ······-·CCE-83555-3
9942 ······-·DISA-STIG-RHEL-07-0303609942 ······-·DISA-STIG-RHEL-07-030360
9943 ······-·NIST-800-53-AC-6(9)9943 ······-·NIST-800-53-AC-6(9)
9944 ······-·NIST-800-53-AU-12(3)9944 ······-·NIST-800-53-AU-12(3)
9945 ······-·NIST-800-53-AU-7(a)9945 ······-·NIST-800-53-AU-7(a)
9946 ······-·NIST-800-53-AU-7(b)9946 ······-·NIST-800-53-AU-7(b)
Offset 9955, 16 lines modifiedOffset 9955, 16 lines modified
  
9955 ····-·name:·Update·/etc/audit/rules.d/privileged.rules·to·audit·privileged·functions9955 ····-·name:·Update·/etc/audit/rules.d/privileged.rules·to·audit·privileged·functions
9956 ······lineinfile:9956 ······lineinfile:
9957 ········path:·/etc/audit/rules.d/privileged.rules9957 ········path:·/etc/audit/rules.d/privileged.rules
9958 ········line:·'{{··item··}}'9958 ········line:·'{{··item··}}'
9959 ········create:·true9959 ········create:·true
9960 ······when:9960 ······when:
9961 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
9962 ······-·'"audit"·in·ansible_facts.packages'9961 ······-·'"audit"·in·ansible_facts.packages'
 9962 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
9963 ······-·'"auditd.service"·in·ansible_facts.services'9963 ······-·'"auditd.service"·in·ansible_facts.services'
9964 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'9964 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
9965 ······register:·augenrules_audit_rules_privilege_function_update_result9965 ······register:·augenrules_audit_rules_privilege_function_update_result
9966 ······with_items:·'{{·suid_audit_rules·}}'9966 ······with_items:·'{{·suid_audit_rules·}}'
9967 ······tags:9967 ······tags:
9968 ······-·CCE-83555-39968 ······-·CCE-83555-3
9969 ······-·DISA-STIG-RHEL-07-0303609969 ······-·DISA-STIG-RHEL-07-030360
Offset 9983, 16 lines modifiedOffset 9983, 16 lines modified
  
Max diff block lines reached; 141490/146602 bytes (96.51%) of diff not shown.
854 B
./usr/share/scap-security-guide/ansible/rhel8-playbook-anssi_bp28_enhanced.yml
Ordering differences only
    
Offset 5746, 16 lines modifiedOffset 5746, 16 lines modified
5746 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5746 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5747 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5747 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5748 ··········create:·true5748 ··········create:·true
5749 ··········mode:·o-rwx5749 ··········mode:·o-rwx
5750 ··········state:·present5750 ··········state:·present
5751 ········when:·syscalls_found·|·length·==·05751 ········when:·syscalls_found·|·length·==·0
5752 ······when:5752 ······when:
5753 ······-·'"audit"·in·ansible_facts.packages' 
5754 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5753 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5754 ······-·'"audit"·in·ansible_facts.packages'
5755 ······tags:5755 ······tags:
5756 ······-·CCE-80737-05756 ······-·CCE-80737-0
5757 ······-·DISA-STIG-RHEL-08-0305505757 ······-·DISA-STIG-RHEL-08-030550
5758 ······-·NIST-800-171-3.1.75758 ······-·NIST-800-171-3.1.7
5759 ······-·NIST-800-53-AC-6(9)5759 ······-·NIST-800-53-AC-6(9)
5760 ······-·NIST-800-53-AU-12(c)5760 ······-·NIST-800-53-AU-12(c)
5761 ······-·NIST-800-53-AU-2(d)5761 ······-·NIST-800-53-AU-2(d)
846 B
./usr/share/scap-security-guide/ansible/rhel8-playbook-anssi_bp28_high.yml
Ordering differences only
    
Offset 5900, 16 lines modifiedOffset 5900, 16 lines modified
5900 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5900 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5901 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5901 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5902 ··········create:·true5902 ··········create:·true
5903 ··········mode:·o-rwx5903 ··········mode:·o-rwx
5904 ··········state:·present5904 ··········state:·present
5905 ········when:·syscalls_found·|·length·==·05905 ········when:·syscalls_found·|·length·==·0
5906 ······when:5906 ······when:
5907 ······-·'"audit"·in·ansible_facts.packages' 
5908 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5907 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5908 ······-·'"audit"·in·ansible_facts.packages'
5909 ······tags:5909 ······tags:
5910 ······-·CCE-80737-05910 ······-·CCE-80737-0
5911 ······-·DISA-STIG-RHEL-08-0305505911 ······-·DISA-STIG-RHEL-08-030550
5912 ······-·NIST-800-171-3.1.75912 ······-·NIST-800-171-3.1.7
5913 ······-·NIST-800-53-AC-6(9)5913 ······-·NIST-800-53-AC-6(9)
5914 ······-·NIST-800-53-AU-12(c)5914 ······-·NIST-800-53-AU-12(c)
5915 ······-·NIST-800-53-AU-2(d)5915 ······-·NIST-800-53-AU-2(d)
862 B
./usr/share/scap-security-guide/ansible/rhel8-playbook-anssi_bp28_intermediary.yml
Ordering differences only
    
Offset 5457, 16 lines modifiedOffset 5457, 16 lines modified
5457 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5457 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5458 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5458 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5459 ··········create:·true5459 ··········create:·true
5460 ··········mode:·o-rwx5460 ··········mode:·o-rwx
5461 ··········state:·present5461 ··········state:·present
5462 ········when:·syscalls_found·|·length·==·05462 ········when:·syscalls_found·|·length·==·0
5463 ······when:5463 ······when:
5464 ······-·'"audit"·in·ansible_facts.packages' 
5465 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5464 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5465 ······-·'"audit"·in·ansible_facts.packages'
5466 ······tags:5466 ······tags:
5467 ······-·CCE-80737-05467 ······-·CCE-80737-0
5468 ······-·DISA-STIG-RHEL-08-0305505468 ······-·DISA-STIG-RHEL-08-030550
5469 ······-·NIST-800-171-3.1.75469 ······-·NIST-800-171-3.1.7
5470 ······-·NIST-800-53-AC-6(9)5470 ······-·NIST-800-53-AC-6(9)
5471 ······-·NIST-800-53-AU-12(c)5471 ······-·NIST-800-53-AU-12(c)
5472 ······-·NIST-800-53-AU-2(d)5472 ······-·NIST-800-53-AU-2(d)
159 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-cis.yml
Ordering differences only
    
Offset 5653, 16 lines modifiedOffset 5653, 16 lines modified
  
5653 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5653 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5654 ······find:5654 ······find:
5655 ········paths:·/etc/audit/rules.d/5655 ········paths:·/etc/audit/rules.d/
5656 ········patterns:·'*.rules'5656 ········patterns:·'*.rules'
5657 ······register:·find_rules_d5657 ······register:·find_rules_d
5658 ······when:5658 ······when:
5659 ······-·'"audit"·in·ansible_facts.packages' 
5660 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5659 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5660 ······-·'"audit"·in·ansible_facts.packages'
5661 ······tags:5661 ······tags:
5662 ······-·CCE-80708-15662 ······-·CCE-80708-1
5663 ······-·CJIS-5.4.1.15663 ······-·CJIS-5.4.1.1
5664 ······-·DISA-STIG-RHEL-08-0301215664 ······-·DISA-STIG-RHEL-08-030121
5665 ······-·NIST-800-171-3.3.15665 ······-·NIST-800-171-3.3.1
5666 ······-·NIST-800-171-3.4.35666 ······-·NIST-800-171-3.4.3
5667 ······-·NIST-800-53-AC-6(9)5667 ······-·NIST-800-53-AC-6(9)
Offset 5679, 16 lines modifiedOffset 5679, 16 lines modified
5679 ······lineinfile:5679 ······lineinfile:
5680 ········path:·'{{·item·}}'5680 ········path:·'{{·item·}}'
5681 ········regexp:·^\s*(?:-e)\s+.*$5681 ········regexp:·^\s*(?:-e)\s+.*$
5682 ········state:·absent5682 ········state:·absent
5683 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5683 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5684 ········}}'5684 ········}}'
5685 ······when:5685 ······when:
5686 ······-·'"audit"·in·ansible_facts.packages' 
5687 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5686 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5687 ······-·'"audit"·in·ansible_facts.packages'
5688 ······tags:5688 ······tags:
5689 ······-·CCE-80708-15689 ······-·CCE-80708-1
5690 ······-·CJIS-5.4.1.15690 ······-·CJIS-5.4.1.1
5691 ······-·DISA-STIG-RHEL-08-0301215691 ······-·DISA-STIG-RHEL-08-030121
5692 ······-·NIST-800-171-3.3.15692 ······-·NIST-800-171-3.3.1
5693 ······-·NIST-800-171-3.4.35693 ······-·NIST-800-171-3.4.3
5694 ······-·NIST-800-53-AC-6(9)5694 ······-·NIST-800-53-AC-6(9)
Offset 5707, 16 lines modifiedOffset 5707, 16 lines modified
5707 ········create:·true5707 ········create:·true
5708 ········line:·-e·25708 ········line:·-e·2
5709 ········mode:·o-rwx5709 ········mode:·o-rwx
5710 ······loop:5710 ······loop:
5711 ······-·/etc/audit/audit.rules5711 ······-·/etc/audit/audit.rules
5712 ······-·/etc/audit/rules.d/immutable.rules5712 ······-·/etc/audit/rules.d/immutable.rules
5713 ······when:5713 ······when:
5714 ······-·'"audit"·in·ansible_facts.packages' 
5715 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5714 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5715 ······-·'"audit"·in·ansible_facts.packages'
5716 ······tags:5716 ······tags:
5717 ······-·CCE-80708-15717 ······-·CCE-80708-1
5718 ······-·CJIS-5.4.1.15718 ······-·CJIS-5.4.1.1
5719 ······-·DISA-STIG-RHEL-08-0301215719 ······-·DISA-STIG-RHEL-08-030121
5720 ······-·NIST-800-171-3.3.15720 ······-·NIST-800-171-3.3.1
5721 ······-·NIST-800-171-3.4.35721 ······-·NIST-800-171-3.4.3
5722 ······-·NIST-800-53-AC-6(9)5722 ······-·NIST-800-53-AC-6(9)
Offset 5751, 16 lines modifiedOffset 5751, 16 lines modified
5751 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5751 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5752 ······find:5752 ······find:
5753 ········paths:·/etc/audit/rules.d5753 ········paths:·/etc/audit/rules.d
5754 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5754 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5755 ········patterns:·'*.rules'5755 ········patterns:·'*.rules'
5756 ······register:·find_existing_watch_rules_d5756 ······register:·find_existing_watch_rules_d
5757 ······when:5757 ······when:
5758 ······-·'"audit"·in·ansible_facts.packages' 
5759 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5758 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5759 ······-·'"audit"·in·ansible_facts.packages'
5760 ······tags:5760 ······tags:
5761 ······-·CCE-80721-45761 ······-·CCE-80721-4
5762 ······-·CJIS-5.4.1.15762 ······-·CJIS-5.4.1.1
5763 ······-·NIST-800-171-3.1.85763 ······-·NIST-800-171-3.1.8
5764 ······-·NIST-800-53-AU-12(c)5764 ······-·NIST-800-53-AU-12(c)
5765 ······-·NIST-800-53-AU-2(d)5765 ······-·NIST-800-53-AU-2(d)
5766 ······-·NIST-800-53-CM-6(a)5766 ······-·NIST-800-53-CM-6(a)
Offset 5775, 16 lines modifiedOffset 5775, 16 lines modified
5775 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5775 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5776 ······find:5776 ······find:
5777 ········paths:·/etc/audit/rules.d5777 ········paths:·/etc/audit/rules.d
5778 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5778 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5779 ········patterns:·'*.rules'5779 ········patterns:·'*.rules'
5780 ······register:·find_watch_key5780 ······register:·find_watch_key
5781 ······when:5781 ······when:
5782 ······-·'"audit"·in·ansible_facts.packages' 
5783 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5782 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5783 ······-·'"audit"·in·ansible_facts.packages'
5784 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5784 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5785 ········==·05785 ········==·0
5786 ······tags:5786 ······tags:
5787 ······-·CCE-80721-45787 ······-·CCE-80721-4
5788 ······-·CJIS-5.4.1.15788 ······-·CJIS-5.4.1.1
5789 ······-·NIST-800-171-3.1.85789 ······-·NIST-800-171-3.1.8
5790 ······-·NIST-800-53-AU-12(c)5790 ······-·NIST-800-53-AU-12(c)
Offset 5799, 16 lines modifiedOffset 5799, 16 lines modified
5799 ······-·restrict_strategy5799 ······-·restrict_strategy
  
5800 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5800 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5801 ······set_fact:5801 ······set_fact:
5802 ········all_files:5802 ········all_files:
5803 ········-·/etc/audit/rules.d/MAC-policy.rules5803 ········-·/etc/audit/rules.d/MAC-policy.rules
5804 ······when:5804 ······when:
5805 ······-·'"audit"·in·ansible_facts.packages' 
5806 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5805 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5806 ······-·'"audit"·in·ansible_facts.packages'
5807 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5807 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5808 ········is·defined·and·find_existing_watch_rules_d.matched·==·05808 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5809 ······tags:5809 ······tags:
5810 ······-·CCE-80721-45810 ······-·CCE-80721-4
5811 ······-·CJIS-5.4.1.15811 ······-·CJIS-5.4.1.1
5812 ······-·NIST-800-171-3.1.85812 ······-·NIST-800-171-3.1.8
5813 ······-·NIST-800-53-AU-12(c)5813 ······-·NIST-800-53-AU-12(c)
Offset 5823, 16 lines modifiedOffset 5823, 16 lines modified
5823 ······-·restrict_strategy5823 ······-·restrict_strategy
  
5824 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5824 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5825 ······set_fact:5825 ······set_fact:
5826 ········all_files:5826 ········all_files:
5827 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5827 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5828 ······when:5828 ······when:
5829 ······-·'"audit"·in·ansible_facts.packages' 
5830 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5829 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5830 ······-·'"audit"·in·ansible_facts.packages'
5831 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5831 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5832 ········is·defined·and·find_existing_watch_rules_d.matched·==·05832 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5833 ······tags:5833 ······tags:
5834 ······-·CCE-80721-45834 ······-·CCE-80721-4
5835 ······-·CJIS-5.4.1.15835 ······-·CJIS-5.4.1.1
5836 ······-·NIST-800-171-3.1.85836 ······-·NIST-800-171-3.1.8
5837 ······-·NIST-800-53-AU-12(c)5837 ······-·NIST-800-53-AU-12(c)
Offset 5849, 16 lines modifiedOffset 5849, 16 lines modified
5849 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5849 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 158076/162724 bytes (97.14%) of diff not shown.
7.62 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-cis_server_l1.yml
Ordering differences only
    
Offset 5473, 16 lines modifiedOffset 5473, 16 lines modified
5473 ······-·no_reboot_needed5473 ······-·no_reboot_needed
  
5474 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5474 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5475 ······stat:5475 ······stat:
5476 ········path:·/boot/grub2/grub.cfg5476 ········path:·/boot/grub2/grub.cfg
5477 ······register:·file_exists5477 ······register:·file_exists
5478 ······when:5478 ······when:
5479 ······-·'"grub2-common"·in·ansible_facts.packages' 
5480 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5479 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5480 ······-·'"grub2-common"·in·ansible_facts.packages'
5481 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5481 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5482 ······tags:5482 ······tags:
5483 ······-·CCE-80800-65483 ······-·CCE-80800-6
5484 ······-·CJIS-5.5.2.25484 ······-·CJIS-5.5.2.2
5485 ······-·NIST-800-171-3.4.55485 ······-·NIST-800-171-3.4.5
5486 ······-·NIST-800-53-AC-6(1)5486 ······-·NIST-800-53-AC-6(1)
5487 ······-·NIST-800-53-CM-6(a)5487 ······-·NIST-800-53-CM-6(a)
Offset 5495, 16 lines modifiedOffset 5495, 16 lines modified
5495 ······-·no_reboot_needed5495 ······-·no_reboot_needed
  
5496 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg5496 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
5497 ······file:5497 ······file:
5498 ········path:·/boot/grub2/grub.cfg5498 ········path:·/boot/grub2/grub.cfg
5499 ········group:·'0'5499 ········group:·'0'
5500 ······when:5500 ······when:
5501 ······-·'"grub2-common"·in·ansible_facts.packages' 
5502 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5501 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5502 ······-·'"grub2-common"·in·ansible_facts.packages'
5503 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5503 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5504 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5504 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5505 ······tags:5505 ······tags:
5506 ······-·CCE-80800-65506 ······-·CCE-80800-6
5507 ······-·CJIS-5.5.2.25507 ······-·CJIS-5.5.2.2
5508 ······-·NIST-800-171-3.4.55508 ······-·NIST-800-171-3.4.5
5509 ······-·NIST-800-53-AC-6(1)5509 ······-·NIST-800-53-AC-6(1)
Offset 5536, 16 lines modifiedOffset 5536, 16 lines modified
5536 ······-·no_reboot_needed5536 ······-·no_reboot_needed
  
5537 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5537 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5538 ······stat:5538 ······stat:
5539 ········path:·/boot/grub2/user.cfg5539 ········path:·/boot/grub2/user.cfg
5540 ······register:·file_exists5540 ······register:·file_exists
5541 ······when:5541 ······when:
5542 ······-·'"grub2-common"·in·ansible_facts.packages' 
5543 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5542 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5543 ······-·'"grub2-common"·in·ansible_facts.packages'
5544 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5544 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5545 ······tags:5545 ······tags:
5546 ······-·CCE-86009-85546 ······-·CCE-86009-8
5547 ······-·CJIS-5.5.2.25547 ······-·CJIS-5.5.2.2
5548 ······-·NIST-800-171-3.4.55548 ······-·NIST-800-171-3.4.5
5549 ······-·NIST-800-53-AC-6(1)5549 ······-·NIST-800-53-AC-6(1)
5550 ······-·NIST-800-53-CM-6(a)5550 ······-·NIST-800-53-CM-6(a)
Offset 5558, 16 lines modifiedOffset 5558, 16 lines modified
5558 ······-·no_reboot_needed5558 ······-·no_reboot_needed
  
5559 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg5559 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
5560 ······file:5560 ······file:
5561 ········path:·/boot/grub2/user.cfg5561 ········path:·/boot/grub2/user.cfg
5562 ········group:·'0'5562 ········group:·'0'
5563 ······when:5563 ······when:
5564 ······-·'"grub2-common"·in·ansible_facts.packages' 
5565 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5564 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5565 ······-·'"grub2-common"·in·ansible_facts.packages'
5566 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5566 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5567 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5567 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5568 ······tags:5568 ······tags:
5569 ······-·CCE-86009-85569 ······-·CCE-86009-8
5570 ······-·CJIS-5.5.2.25570 ······-·CJIS-5.5.2.2
5571 ······-·NIST-800-171-3.4.55571 ······-·NIST-800-171-3.4.5
5572 ······-·NIST-800-53-AC-6(1)5572 ······-·NIST-800-53-AC-6(1)
Offset 5599, 16 lines modifiedOffset 5599, 16 lines modified
5599 ······-·no_reboot_needed5599 ······-·no_reboot_needed
  
5600 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5600 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5601 ······stat:5601 ······stat:
5602 ········path:·/boot/grub2/grub.cfg5602 ········path:·/boot/grub2/grub.cfg
5603 ······register:·file_exists5603 ······register:·file_exists
5604 ······when:5604 ······when:
5605 ······-·'"grub2-common"·in·ansible_facts.packages' 
5606 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5605 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5606 ······-·'"grub2-common"·in·ansible_facts.packages'
5607 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5607 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5608 ······tags:5608 ······tags:
5609 ······-·CCE-80805-55609 ······-·CCE-80805-5
5610 ······-·CJIS-5.5.2.25610 ······-·CJIS-5.5.2.2
5611 ······-·NIST-800-171-3.4.55611 ······-·NIST-800-171-3.4.5
5612 ······-·NIST-800-53-AC-6(1)5612 ······-·NIST-800-53-AC-6(1)
5613 ······-·NIST-800-53-CM-6(a)5613 ······-·NIST-800-53-CM-6(a)
Offset 5621, 16 lines modifiedOffset 5621, 16 lines modified
5621 ······-·no_reboot_needed5621 ······-·no_reboot_needed
  
5622 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg5622 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
5623 ······file:5623 ······file:
5624 ········path:·/boot/grub2/grub.cfg5624 ········path:·/boot/grub2/grub.cfg
5625 ········owner:·'0'5625 ········owner:·'0'
5626 ······when:5626 ······when:
5627 ······-·'"grub2-common"·in·ansible_facts.packages' 
5628 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5627 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5628 ······-·'"grub2-common"·in·ansible_facts.packages'
5629 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5629 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5630 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5630 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5631 ······tags:5631 ······tags:
5632 ······-·CCE-80805-55632 ······-·CCE-80805-5
5633 ······-·CJIS-5.5.2.25633 ······-·CJIS-5.5.2.2
5634 ······-·NIST-800-171-3.4.55634 ······-·NIST-800-171-3.4.5
5635 ······-·NIST-800-53-AC-6(1)5635 ······-·NIST-800-53-AC-6(1)
Offset 5662, 16 lines modifiedOffset 5662, 16 lines modified
5662 ······-·no_reboot_needed5662 ······-·no_reboot_needed
  
5663 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5663 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5664 ······stat:5664 ······stat:
5665 ········path:·/boot/grub2/user.cfg5665 ········path:·/boot/grub2/user.cfg
5666 ······register:·file_exists5666 ······register:·file_exists
5667 ······when:5667 ······when:
5668 ······-·'"grub2-common"·in·ansible_facts.packages' 
5669 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5668 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5669 ······-·'"grub2-common"·in·ansible_facts.packages'
5670 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5670 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5671 ······tags:5671 ······tags:
5672 ······-·CCE-86015-55672 ······-·CCE-86015-5
5673 ······-·CJIS-5.5.2.25673 ······-·CJIS-5.5.2.2
5674 ······-·NIST-800-171-3.4.55674 ······-·NIST-800-171-3.4.5
5675 ······-·NIST-800-53-AC-6(1)5675 ······-·NIST-800-53-AC-6(1)
5676 ······-·NIST-800-53-CM-6(a)5676 ······-·NIST-800-53-CM-6(a)
Offset 5684, 16 lines modifiedOffset 5684, 16 lines modified
5684 ······-·no_reboot_needed5684 ······-·no_reboot_needed
Max diff block lines reached; 3194/7634 bytes (41.84%) of diff not shown.
7.63 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-cis_workstation_l1.yml
Ordering differences only
    
Offset 5473, 16 lines modifiedOffset 5473, 16 lines modified
5473 ······-·no_reboot_needed5473 ······-·no_reboot_needed
  
5474 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5474 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5475 ······stat:5475 ······stat:
5476 ········path:·/boot/grub2/grub.cfg5476 ········path:·/boot/grub2/grub.cfg
5477 ······register:·file_exists5477 ······register:·file_exists
5478 ······when:5478 ······when:
5479 ······-·'"grub2-common"·in·ansible_facts.packages' 
5480 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5479 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5480 ······-·'"grub2-common"·in·ansible_facts.packages'
5481 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5481 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5482 ······tags:5482 ······tags:
5483 ······-·CCE-80800-65483 ······-·CCE-80800-6
5484 ······-·CJIS-5.5.2.25484 ······-·CJIS-5.5.2.2
5485 ······-·NIST-800-171-3.4.55485 ······-·NIST-800-171-3.4.5
5486 ······-·NIST-800-53-AC-6(1)5486 ······-·NIST-800-53-AC-6(1)
5487 ······-·NIST-800-53-CM-6(a)5487 ······-·NIST-800-53-CM-6(a)
Offset 5495, 16 lines modifiedOffset 5495, 16 lines modified
5495 ······-·no_reboot_needed5495 ······-·no_reboot_needed
  
5496 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg5496 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
5497 ······file:5497 ······file:
5498 ········path:·/boot/grub2/grub.cfg5498 ········path:·/boot/grub2/grub.cfg
5499 ········group:·'0'5499 ········group:·'0'
5500 ······when:5500 ······when:
5501 ······-·'"grub2-common"·in·ansible_facts.packages' 
5502 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5501 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5502 ······-·'"grub2-common"·in·ansible_facts.packages'
5503 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5503 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5504 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5504 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5505 ······tags:5505 ······tags:
5506 ······-·CCE-80800-65506 ······-·CCE-80800-6
5507 ······-·CJIS-5.5.2.25507 ······-·CJIS-5.5.2.2
5508 ······-·NIST-800-171-3.4.55508 ······-·NIST-800-171-3.4.5
5509 ······-·NIST-800-53-AC-6(1)5509 ······-·NIST-800-53-AC-6(1)
Offset 5536, 16 lines modifiedOffset 5536, 16 lines modified
5536 ······-·no_reboot_needed5536 ······-·no_reboot_needed
  
5537 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5537 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5538 ······stat:5538 ······stat:
5539 ········path:·/boot/grub2/user.cfg5539 ········path:·/boot/grub2/user.cfg
5540 ······register:·file_exists5540 ······register:·file_exists
5541 ······when:5541 ······when:
5542 ······-·'"grub2-common"·in·ansible_facts.packages' 
5543 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5542 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5543 ······-·'"grub2-common"·in·ansible_facts.packages'
5544 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5544 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5545 ······tags:5545 ······tags:
5546 ······-·CCE-86009-85546 ······-·CCE-86009-8
5547 ······-·CJIS-5.5.2.25547 ······-·CJIS-5.5.2.2
5548 ······-·NIST-800-171-3.4.55548 ······-·NIST-800-171-3.4.5
5549 ······-·NIST-800-53-AC-6(1)5549 ······-·NIST-800-53-AC-6(1)
5550 ······-·NIST-800-53-CM-6(a)5550 ······-·NIST-800-53-CM-6(a)
Offset 5558, 16 lines modifiedOffset 5558, 16 lines modified
5558 ······-·no_reboot_needed5558 ······-·no_reboot_needed
  
5559 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg5559 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
5560 ······file:5560 ······file:
5561 ········path:·/boot/grub2/user.cfg5561 ········path:·/boot/grub2/user.cfg
5562 ········group:·'0'5562 ········group:·'0'
5563 ······when:5563 ······when:
5564 ······-·'"grub2-common"·in·ansible_facts.packages' 
5565 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5564 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5565 ······-·'"grub2-common"·in·ansible_facts.packages'
5566 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5566 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5567 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5567 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5568 ······tags:5568 ······tags:
5569 ······-·CCE-86009-85569 ······-·CCE-86009-8
5570 ······-·CJIS-5.5.2.25570 ······-·CJIS-5.5.2.2
5571 ······-·NIST-800-171-3.4.55571 ······-·NIST-800-171-3.4.5
5572 ······-·NIST-800-53-AC-6(1)5572 ······-·NIST-800-53-AC-6(1)
Offset 5599, 16 lines modifiedOffset 5599, 16 lines modified
5599 ······-·no_reboot_needed5599 ······-·no_reboot_needed
  
5600 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5600 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5601 ······stat:5601 ······stat:
5602 ········path:·/boot/grub2/grub.cfg5602 ········path:·/boot/grub2/grub.cfg
5603 ······register:·file_exists5603 ······register:·file_exists
5604 ······when:5604 ······when:
5605 ······-·'"grub2-common"·in·ansible_facts.packages' 
5606 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5605 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5606 ······-·'"grub2-common"·in·ansible_facts.packages'
5607 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5607 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5608 ······tags:5608 ······tags:
5609 ······-·CCE-80805-55609 ······-·CCE-80805-5
5610 ······-·CJIS-5.5.2.25610 ······-·CJIS-5.5.2.2
5611 ······-·NIST-800-171-3.4.55611 ······-·NIST-800-171-3.4.5
5612 ······-·NIST-800-53-AC-6(1)5612 ······-·NIST-800-53-AC-6(1)
5613 ······-·NIST-800-53-CM-6(a)5613 ······-·NIST-800-53-CM-6(a)
Offset 5621, 16 lines modifiedOffset 5621, 16 lines modified
5621 ······-·no_reboot_needed5621 ······-·no_reboot_needed
  
5622 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg5622 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
5623 ······file:5623 ······file:
5624 ········path:·/boot/grub2/grub.cfg5624 ········path:·/boot/grub2/grub.cfg
5625 ········owner:·'0'5625 ········owner:·'0'
5626 ······when:5626 ······when:
5627 ······-·'"grub2-common"·in·ansible_facts.packages' 
5628 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5627 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5628 ······-·'"grub2-common"·in·ansible_facts.packages'
5629 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5629 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5630 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5630 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5631 ······tags:5631 ······tags:
5632 ······-·CCE-80805-55632 ······-·CCE-80805-5
5633 ······-·CJIS-5.5.2.25633 ······-·CJIS-5.5.2.2
5634 ······-·NIST-800-171-3.4.55634 ······-·NIST-800-171-3.4.5
5635 ······-·NIST-800-53-AC-6(1)5635 ······-·NIST-800-53-AC-6(1)
Offset 5662, 16 lines modifiedOffset 5662, 16 lines modified
5662 ······-·no_reboot_needed5662 ······-·no_reboot_needed
  
5663 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5663 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5664 ······stat:5664 ······stat:
5665 ········path:·/boot/grub2/user.cfg5665 ········path:·/boot/grub2/user.cfg
5666 ······register:·file_exists5666 ······register:·file_exists
5667 ······when:5667 ······when:
5668 ······-·'"grub2-common"·in·ansible_facts.packages' 
5669 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5668 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5669 ······-·'"grub2-common"·in·ansible_facts.packages'
5670 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5670 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5671 ······tags:5671 ······tags:
5672 ······-·CCE-86015-55672 ······-·CCE-86015-5
5673 ······-·CJIS-5.5.2.25673 ······-·CJIS-5.5.2.2
5674 ······-·NIST-800-171-3.4.55674 ······-·NIST-800-171-3.4.5
5675 ······-·NIST-800-53-AC-6(1)5675 ······-·NIST-800-53-AC-6(1)
5676 ······-·NIST-800-53-CM-6(a)5676 ······-·NIST-800-53-CM-6(a)
Offset 5684, 16 lines modifiedOffset 5684, 16 lines modified
5684 ······-·no_reboot_needed5684 ······-·no_reboot_needed
Max diff block lines reached; 3194/7634 bytes (41.84%) of diff not shown.
159 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-cis_workstation_l2.yml
Ordering differences only
    
Offset 5653, 16 lines modifiedOffset 5653, 16 lines modified
  
5653 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5653 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5654 ······find:5654 ······find:
5655 ········paths:·/etc/audit/rules.d/5655 ········paths:·/etc/audit/rules.d/
5656 ········patterns:·'*.rules'5656 ········patterns:·'*.rules'
5657 ······register:·find_rules_d5657 ······register:·find_rules_d
5658 ······when:5658 ······when:
5659 ······-·'"audit"·in·ansible_facts.packages' 
5660 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5659 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5660 ······-·'"audit"·in·ansible_facts.packages'
5661 ······tags:5661 ······tags:
5662 ······-·CCE-80708-15662 ······-·CCE-80708-1
5663 ······-·CJIS-5.4.1.15663 ······-·CJIS-5.4.1.1
5664 ······-·DISA-STIG-RHEL-08-0301215664 ······-·DISA-STIG-RHEL-08-030121
5665 ······-·NIST-800-171-3.3.15665 ······-·NIST-800-171-3.3.1
5666 ······-·NIST-800-171-3.4.35666 ······-·NIST-800-171-3.4.3
5667 ······-·NIST-800-53-AC-6(9)5667 ······-·NIST-800-53-AC-6(9)
Offset 5679, 16 lines modifiedOffset 5679, 16 lines modified
5679 ······lineinfile:5679 ······lineinfile:
5680 ········path:·'{{·item·}}'5680 ········path:·'{{·item·}}'
5681 ········regexp:·^\s*(?:-e)\s+.*$5681 ········regexp:·^\s*(?:-e)\s+.*$
5682 ········state:·absent5682 ········state:·absent
5683 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5683 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5684 ········}}'5684 ········}}'
5685 ······when:5685 ······when:
5686 ······-·'"audit"·in·ansible_facts.packages' 
5687 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5686 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5687 ······-·'"audit"·in·ansible_facts.packages'
5688 ······tags:5688 ······tags:
5689 ······-·CCE-80708-15689 ······-·CCE-80708-1
5690 ······-·CJIS-5.4.1.15690 ······-·CJIS-5.4.1.1
5691 ······-·DISA-STIG-RHEL-08-0301215691 ······-·DISA-STIG-RHEL-08-030121
5692 ······-·NIST-800-171-3.3.15692 ······-·NIST-800-171-3.3.1
5693 ······-·NIST-800-171-3.4.35693 ······-·NIST-800-171-3.4.3
5694 ······-·NIST-800-53-AC-6(9)5694 ······-·NIST-800-53-AC-6(9)
Offset 5707, 16 lines modifiedOffset 5707, 16 lines modified
5707 ········create:·true5707 ········create:·true
5708 ········line:·-e·25708 ········line:·-e·2
5709 ········mode:·o-rwx5709 ········mode:·o-rwx
5710 ······loop:5710 ······loop:
5711 ······-·/etc/audit/audit.rules5711 ······-·/etc/audit/audit.rules
5712 ······-·/etc/audit/rules.d/immutable.rules5712 ······-·/etc/audit/rules.d/immutable.rules
5713 ······when:5713 ······when:
5714 ······-·'"audit"·in·ansible_facts.packages' 
5715 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5714 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5715 ······-·'"audit"·in·ansible_facts.packages'
5716 ······tags:5716 ······tags:
5717 ······-·CCE-80708-15717 ······-·CCE-80708-1
5718 ······-·CJIS-5.4.1.15718 ······-·CJIS-5.4.1.1
5719 ······-·DISA-STIG-RHEL-08-0301215719 ······-·DISA-STIG-RHEL-08-030121
5720 ······-·NIST-800-171-3.3.15720 ······-·NIST-800-171-3.3.1
5721 ······-·NIST-800-171-3.4.35721 ······-·NIST-800-171-3.4.3
5722 ······-·NIST-800-53-AC-6(9)5722 ······-·NIST-800-53-AC-6(9)
Offset 5751, 16 lines modifiedOffset 5751, 16 lines modified
5751 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5751 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5752 ······find:5752 ······find:
5753 ········paths:·/etc/audit/rules.d5753 ········paths:·/etc/audit/rules.d
5754 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5754 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5755 ········patterns:·'*.rules'5755 ········patterns:·'*.rules'
5756 ······register:·find_existing_watch_rules_d5756 ······register:·find_existing_watch_rules_d
5757 ······when:5757 ······when:
5758 ······-·'"audit"·in·ansible_facts.packages' 
5759 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5758 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5759 ······-·'"audit"·in·ansible_facts.packages'
5760 ······tags:5760 ······tags:
5761 ······-·CCE-80721-45761 ······-·CCE-80721-4
5762 ······-·CJIS-5.4.1.15762 ······-·CJIS-5.4.1.1
5763 ······-·NIST-800-171-3.1.85763 ······-·NIST-800-171-3.1.8
5764 ······-·NIST-800-53-AU-12(c)5764 ······-·NIST-800-53-AU-12(c)
5765 ······-·NIST-800-53-AU-2(d)5765 ······-·NIST-800-53-AU-2(d)
5766 ······-·NIST-800-53-CM-6(a)5766 ······-·NIST-800-53-CM-6(a)
Offset 5775, 16 lines modifiedOffset 5775, 16 lines modified
5775 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5775 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5776 ······find:5776 ······find:
5777 ········paths:·/etc/audit/rules.d5777 ········paths:·/etc/audit/rules.d
5778 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5778 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5779 ········patterns:·'*.rules'5779 ········patterns:·'*.rules'
5780 ······register:·find_watch_key5780 ······register:·find_watch_key
5781 ······when:5781 ······when:
5782 ······-·'"audit"·in·ansible_facts.packages' 
5783 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5782 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5783 ······-·'"audit"·in·ansible_facts.packages'
5784 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5784 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5785 ········==·05785 ········==·0
5786 ······tags:5786 ······tags:
5787 ······-·CCE-80721-45787 ······-·CCE-80721-4
5788 ······-·CJIS-5.4.1.15788 ······-·CJIS-5.4.1.1
5789 ······-·NIST-800-171-3.1.85789 ······-·NIST-800-171-3.1.8
5790 ······-·NIST-800-53-AU-12(c)5790 ······-·NIST-800-53-AU-12(c)
Offset 5799, 16 lines modifiedOffset 5799, 16 lines modified
5799 ······-·restrict_strategy5799 ······-·restrict_strategy
  
5800 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5800 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5801 ······set_fact:5801 ······set_fact:
5802 ········all_files:5802 ········all_files:
5803 ········-·/etc/audit/rules.d/MAC-policy.rules5803 ········-·/etc/audit/rules.d/MAC-policy.rules
5804 ······when:5804 ······when:
5805 ······-·'"audit"·in·ansible_facts.packages' 
5806 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5805 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5806 ······-·'"audit"·in·ansible_facts.packages'
5807 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5807 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5808 ········is·defined·and·find_existing_watch_rules_d.matched·==·05808 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5809 ······tags:5809 ······tags:
5810 ······-·CCE-80721-45810 ······-·CCE-80721-4
5811 ······-·CJIS-5.4.1.15811 ······-·CJIS-5.4.1.1
5812 ······-·NIST-800-171-3.1.85812 ······-·NIST-800-171-3.1.8
5813 ······-·NIST-800-53-AU-12(c)5813 ······-·NIST-800-53-AU-12(c)
Offset 5823, 16 lines modifiedOffset 5823, 16 lines modified
5823 ······-·restrict_strategy5823 ······-·restrict_strategy
  
5824 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5824 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5825 ······set_fact:5825 ······set_fact:
5826 ········all_files:5826 ········all_files:
5827 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5827 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5828 ······when:5828 ······when:
5829 ······-·'"audit"·in·ansible_facts.packages' 
5830 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5829 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5830 ······-·'"audit"·in·ansible_facts.packages'
5831 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5831 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5832 ········is·defined·and·find_existing_watch_rules_d.matched·==·05832 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5833 ······tags:5833 ······tags:
5834 ······-·CCE-80721-45834 ······-·CCE-80721-4
5835 ······-·CJIS-5.4.1.15835 ······-·CJIS-5.4.1.1
5836 ······-·NIST-800-171-3.1.85836 ······-·NIST-800-171-3.1.8
5837 ······-·NIST-800-53-AU-12(c)5837 ······-·NIST-800-53-AU-12(c)
Offset 5849, 16 lines modifiedOffset 5849, 16 lines modified
5849 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5849 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 158076/162724 bytes (97.14%) of diff not shown.
100 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-cjis.yml
Ordering differences only
    
Offset 3049, 16 lines modifiedOffset 3049, 16 lines modified
  
3049 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension3049 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
3050 ······find:3050 ······find:
3051 ········paths:·/etc/audit/rules.d/3051 ········paths:·/etc/audit/rules.d/
3052 ········patterns:·'*.rules'3052 ········patterns:·'*.rules'
3053 ······register:·find_rules_d3053 ······register:·find_rules_d
3054 ······when:3054 ······when:
3055 ······-·'"audit"·in·ansible_facts.packages' 
3056 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3055 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3056 ······-·'"audit"·in·ansible_facts.packages'
3057 ······tags:3057 ······tags:
3058 ······-·CCE-80708-13058 ······-·CCE-80708-1
3059 ······-·CJIS-5.4.1.13059 ······-·CJIS-5.4.1.1
3060 ······-·DISA-STIG-RHEL-08-0301213060 ······-·DISA-STIG-RHEL-08-030121
3061 ······-·NIST-800-171-3.3.13061 ······-·NIST-800-171-3.3.1
3062 ······-·NIST-800-171-3.4.33062 ······-·NIST-800-171-3.4.3
3063 ······-·NIST-800-53-AC-6(9)3063 ······-·NIST-800-53-AC-6(9)
Offset 3075, 16 lines modifiedOffset 3075, 16 lines modified
3075 ······lineinfile:3075 ······lineinfile:
3076 ········path:·'{{·item·}}'3076 ········path:·'{{·item·}}'
3077 ········regexp:·^\s*(?:-e)\s+.*$3077 ········regexp:·^\s*(?:-e)\s+.*$
3078 ········state:·absent3078 ········state:·absent
3079 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']3079 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
3080 ········}}'3080 ········}}'
3081 ······when:3081 ······when:
3082 ······-·'"audit"·in·ansible_facts.packages' 
3083 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3082 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3083 ······-·'"audit"·in·ansible_facts.packages'
3084 ······tags:3084 ······tags:
3085 ······-·CCE-80708-13085 ······-·CCE-80708-1
3086 ······-·CJIS-5.4.1.13086 ······-·CJIS-5.4.1.1
3087 ······-·DISA-STIG-RHEL-08-0301213087 ······-·DISA-STIG-RHEL-08-030121
3088 ······-·NIST-800-171-3.3.13088 ······-·NIST-800-171-3.3.1
3089 ······-·NIST-800-171-3.4.33089 ······-·NIST-800-171-3.4.3
3090 ······-·NIST-800-53-AC-6(9)3090 ······-·NIST-800-53-AC-6(9)
Offset 3103, 16 lines modifiedOffset 3103, 16 lines modified
3103 ········create:·true3103 ········create:·true
3104 ········line:·-e·23104 ········line:·-e·2
3105 ········mode:·o-rwx3105 ········mode:·o-rwx
3106 ······loop:3106 ······loop:
3107 ······-·/etc/audit/audit.rules3107 ······-·/etc/audit/audit.rules
3108 ······-·/etc/audit/rules.d/immutable.rules3108 ······-·/etc/audit/rules.d/immutable.rules
3109 ······when:3109 ······when:
3110 ······-·'"audit"·in·ansible_facts.packages' 
3111 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3110 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3111 ······-·'"audit"·in·ansible_facts.packages'
3112 ······tags:3112 ······tags:
3113 ······-·CCE-80708-13113 ······-·CCE-80708-1
3114 ······-·CJIS-5.4.1.13114 ······-·CJIS-5.4.1.1
3115 ······-·DISA-STIG-RHEL-08-0301213115 ······-·DISA-STIG-RHEL-08-030121
3116 ······-·NIST-800-171-3.3.13116 ······-·NIST-800-171-3.3.1
3117 ······-·NIST-800-171-3.4.33117 ······-·NIST-800-171-3.4.3
3118 ······-·NIST-800-53-AC-6(9)3118 ······-·NIST-800-53-AC-6(9)
Offset 3147, 16 lines modifiedOffset 3147, 16 lines modified
3147 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/3147 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
3148 ······find:3148 ······find:
3149 ········paths:·/etc/audit/rules.d3149 ········paths:·/etc/audit/rules.d
3150 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+3150 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
3151 ········patterns:·'*.rules'3151 ········patterns:·'*.rules'
3152 ······register:·find_existing_watch_rules_d3152 ······register:·find_existing_watch_rules_d
3153 ······when:3153 ······when:
3154 ······-·'"audit"·in·ansible_facts.packages' 
3155 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3154 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3155 ······-·'"audit"·in·ansible_facts.packages'
3156 ······tags:3156 ······tags:
3157 ······-·CCE-80721-43157 ······-·CCE-80721-4
3158 ······-·CJIS-5.4.1.13158 ······-·CJIS-5.4.1.1
3159 ······-·NIST-800-171-3.1.83159 ······-·NIST-800-171-3.1.8
3160 ······-·NIST-800-53-AU-12(c)3160 ······-·NIST-800-53-AU-12(c)
3161 ······-·NIST-800-53-AU-2(d)3161 ······-·NIST-800-53-AU-2(d)
3162 ······-·NIST-800-53-CM-6(a)3162 ······-·NIST-800-53-CM-6(a)
Offset 3171, 16 lines modifiedOffset 3171, 16 lines modified
3171 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy3171 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
3172 ······find:3172 ······find:
3173 ········paths:·/etc/audit/rules.d3173 ········paths:·/etc/audit/rules.d
3174 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$3174 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
3175 ········patterns:·'*.rules'3175 ········patterns:·'*.rules'
3176 ······register:·find_watch_key3176 ······register:·find_watch_key
3177 ······when:3177 ······when:
3178 ······-·'"audit"·in·ansible_facts.packages' 
3179 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3178 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3179 ······-·'"audit"·in·ansible_facts.packages'
3180 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3180 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3181 ········==·03181 ········==·0
3182 ······tags:3182 ······tags:
3183 ······-·CCE-80721-43183 ······-·CCE-80721-4
3184 ······-·CJIS-5.4.1.13184 ······-·CJIS-5.4.1.1
3185 ······-·NIST-800-171-3.1.83185 ······-·NIST-800-171-3.1.8
3186 ······-·NIST-800-53-AU-12(c)3186 ······-·NIST-800-53-AU-12(c)
Offset 3195, 16 lines modifiedOffset 3195, 16 lines modified
3195 ······-·restrict_strategy3195 ······-·restrict_strategy
  
3196 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule3196 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
3197 ······set_fact:3197 ······set_fact:
3198 ········all_files:3198 ········all_files:
3199 ········-·/etc/audit/rules.d/MAC-policy.rules3199 ········-·/etc/audit/rules.d/MAC-policy.rules
3200 ······when:3200 ······when:
3201 ······-·'"audit"·in·ansible_facts.packages' 
3202 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3201 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3202 ······-·'"audit"·in·ansible_facts.packages'
3203 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched3203 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
3204 ········is·defined·and·find_existing_watch_rules_d.matched·==·03204 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3205 ······tags:3205 ······tags:
3206 ······-·CCE-80721-43206 ······-·CCE-80721-4
3207 ······-·CJIS-5.4.1.13207 ······-·CJIS-5.4.1.1
3208 ······-·NIST-800-171-3.1.83208 ······-·NIST-800-171-3.1.8
3209 ······-·NIST-800-53-AU-12(c)3209 ······-·NIST-800-53-AU-12(c)
Offset 3219, 16 lines modifiedOffset 3219, 16 lines modified
3219 ······-·restrict_strategy3219 ······-·restrict_strategy
  
3220 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule3220 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
3221 ······set_fact:3221 ······set_fact:
3222 ········all_files:3222 ········all_files:
3223 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'3223 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
3224 ······when:3224 ······when:
3225 ······-·'"audit"·in·ansible_facts.packages' 
3226 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3225 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3226 ······-·'"audit"·in·ansible_facts.packages'
3227 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched3227 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
3228 ········is·defined·and·find_existing_watch_rules_d.matched·==·03228 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3229 ······tags:3229 ······tags:
3230 ······-·CCE-80721-43230 ······-·CCE-80721-4
3231 ······-·CJIS-5.4.1.13231 ······-·CJIS-5.4.1.1
3232 ······-·NIST-800-171-3.1.83232 ······-·NIST-800-171-3.1.8
3233 ······-·NIST-800-53-AU-12(c)3233 ······-·NIST-800-53-AU-12(c)
Offset 3245, 16 lines modifiedOffset 3245, 16 lines modified
3245 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/3245 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 97844/102492 bytes (95.47%) of diff not shown.
3.54 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-cui.yml
Ordering differences only
    
Offset 4972, 16 lines modifiedOffset 4972, 16 lines modified
4972 ······lineinfile:4972 ······lineinfile:
4973 ········dest:·/etc/audit/auditd.conf4973 ········dest:·/etc/audit/auditd.conf
4974 ········regexp:·^\s*flush\s*=\s*.*$4974 ········regexp:·^\s*flush\s*=\s*.*$
4975 ········line:·flush·=·{{·var_auditd_flush·}}4975 ········line:·flush·=·{{·var_auditd_flush·}}
4976 ········state:·present4976 ········state:·present
4977 ········create:·true4977 ········create:·true
4978 ······when:4978 ······when:
4979 ······-·'"audit"·in·ansible_facts.packages' 
4980 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4979 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4980 ······-·'"audit"·in·ansible_facts.packages'
4981 ······tags:4981 ······tags:
4982 ······-·CCE-80680-24982 ······-·CCE-80680-2
4983 ······-·NIST-800-171-3.3.14983 ······-·NIST-800-171-3.3.1
4984 ······-·NIST-800-53-AU-114984 ······-·NIST-800-53-AU-11
4985 ······-·NIST-800-53-CM-6(a)4985 ······-·NIST-800-53-CM-6(a)
4986 ······-·auditd_data_retention_flush4986 ······-·auditd_data_retention_flush
4987 ······-·low_complexity4987 ······-·low_complexity
Offset 5029, 16 lines modifiedOffset 5029, 16 lines modified
5029 ········lineinfile:5029 ········lineinfile:
5030 ··········path:·/etc/audit/auditd.conf5030 ··········path:·/etc/audit/auditd.conf
5031 ··········create:·true5031 ··········create:·true
5032 ··········regexp:·(?i)^\s*freq\s*=\s*5032 ··········regexp:·(?i)^\s*freq\s*=\s*
5033 ··········line:·freq·=·505033 ··········line:·freq·=·50
5034 ··········state:·present5034 ··········state:·present
5035 ······when:5035 ······when:
5036 ······-·'"audit"·in·ansible_facts.packages' 
5037 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5036 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5037 ······-·'"audit"·in·ansible_facts.packages'
5038 ······tags:5038 ······tags:
5039 ······-·CCE-82258-55039 ······-·CCE-82258-5
5040 ······-·NIST-800-53-CM-65040 ······-·NIST-800-53-CM-6
5041 ······-·auditd_freq5041 ······-·auditd_freq
5042 ······-·low_complexity5042 ······-·low_complexity
5043 ······-·low_disruption5043 ······-·low_disruption
5044 ······-·medium_severity5044 ······-·medium_severity
Offset 5085, 16 lines modifiedOffset 5085, 16 lines modified
5085 ········lineinfile:5085 ········lineinfile:
5086 ··········path:·/etc/audit/auditd.conf5086 ··········path:·/etc/audit/auditd.conf
5087 ··········create:·true5087 ··········create:·true
5088 ··········regexp:·(?i)^\s*local_events\s*=\s*5088 ··········regexp:·(?i)^\s*local_events\s*=\s*
5089 ··········line:·local_events·=·yes5089 ··········line:·local_events·=·yes
5090 ··········state:·present5090 ··········state:·present
5091 ······when:5091 ······when:
5092 ······-·'"audit"·in·ansible_facts.packages' 
5093 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5092 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5093 ······-·'"audit"·in·ansible_facts.packages'
5094 ······tags:5094 ······tags:
5095 ······-·CCE-82233-85095 ······-·CCE-82233-8
5096 ······-·DISA-STIG-RHEL-08-0300615096 ······-·DISA-STIG-RHEL-08-030061
5097 ······-·NIST-800-53-CM-65097 ······-·NIST-800-53-CM-6
5098 ······-·auditd_local_events5098 ······-·auditd_local_events
5099 ······-·low_complexity5099 ······-·low_complexity
5100 ······-·low_disruption5100 ······-·low_disruption
Offset 5143, 16 lines modifiedOffset 5143, 16 lines modified
5143 ········lineinfile:5143 ········lineinfile:
5144 ··········path:·/etc/audit/auditd.conf5144 ··········path:·/etc/audit/auditd.conf
5145 ··········create:·true5145 ··········create:·true
5146 ··········regexp:·(?i)^\s*log_format\s*=\s*5146 ··········regexp:·(?i)^\s*log_format\s*=\s*
5147 ··········line:·log_format·=·ENRICHED5147 ··········line:·log_format·=·ENRICHED
5148 ··········state:·present5148 ··········state:·present
5149 ······when:5149 ······when:
5150 ······-·'"audit"·in·ansible_facts.packages' 
5151 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5150 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5151 ······-·'"audit"·in·ansible_facts.packages'
5152 ······tags:5152 ······tags:
5153 ······-·CCE-82201-55153 ······-·CCE-82201-5
5154 ······-·DISA-STIG-RHEL-08-0300635154 ······-·DISA-STIG-RHEL-08-030063
5155 ······-·NIST-800-53-AU-35155 ······-·NIST-800-53-AU-3
5156 ······-·NIST-800-53-CM-65156 ······-·NIST-800-53-CM-6
5157 ······-·auditd_log_format5157 ······-·auditd_log_format
5158 ······-·low_complexity5158 ······-·low_complexity
Offset 5202, 16 lines modifiedOffset 5202, 16 lines modified
5202 ········lineinfile:5202 ········lineinfile:
5203 ··········path:·/etc/audit/auditd.conf5203 ··········path:·/etc/audit/auditd.conf
5204 ··········create:·true5204 ··········create:·true
5205 ··········regexp:·(?i)^\s*name_format\s*=\s*5205 ··········regexp:·(?i)^\s*name_format\s*=\s*
5206 ··········line:·name_format·=·hostname5206 ··········line:·name_format·=·hostname
5207 ··········state:·present5207 ··········state:·present
5208 ······when:5208 ······when:
5209 ······-·'"audit"·in·ansible_facts.packages' 
5210 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5209 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5210 ······-·'"audit"·in·ansible_facts.packages'
5211 ······tags:5211 ······tags:
5212 ······-·CCE-82897-05212 ······-·CCE-82897-0
5213 ······-·DISA-STIG-RHEL-08-0300625213 ······-·DISA-STIG-RHEL-08-030062
5214 ······-·NIST-800-53-AU-35214 ······-·NIST-800-53-AU-3
5215 ······-·NIST-800-53-CM-65215 ······-·NIST-800-53-CM-6
5216 ······-·auditd_name_format5216 ······-·auditd_name_format
5217 ······-·low_complexity5217 ······-·low_complexity
Offset 5259, 16 lines modifiedOffset 5259, 16 lines modified
5259 ········lineinfile:5259 ········lineinfile:
5260 ··········path:·/etc/audit/auditd.conf5260 ··········path:·/etc/audit/auditd.conf
5261 ··········create:·true5261 ··········create:·true
5262 ··········regexp:·(?i)^\s*write_logs\s*=\s*5262 ··········regexp:·(?i)^\s*write_logs\s*=\s*
5263 ··········line:·write_logs·=·yes5263 ··········line:·write_logs·=·yes
5264 ··········state:·present5264 ··········state:·present
5265 ······when:5265 ······when:
5266 ······-·'"audit"·in·ansible_facts.packages' 
5267 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5266 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5267 ······-·'"audit"·in·ansible_facts.packages'
5268 ······tags:5268 ······tags:
5269 ······-·CCE-82366-65269 ······-·CCE-82366-6
5270 ······-·NIST-800-53-CM-65270 ······-·NIST-800-53-CM-6
5271 ······-·auditd_write_logs5271 ······-·auditd_write_logs
5272 ······-·low_complexity5272 ······-·low_complexity
5273 ······-·low_disruption5273 ······-·low_disruption
5274 ······-·medium_severity5274 ······-·medium_severity
68.8 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-e8.yml
Ordering differences only
    
Offset 1201, 16 lines modifiedOffset 1201, 16 lines modified
1201 ······-·no_reboot_needed1201 ······-·no_reboot_needed
1202 ······-·restrict_strategy1202 ······-·restrict_strategy
  
1203 ····-·name:·Set·architecture·for·audit·tasks1203 ····-·name:·Set·architecture·for·audit·tasks
1204 ······set_fact:1204 ······set_fact:
1205 ········audit_arch:·b641205 ········audit_arch:·b64
1206 ······when:1206 ······when:
1207 ······-·'"audit"·in·ansible_facts.packages' 
1208 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1207 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1208 ······-·'"audit"·in·ansible_facts.packages'
1209 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1209 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1210 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1210 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1211 ······tags:1211 ······tags:
1212 ······-·CCE-80723-01212 ······-·CCE-80723-0
1213 ······-·CJIS-5.4.1.11213 ······-·CJIS-5.4.1.1
1214 ······-·NIST-800-171-3.1.71214 ······-·NIST-800-171-3.1.7
1215 ······-·NIST-800-53-AC-6(9)1215 ······-·NIST-800-53-AC-6(9)
Offset 1344, 16 lines modifiedOffset 1344, 16 lines modified
1344 ··········path:·'{{·audit_file·}}'1344 ··········path:·'{{·audit_file·}}'
1345 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1345 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1346 ··········create:·true1346 ··········create:·true
1347 ··········mode:·o-rwx1347 ··········mode:·o-rwx
1348 ··········state:·present1348 ··········state:·present
1349 ········when:·syscalls_found·|·length·==·01349 ········when:·syscalls_found·|·length·==·0
1350 ······when:1350 ······when:
1351 ······-·'"audit"·in·ansible_facts.packages' 
1352 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1351 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1352 ······-·'"audit"·in·ansible_facts.packages'
1353 ······tags:1353 ······tags:
1354 ······-·CCE-80723-01354 ······-·CCE-80723-0
1355 ······-·CJIS-5.4.1.11355 ······-·CJIS-5.4.1.1
1356 ······-·NIST-800-171-3.1.71356 ······-·NIST-800-171-3.1.7
1357 ······-·NIST-800-53-AC-6(9)1357 ······-·NIST-800-53-AC-6(9)
1358 ······-·NIST-800-53-AU-12(c)1358 ······-·NIST-800-53-AU-12(c)
1359 ······-·NIST-800-53-AU-2(d)1359 ······-·NIST-800-53-AU-2(d)
Offset 1485, 16 lines modifiedOffset 1485, 16 lines modified
1485 ··········path:·'{{·audit_file·}}'1485 ··········path:·'{{·audit_file·}}'
1486 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1486 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1487 ··········create:·true1487 ··········create:·true
1488 ··········mode:·o-rwx1488 ··········mode:·o-rwx
1489 ··········state:·present1489 ··········state:·present
1490 ········when:·syscalls_found·|·length·==·01490 ········when:·syscalls_found·|·length·==·0
1491 ······when:1491 ······when:
1492 ······-·'"audit"·in·ansible_facts.packages' 
1493 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1492 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1493 ······-·'"audit"·in·ansible_facts.packages'
1494 ······-·audit_arch·==·"b64"1494 ······-·audit_arch·==·"b64"
1495 ······tags:1495 ······tags:
1496 ······-·CCE-80723-01496 ······-·CCE-80723-0
1497 ······-·CJIS-5.4.1.11497 ······-·CJIS-5.4.1.1
1498 ······-·NIST-800-171-3.1.71498 ······-·NIST-800-171-3.1.7
1499 ······-·NIST-800-53-AC-6(9)1499 ······-·NIST-800-53-AC-6(9)
1500 ······-·NIST-800-53-AU-12(c)1500 ······-·NIST-800-53-AU-12(c)
Offset 1511, 16 lines modifiedOffset 1511, 16 lines modified
1511 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/1511 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
1512 ······find:1512 ······find:
1513 ········paths:·/etc/audit/rules.d1513 ········paths:·/etc/audit/rules.d
1514 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+1514 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
1515 ········patterns:·'*.rules'1515 ········patterns:·'*.rules'
1516 ······register:·find_existing_watch_rules_d1516 ······register:·find_existing_watch_rules_d
1517 ······when:1517 ······when:
1518 ······-·'"audit"·in·ansible_facts.packages' 
1519 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1518 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1519 ······-·'"audit"·in·ansible_facts.packages'
1520 ······tags:1520 ······tags:
1521 ······-·CCE-80723-01521 ······-·CCE-80723-0
1522 ······-·CJIS-5.4.1.11522 ······-·CJIS-5.4.1.1
1523 ······-·NIST-800-171-3.1.71523 ······-·NIST-800-171-3.1.7
1524 ······-·NIST-800-53-AC-6(9)1524 ······-·NIST-800-53-AC-6(9)
1525 ······-·NIST-800-53-AU-12(c)1525 ······-·NIST-800-53-AU-12(c)
1526 ······-·NIST-800-53-AU-2(d)1526 ······-·NIST-800-53-AU-2(d)
Offset 1536, 16 lines modifiedOffset 1536, 16 lines modified
1536 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification1536 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
1537 ······find:1537 ······find:
1538 ········paths:·/etc/audit/rules.d1538 ········paths:·/etc/audit/rules.d
1539 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$1539 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
1540 ········patterns:·'*.rules'1540 ········patterns:·'*.rules'
1541 ······register:·find_watch_key1541 ······register:·find_watch_key
1542 ······when:1542 ······when:
1543 ······-·'"audit"·in·ansible_facts.packages' 
1544 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1543 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1544 ······-·'"audit"·in·ansible_facts.packages'
1545 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1545 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1546 ········==·01546 ········==·0
1547 ······tags:1547 ······tags:
1548 ······-·CCE-80723-01548 ······-·CCE-80723-0
1549 ······-·CJIS-5.4.1.11549 ······-·CJIS-5.4.1.1
1550 ······-·NIST-800-171-3.1.71550 ······-·NIST-800-171-3.1.7
1551 ······-·NIST-800-53-AC-6(9)1551 ······-·NIST-800-53-AC-6(9)
Offset 1562, 16 lines modifiedOffset 1562, 16 lines modified
  
1562 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the1562 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
1563 ········recipient·for·the·rule1563 ········recipient·for·the·rule
1564 ······set_fact:1564 ······set_fact:
1565 ········all_files:1565 ········all_files:
1566 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules1566 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
1567 ······when:1567 ······when:
1568 ······-·'"audit"·in·ansible_facts.packages' 
1569 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1568 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1569 ······-·'"audit"·in·ansible_facts.packages'
1570 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1570 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1571 ········is·defined·and·find_existing_watch_rules_d.matched·==·01571 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1572 ······tags:1572 ······tags:
1573 ······-·CCE-80723-01573 ······-·CCE-80723-0
1574 ······-·CJIS-5.4.1.11574 ······-·CJIS-5.4.1.1
1575 ······-·NIST-800-171-3.1.71575 ······-·NIST-800-171-3.1.7
1576 ······-·NIST-800-53-AC-6(9)1576 ······-·NIST-800-53-AC-6(9)
Offset 1587, 16 lines modifiedOffset 1587, 16 lines modified
1587 ······-·restrict_strategy1587 ······-·restrict_strategy
  
1588 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1588 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1589 ······set_fact:1589 ······set_fact:
1590 ········all_files:1590 ········all_files:
1591 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1591 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1592 ······when:1592 ······when:
1593 ······-·'"audit"·in·ansible_facts.packages' 
1594 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1593 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1594 ······-·'"audit"·in·ansible_facts.packages'
1595 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1595 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1596 ········is·defined·and·find_existing_watch_rules_d.matched·==·01596 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1597 ······tags:1597 ······tags:
1598 ······-·CCE-80723-01598 ······-·CCE-80723-0
1599 ······-·CJIS-5.4.1.11599 ······-·CJIS-5.4.1.1
1600 ······-·NIST-800-171-3.1.71600 ······-·NIST-800-171-3.1.7
1601 ······-·NIST-800-53-AC-6(9)1601 ······-·NIST-800-53-AC-6(9)
Offset 1614, 16 lines modifiedOffset 1614, 16 lines modified
1614 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/1614 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 65360/70350 bytes (92.91%) of diff not shown.
179 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-hipaa.yml
Ordering differences only
    
Offset 1416, 16 lines modifiedOffset 1416, 16 lines modified
  
1416 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1416 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1417 ······find:1417 ······find:
1418 ········paths:·/etc/audit/rules.d/1418 ········paths:·/etc/audit/rules.d/
1419 ········patterns:·'*.rules'1419 ········patterns:·'*.rules'
1420 ······register:·find_rules_d1420 ······register:·find_rules_d
1421 ······when:1421 ······when:
1422 ······-·'"audit"·in·ansible_facts.packages' 
1423 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1422 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1423 ······-·'"audit"·in·ansible_facts.packages'
1424 ······tags:1424 ······tags:
1425 ······-·CCE-80708-11425 ······-·CCE-80708-1
1426 ······-·CJIS-5.4.1.11426 ······-·CJIS-5.4.1.1
1427 ······-·DISA-STIG-RHEL-08-0301211427 ······-·DISA-STIG-RHEL-08-030121
1428 ······-·NIST-800-171-3.3.11428 ······-·NIST-800-171-3.3.1
1429 ······-·NIST-800-171-3.4.31429 ······-·NIST-800-171-3.4.3
1430 ······-·NIST-800-53-AC-6(9)1430 ······-·NIST-800-53-AC-6(9)
Offset 1442, 16 lines modifiedOffset 1442, 16 lines modified
1442 ······lineinfile:1442 ······lineinfile:
1443 ········path:·'{{·item·}}'1443 ········path:·'{{·item·}}'
1444 ········regexp:·^\s*(?:-e)\s+.*$1444 ········regexp:·^\s*(?:-e)\s+.*$
1445 ········state:·absent1445 ········state:·absent
1446 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1446 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1447 ········}}'1447 ········}}'
1448 ······when:1448 ······when:
1449 ······-·'"audit"·in·ansible_facts.packages' 
1450 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1449 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1450 ······-·'"audit"·in·ansible_facts.packages'
1451 ······tags:1451 ······tags:
1452 ······-·CCE-80708-11452 ······-·CCE-80708-1
1453 ······-·CJIS-5.4.1.11453 ······-·CJIS-5.4.1.1
1454 ······-·DISA-STIG-RHEL-08-0301211454 ······-·DISA-STIG-RHEL-08-030121
1455 ······-·NIST-800-171-3.3.11455 ······-·NIST-800-171-3.3.1
1456 ······-·NIST-800-171-3.4.31456 ······-·NIST-800-171-3.4.3
1457 ······-·NIST-800-53-AC-6(9)1457 ······-·NIST-800-53-AC-6(9)
Offset 1470, 16 lines modifiedOffset 1470, 16 lines modified
1470 ········create:·true1470 ········create:·true
1471 ········line:·-e·21471 ········line:·-e·2
1472 ········mode:·o-rwx1472 ········mode:·o-rwx
1473 ······loop:1473 ······loop:
1474 ······-·/etc/audit/audit.rules1474 ······-·/etc/audit/audit.rules
1475 ······-·/etc/audit/rules.d/immutable.rules1475 ······-·/etc/audit/rules.d/immutable.rules
1476 ······when:1476 ······when:
1477 ······-·'"audit"·in·ansible_facts.packages' 
1478 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1477 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1478 ······-·'"audit"·in·ansible_facts.packages'
1479 ······tags:1479 ······tags:
1480 ······-·CCE-80708-11480 ······-·CCE-80708-1
1481 ······-·CJIS-5.4.1.11481 ······-·CJIS-5.4.1.1
1482 ······-·DISA-STIG-RHEL-08-0301211482 ······-·DISA-STIG-RHEL-08-030121
1483 ······-·NIST-800-171-3.3.11483 ······-·NIST-800-171-3.3.1
1484 ······-·NIST-800-171-3.4.31484 ······-·NIST-800-171-3.4.3
1485 ······-·NIST-800-53-AC-6(9)1485 ······-·NIST-800-53-AC-6(9)
Offset 1514, 16 lines modifiedOffset 1514, 16 lines modified
1514 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1514 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1515 ······find:1515 ······find:
1516 ········paths:·/etc/audit/rules.d1516 ········paths:·/etc/audit/rules.d
1517 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1517 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1518 ········patterns:·'*.rules'1518 ········patterns:·'*.rules'
1519 ······register:·find_existing_watch_rules_d1519 ······register:·find_existing_watch_rules_d
1520 ······when:1520 ······when:
1521 ······-·'"audit"·in·ansible_facts.packages' 
1522 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1521 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1522 ······-·'"audit"·in·ansible_facts.packages'
1523 ······tags:1523 ······tags:
1524 ······-·CCE-80721-41524 ······-·CCE-80721-4
1525 ······-·CJIS-5.4.1.11525 ······-·CJIS-5.4.1.1
1526 ······-·NIST-800-171-3.1.81526 ······-·NIST-800-171-3.1.8
1527 ······-·NIST-800-53-AU-12(c)1527 ······-·NIST-800-53-AU-12(c)
1528 ······-·NIST-800-53-AU-2(d)1528 ······-·NIST-800-53-AU-2(d)
1529 ······-·NIST-800-53-CM-6(a)1529 ······-·NIST-800-53-CM-6(a)
Offset 1538, 16 lines modifiedOffset 1538, 16 lines modified
1538 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1538 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1539 ······find:1539 ······find:
1540 ········paths:·/etc/audit/rules.d1540 ········paths:·/etc/audit/rules.d
1541 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1541 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1542 ········patterns:·'*.rules'1542 ········patterns:·'*.rules'
1543 ······register:·find_watch_key1543 ······register:·find_watch_key
1544 ······when:1544 ······when:
1545 ······-·'"audit"·in·ansible_facts.packages' 
1546 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1545 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1546 ······-·'"audit"·in·ansible_facts.packages'
1547 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1547 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1548 ········==·01548 ········==·0
1549 ······tags:1549 ······tags:
1550 ······-·CCE-80721-41550 ······-·CCE-80721-4
1551 ······-·CJIS-5.4.1.11551 ······-·CJIS-5.4.1.1
1552 ······-·NIST-800-171-3.1.81552 ······-·NIST-800-171-3.1.8
1553 ······-·NIST-800-53-AU-12(c)1553 ······-·NIST-800-53-AU-12(c)
Offset 1562, 16 lines modifiedOffset 1562, 16 lines modified
1562 ······-·restrict_strategy1562 ······-·restrict_strategy
  
1563 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1563 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1564 ······set_fact:1564 ······set_fact:
1565 ········all_files:1565 ········all_files:
1566 ········-·/etc/audit/rules.d/MAC-policy.rules1566 ········-·/etc/audit/rules.d/MAC-policy.rules
1567 ······when:1567 ······when:
1568 ······-·'"audit"·in·ansible_facts.packages' 
1569 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1568 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1569 ······-·'"audit"·in·ansible_facts.packages'
1570 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1570 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1571 ········is·defined·and·find_existing_watch_rules_d.matched·==·01571 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1572 ······tags:1572 ······tags:
1573 ······-·CCE-80721-41573 ······-·CCE-80721-4
1574 ······-·CJIS-5.4.1.11574 ······-·CJIS-5.4.1.1
1575 ······-·NIST-800-171-3.1.81575 ······-·NIST-800-171-3.1.8
1576 ······-·NIST-800-53-AU-12(c)1576 ······-·NIST-800-53-AU-12(c)
Offset 1586, 16 lines modifiedOffset 1586, 16 lines modified
1586 ······-·restrict_strategy1586 ······-·restrict_strategy
  
1587 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1587 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1588 ······set_fact:1588 ······set_fact:
1589 ········all_files:1589 ········all_files:
1590 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1590 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1591 ······when:1591 ······when:
1592 ······-·'"audit"·in·ansible_facts.packages' 
1593 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1592 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1593 ······-·'"audit"·in·ansible_facts.packages'
1594 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1594 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1595 ········is·defined·and·find_existing_watch_rules_d.matched·==·01595 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1596 ······tags:1596 ······tags:
1597 ······-·CCE-80721-41597 ······-·CCE-80721-4
1598 ······-·CJIS-5.4.1.11598 ······-·CJIS-5.4.1.1
1599 ······-·NIST-800-171-3.1.81599 ······-·NIST-800-171-3.1.8
1600 ······-·NIST-800-53-AU-12(c)1600 ······-·NIST-800-53-AU-12(c)
Offset 1612, 16 lines modifiedOffset 1612, 16 lines modified
1612 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1612 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 178430/183078 bytes (97.46%) of diff not shown.
85.7 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-ism_o.yml
Ordering differences only
    
Offset 4745, 16 lines modifiedOffset 4745, 16 lines modified
4745 ······-·no_reboot_needed4745 ······-·no_reboot_needed
4746 ······-·restrict_strategy4746 ······-·restrict_strategy
  
4747 ····-·name:·Set·architecture·for·audit·tasks4747 ····-·name:·Set·architecture·for·audit·tasks
4748 ······set_fact:4748 ······set_fact:
4749 ········audit_arch:·b644749 ········audit_arch:·b64
4750 ······when:4750 ······when:
4751 ······-·'"audit"·in·ansible_facts.packages' 
4752 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4751 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4752 ······-·'"audit"·in·ansible_facts.packages'
4753 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4753 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4754 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4754 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4755 ······tags:4755 ······tags:
4756 ······-·CCE-80723-04756 ······-·CCE-80723-0
4757 ······-·CJIS-5.4.1.14757 ······-·CJIS-5.4.1.1
4758 ······-·NIST-800-171-3.1.74758 ······-·NIST-800-171-3.1.7
4759 ······-·NIST-800-53-AC-6(9)4759 ······-·NIST-800-53-AC-6(9)
Offset 4888, 16 lines modifiedOffset 4888, 16 lines modified
4888 ··········path:·'{{·audit_file·}}'4888 ··········path:·'{{·audit_file·}}'
4889 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification4889 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
4890 ··········create:·true4890 ··········create:·true
4891 ··········mode:·o-rwx4891 ··········mode:·o-rwx
4892 ··········state:·present4892 ··········state:·present
4893 ········when:·syscalls_found·|·length·==·04893 ········when:·syscalls_found·|·length·==·0
4894 ······when:4894 ······when:
4895 ······-·'"audit"·in·ansible_facts.packages' 
4896 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4895 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4896 ······-·'"audit"·in·ansible_facts.packages'
4897 ······tags:4897 ······tags:
4898 ······-·CCE-80723-04898 ······-·CCE-80723-0
4899 ······-·CJIS-5.4.1.14899 ······-·CJIS-5.4.1.1
4900 ······-·NIST-800-171-3.1.74900 ······-·NIST-800-171-3.1.7
4901 ······-·NIST-800-53-AC-6(9)4901 ······-·NIST-800-53-AC-6(9)
4902 ······-·NIST-800-53-AU-12(c)4902 ······-·NIST-800-53-AU-12(c)
4903 ······-·NIST-800-53-AU-2(d)4903 ······-·NIST-800-53-AU-2(d)
Offset 5029, 16 lines modifiedOffset 5029, 16 lines modified
5029 ··········path:·'{{·audit_file·}}'5029 ··········path:·'{{·audit_file·}}'
5030 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification5030 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
5031 ··········create:·true5031 ··········create:·true
5032 ··········mode:·o-rwx5032 ··········mode:·o-rwx
5033 ··········state:·present5033 ··········state:·present
5034 ········when:·syscalls_found·|·length·==·05034 ········when:·syscalls_found·|·length·==·0
5035 ······when:5035 ······when:
5036 ······-·'"audit"·in·ansible_facts.packages' 
5037 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5036 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5037 ······-·'"audit"·in·ansible_facts.packages'
5038 ······-·audit_arch·==·"b64"5038 ······-·audit_arch·==·"b64"
5039 ······tags:5039 ······tags:
5040 ······-·CCE-80723-05040 ······-·CCE-80723-0
5041 ······-·CJIS-5.4.1.15041 ······-·CJIS-5.4.1.1
5042 ······-·NIST-800-171-3.1.75042 ······-·NIST-800-171-3.1.7
5043 ······-·NIST-800-53-AC-6(9)5043 ······-·NIST-800-53-AC-6(9)
5044 ······-·NIST-800-53-AU-12(c)5044 ······-·NIST-800-53-AU-12(c)
Offset 5055, 16 lines modifiedOffset 5055, 16 lines modified
5055 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/5055 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
5056 ······find:5056 ······find:
5057 ········paths:·/etc/audit/rules.d5057 ········paths:·/etc/audit/rules.d
5058 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+5058 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
5059 ········patterns:·'*.rules'5059 ········patterns:·'*.rules'
5060 ······register:·find_existing_watch_rules_d5060 ······register:·find_existing_watch_rules_d
5061 ······when:5061 ······when:
5062 ······-·'"audit"·in·ansible_facts.packages' 
5063 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5062 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5063 ······-·'"audit"·in·ansible_facts.packages'
5064 ······tags:5064 ······tags:
5065 ······-·CCE-80723-05065 ······-·CCE-80723-0
5066 ······-·CJIS-5.4.1.15066 ······-·CJIS-5.4.1.1
5067 ······-·NIST-800-171-3.1.75067 ······-·NIST-800-171-3.1.7
5068 ······-·NIST-800-53-AC-6(9)5068 ······-·NIST-800-53-AC-6(9)
5069 ······-·NIST-800-53-AU-12(c)5069 ······-·NIST-800-53-AU-12(c)
5070 ······-·NIST-800-53-AU-2(d)5070 ······-·NIST-800-53-AU-2(d)
Offset 5080, 16 lines modifiedOffset 5080, 16 lines modified
5080 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification5080 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
5081 ······find:5081 ······find:
5082 ········paths:·/etc/audit/rules.d5082 ········paths:·/etc/audit/rules.d
5083 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$5083 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
5084 ········patterns:·'*.rules'5084 ········patterns:·'*.rules'
5085 ······register:·find_watch_key5085 ······register:·find_watch_key
5086 ······when:5086 ······when:
5087 ······-·'"audit"·in·ansible_facts.packages' 
5088 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5087 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5088 ······-·'"audit"·in·ansible_facts.packages'
5089 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5089 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5090 ········==·05090 ········==·0
5091 ······tags:5091 ······tags:
5092 ······-·CCE-80723-05092 ······-·CCE-80723-0
5093 ······-·CJIS-5.4.1.15093 ······-·CJIS-5.4.1.1
5094 ······-·NIST-800-171-3.1.75094 ······-·NIST-800-171-3.1.7
5095 ······-·NIST-800-53-AC-6(9)5095 ······-·NIST-800-53-AC-6(9)
Offset 5106, 16 lines modifiedOffset 5106, 16 lines modified
  
5106 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the5106 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
5107 ········recipient·for·the·rule5107 ········recipient·for·the·rule
5108 ······set_fact:5108 ······set_fact:
5109 ········all_files:5109 ········all_files:
5110 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules5110 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
5111 ······when:5111 ······when:
5112 ······-·'"audit"·in·ansible_facts.packages' 
5113 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5112 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5113 ······-·'"audit"·in·ansible_facts.packages'
5114 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5114 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5115 ········is·defined·and·find_existing_watch_rules_d.matched·==·05115 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5116 ······tags:5116 ······tags:
5117 ······-·CCE-80723-05117 ······-·CCE-80723-0
5118 ······-·CJIS-5.4.1.15118 ······-·CJIS-5.4.1.1
5119 ······-·NIST-800-171-3.1.75119 ······-·NIST-800-171-3.1.7
5120 ······-·NIST-800-53-AC-6(9)5120 ······-·NIST-800-53-AC-6(9)
Offset 5131, 16 lines modifiedOffset 5131, 16 lines modified
5131 ······-·restrict_strategy5131 ······-·restrict_strategy
  
5132 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5132 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5133 ······set_fact:5133 ······set_fact:
5134 ········all_files:5134 ········all_files:
5135 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5135 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5136 ······when:5136 ······when:
5137 ······-·'"audit"·in·ansible_facts.packages' 
5138 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5137 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5138 ······-·'"audit"·in·ansible_facts.packages'
5139 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5139 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5140 ········is·defined·and·find_existing_watch_rules_d.matched·==·05140 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5141 ······tags:5141 ······tags:
5142 ······-·CCE-80723-05142 ······-·CCE-80723-0
5143 ······-·CJIS-5.4.1.15143 ······-·CJIS-5.4.1.1
5144 ······-·NIST-800-171-3.1.75144 ······-·NIST-800-171-3.1.7
5145 ······-·NIST-800-53-AC-6(9)5145 ······-·NIST-800-53-AC-6(9)
Offset 5158, 16 lines modifiedOffset 5158, 16 lines modified
5158 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/5158 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 82625/87615 bytes (94.30%) of diff not shown.
3.54 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-ospp.yml
Ordering differences only
    
Offset 4965, 16 lines modifiedOffset 4965, 16 lines modified
4965 ······lineinfile:4965 ······lineinfile:
4966 ········dest:·/etc/audit/auditd.conf4966 ········dest:·/etc/audit/auditd.conf
4967 ········regexp:·^\s*flush\s*=\s*.*$4967 ········regexp:·^\s*flush\s*=\s*.*$
4968 ········line:·flush·=·{{·var_auditd_flush·}}4968 ········line:·flush·=·{{·var_auditd_flush·}}
4969 ········state:·present4969 ········state:·present
4970 ········create:·true4970 ········create:·true
4971 ······when:4971 ······when:
4972 ······-·'"audit"·in·ansible_facts.packages' 
4973 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4972 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4973 ······-·'"audit"·in·ansible_facts.packages'
4974 ······tags:4974 ······tags:
4975 ······-·CCE-80680-24975 ······-·CCE-80680-2
4976 ······-·NIST-800-171-3.3.14976 ······-·NIST-800-171-3.3.1
4977 ······-·NIST-800-53-AU-114977 ······-·NIST-800-53-AU-11
4978 ······-·NIST-800-53-CM-6(a)4978 ······-·NIST-800-53-CM-6(a)
4979 ······-·auditd_data_retention_flush4979 ······-·auditd_data_retention_flush
4980 ······-·low_complexity4980 ······-·low_complexity
Offset 5022, 16 lines modifiedOffset 5022, 16 lines modified
5022 ········lineinfile:5022 ········lineinfile:
5023 ··········path:·/etc/audit/auditd.conf5023 ··········path:·/etc/audit/auditd.conf
5024 ··········create:·true5024 ··········create:·true
5025 ··········regexp:·(?i)^\s*freq\s*=\s*5025 ··········regexp:·(?i)^\s*freq\s*=\s*
5026 ··········line:·freq·=·505026 ··········line:·freq·=·50
5027 ··········state:·present5027 ··········state:·present
5028 ······when:5028 ······when:
5029 ······-·'"audit"·in·ansible_facts.packages' 
5030 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5029 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5030 ······-·'"audit"·in·ansible_facts.packages'
5031 ······tags:5031 ······tags:
5032 ······-·CCE-82258-55032 ······-·CCE-82258-5
5033 ······-·NIST-800-53-CM-65033 ······-·NIST-800-53-CM-6
5034 ······-·auditd_freq5034 ······-·auditd_freq
5035 ······-·low_complexity5035 ······-·low_complexity
5036 ······-·low_disruption5036 ······-·low_disruption
5037 ······-·medium_severity5037 ······-·medium_severity
Offset 5078, 16 lines modifiedOffset 5078, 16 lines modified
5078 ········lineinfile:5078 ········lineinfile:
5079 ··········path:·/etc/audit/auditd.conf5079 ··········path:·/etc/audit/auditd.conf
5080 ··········create:·true5080 ··········create:·true
5081 ··········regexp:·(?i)^\s*local_events\s*=\s*5081 ··········regexp:·(?i)^\s*local_events\s*=\s*
5082 ··········line:·local_events·=·yes5082 ··········line:·local_events·=·yes
5083 ··········state:·present5083 ··········state:·present
5084 ······when:5084 ······when:
5085 ······-·'"audit"·in·ansible_facts.packages' 
5086 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5085 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5086 ······-·'"audit"·in·ansible_facts.packages'
5087 ······tags:5087 ······tags:
5088 ······-·CCE-82233-85088 ······-·CCE-82233-8
5089 ······-·DISA-STIG-RHEL-08-0300615089 ······-·DISA-STIG-RHEL-08-030061
5090 ······-·NIST-800-53-CM-65090 ······-·NIST-800-53-CM-6
5091 ······-·auditd_local_events5091 ······-·auditd_local_events
5092 ······-·low_complexity5092 ······-·low_complexity
5093 ······-·low_disruption5093 ······-·low_disruption
Offset 5136, 16 lines modifiedOffset 5136, 16 lines modified
5136 ········lineinfile:5136 ········lineinfile:
5137 ··········path:·/etc/audit/auditd.conf5137 ··········path:·/etc/audit/auditd.conf
5138 ··········create:·true5138 ··········create:·true
5139 ··········regexp:·(?i)^\s*log_format\s*=\s*5139 ··········regexp:·(?i)^\s*log_format\s*=\s*
5140 ··········line:·log_format·=·ENRICHED5140 ··········line:·log_format·=·ENRICHED
5141 ··········state:·present5141 ··········state:·present
5142 ······when:5142 ······when:
5143 ······-·'"audit"·in·ansible_facts.packages' 
5144 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5143 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5144 ······-·'"audit"·in·ansible_facts.packages'
5145 ······tags:5145 ······tags:
5146 ······-·CCE-82201-55146 ······-·CCE-82201-5
5147 ······-·DISA-STIG-RHEL-08-0300635147 ······-·DISA-STIG-RHEL-08-030063
5148 ······-·NIST-800-53-AU-35148 ······-·NIST-800-53-AU-3
5149 ······-·NIST-800-53-CM-65149 ······-·NIST-800-53-CM-6
5150 ······-·auditd_log_format5150 ······-·auditd_log_format
5151 ······-·low_complexity5151 ······-·low_complexity
Offset 5195, 16 lines modifiedOffset 5195, 16 lines modified
5195 ········lineinfile:5195 ········lineinfile:
5196 ··········path:·/etc/audit/auditd.conf5196 ··········path:·/etc/audit/auditd.conf
5197 ··········create:·true5197 ··········create:·true
5198 ··········regexp:·(?i)^\s*name_format\s*=\s*5198 ··········regexp:·(?i)^\s*name_format\s*=\s*
5199 ··········line:·name_format·=·hostname5199 ··········line:·name_format·=·hostname
5200 ··········state:·present5200 ··········state:·present
5201 ······when:5201 ······when:
5202 ······-·'"audit"·in·ansible_facts.packages' 
5203 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5202 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5203 ······-·'"audit"·in·ansible_facts.packages'
5204 ······tags:5204 ······tags:
5205 ······-·CCE-82897-05205 ······-·CCE-82897-0
5206 ······-·DISA-STIG-RHEL-08-0300625206 ······-·DISA-STIG-RHEL-08-030062
5207 ······-·NIST-800-53-AU-35207 ······-·NIST-800-53-AU-3
5208 ······-·NIST-800-53-CM-65208 ······-·NIST-800-53-CM-6
5209 ······-·auditd_name_format5209 ······-·auditd_name_format
5210 ······-·low_complexity5210 ······-·low_complexity
Offset 5252, 16 lines modifiedOffset 5252, 16 lines modified
5252 ········lineinfile:5252 ········lineinfile:
5253 ··········path:·/etc/audit/auditd.conf5253 ··········path:·/etc/audit/auditd.conf
5254 ··········create:·true5254 ··········create:·true
5255 ··········regexp:·(?i)^\s*write_logs\s*=\s*5255 ··········regexp:·(?i)^\s*write_logs\s*=\s*
5256 ··········line:·write_logs·=·yes5256 ··········line:·write_logs·=·yes
5257 ··········state:·present5257 ··········state:·present
5258 ······when:5258 ······when:
5259 ······-·'"audit"·in·ansible_facts.packages' 
5260 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5259 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5260 ······-·'"audit"·in·ansible_facts.packages'
5261 ······tags:5261 ······tags:
5262 ······-·CCE-82366-65262 ······-·CCE-82366-6
5263 ······-·NIST-800-53-CM-65263 ······-·NIST-800-53-CM-6
5264 ······-·auditd_write_logs5264 ······-·auditd_write_logs
5265 ······-·low_complexity5265 ······-·low_complexity
5266 ······-·low_disruption5266 ······-·low_disruption
5267 ······-·medium_severity5267 ······-·medium_severity
158 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-pci-dss.yml
Ordering differences only
    
Offset 5290, 16 lines modifiedOffset 5290, 16 lines modified
  
5290 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5290 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5291 ······find:5291 ······find:
5292 ········paths:·/etc/audit/rules.d/5292 ········paths:·/etc/audit/rules.d/
5293 ········patterns:·'*.rules'5293 ········patterns:·'*.rules'
5294 ······register:·find_rules_d5294 ······register:·find_rules_d
5295 ······when:5295 ······when:
5296 ······-·'"audit"·in·ansible_facts.packages' 
5297 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5296 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5297 ······-·'"audit"·in·ansible_facts.packages'
5298 ······tags:5298 ······tags:
5299 ······-·CCE-80708-15299 ······-·CCE-80708-1
5300 ······-·CJIS-5.4.1.15300 ······-·CJIS-5.4.1.1
5301 ······-·DISA-STIG-RHEL-08-0301215301 ······-·DISA-STIG-RHEL-08-030121
5302 ······-·NIST-800-171-3.3.15302 ······-·NIST-800-171-3.3.1
5303 ······-·NIST-800-171-3.4.35303 ······-·NIST-800-171-3.4.3
5304 ······-·NIST-800-53-AC-6(9)5304 ······-·NIST-800-53-AC-6(9)
Offset 5316, 16 lines modifiedOffset 5316, 16 lines modified
5316 ······lineinfile:5316 ······lineinfile:
5317 ········path:·'{{·item·}}'5317 ········path:·'{{·item·}}'
5318 ········regexp:·^\s*(?:-e)\s+.*$5318 ········regexp:·^\s*(?:-e)\s+.*$
5319 ········state:·absent5319 ········state:·absent
5320 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5320 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5321 ········}}'5321 ········}}'
5322 ······when:5322 ······when:
5323 ······-·'"audit"·in·ansible_facts.packages' 
5324 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5323 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5324 ······-·'"audit"·in·ansible_facts.packages'
5325 ······tags:5325 ······tags:
5326 ······-·CCE-80708-15326 ······-·CCE-80708-1
5327 ······-·CJIS-5.4.1.15327 ······-·CJIS-5.4.1.1
5328 ······-·DISA-STIG-RHEL-08-0301215328 ······-·DISA-STIG-RHEL-08-030121
5329 ······-·NIST-800-171-3.3.15329 ······-·NIST-800-171-3.3.1
5330 ······-·NIST-800-171-3.4.35330 ······-·NIST-800-171-3.4.3
5331 ······-·NIST-800-53-AC-6(9)5331 ······-·NIST-800-53-AC-6(9)
Offset 5344, 16 lines modifiedOffset 5344, 16 lines modified
5344 ········create:·true5344 ········create:·true
5345 ········line:·-e·25345 ········line:·-e·2
5346 ········mode:·o-rwx5346 ········mode:·o-rwx
5347 ······loop:5347 ······loop:
5348 ······-·/etc/audit/audit.rules5348 ······-·/etc/audit/audit.rules
5349 ······-·/etc/audit/rules.d/immutable.rules5349 ······-·/etc/audit/rules.d/immutable.rules
5350 ······when:5350 ······when:
5351 ······-·'"audit"·in·ansible_facts.packages' 
5352 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5351 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5352 ······-·'"audit"·in·ansible_facts.packages'
5353 ······tags:5353 ······tags:
5354 ······-·CCE-80708-15354 ······-·CCE-80708-1
5355 ······-·CJIS-5.4.1.15355 ······-·CJIS-5.4.1.1
5356 ······-·DISA-STIG-RHEL-08-0301215356 ······-·DISA-STIG-RHEL-08-030121
5357 ······-·NIST-800-171-3.3.15357 ······-·NIST-800-171-3.3.1
5358 ······-·NIST-800-171-3.4.35358 ······-·NIST-800-171-3.4.3
5359 ······-·NIST-800-53-AC-6(9)5359 ······-·NIST-800-53-AC-6(9)
Offset 5388, 16 lines modifiedOffset 5388, 16 lines modified
5388 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5388 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5389 ······find:5389 ······find:
5390 ········paths:·/etc/audit/rules.d5390 ········paths:·/etc/audit/rules.d
5391 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5391 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5392 ········patterns:·'*.rules'5392 ········patterns:·'*.rules'
5393 ······register:·find_existing_watch_rules_d5393 ······register:·find_existing_watch_rules_d
5394 ······when:5394 ······when:
5395 ······-·'"audit"·in·ansible_facts.packages' 
5396 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5395 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5396 ······-·'"audit"·in·ansible_facts.packages'
5397 ······tags:5397 ······tags:
5398 ······-·CCE-80721-45398 ······-·CCE-80721-4
5399 ······-·CJIS-5.4.1.15399 ······-·CJIS-5.4.1.1
5400 ······-·NIST-800-171-3.1.85400 ······-·NIST-800-171-3.1.8
5401 ······-·NIST-800-53-AU-12(c)5401 ······-·NIST-800-53-AU-12(c)
5402 ······-·NIST-800-53-AU-2(d)5402 ······-·NIST-800-53-AU-2(d)
5403 ······-·NIST-800-53-CM-6(a)5403 ······-·NIST-800-53-CM-6(a)
Offset 5412, 16 lines modifiedOffset 5412, 16 lines modified
5412 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5412 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5413 ······find:5413 ······find:
5414 ········paths:·/etc/audit/rules.d5414 ········paths:·/etc/audit/rules.d
5415 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5415 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5416 ········patterns:·'*.rules'5416 ········patterns:·'*.rules'
5417 ······register:·find_watch_key5417 ······register:·find_watch_key
5418 ······when:5418 ······when:
5419 ······-·'"audit"·in·ansible_facts.packages' 
5420 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5419 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5420 ······-·'"audit"·in·ansible_facts.packages'
5421 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5421 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5422 ········==·05422 ········==·0
5423 ······tags:5423 ······tags:
5424 ······-·CCE-80721-45424 ······-·CCE-80721-4
5425 ······-·CJIS-5.4.1.15425 ······-·CJIS-5.4.1.1
5426 ······-·NIST-800-171-3.1.85426 ······-·NIST-800-171-3.1.8
5427 ······-·NIST-800-53-AU-12(c)5427 ······-·NIST-800-53-AU-12(c)
Offset 5436, 16 lines modifiedOffset 5436, 16 lines modified
5436 ······-·restrict_strategy5436 ······-·restrict_strategy
  
5437 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5437 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5438 ······set_fact:5438 ······set_fact:
5439 ········all_files:5439 ········all_files:
5440 ········-·/etc/audit/rules.d/MAC-policy.rules5440 ········-·/etc/audit/rules.d/MAC-policy.rules
5441 ······when:5441 ······when:
5442 ······-·'"audit"·in·ansible_facts.packages' 
5443 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5442 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5443 ······-·'"audit"·in·ansible_facts.packages'
5444 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5444 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5445 ········is·defined·and·find_existing_watch_rules_d.matched·==·05445 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5446 ······tags:5446 ······tags:
5447 ······-·CCE-80721-45447 ······-·CCE-80721-4
5448 ······-·CJIS-5.4.1.15448 ······-·CJIS-5.4.1.1
5449 ······-·NIST-800-171-3.1.85449 ······-·NIST-800-171-3.1.8
5450 ······-·NIST-800-53-AU-12(c)5450 ······-·NIST-800-53-AU-12(c)
Offset 5460, 16 lines modifiedOffset 5460, 16 lines modified
5460 ······-·restrict_strategy5460 ······-·restrict_strategy
  
5461 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5461 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5462 ······set_fact:5462 ······set_fact:
5463 ········all_files:5463 ········all_files:
5464 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5464 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5465 ······when:5465 ······when:
5466 ······-·'"audit"·in·ansible_facts.packages' 
5467 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5466 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5467 ······-·'"audit"·in·ansible_facts.packages'
5468 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5468 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5469 ········is·defined·and·find_existing_watch_rules_d.matched·==·05469 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5470 ······tags:5470 ······tags:
5471 ······-·CCE-80721-45471 ······-·CCE-80721-4
5472 ······-·CJIS-5.4.1.15472 ······-·CJIS-5.4.1.1
5473 ······-·NIST-800-171-3.1.85473 ······-·NIST-800-171-3.1.8
5474 ······-·NIST-800-53-AU-12(c)5474 ······-·NIST-800-53-AU-12(c)
Offset 5486, 16 lines modifiedOffset 5486, 16 lines modified
5486 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5486 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 156814/161462 bytes (97.12%) of diff not shown.
3.88 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-rht-ccp.yml
Ordering differences only
    
Offset 3276, 16 lines modifiedOffset 3276, 16 lines modified
3276 ······-·no_reboot_needed3276 ······-·no_reboot_needed
  
3277 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg3277 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
3278 ······stat:3278 ······stat:
3279 ········path:·/boot/grub2/grub.cfg3279 ········path:·/boot/grub2/grub.cfg
3280 ······register:·file_exists3280 ······register:·file_exists
3281 ······when:3281 ······when:
3282 ······-·'"grub2-common"·in·ansible_facts.packages' 
3283 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3282 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3283 ······-·'"grub2-common"·in·ansible_facts.packages'
3284 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3284 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3285 ······tags:3285 ······tags:
3286 ······-·CCE-80800-63286 ······-·CCE-80800-6
3287 ······-·CJIS-5.5.2.23287 ······-·CJIS-5.5.2.2
3288 ······-·NIST-800-171-3.4.53288 ······-·NIST-800-171-3.4.5
3289 ······-·NIST-800-53-AC-6(1)3289 ······-·NIST-800-53-AC-6(1)
3290 ······-·NIST-800-53-CM-6(a)3290 ······-·NIST-800-53-CM-6(a)
Offset 3298, 16 lines modifiedOffset 3298, 16 lines modified
3298 ······-·no_reboot_needed3298 ······-·no_reboot_needed
  
3299 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg3299 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
3300 ······file:3300 ······file:
3301 ········path:·/boot/grub2/grub.cfg3301 ········path:·/boot/grub2/grub.cfg
3302 ········group:·'0'3302 ········group:·'0'
3303 ······when:3303 ······when:
3304 ······-·'"grub2-common"·in·ansible_facts.packages' 
3305 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3304 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3305 ······-·'"grub2-common"·in·ansible_facts.packages'
3306 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3306 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3307 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists3307 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
3308 ······tags:3308 ······tags:
3309 ······-·CCE-80800-63309 ······-·CCE-80800-6
3310 ······-·CJIS-5.5.2.23310 ······-·CJIS-5.5.2.2
3311 ······-·NIST-800-171-3.4.53311 ······-·NIST-800-171-3.4.5
3312 ······-·NIST-800-53-AC-6(1)3312 ······-·NIST-800-53-AC-6(1)
Offset 3339, 16 lines modifiedOffset 3339, 16 lines modified
3339 ······-·no_reboot_needed3339 ······-·no_reboot_needed
  
3340 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg3340 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
3341 ······stat:3341 ······stat:
3342 ········path:·/boot/grub2/grub.cfg3342 ········path:·/boot/grub2/grub.cfg
3343 ······register:·file_exists3343 ······register:·file_exists
3344 ······when:3344 ······when:
3345 ······-·'"grub2-common"·in·ansible_facts.packages' 
3346 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3345 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3346 ······-·'"grub2-common"·in·ansible_facts.packages'
3347 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3347 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3348 ······tags:3348 ······tags:
3349 ······-·CCE-80805-53349 ······-·CCE-80805-5
3350 ······-·CJIS-5.5.2.23350 ······-·CJIS-5.5.2.2
3351 ······-·NIST-800-171-3.4.53351 ······-·NIST-800-171-3.4.5
3352 ······-·NIST-800-53-AC-6(1)3352 ······-·NIST-800-53-AC-6(1)
3353 ······-·NIST-800-53-CM-6(a)3353 ······-·NIST-800-53-CM-6(a)
Offset 3361, 16 lines modifiedOffset 3361, 16 lines modified
3361 ······-·no_reboot_needed3361 ······-·no_reboot_needed
  
3362 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg3362 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
3363 ······file:3363 ······file:
3364 ········path:·/boot/grub2/grub.cfg3364 ········path:·/boot/grub2/grub.cfg
3365 ········owner:·'0'3365 ········owner:·'0'
3366 ······when:3366 ······when:
3367 ······-·'"grub2-common"·in·ansible_facts.packages' 
3368 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3367 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3368 ······-·'"grub2-common"·in·ansible_facts.packages'
3369 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3369 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3370 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists3370 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
3371 ······tags:3371 ······tags:
3372 ······-·CCE-80805-53372 ······-·CCE-80805-5
3373 ······-·CJIS-5.5.2.23373 ······-·CJIS-5.5.2.2
3374 ······-·NIST-800-171-3.4.53374 ······-·NIST-800-171-3.4.5
3375 ······-·NIST-800-53-AC-6(1)3375 ······-·NIST-800-53-AC-6(1)
Offset 3400, 16 lines modifiedOffset 3400, 16 lines modified
3400 ······-·no_reboot_needed3400 ······-·no_reboot_needed
  
3401 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg3401 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
3402 ······stat:3402 ······stat:
3403 ········path:·/boot/grub2/grub.cfg3403 ········path:·/boot/grub2/grub.cfg
3404 ······register:·file_exists3404 ······register:·file_exists
3405 ······when:3405 ······when:
3406 ······-·'"grub2-common"·in·ansible_facts.packages' 
3407 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3406 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3407 ······-·'"grub2-common"·in·ansible_facts.packages'
3408 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3408 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3409 ······tags:3409 ······tags:
3410 ······-·CCE-80814-73410 ······-·CCE-80814-7
3411 ······-·NIST-800-171-3.4.53411 ······-·NIST-800-171-3.4.5
3412 ······-·NIST-800-53-AC-6(1)3412 ······-·NIST-800-53-AC-6(1)
3413 ······-·NIST-800-53-CM-6(a)3413 ······-·NIST-800-53-CM-6(a)
3414 ······-·configure_strategy3414 ······-·configure_strategy
Offset 3420, 16 lines modifiedOffset 3420, 16 lines modified
3420 ······-·no_reboot_needed3420 ······-·no_reboot_needed
  
3421 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg3421 ····-·name:·Ensure·permission·u-xs,g-xwrs,o-xwrt·on·/boot/grub2/grub.cfg
3422 ······file:3422 ······file:
3423 ········path:·/boot/grub2/grub.cfg3423 ········path:·/boot/grub2/grub.cfg
3424 ········mode:·u-xs,g-xwrs,o-xwrt3424 ········mode:·u-xs,g-xwrs,o-xwrt
3425 ······when:3425 ······when:
3426 ······-·'"grub2-common"·in·ansible_facts.packages' 
3427 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'3426 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 3427 ······-·'"grub2-common"·in·ansible_facts.packages'
3428 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3428 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
3429 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists3429 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
3430 ······tags:3430 ······tags:
3431 ······-·CCE-80814-73431 ······-·CCE-80814-7
3432 ······-·NIST-800-171-3.4.53432 ······-·NIST-800-171-3.4.5
3433 ······-·NIST-800-53-AC-6(1)3433 ······-·NIST-800-53-AC-6(1)
3434 ······-·NIST-800-53-CM-6(a)3434 ······-·NIST-800-53-CM-6(a)
78.0 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-standard.yml
Ordering differences only
    
Offset 849, 16 lines modifiedOffset 849, 16 lines modified
849 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/849 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
850 ······find:850 ······find:
851 ········paths:·/etc/audit/rules.d851 ········paths:·/etc/audit/rules.d
852 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+852 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
853 ········patterns:·'*.rules'853 ········patterns:·'*.rules'
854 ······register:·find_existing_watch_rules_d854 ······register:·find_existing_watch_rules_d
855 ······when:855 ······when:
856 ······-·'"audit"·in·ansible_facts.packages' 
857 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]856 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 857 ······-·'"audit"·in·ansible_facts.packages'
858 ······tags:858 ······tags:
859 ······-·CCE-80721-4859 ······-·CCE-80721-4
860 ······-·CJIS-5.4.1.1860 ······-·CJIS-5.4.1.1
861 ······-·NIST-800-171-3.1.8861 ······-·NIST-800-171-3.1.8
862 ······-·NIST-800-53-AU-12(c)862 ······-·NIST-800-53-AU-12(c)
863 ······-·NIST-800-53-AU-2(d)863 ······-·NIST-800-53-AU-2(d)
864 ······-·NIST-800-53-CM-6(a)864 ······-·NIST-800-53-CM-6(a)
Offset 873, 16 lines modifiedOffset 873, 16 lines modified
873 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy873 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
874 ······find:874 ······find:
875 ········paths:·/etc/audit/rules.d875 ········paths:·/etc/audit/rules.d
876 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$876 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
877 ········patterns:·'*.rules'877 ········patterns:·'*.rules'
878 ······register:·find_watch_key878 ······register:·find_watch_key
879 ······when:879 ······when:
880 ······-·'"audit"·in·ansible_facts.packages' 
881 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]880 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 881 ······-·'"audit"·in·ansible_facts.packages'
882 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched882 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
883 ········==·0883 ········==·0
884 ······tags:884 ······tags:
885 ······-·CCE-80721-4885 ······-·CCE-80721-4
886 ······-·CJIS-5.4.1.1886 ······-·CJIS-5.4.1.1
887 ······-·NIST-800-171-3.1.8887 ······-·NIST-800-171-3.1.8
888 ······-·NIST-800-53-AU-12(c)888 ······-·NIST-800-53-AU-12(c)
Offset 897, 16 lines modifiedOffset 897, 16 lines modified
897 ······-·restrict_strategy897 ······-·restrict_strategy
  
898 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule898 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
899 ······set_fact:899 ······set_fact:
900 ········all_files:900 ········all_files:
901 ········-·/etc/audit/rules.d/MAC-policy.rules901 ········-·/etc/audit/rules.d/MAC-policy.rules
902 ······when:902 ······when:
903 ······-·'"audit"·in·ansible_facts.packages' 
904 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]903 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 904 ······-·'"audit"·in·ansible_facts.packages'
905 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched905 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
906 ········is·defined·and·find_existing_watch_rules_d.matched·==·0906 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
907 ······tags:907 ······tags:
908 ······-·CCE-80721-4908 ······-·CCE-80721-4
909 ······-·CJIS-5.4.1.1909 ······-·CJIS-5.4.1.1
910 ······-·NIST-800-171-3.1.8910 ······-·NIST-800-171-3.1.8
911 ······-·NIST-800-53-AU-12(c)911 ······-·NIST-800-53-AU-12(c)
Offset 921, 16 lines modifiedOffset 921, 16 lines modified
921 ······-·restrict_strategy921 ······-·restrict_strategy
  
922 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule922 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
923 ······set_fact:923 ······set_fact:
924 ········all_files:924 ········all_files:
925 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'925 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
926 ······when:926 ······when:
927 ······-·'"audit"·in·ansible_facts.packages' 
928 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]927 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 928 ······-·'"audit"·in·ansible_facts.packages'
929 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched929 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
930 ········is·defined·and·find_existing_watch_rules_d.matched·==·0930 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
931 ······tags:931 ······tags:
932 ······-·CCE-80721-4932 ······-·CCE-80721-4
933 ······-·CJIS-5.4.1.1933 ······-·CJIS-5.4.1.1
934 ······-·NIST-800-171-3.1.8934 ······-·NIST-800-171-3.1.8
935 ······-·NIST-800-53-AU-12(c)935 ······-·NIST-800-53-AU-12(c)
Offset 947, 16 lines modifiedOffset 947, 16 lines modified
947 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/947 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
948 ······lineinfile:948 ······lineinfile:
949 ········path:·'{{·all_files[0]·}}'949 ········path:·'{{·all_files[0]·}}'
950 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy950 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
951 ········create:·true951 ········create:·true
952 ········mode:·'0640'952 ········mode:·'0640'
953 ······when:953 ······when:
954 ······-·'"audit"·in·ansible_facts.packages' 
955 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]954 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 955 ······-·'"audit"·in·ansible_facts.packages'
956 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched956 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
957 ········==·0957 ········==·0
958 ······tags:958 ······tags:
959 ······-·CCE-80721-4959 ······-·CCE-80721-4
960 ······-·CJIS-5.4.1.1960 ······-·CJIS-5.4.1.1
961 ······-·NIST-800-171-3.1.8961 ······-·NIST-800-171-3.1.8
962 ······-·NIST-800-53-AU-12(c)962 ······-·NIST-800-53-AU-12(c)
Offset 973, 16 lines modifiedOffset 973, 16 lines modified
973 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules973 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules
974 ······find:974 ······find:
975 ········paths:·/etc/audit/975 ········paths:·/etc/audit/
976 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+976 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
977 ········patterns:·audit.rules977 ········patterns:·audit.rules
978 ······register:·find_existing_watch_audit_rules978 ······register:·find_existing_watch_audit_rules
979 ······when:979 ······when:
980 ······-·'"audit"·in·ansible_facts.packages' 
981 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]980 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 981 ······-·'"audit"·in·ansible_facts.packages'
982 ······tags:982 ······tags:
983 ······-·CCE-80721-4983 ······-·CCE-80721-4
984 ······-·CJIS-5.4.1.1984 ······-·CJIS-5.4.1.1
985 ······-·NIST-800-171-3.1.8985 ······-·NIST-800-171-3.1.8
986 ······-·NIST-800-53-AU-12(c)986 ······-·NIST-800-53-AU-12(c)
987 ······-·NIST-800-53-AU-2(d)987 ······-·NIST-800-53-AU-2(d)
988 ······-·NIST-800-53-CM-6(a)988 ······-·NIST-800-53-CM-6(a)
Offset 998, 16 lines modifiedOffset 998, 16 lines modified
998 ······lineinfile:998 ······lineinfile:
999 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy999 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
1000 ········state:·present1000 ········state:·present
1001 ········dest:·/etc/audit/audit.rules1001 ········dest:·/etc/audit/audit.rules
1002 ········create:·true1002 ········create:·true
1003 ········mode:·'0640'1003 ········mode:·'0640'
1004 ······when:1004 ······when:
1005 ······-·'"audit"·in·ansible_facts.packages' 
1006 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1005 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1006 ······-·'"audit"·in·ansible_facts.packages'
1007 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched1007 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
1008 ········==·01008 ········==·0
1009 ······tags:1009 ······tags:
1010 ······-·CCE-80721-41010 ······-·CCE-80721-4
1011 ······-·CJIS-5.4.1.11011 ······-·CJIS-5.4.1.1
1012 ······-·NIST-800-171-3.1.81012 ······-·NIST-800-171-3.1.8
1013 ······-·NIST-800-53-AU-12(c)1013 ······-·NIST-800-53-AU-12(c)
Offset 1042, 16 lines modifiedOffset 1042, 16 lines modified
1042 ······-·reboot_required1042 ······-·reboot_required
Max diff block lines reached; 74862/79676 bytes (93.96%) of diff not shown.
129 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-stig.yml
Ordering differences only
    
Offset 11836, 16 lines modifiedOffset 11836, 16 lines modified
  
11836 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension11836 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
11837 ······find:11837 ······find:
11838 ········paths:·/etc/audit/rules.d/11838 ········paths:·/etc/audit/rules.d/
11839 ········patterns:·'*.rules'11839 ········patterns:·'*.rules'
11840 ······register:·find_rules_d11840 ······register:·find_rules_d
11841 ······when:11841 ······when:
11842 ······-·'"audit"·in·ansible_facts.packages' 
11843 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11842 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11843 ······-·'"audit"·in·ansible_facts.packages'
11844 ······tags:11844 ······tags:
11845 ······-·CCE-80708-111845 ······-·CCE-80708-1
11846 ······-·CJIS-5.4.1.111846 ······-·CJIS-5.4.1.1
11847 ······-·DISA-STIG-RHEL-08-03012111847 ······-·DISA-STIG-RHEL-08-030121
11848 ······-·NIST-800-171-3.3.111848 ······-·NIST-800-171-3.3.1
11849 ······-·NIST-800-171-3.4.311849 ······-·NIST-800-171-3.4.3
11850 ······-·NIST-800-53-AC-6(9)11850 ······-·NIST-800-53-AC-6(9)
Offset 11862, 16 lines modifiedOffset 11862, 16 lines modified
11862 ······lineinfile:11862 ······lineinfile:
11863 ········path:·'{{·item·}}'11863 ········path:·'{{·item·}}'
11864 ········regexp:·^\s*(?:-e)\s+.*$11864 ········regexp:·^\s*(?:-e)\s+.*$
11865 ········state:·absent11865 ········state:·absent
11866 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']11866 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
11867 ········}}'11867 ········}}'
11868 ······when:11868 ······when:
11869 ······-·'"audit"·in·ansible_facts.packages' 
11870 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11869 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11870 ······-·'"audit"·in·ansible_facts.packages'
11871 ······tags:11871 ······tags:
11872 ······-·CCE-80708-111872 ······-·CCE-80708-1
11873 ······-·CJIS-5.4.1.111873 ······-·CJIS-5.4.1.1
11874 ······-·DISA-STIG-RHEL-08-03012111874 ······-·DISA-STIG-RHEL-08-030121
11875 ······-·NIST-800-171-3.3.111875 ······-·NIST-800-171-3.3.1
11876 ······-·NIST-800-171-3.4.311876 ······-·NIST-800-171-3.4.3
11877 ······-·NIST-800-53-AC-6(9)11877 ······-·NIST-800-53-AC-6(9)
Offset 11890, 16 lines modifiedOffset 11890, 16 lines modified
11890 ········create:·true11890 ········create:·true
11891 ········line:·-e·211891 ········line:·-e·2
11892 ········mode:·o-rwx11892 ········mode:·o-rwx
11893 ······loop:11893 ······loop:
11894 ······-·/etc/audit/audit.rules11894 ······-·/etc/audit/audit.rules
11895 ······-·/etc/audit/rules.d/immutable.rules11895 ······-·/etc/audit/rules.d/immutable.rules
11896 ······when:11896 ······when:
11897 ······-·'"audit"·in·ansible_facts.packages' 
11898 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11897 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11898 ······-·'"audit"·in·ansible_facts.packages'
11899 ······tags:11899 ······tags:
11900 ······-·CCE-80708-111900 ······-·CCE-80708-1
11901 ······-·CJIS-5.4.1.111901 ······-·CJIS-5.4.1.1
11902 ······-·DISA-STIG-RHEL-08-03012111902 ······-·DISA-STIG-RHEL-08-030121
11903 ······-·NIST-800-171-3.3.111903 ······-·NIST-800-171-3.3.1
11904 ······-·NIST-800-171-3.4.311904 ······-·NIST-800-171-3.4.3
11905 ······-·NIST-800-53-AC-6(9)11905 ······-·NIST-800-53-AC-6(9)
Offset 11933, 16 lines modifiedOffset 11933, 16 lines modified
11933 ······-·reboot_required11933 ······-·reboot_required
11934 ······-·restrict_strategy11934 ······-·restrict_strategy
  
11935 ····-·name:·Set·architecture·for·audit·mount·tasks11935 ····-·name:·Set·architecture·for·audit·mount·tasks
11936 ······set_fact:11936 ······set_fact:
11937 ········audit_arch:·b6411937 ········audit_arch:·b64
11938 ······when:11938 ······when:
11939 ······-·'"audit"·in·ansible_facts.packages' 
11940 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11939 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11940 ······-·'"audit"·in·ansible_facts.packages'
11941 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture11941 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
11942 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"11942 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
11943 ······tags:11943 ······tags:
11944 ······-·CCE-80722-211944 ······-·CCE-80722-2
11945 ······-·CJIS-5.4.1.111945 ······-·CJIS-5.4.1.1
11946 ······-·DISA-STIG-RHEL-08-03030211946 ······-·DISA-STIG-RHEL-08-030302
11947 ······-·NIST-800-171-3.1.711947 ······-·NIST-800-171-3.1.7
Offset 12075, 16 lines modifiedOffset 12075, 16 lines modified
12075 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012075 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12076 ············-F·auid!=unset·-F·key=perm_mod12076 ············-F·auid!=unset·-F·key=perm_mod
12077 ··········create:·true12077 ··········create:·true
12078 ··········mode:·o-rwx12078 ··········mode:·o-rwx
12079 ··········state:·present12079 ··········state:·present
12080 ········when:·syscalls_found·|·length·==·012080 ········when:·syscalls_found·|·length·==·0
12081 ······when:12081 ······when:
12082 ······-·'"audit"·in·ansible_facts.packages' 
12083 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12082 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12083 ······-·'"audit"·in·ansible_facts.packages'
12084 ······tags:12084 ······tags:
12085 ······-·CCE-80722-212085 ······-·CCE-80722-2
12086 ······-·CJIS-5.4.1.112086 ······-·CJIS-5.4.1.1
12087 ······-·DISA-STIG-RHEL-08-03030212087 ······-·DISA-STIG-RHEL-08-030302
12088 ······-·NIST-800-171-3.1.712088 ······-·NIST-800-171-3.1.7
12089 ······-·NIST-800-53-AC-6(9)12089 ······-·NIST-800-53-AC-6(9)
12090 ······-·NIST-800-53-AU-12(c)12090 ······-·NIST-800-53-AU-12(c)
Offset 12215, 16 lines modifiedOffset 12215, 16 lines modified
12215 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012215 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12216 ············-F·auid!=unset·-F·key=perm_mod12216 ············-F·auid!=unset·-F·key=perm_mod
12217 ··········create:·true12217 ··········create:·true
12218 ··········mode:·o-rwx12218 ··········mode:·o-rwx
12219 ··········state:·present12219 ··········state:·present
12220 ········when:·syscalls_found·|·length·==·012220 ········when:·syscalls_found·|·length·==·0
12221 ······when:12221 ······when:
12222 ······-·'"audit"·in·ansible_facts.packages' 
12223 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12222 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12223 ······-·'"audit"·in·ansible_facts.packages'
12224 ······-·audit_arch·==·"b64"12224 ······-·audit_arch·==·"b64"
12225 ······tags:12225 ······tags:
12226 ······-·CCE-80722-212226 ······-·CCE-80722-2
12227 ······-·CJIS-5.4.1.112227 ······-·CJIS-5.4.1.1
12228 ······-·DISA-STIG-RHEL-08-03030212228 ······-·DISA-STIG-RHEL-08-030302
12229 ······-·NIST-800-171-3.1.712229 ······-·NIST-800-171-3.1.7
12230 ······-·NIST-800-53-AC-6(9)12230 ······-·NIST-800-53-AC-6(9)
Offset 12256, 16 lines modifiedOffset 12256, 16 lines modified
12256 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/12256 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
12257 ······find:12257 ······find:
12258 ········paths:·/etc/audit/rules.d12258 ········paths:·/etc/audit/rules.d
12259 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+12259 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
12260 ········patterns:·'*.rules'12260 ········patterns:·'*.rules'
12261 ······register:·find_existing_watch_rules_d12261 ······register:·find_existing_watch_rules_d
12262 ······when:12262 ······when:
12263 ······-·'"audit"·in·ansible_facts.packages' 
12264 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12263 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12264 ······-·'"audit"·in·ansible_facts.packages'
12265 ······tags:12265 ······tags:
12266 ······-·CCE-90175-112266 ······-·CCE-90175-1
12267 ······-·DISA-STIG-RHEL-08-03017112267 ······-·DISA-STIG-RHEL-08-030171
12268 ······-·audit_rules_sudoers12268 ······-·audit_rules_sudoers
12269 ······-·low_complexity12269 ······-·low_complexity
12270 ······-·low_disruption12270 ······-·low_disruption
12271 ······-·medium_severity12271 ······-·medium_severity
Offset 12275, 16 lines modifiedOffset 12275, 16 lines modified
12275 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions12275 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 127558/132078 bytes (96.58%) of diff not shown.
129 KB
./usr/share/scap-security-guide/ansible/rhel8-playbook-stig_gui.yml
Ordering differences only
    
Offset 11826, 16 lines modifiedOffset 11826, 16 lines modified
  
11826 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension11826 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
11827 ······find:11827 ······find:
11828 ········paths:·/etc/audit/rules.d/11828 ········paths:·/etc/audit/rules.d/
11829 ········patterns:·'*.rules'11829 ········patterns:·'*.rules'
11830 ······register:·find_rules_d11830 ······register:·find_rules_d
11831 ······when:11831 ······when:
11832 ······-·'"audit"·in·ansible_facts.packages' 
11833 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11832 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11833 ······-·'"audit"·in·ansible_facts.packages'
11834 ······tags:11834 ······tags:
11835 ······-·CCE-80708-111835 ······-·CCE-80708-1
11836 ······-·CJIS-5.4.1.111836 ······-·CJIS-5.4.1.1
11837 ······-·DISA-STIG-RHEL-08-03012111837 ······-·DISA-STIG-RHEL-08-030121
11838 ······-·NIST-800-171-3.3.111838 ······-·NIST-800-171-3.3.1
11839 ······-·NIST-800-171-3.4.311839 ······-·NIST-800-171-3.4.3
11840 ······-·NIST-800-53-AC-6(9)11840 ······-·NIST-800-53-AC-6(9)
Offset 11852, 16 lines modifiedOffset 11852, 16 lines modified
11852 ······lineinfile:11852 ······lineinfile:
11853 ········path:·'{{·item·}}'11853 ········path:·'{{·item·}}'
11854 ········regexp:·^\s*(?:-e)\s+.*$11854 ········regexp:·^\s*(?:-e)\s+.*$
11855 ········state:·absent11855 ········state:·absent
11856 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']11856 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
11857 ········}}'11857 ········}}'
11858 ······when:11858 ······when:
11859 ······-·'"audit"·in·ansible_facts.packages' 
11860 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11859 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11860 ······-·'"audit"·in·ansible_facts.packages'
11861 ······tags:11861 ······tags:
11862 ······-·CCE-80708-111862 ······-·CCE-80708-1
11863 ······-·CJIS-5.4.1.111863 ······-·CJIS-5.4.1.1
11864 ······-·DISA-STIG-RHEL-08-03012111864 ······-·DISA-STIG-RHEL-08-030121
11865 ······-·NIST-800-171-3.3.111865 ······-·NIST-800-171-3.3.1
11866 ······-·NIST-800-171-3.4.311866 ······-·NIST-800-171-3.4.3
11867 ······-·NIST-800-53-AC-6(9)11867 ······-·NIST-800-53-AC-6(9)
Offset 11880, 16 lines modifiedOffset 11880, 16 lines modified
11880 ········create:·true11880 ········create:·true
11881 ········line:·-e·211881 ········line:·-e·2
11882 ········mode:·o-rwx11882 ········mode:·o-rwx
11883 ······loop:11883 ······loop:
11884 ······-·/etc/audit/audit.rules11884 ······-·/etc/audit/audit.rules
11885 ······-·/etc/audit/rules.d/immutable.rules11885 ······-·/etc/audit/rules.d/immutable.rules
11886 ······when:11886 ······when:
11887 ······-·'"audit"·in·ansible_facts.packages' 
11888 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11887 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11888 ······-·'"audit"·in·ansible_facts.packages'
11889 ······tags:11889 ······tags:
11890 ······-·CCE-80708-111890 ······-·CCE-80708-1
11891 ······-·CJIS-5.4.1.111891 ······-·CJIS-5.4.1.1
11892 ······-·DISA-STIG-RHEL-08-03012111892 ······-·DISA-STIG-RHEL-08-030121
11893 ······-·NIST-800-171-3.3.111893 ······-·NIST-800-171-3.3.1
11894 ······-·NIST-800-171-3.4.311894 ······-·NIST-800-171-3.4.3
11895 ······-·NIST-800-53-AC-6(9)11895 ······-·NIST-800-53-AC-6(9)
Offset 11923, 16 lines modifiedOffset 11923, 16 lines modified
11923 ······-·reboot_required11923 ······-·reboot_required
11924 ······-·restrict_strategy11924 ······-·restrict_strategy
  
11925 ····-·name:·Set·architecture·for·audit·mount·tasks11925 ····-·name:·Set·architecture·for·audit·mount·tasks
11926 ······set_fact:11926 ······set_fact:
11927 ········audit_arch:·b6411927 ········audit_arch:·b64
11928 ······when:11928 ······when:
11929 ······-·'"audit"·in·ansible_facts.packages' 
11930 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]11929 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 11930 ······-·'"audit"·in·ansible_facts.packages'
11931 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture11931 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
11932 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"11932 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
11933 ······tags:11933 ······tags:
11934 ······-·CCE-80722-211934 ······-·CCE-80722-2
11935 ······-·CJIS-5.4.1.111935 ······-·CJIS-5.4.1.1
11936 ······-·DISA-STIG-RHEL-08-03030211936 ······-·DISA-STIG-RHEL-08-030302
11937 ······-·NIST-800-171-3.1.711937 ······-·NIST-800-171-3.1.7
Offset 12065, 16 lines modifiedOffset 12065, 16 lines modified
12065 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012065 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12066 ············-F·auid!=unset·-F·key=perm_mod12066 ············-F·auid!=unset·-F·key=perm_mod
12067 ··········create:·true12067 ··········create:·true
12068 ··········mode:·o-rwx12068 ··········mode:·o-rwx
12069 ··········state:·present12069 ··········state:·present
12070 ········when:·syscalls_found·|·length·==·012070 ········when:·syscalls_found·|·length·==·0
12071 ······when:12071 ······when:
12072 ······-·'"audit"·in·ansible_facts.packages' 
12073 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12072 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12073 ······-·'"audit"·in·ansible_facts.packages'
12074 ······tags:12074 ······tags:
12075 ······-·CCE-80722-212075 ······-·CCE-80722-2
12076 ······-·CJIS-5.4.1.112076 ······-·CJIS-5.4.1.1
12077 ······-·DISA-STIG-RHEL-08-03030212077 ······-·DISA-STIG-RHEL-08-030302
12078 ······-·NIST-800-171-3.1.712078 ······-·NIST-800-171-3.1.7
12079 ······-·NIST-800-53-AC-6(9)12079 ······-·NIST-800-53-AC-6(9)
12080 ······-·NIST-800-53-AU-12(c)12080 ······-·NIST-800-53-AU-12(c)
Offset 12205, 16 lines modifiedOffset 12205, 16 lines modified
12205 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012205 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12206 ············-F·auid!=unset·-F·key=perm_mod12206 ············-F·auid!=unset·-F·key=perm_mod
12207 ··········create:·true12207 ··········create:·true
12208 ··········mode:·o-rwx12208 ··········mode:·o-rwx
12209 ··········state:·present12209 ··········state:·present
12210 ········when:·syscalls_found·|·length·==·012210 ········when:·syscalls_found·|·length·==·0
12211 ······when:12211 ······when:
12212 ······-·'"audit"·in·ansible_facts.packages' 
12213 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12212 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12213 ······-·'"audit"·in·ansible_facts.packages'
12214 ······-·audit_arch·==·"b64"12214 ······-·audit_arch·==·"b64"
12215 ······tags:12215 ······tags:
12216 ······-·CCE-80722-212216 ······-·CCE-80722-2
12217 ······-·CJIS-5.4.1.112217 ······-·CJIS-5.4.1.1
12218 ······-·DISA-STIG-RHEL-08-03030212218 ······-·DISA-STIG-RHEL-08-030302
12219 ······-·NIST-800-171-3.1.712219 ······-·NIST-800-171-3.1.7
12220 ······-·NIST-800-53-AC-6(9)12220 ······-·NIST-800-53-AC-6(9)
Offset 12246, 16 lines modifiedOffset 12246, 16 lines modified
12246 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/12246 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
12247 ······find:12247 ······find:
12248 ········paths:·/etc/audit/rules.d12248 ········paths:·/etc/audit/rules.d
12249 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+12249 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
12250 ········patterns:·'*.rules'12250 ········patterns:·'*.rules'
12251 ······register:·find_existing_watch_rules_d12251 ······register:·find_existing_watch_rules_d
12252 ······when:12252 ······when:
12253 ······-·'"audit"·in·ansible_facts.packages' 
12254 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12253 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12254 ······-·'"audit"·in·ansible_facts.packages'
12255 ······tags:12255 ······tags:
12256 ······-·CCE-90175-112256 ······-·CCE-90175-1
12257 ······-·DISA-STIG-RHEL-08-03017112257 ······-·DISA-STIG-RHEL-08-030171
12258 ······-·audit_rules_sudoers12258 ······-·audit_rules_sudoers
12259 ······-·low_complexity12259 ······-·low_complexity
12260 ······-·low_disruption12260 ······-·low_disruption
12261 ······-·medium_severity12261 ······-·medium_severity
Offset 12265, 16 lines modifiedOffset 12265, 16 lines modified
12265 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions12265 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 127558/132078 bytes (96.58%) of diff not shown.
849 B
./usr/share/scap-security-guide/ansible/rhel9-playbook-anssi_bp28_enhanced.yml
Ordering differences only
    
Offset 5432, 16 lines modifiedOffset 5432, 16 lines modified
5432 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5432 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5433 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5433 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5434 ··········create:·true5434 ··········create:·true
5435 ··········mode:·o-rwx5435 ··········mode:·o-rwx
5436 ··········state:·present5436 ··········state:·present
5437 ········when:·syscalls_found·|·length·==·05437 ········when:·syscalls_found·|·length·==·0
5438 ······when:5438 ······when:
5439 ······-·'"audit"·in·ansible_facts.packages' 
5440 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5439 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5440 ······-·'"audit"·in·ansible_facts.packages'
5441 ······tags:5441 ······tags:
5442 ······-·CCE-83780-75442 ······-·CCE-83780-7
5443 ······-·NIST-800-171-3.1.75443 ······-·NIST-800-171-3.1.7
5444 ······-·NIST-800-53-AC-6(9)5444 ······-·NIST-800-53-AC-6(9)
5445 ······-·NIST-800-53-AU-12(c)5445 ······-·NIST-800-53-AU-12(c)
5446 ······-·NIST-800-53-AU-2(d)5446 ······-·NIST-800-53-AU-2(d)
5447 ······-·NIST-800-53-CM-6(a)5447 ······-·NIST-800-53-CM-6(a)
841 B
./usr/share/scap-security-guide/ansible/rhel9-playbook-anssi_bp28_high.yml
Ordering differences only
    
Offset 5540, 16 lines modifiedOffset 5540, 16 lines modified
5540 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5540 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5541 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5541 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5542 ··········create:·true5542 ··········create:·true
5543 ··········mode:·o-rwx5543 ··········mode:·o-rwx
5544 ··········state:·present5544 ··········state:·present
5545 ········when:·syscalls_found·|·length·==·05545 ········when:·syscalls_found·|·length·==·0
5546 ······when:5546 ······when:
5547 ······-·'"audit"·in·ansible_facts.packages' 
5548 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5547 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5548 ······-·'"audit"·in·ansible_facts.packages'
5549 ······tags:5549 ······tags:
5550 ······-·CCE-83780-75550 ······-·CCE-83780-7
5551 ······-·NIST-800-171-3.1.75551 ······-·NIST-800-171-3.1.7
5552 ······-·NIST-800-53-AC-6(9)5552 ······-·NIST-800-53-AC-6(9)
5553 ······-·NIST-800-53-AU-12(c)5553 ······-·NIST-800-53-AU-12(c)
5554 ······-·NIST-800-53-AU-2(d)5554 ······-·NIST-800-53-AU-2(d)
5555 ······-·NIST-800-53-CM-6(a)5555 ······-·NIST-800-53-CM-6(a)
857 B
./usr/share/scap-security-guide/ansible/rhel9-playbook-anssi_bp28_intermediary.yml
Ordering differences only
    
Offset 5153, 16 lines modifiedOffset 5153, 16 lines modified
5153 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5153 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5154 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5154 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5155 ··········create:·true5155 ··········create:·true
5156 ··········mode:·o-rwx5156 ··········mode:·o-rwx
5157 ··········state:·present5157 ··········state:·present
5158 ········when:·syscalls_found·|·length·==·05158 ········when:·syscalls_found·|·length·==·0
5159 ······when:5159 ······when:
5160 ······-·'"audit"·in·ansible_facts.packages' 
5161 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5160 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5161 ······-·'"audit"·in·ansible_facts.packages'
5162 ······tags:5162 ······tags:
5163 ······-·CCE-83780-75163 ······-·CCE-83780-7
5164 ······-·NIST-800-171-3.1.75164 ······-·NIST-800-171-3.1.7
5165 ······-·NIST-800-53-AC-6(9)5165 ······-·NIST-800-53-AC-6(9)
5166 ······-·NIST-800-53-AU-12(c)5166 ······-·NIST-800-53-AU-12(c)
5167 ······-·NIST-800-53-AU-2(d)5167 ······-·NIST-800-53-AU-2(d)
5168 ······-·NIST-800-53-CM-6(a)5168 ······-·NIST-800-53-CM-6(a)
158 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-cis.yml
Ordering differences only
    
Offset 5378, 16 lines modifiedOffset 5378, 16 lines modified
  
5378 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5378 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5379 ······find:5379 ······find:
5380 ········paths:·/etc/audit/rules.d/5380 ········paths:·/etc/audit/rules.d/
5381 ········patterns:·'*.rules'5381 ········patterns:·'*.rules'
5382 ······register:·find_rules_d5382 ······register:·find_rules_d
5383 ······when:5383 ······when:
5384 ······-·'"audit"·in·ansible_facts.packages' 
5385 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5384 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5385 ······-·'"audit"·in·ansible_facts.packages'
5386 ······tags:5386 ······tags:
5387 ······-·CCE-83716-15387 ······-·CCE-83716-1
5388 ······-·CJIS-5.4.1.15388 ······-·CJIS-5.4.1.1
5389 ······-·NIST-800-171-3.3.15389 ······-·NIST-800-171-3.3.1
5390 ······-·NIST-800-171-3.4.35390 ······-·NIST-800-171-3.4.3
5391 ······-·NIST-800-53-AC-6(9)5391 ······-·NIST-800-53-AC-6(9)
5392 ······-·NIST-800-53-CM-6(a)5392 ······-·NIST-800-53-CM-6(a)
Offset 5403, 16 lines modifiedOffset 5403, 16 lines modified
5403 ······lineinfile:5403 ······lineinfile:
5404 ········path:·'{{·item·}}'5404 ········path:·'{{·item·}}'
5405 ········regexp:·^\s*(?:-e)\s+.*$5405 ········regexp:·^\s*(?:-e)\s+.*$
5406 ········state:·absent5406 ········state:·absent
5407 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5407 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5408 ········}}'5408 ········}}'
5409 ······when:5409 ······when:
5410 ······-·'"audit"·in·ansible_facts.packages' 
5411 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5410 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5411 ······-·'"audit"·in·ansible_facts.packages'
5412 ······tags:5412 ······tags:
5413 ······-·CCE-83716-15413 ······-·CCE-83716-1
5414 ······-·CJIS-5.4.1.15414 ······-·CJIS-5.4.1.1
5415 ······-·NIST-800-171-3.3.15415 ······-·NIST-800-171-3.3.1
5416 ······-·NIST-800-171-3.4.35416 ······-·NIST-800-171-3.4.3
5417 ······-·NIST-800-53-AC-6(9)5417 ······-·NIST-800-53-AC-6(9)
5418 ······-·NIST-800-53-CM-6(a)5418 ······-·NIST-800-53-CM-6(a)
Offset 5430, 16 lines modifiedOffset 5430, 16 lines modified
5430 ········create:·true5430 ········create:·true
5431 ········line:·-e·25431 ········line:·-e·2
5432 ········mode:·o-rwx5432 ········mode:·o-rwx
5433 ······loop:5433 ······loop:
5434 ······-·/etc/audit/audit.rules5434 ······-·/etc/audit/audit.rules
5435 ······-·/etc/audit/rules.d/immutable.rules5435 ······-·/etc/audit/rules.d/immutable.rules
5436 ······when:5436 ······when:
5437 ······-·'"audit"·in·ansible_facts.packages' 
5438 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5437 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5438 ······-·'"audit"·in·ansible_facts.packages'
5439 ······tags:5439 ······tags:
5440 ······-·CCE-83716-15440 ······-·CCE-83716-1
5441 ······-·CJIS-5.4.1.15441 ······-·CJIS-5.4.1.1
5442 ······-·NIST-800-171-3.3.15442 ······-·NIST-800-171-3.3.1
5443 ······-·NIST-800-171-3.4.35443 ······-·NIST-800-171-3.4.3
5444 ······-·NIST-800-53-AC-6(9)5444 ······-·NIST-800-53-AC-6(9)
5445 ······-·NIST-800-53-CM-6(a)5445 ······-·NIST-800-53-CM-6(a)
Offset 5473, 16 lines modifiedOffset 5473, 16 lines modified
5473 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5473 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5474 ······find:5474 ······find:
5475 ········paths:·/etc/audit/rules.d5475 ········paths:·/etc/audit/rules.d
5476 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5476 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5477 ········patterns:·'*.rules'5477 ········patterns:·'*.rules'
5478 ······register:·find_existing_watch_rules_d5478 ······register:·find_existing_watch_rules_d
5479 ······when:5479 ······when:
5480 ······-·'"audit"·in·ansible_facts.packages' 
5481 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5480 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5481 ······-·'"audit"·in·ansible_facts.packages'
5482 ······tags:5482 ······tags:
5483 ······-·CCE-83721-15483 ······-·CCE-83721-1
5484 ······-·CJIS-5.4.1.15484 ······-·CJIS-5.4.1.1
5485 ······-·NIST-800-171-3.1.85485 ······-·NIST-800-171-3.1.8
5486 ······-·NIST-800-53-AU-12(c)5486 ······-·NIST-800-53-AU-12(c)
5487 ······-·NIST-800-53-AU-2(d)5487 ······-·NIST-800-53-AU-2(d)
5488 ······-·NIST-800-53-CM-6(a)5488 ······-·NIST-800-53-CM-6(a)
Offset 5497, 16 lines modifiedOffset 5497, 16 lines modified
5497 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5497 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5498 ······find:5498 ······find:
5499 ········paths:·/etc/audit/rules.d5499 ········paths:·/etc/audit/rules.d
5500 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5500 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5501 ········patterns:·'*.rules'5501 ········patterns:·'*.rules'
5502 ······register:·find_watch_key5502 ······register:·find_watch_key
5503 ······when:5503 ······when:
5504 ······-·'"audit"·in·ansible_facts.packages' 
5505 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5504 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5505 ······-·'"audit"·in·ansible_facts.packages'
5506 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5506 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5507 ········==·05507 ········==·0
5508 ······tags:5508 ······tags:
5509 ······-·CCE-83721-15509 ······-·CCE-83721-1
5510 ······-·CJIS-5.4.1.15510 ······-·CJIS-5.4.1.1
5511 ······-·NIST-800-171-3.1.85511 ······-·NIST-800-171-3.1.8
5512 ······-·NIST-800-53-AU-12(c)5512 ······-·NIST-800-53-AU-12(c)
Offset 5521, 16 lines modifiedOffset 5521, 16 lines modified
5521 ······-·restrict_strategy5521 ······-·restrict_strategy
  
5522 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5522 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5523 ······set_fact:5523 ······set_fact:
5524 ········all_files:5524 ········all_files:
5525 ········-·/etc/audit/rules.d/MAC-policy.rules5525 ········-·/etc/audit/rules.d/MAC-policy.rules
5526 ······when:5526 ······when:
5527 ······-·'"audit"·in·ansible_facts.packages' 
5528 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5527 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5528 ······-·'"audit"·in·ansible_facts.packages'
5529 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5529 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5530 ········is·defined·and·find_existing_watch_rules_d.matched·==·05530 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5531 ······tags:5531 ······tags:
5532 ······-·CCE-83721-15532 ······-·CCE-83721-1
5533 ······-·CJIS-5.4.1.15533 ······-·CJIS-5.4.1.1
5534 ······-·NIST-800-171-3.1.85534 ······-·NIST-800-171-3.1.8
5535 ······-·NIST-800-53-AU-12(c)5535 ······-·NIST-800-53-AU-12(c)
Offset 5545, 16 lines modifiedOffset 5545, 16 lines modified
5545 ······-·restrict_strategy5545 ······-·restrict_strategy
  
5546 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5546 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5547 ······set_fact:5547 ······set_fact:
5548 ········all_files:5548 ········all_files:
5549 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5549 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5550 ······when:5550 ······when:
5551 ······-·'"audit"·in·ansible_facts.packages' 
5552 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5551 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5552 ······-·'"audit"·in·ansible_facts.packages'
5553 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5553 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5554 ········is·defined·and·find_existing_watch_rules_d.matched·==·05554 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5555 ······tags:5555 ······tags:
5556 ······-·CCE-83721-15556 ······-·CCE-83721-1
5557 ······-·CJIS-5.4.1.15557 ······-·CJIS-5.4.1.1
5558 ······-·NIST-800-171-3.1.85558 ······-·NIST-800-171-3.1.8
5559 ······-·NIST-800-53-AU-12(c)5559 ······-·NIST-800-53-AU-12(c)
Offset 5571, 16 lines modifiedOffset 5571, 16 lines modified
5571 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5571 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 157412/162045 bytes (97.14%) of diff not shown.
7.62 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-cis_server_l1.yml
Ordering differences only
    
Offset 5206, 16 lines modifiedOffset 5206, 16 lines modified
5206 ······-·no_reboot_needed5206 ······-·no_reboot_needed
  
5207 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5207 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5208 ······stat:5208 ······stat:
5209 ········path:·/boot/grub2/grub.cfg5209 ········path:·/boot/grub2/grub.cfg
5210 ······register:·file_exists5210 ······register:·file_exists
5211 ······when:5211 ······when:
5212 ······-·'"grub2-common"·in·ansible_facts.packages' 
5213 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5212 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5213 ······-·'"grub2-common"·in·ansible_facts.packages'
5214 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5214 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5215 ······tags:5215 ······tags:
5216 ······-·CCE-83848-25216 ······-·CCE-83848-2
5217 ······-·CJIS-5.5.2.25217 ······-·CJIS-5.5.2.2
5218 ······-·NIST-800-171-3.4.55218 ······-·NIST-800-171-3.4.5
5219 ······-·NIST-800-53-AC-6(1)5219 ······-·NIST-800-53-AC-6(1)
5220 ······-·NIST-800-53-CM-6(a)5220 ······-·NIST-800-53-CM-6(a)
Offset 5228, 16 lines modifiedOffset 5228, 16 lines modified
5228 ······-·no_reboot_needed5228 ······-·no_reboot_needed
  
5229 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg5229 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
5230 ······file:5230 ······file:
5231 ········path:·/boot/grub2/grub.cfg5231 ········path:·/boot/grub2/grub.cfg
5232 ········group:·'0'5232 ········group:·'0'
5233 ······when:5233 ······when:
5234 ······-·'"grub2-common"·in·ansible_facts.packages' 
5235 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5234 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5235 ······-·'"grub2-common"·in·ansible_facts.packages'
5236 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5236 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5237 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5237 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5238 ······tags:5238 ······tags:
5239 ······-·CCE-83848-25239 ······-·CCE-83848-2
5240 ······-·CJIS-5.5.2.25240 ······-·CJIS-5.5.2.2
5241 ······-·NIST-800-171-3.4.55241 ······-·NIST-800-171-3.4.5
5242 ······-·NIST-800-53-AC-6(1)5242 ······-·NIST-800-53-AC-6(1)
Offset 5269, 16 lines modifiedOffset 5269, 16 lines modified
5269 ······-·no_reboot_needed5269 ······-·no_reboot_needed
  
5270 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5270 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5271 ······stat:5271 ······stat:
5272 ········path:·/boot/grub2/user.cfg5272 ········path:·/boot/grub2/user.cfg
5273 ······register:·file_exists5273 ······register:·file_exists
5274 ······when:5274 ······when:
5275 ······-·'"grub2-common"·in·ansible_facts.packages' 
5276 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5275 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5276 ······-·'"grub2-common"·in·ansible_facts.packages'
5277 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5277 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5278 ······tags:5278 ······tags:
5279 ······-·CCE-86010-65279 ······-·CCE-86010-6
5280 ······-·CJIS-5.5.2.25280 ······-·CJIS-5.5.2.2
5281 ······-·NIST-800-171-3.4.55281 ······-·NIST-800-171-3.4.5
5282 ······-·NIST-800-53-AC-6(1)5282 ······-·NIST-800-53-AC-6(1)
5283 ······-·NIST-800-53-CM-6(a)5283 ······-·NIST-800-53-CM-6(a)
Offset 5291, 16 lines modifiedOffset 5291, 16 lines modified
5291 ······-·no_reboot_needed5291 ······-·no_reboot_needed
  
5292 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg5292 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
5293 ······file:5293 ······file:
5294 ········path:·/boot/grub2/user.cfg5294 ········path:·/boot/grub2/user.cfg
5295 ········group:·'0'5295 ········group:·'0'
5296 ······when:5296 ······when:
5297 ······-·'"grub2-common"·in·ansible_facts.packages' 
5298 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5297 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5298 ······-·'"grub2-common"·in·ansible_facts.packages'
5299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5300 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5300 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5301 ······tags:5301 ······tags:
5302 ······-·CCE-86010-65302 ······-·CCE-86010-6
5303 ······-·CJIS-5.5.2.25303 ······-·CJIS-5.5.2.2
5304 ······-·NIST-800-171-3.4.55304 ······-·NIST-800-171-3.4.5
5305 ······-·NIST-800-53-AC-6(1)5305 ······-·NIST-800-53-AC-6(1)
Offset 5332, 16 lines modifiedOffset 5332, 16 lines modified
5332 ······-·no_reboot_needed5332 ······-·no_reboot_needed
  
5333 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5333 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5334 ······stat:5334 ······stat:
5335 ········path:·/boot/grub2/grub.cfg5335 ········path:·/boot/grub2/grub.cfg
5336 ······register:·file_exists5336 ······register:·file_exists
5337 ······when:5337 ······when:
5338 ······-·'"grub2-common"·in·ansible_facts.packages' 
5339 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5338 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5339 ······-·'"grub2-common"·in·ansible_facts.packages'
5340 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5340 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5341 ······tags:5341 ······tags:
5342 ······-·CCE-83845-85342 ······-·CCE-83845-8
5343 ······-·CJIS-5.5.2.25343 ······-·CJIS-5.5.2.2
5344 ······-·NIST-800-171-3.4.55344 ······-·NIST-800-171-3.4.5
5345 ······-·NIST-800-53-AC-6(1)5345 ······-·NIST-800-53-AC-6(1)
5346 ······-·NIST-800-53-CM-6(a)5346 ······-·NIST-800-53-CM-6(a)
Offset 5354, 16 lines modifiedOffset 5354, 16 lines modified
5354 ······-·no_reboot_needed5354 ······-·no_reboot_needed
  
5355 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg5355 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
5356 ······file:5356 ······file:
5357 ········path:·/boot/grub2/grub.cfg5357 ········path:·/boot/grub2/grub.cfg
5358 ········owner:·'0'5358 ········owner:·'0'
5359 ······when:5359 ······when:
5360 ······-·'"grub2-common"·in·ansible_facts.packages' 
5361 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5360 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5361 ······-·'"grub2-common"·in·ansible_facts.packages'
5362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5363 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5363 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5364 ······tags:5364 ······tags:
5365 ······-·CCE-83845-85365 ······-·CCE-83845-8
5366 ······-·CJIS-5.5.2.25366 ······-·CJIS-5.5.2.2
5367 ······-·NIST-800-171-3.4.55367 ······-·NIST-800-171-3.4.5
5368 ······-·NIST-800-53-AC-6(1)5368 ······-·NIST-800-53-AC-6(1)
Offset 5395, 16 lines modifiedOffset 5395, 16 lines modified
5395 ······-·no_reboot_needed5395 ······-·no_reboot_needed
  
5396 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5396 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5397 ······stat:5397 ······stat:
5398 ········path:·/boot/grub2/user.cfg5398 ········path:·/boot/grub2/user.cfg
5399 ······register:·file_exists5399 ······register:·file_exists
5400 ······when:5400 ······when:
5401 ······-·'"grub2-common"·in·ansible_facts.packages' 
5402 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5401 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5402 ······-·'"grub2-common"·in·ansible_facts.packages'
5403 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5403 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5404 ······tags:5404 ······tags:
5405 ······-·CCE-86016-35405 ······-·CCE-86016-3
5406 ······-·CJIS-5.5.2.25406 ······-·CJIS-5.5.2.2
5407 ······-·NIST-800-171-3.4.55407 ······-·NIST-800-171-3.4.5
5408 ······-·NIST-800-53-AC-6(1)5408 ······-·NIST-800-53-AC-6(1)
5409 ······-·NIST-800-53-CM-6(a)5409 ······-·NIST-800-53-CM-6(a)
Offset 5417, 16 lines modifiedOffset 5417, 16 lines modified
5417 ······-·no_reboot_needed5417 ······-·no_reboot_needed
Max diff block lines reached; 3194/7634 bytes (41.84%) of diff not shown.
7.63 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-cis_workstation_l1.yml
Ordering differences only
    
Offset 5206, 16 lines modifiedOffset 5206, 16 lines modified
5206 ······-·no_reboot_needed5206 ······-·no_reboot_needed
  
5207 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5207 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5208 ······stat:5208 ······stat:
5209 ········path:·/boot/grub2/grub.cfg5209 ········path:·/boot/grub2/grub.cfg
5210 ······register:·file_exists5210 ······register:·file_exists
5211 ······when:5211 ······when:
5212 ······-·'"grub2-common"·in·ansible_facts.packages' 
5213 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5212 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5213 ······-·'"grub2-common"·in·ansible_facts.packages'
5214 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5214 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5215 ······tags:5215 ······tags:
5216 ······-·CCE-83848-25216 ······-·CCE-83848-2
5217 ······-·CJIS-5.5.2.25217 ······-·CJIS-5.5.2.2
5218 ······-·NIST-800-171-3.4.55218 ······-·NIST-800-171-3.4.5
5219 ······-·NIST-800-53-AC-6(1)5219 ······-·NIST-800-53-AC-6(1)
5220 ······-·NIST-800-53-CM-6(a)5220 ······-·NIST-800-53-CM-6(a)
Offset 5228, 16 lines modifiedOffset 5228, 16 lines modified
5228 ······-·no_reboot_needed5228 ······-·no_reboot_needed
  
5229 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg5229 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/grub.cfg
5230 ······file:5230 ······file:
5231 ········path:·/boot/grub2/grub.cfg5231 ········path:·/boot/grub2/grub.cfg
5232 ········group:·'0'5232 ········group:·'0'
5233 ······when:5233 ······when:
5234 ······-·'"grub2-common"·in·ansible_facts.packages' 
5235 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5234 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5235 ······-·'"grub2-common"·in·ansible_facts.packages'
5236 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5236 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5237 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5237 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5238 ······tags:5238 ······tags:
5239 ······-·CCE-83848-25239 ······-·CCE-83848-2
5240 ······-·CJIS-5.5.2.25240 ······-·CJIS-5.5.2.2
5241 ······-·NIST-800-171-3.4.55241 ······-·NIST-800-171-3.4.5
5242 ······-·NIST-800-53-AC-6(1)5242 ······-·NIST-800-53-AC-6(1)
Offset 5269, 16 lines modifiedOffset 5269, 16 lines modified
5269 ······-·no_reboot_needed5269 ······-·no_reboot_needed
  
5270 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5270 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5271 ······stat:5271 ······stat:
5272 ········path:·/boot/grub2/user.cfg5272 ········path:·/boot/grub2/user.cfg
5273 ······register:·file_exists5273 ······register:·file_exists
5274 ······when:5274 ······when:
5275 ······-·'"grub2-common"·in·ansible_facts.packages' 
5276 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5275 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5276 ······-·'"grub2-common"·in·ansible_facts.packages'
5277 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5277 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5278 ······tags:5278 ······tags:
5279 ······-·CCE-86010-65279 ······-·CCE-86010-6
5280 ······-·CJIS-5.5.2.25280 ······-·CJIS-5.5.2.2
5281 ······-·NIST-800-171-3.4.55281 ······-·NIST-800-171-3.4.5
5282 ······-·NIST-800-53-AC-6(1)5282 ······-·NIST-800-53-AC-6(1)
5283 ······-·NIST-800-53-CM-6(a)5283 ······-·NIST-800-53-CM-6(a)
Offset 5291, 16 lines modifiedOffset 5291, 16 lines modified
5291 ······-·no_reboot_needed5291 ······-·no_reboot_needed
  
5292 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg5292 ····-·name:·Ensure·group·owner·0·on·/boot/grub2/user.cfg
5293 ······file:5293 ······file:
5294 ········path:·/boot/grub2/user.cfg5294 ········path:·/boot/grub2/user.cfg
5295 ········group:·'0'5295 ········group:·'0'
5296 ······when:5296 ······when:
5297 ······-·'"grub2-common"·in·ansible_facts.packages' 
5298 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5297 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5298 ······-·'"grub2-common"·in·ansible_facts.packages'
5299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5299 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5300 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5300 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5301 ······tags:5301 ······tags:
5302 ······-·CCE-86010-65302 ······-·CCE-86010-6
5303 ······-·CJIS-5.5.2.25303 ······-·CJIS-5.5.2.2
5304 ······-·NIST-800-171-3.4.55304 ······-·NIST-800-171-3.4.5
5305 ······-·NIST-800-53-AC-6(1)5305 ······-·NIST-800-53-AC-6(1)
Offset 5332, 16 lines modifiedOffset 5332, 16 lines modified
5332 ······-·no_reboot_needed5332 ······-·no_reboot_needed
  
5333 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg5333 ····-·name:·Test·for·existence·/boot/grub2/grub.cfg
5334 ······stat:5334 ······stat:
5335 ········path:·/boot/grub2/grub.cfg5335 ········path:·/boot/grub2/grub.cfg
5336 ······register:·file_exists5336 ······register:·file_exists
5337 ······when:5337 ······when:
5338 ······-·'"grub2-common"·in·ansible_facts.packages' 
5339 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5338 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5339 ······-·'"grub2-common"·in·ansible_facts.packages'
5340 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5340 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5341 ······tags:5341 ······tags:
5342 ······-·CCE-83845-85342 ······-·CCE-83845-8
5343 ······-·CJIS-5.5.2.25343 ······-·CJIS-5.5.2.2
5344 ······-·NIST-800-171-3.4.55344 ······-·NIST-800-171-3.4.5
5345 ······-·NIST-800-53-AC-6(1)5345 ······-·NIST-800-53-AC-6(1)
5346 ······-·NIST-800-53-CM-6(a)5346 ······-·NIST-800-53-CM-6(a)
Offset 5354, 16 lines modifiedOffset 5354, 16 lines modified
5354 ······-·no_reboot_needed5354 ······-·no_reboot_needed
  
5355 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg5355 ····-·name:·Ensure·owner·0·on·/boot/grub2/grub.cfg
5356 ······file:5356 ······file:
5357 ········path:·/boot/grub2/grub.cfg5357 ········path:·/boot/grub2/grub.cfg
5358 ········owner:·'0'5358 ········owner:·'0'
5359 ······when:5359 ······when:
5360 ······-·'"grub2-common"·in·ansible_facts.packages' 
5361 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5360 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5361 ······-·'"grub2-common"·in·ansible_facts.packages'
5362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5363 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists5363 ······-·file_exists.stat·is·defined·and·file_exists.stat.exists
5364 ······tags:5364 ······tags:
5365 ······-·CCE-83845-85365 ······-·CCE-83845-8
5366 ······-·CJIS-5.5.2.25366 ······-·CJIS-5.5.2.2
5367 ······-·NIST-800-171-3.4.55367 ······-·NIST-800-171-3.4.5
5368 ······-·NIST-800-53-AC-6(1)5368 ······-·NIST-800-53-AC-6(1)
Offset 5395, 16 lines modifiedOffset 5395, 16 lines modified
5395 ······-·no_reboot_needed5395 ······-·no_reboot_needed
  
5396 ····-·name:·Test·for·existence·/boot/grub2/user.cfg5396 ····-·name:·Test·for·existence·/boot/grub2/user.cfg
5397 ······stat:5397 ······stat:
5398 ········path:·/boot/grub2/user.cfg5398 ········path:·/boot/grub2/user.cfg
5399 ······register:·file_exists5399 ······register:·file_exists
5400 ······when:5400 ······when:
5401 ······-·'"grub2-common"·in·ansible_facts.packages' 
5402 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'5401 ······-·'"/boot/efi"·not·in·ansible_mounts·|·map(attribute="mount")·|·list'
 5402 ······-·'"grub2-common"·in·ansible_facts.packages'
5403 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5403 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
5404 ······tags:5404 ······tags:
5405 ······-·CCE-86016-35405 ······-·CCE-86016-3
5406 ······-·CJIS-5.5.2.25406 ······-·CJIS-5.5.2.2
5407 ······-·NIST-800-171-3.4.55407 ······-·NIST-800-171-3.4.5
5408 ······-·NIST-800-53-AC-6(1)5408 ······-·NIST-800-53-AC-6(1)
5409 ······-·NIST-800-53-CM-6(a)5409 ······-·NIST-800-53-CM-6(a)
Offset 5417, 16 lines modifiedOffset 5417, 16 lines modified
5417 ······-·no_reboot_needed5417 ······-·no_reboot_needed
Max diff block lines reached; 3194/7634 bytes (41.84%) of diff not shown.
158 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-cis_workstation_l2.yml
Ordering differences only
    
Offset 5378, 16 lines modifiedOffset 5378, 16 lines modified
  
5378 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5378 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5379 ······find:5379 ······find:
5380 ········paths:·/etc/audit/rules.d/5380 ········paths:·/etc/audit/rules.d/
5381 ········patterns:·'*.rules'5381 ········patterns:·'*.rules'
5382 ······register:·find_rules_d5382 ······register:·find_rules_d
5383 ······when:5383 ······when:
5384 ······-·'"audit"·in·ansible_facts.packages' 
5385 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5384 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5385 ······-·'"audit"·in·ansible_facts.packages'
5386 ······tags:5386 ······tags:
5387 ······-·CCE-83716-15387 ······-·CCE-83716-1
5388 ······-·CJIS-5.4.1.15388 ······-·CJIS-5.4.1.1
5389 ······-·NIST-800-171-3.3.15389 ······-·NIST-800-171-3.3.1
5390 ······-·NIST-800-171-3.4.35390 ······-·NIST-800-171-3.4.3
5391 ······-·NIST-800-53-AC-6(9)5391 ······-·NIST-800-53-AC-6(9)
5392 ······-·NIST-800-53-CM-6(a)5392 ······-·NIST-800-53-CM-6(a)
Offset 5403, 16 lines modifiedOffset 5403, 16 lines modified
5403 ······lineinfile:5403 ······lineinfile:
5404 ········path:·'{{·item·}}'5404 ········path:·'{{·item·}}'
5405 ········regexp:·^\s*(?:-e)\s+.*$5405 ········regexp:·^\s*(?:-e)\s+.*$
5406 ········state:·absent5406 ········state:·absent
5407 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5407 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5408 ········}}'5408 ········}}'
5409 ······when:5409 ······when:
5410 ······-·'"audit"·in·ansible_facts.packages' 
5411 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5410 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5411 ······-·'"audit"·in·ansible_facts.packages'
5412 ······tags:5412 ······tags:
5413 ······-·CCE-83716-15413 ······-·CCE-83716-1
5414 ······-·CJIS-5.4.1.15414 ······-·CJIS-5.4.1.1
5415 ······-·NIST-800-171-3.3.15415 ······-·NIST-800-171-3.3.1
5416 ······-·NIST-800-171-3.4.35416 ······-·NIST-800-171-3.4.3
5417 ······-·NIST-800-53-AC-6(9)5417 ······-·NIST-800-53-AC-6(9)
5418 ······-·NIST-800-53-CM-6(a)5418 ······-·NIST-800-53-CM-6(a)
Offset 5430, 16 lines modifiedOffset 5430, 16 lines modified
5430 ········create:·true5430 ········create:·true
5431 ········line:·-e·25431 ········line:·-e·2
5432 ········mode:·o-rwx5432 ········mode:·o-rwx
5433 ······loop:5433 ······loop:
5434 ······-·/etc/audit/audit.rules5434 ······-·/etc/audit/audit.rules
5435 ······-·/etc/audit/rules.d/immutable.rules5435 ······-·/etc/audit/rules.d/immutable.rules
5436 ······when:5436 ······when:
5437 ······-·'"audit"·in·ansible_facts.packages' 
5438 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5437 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5438 ······-·'"audit"·in·ansible_facts.packages'
5439 ······tags:5439 ······tags:
5440 ······-·CCE-83716-15440 ······-·CCE-83716-1
5441 ······-·CJIS-5.4.1.15441 ······-·CJIS-5.4.1.1
5442 ······-·NIST-800-171-3.3.15442 ······-·NIST-800-171-3.3.1
5443 ······-·NIST-800-171-3.4.35443 ······-·NIST-800-171-3.4.3
5444 ······-·NIST-800-53-AC-6(9)5444 ······-·NIST-800-53-AC-6(9)
5445 ······-·NIST-800-53-CM-6(a)5445 ······-·NIST-800-53-CM-6(a)
Offset 5473, 16 lines modifiedOffset 5473, 16 lines modified
5473 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5473 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5474 ······find:5474 ······find:
5475 ········paths:·/etc/audit/rules.d5475 ········paths:·/etc/audit/rules.d
5476 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5476 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5477 ········patterns:·'*.rules'5477 ········patterns:·'*.rules'
5478 ······register:·find_existing_watch_rules_d5478 ······register:·find_existing_watch_rules_d
5479 ······when:5479 ······when:
5480 ······-·'"audit"·in·ansible_facts.packages' 
5481 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5480 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5481 ······-·'"audit"·in·ansible_facts.packages'
5482 ······tags:5482 ······tags:
5483 ······-·CCE-83721-15483 ······-·CCE-83721-1
5484 ······-·CJIS-5.4.1.15484 ······-·CJIS-5.4.1.1
5485 ······-·NIST-800-171-3.1.85485 ······-·NIST-800-171-3.1.8
5486 ······-·NIST-800-53-AU-12(c)5486 ······-·NIST-800-53-AU-12(c)
5487 ······-·NIST-800-53-AU-2(d)5487 ······-·NIST-800-53-AU-2(d)
5488 ······-·NIST-800-53-CM-6(a)5488 ······-·NIST-800-53-CM-6(a)
Offset 5497, 16 lines modifiedOffset 5497, 16 lines modified
5497 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5497 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5498 ······find:5498 ······find:
5499 ········paths:·/etc/audit/rules.d5499 ········paths:·/etc/audit/rules.d
5500 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5500 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5501 ········patterns:·'*.rules'5501 ········patterns:·'*.rules'
5502 ······register:·find_watch_key5502 ······register:·find_watch_key
5503 ······when:5503 ······when:
5504 ······-·'"audit"·in·ansible_facts.packages' 
5505 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5504 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5505 ······-·'"audit"·in·ansible_facts.packages'
5506 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5506 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5507 ········==·05507 ········==·0
5508 ······tags:5508 ······tags:
5509 ······-·CCE-83721-15509 ······-·CCE-83721-1
5510 ······-·CJIS-5.4.1.15510 ······-·CJIS-5.4.1.1
5511 ······-·NIST-800-171-3.1.85511 ······-·NIST-800-171-3.1.8
5512 ······-·NIST-800-53-AU-12(c)5512 ······-·NIST-800-53-AU-12(c)
Offset 5521, 16 lines modifiedOffset 5521, 16 lines modified
5521 ······-·restrict_strategy5521 ······-·restrict_strategy
  
5522 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5522 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5523 ······set_fact:5523 ······set_fact:
5524 ········all_files:5524 ········all_files:
5525 ········-·/etc/audit/rules.d/MAC-policy.rules5525 ········-·/etc/audit/rules.d/MAC-policy.rules
5526 ······when:5526 ······when:
5527 ······-·'"audit"·in·ansible_facts.packages' 
5528 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5527 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5528 ······-·'"audit"·in·ansible_facts.packages'
5529 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5529 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5530 ········is·defined·and·find_existing_watch_rules_d.matched·==·05530 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5531 ······tags:5531 ······tags:
5532 ······-·CCE-83721-15532 ······-·CCE-83721-1
5533 ······-·CJIS-5.4.1.15533 ······-·CJIS-5.4.1.1
5534 ······-·NIST-800-171-3.1.85534 ······-·NIST-800-171-3.1.8
5535 ······-·NIST-800-53-AU-12(c)5535 ······-·NIST-800-53-AU-12(c)
Offset 5545, 16 lines modifiedOffset 5545, 16 lines modified
5545 ······-·restrict_strategy5545 ······-·restrict_strategy
  
5546 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5546 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5547 ······set_fact:5547 ······set_fact:
5548 ········all_files:5548 ········all_files:
5549 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5549 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5550 ······when:5550 ······when:
5551 ······-·'"audit"·in·ansible_facts.packages' 
5552 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5551 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5552 ······-·'"audit"·in·ansible_facts.packages'
5553 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5553 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5554 ········is·defined·and·find_existing_watch_rules_d.matched·==·05554 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5555 ······tags:5555 ······tags:
5556 ······-·CCE-83721-15556 ······-·CCE-83721-1
5557 ······-·CJIS-5.4.1.15557 ······-·CJIS-5.4.1.1
5558 ······-·NIST-800-171-3.1.85558 ······-·NIST-800-171-3.1.8
5559 ······-·NIST-800-53-AU-12(c)5559 ······-·NIST-800-53-AU-12(c)
Offset 5571, 16 lines modifiedOffset 5571, 16 lines modified
5571 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5571 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 157412/162045 bytes (97.14%) of diff not shown.
2.39 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-cui.yml
Ordering differences only
    
Offset 3450, 16 lines modifiedOffset 3450, 16 lines modified
3450 ······lineinfile:3450 ······lineinfile:
3451 ········dest:·/etc/audit/auditd.conf3451 ········dest:·/etc/audit/auditd.conf
3452 ········regexp:·^\s*flush\s*=\s*.*$3452 ········regexp:·^\s*flush\s*=\s*.*$
3453 ········line:·flush·=·{{·var_auditd_flush·}}3453 ········line:·flush·=·{{·var_auditd_flush·}}
3454 ········state:·present3454 ········state:·present
3455 ········create:·true3455 ········create:·true
3456 ······when:3456 ······when:
3457 ······-·'"audit"·in·ansible_facts.packages' 
3458 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3457 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3458 ······-·'"audit"·in·ansible_facts.packages'
3459 ······tags:3459 ······tags:
3460 ······-·CCE-83685-83460 ······-·CCE-83685-8
3461 ······-·NIST-800-171-3.3.13461 ······-·NIST-800-171-3.3.1
3462 ······-·NIST-800-53-AU-113462 ······-·NIST-800-53-AU-11
3463 ······-·NIST-800-53-CM-6(a)3463 ······-·NIST-800-53-CM-6(a)
3464 ······-·auditd_data_retention_flush3464 ······-·auditd_data_retention_flush
3465 ······-·low_complexity3465 ······-·low_complexity
Offset 3507, 16 lines modifiedOffset 3507, 16 lines modified
3507 ········lineinfile:3507 ········lineinfile:
3508 ··········path:·/etc/audit/auditd.conf3508 ··········path:·/etc/audit/auditd.conf
3509 ··········create:·true3509 ··········create:·true
3510 ··········regexp:·(?i)^\s*freq\s*=\s*3510 ··········regexp:·(?i)^\s*freq\s*=\s*
3511 ··········line:·freq·=·503511 ··········line:·freq·=·50
3512 ··········state:·present3512 ··········state:·present
3513 ······when:3513 ······when:
3514 ······-·'"audit"·in·ansible_facts.packages' 
3515 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3514 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3515 ······-·'"audit"·in·ansible_facts.packages'
3516 ······tags:3516 ······tags:
3517 ······-·CCE-83704-73517 ······-·CCE-83704-7
3518 ······-·NIST-800-53-CM-63518 ······-·NIST-800-53-CM-6
3519 ······-·auditd_freq3519 ······-·auditd_freq
3520 ······-·low_complexity3520 ······-·low_complexity
3521 ······-·low_disruption3521 ······-·low_disruption
3522 ······-·medium_severity3522 ······-·medium_severity
Offset 3563, 16 lines modifiedOffset 3563, 16 lines modified
3563 ········lineinfile:3563 ········lineinfile:
3564 ··········path:·/etc/audit/auditd.conf3564 ··········path:·/etc/audit/auditd.conf
3565 ··········create:·true3565 ··········create:·true
3566 ··········regexp:·(?i)^\s*log_format\s*=\s*3566 ··········regexp:·(?i)^\s*log_format\s*=\s*
3567 ··········line:·log_format·=·ENRICHED3567 ··········line:·log_format·=·ENRICHED
3568 ··········state:·present3568 ··········state:·present
3569 ······when:3569 ······when:
3570 ······-·'"audit"·in·ansible_facts.packages' 
3571 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3570 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3571 ······-·'"audit"·in·ansible_facts.packages'
3572 ······tags:3572 ······tags:
3573 ······-·CCE-83696-53573 ······-·CCE-83696-5
3574 ······-·NIST-800-53-AU-33574 ······-·NIST-800-53-AU-3
3575 ······-·NIST-800-53-CM-63575 ······-·NIST-800-53-CM-6
3576 ······-·auditd_log_format3576 ······-·auditd_log_format
3577 ······-·low_complexity3577 ······-·low_complexity
3578 ······-·low_disruption3578 ······-·low_disruption
Offset 3620, 16 lines modifiedOffset 3620, 16 lines modified
3620 ········lineinfile:3620 ········lineinfile:
3621 ··········path:·/etc/audit/auditd.conf3621 ··········path:·/etc/audit/auditd.conf
3622 ··········create:·true3622 ··········create:·true
3623 ··········regexp:·(?i)^\s*name_format\s*=\s*3623 ··········regexp:·(?i)^\s*name_format\s*=\s*
3624 ··········line:·name_format·=·hostname3624 ··········line:·name_format·=·hostname
3625 ··········state:·present3625 ··········state:·present
3626 ······when:3626 ······when:
3627 ······-·'"audit"·in·ansible_facts.packages' 
3628 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3627 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3628 ······-·'"audit"·in·ansible_facts.packages'
3629 ······tags:3629 ······tags:
3630 ······-·CCE-83686-63630 ······-·CCE-83686-6
3631 ······-·NIST-800-53-AU-33631 ······-·NIST-800-53-AU-3
3632 ······-·NIST-800-53-CM-63632 ······-·NIST-800-53-CM-6
3633 ······-·auditd_name_format3633 ······-·auditd_name_format
3634 ······-·low_complexity3634 ······-·low_complexity
3635 ······-·low_disruption3635 ······-·low_disruption
68.7 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-e8.yml
Ordering differences only
    
Offset 1163, 16 lines modifiedOffset 1163, 16 lines modified
1163 ······-·no_reboot_needed1163 ······-·no_reboot_needed
1164 ······-·restrict_strategy1164 ······-·restrict_strategy
  
1165 ····-·name:·Set·architecture·for·audit·tasks1165 ····-·name:·Set·architecture·for·audit·tasks
1166 ······set_fact:1166 ······set_fact:
1167 ········audit_arch:·b641167 ········audit_arch:·b64
1168 ······when:1168 ······when:
1169 ······-·'"audit"·in·ansible_facts.packages' 
1170 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1169 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1170 ······-·'"audit"·in·ansible_facts.packages'
1171 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture1171 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
1172 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"1172 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
1173 ······tags:1173 ······tags:
1174 ······-·CCE-83706-21174 ······-·CCE-83706-2
1175 ······-·CJIS-5.4.1.11175 ······-·CJIS-5.4.1.1
1176 ······-·NIST-800-171-3.1.71176 ······-·NIST-800-171-3.1.7
1177 ······-·NIST-800-53-AC-6(9)1177 ······-·NIST-800-53-AC-6(9)
Offset 1306, 16 lines modifiedOffset 1306, 16 lines modified
1306 ··········path:·'{{·audit_file·}}'1306 ··········path:·'{{·audit_file·}}'
1307 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1307 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1308 ··········create:·true1308 ··········create:·true
1309 ··········mode:·o-rwx1309 ··········mode:·o-rwx
1310 ··········state:·present1310 ··········state:·present
1311 ········when:·syscalls_found·|·length·==·01311 ········when:·syscalls_found·|·length·==·0
1312 ······when:1312 ······when:
1313 ······-·'"audit"·in·ansible_facts.packages' 
1314 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1313 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1314 ······-·'"audit"·in·ansible_facts.packages'
1315 ······tags:1315 ······tags:
1316 ······-·CCE-83706-21316 ······-·CCE-83706-2
1317 ······-·CJIS-5.4.1.11317 ······-·CJIS-5.4.1.1
1318 ······-·NIST-800-171-3.1.71318 ······-·NIST-800-171-3.1.7
1319 ······-·NIST-800-53-AC-6(9)1319 ······-·NIST-800-53-AC-6(9)
1320 ······-·NIST-800-53-AU-12(c)1320 ······-·NIST-800-53-AU-12(c)
1321 ······-·NIST-800-53-AU-2(d)1321 ······-·NIST-800-53-AU-2(d)
Offset 1447, 16 lines modifiedOffset 1447, 16 lines modified
1447 ··········path:·'{{·audit_file·}}'1447 ··········path:·'{{·audit_file·}}'
1448 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification1448 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
1449 ··········create:·true1449 ··········create:·true
1450 ··········mode:·o-rwx1450 ··········mode:·o-rwx
1451 ··········state:·present1451 ··········state:·present
1452 ········when:·syscalls_found·|·length·==·01452 ········when:·syscalls_found·|·length·==·0
1453 ······when:1453 ······when:
1454 ······-·'"audit"·in·ansible_facts.packages' 
1455 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1454 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1455 ······-·'"audit"·in·ansible_facts.packages'
1456 ······-·audit_arch·==·"b64"1456 ······-·audit_arch·==·"b64"
1457 ······tags:1457 ······tags:
1458 ······-·CCE-83706-21458 ······-·CCE-83706-2
1459 ······-·CJIS-5.4.1.11459 ······-·CJIS-5.4.1.1
1460 ······-·NIST-800-171-3.1.71460 ······-·NIST-800-171-3.1.7
1461 ······-·NIST-800-53-AC-6(9)1461 ······-·NIST-800-53-AC-6(9)
1462 ······-·NIST-800-53-AU-12(c)1462 ······-·NIST-800-53-AU-12(c)
Offset 1473, 16 lines modifiedOffset 1473, 16 lines modified
1473 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/1473 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
1474 ······find:1474 ······find:
1475 ········paths:·/etc/audit/rules.d1475 ········paths:·/etc/audit/rules.d
1476 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+1476 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
1477 ········patterns:·'*.rules'1477 ········patterns:·'*.rules'
1478 ······register:·find_existing_watch_rules_d1478 ······register:·find_existing_watch_rules_d
1479 ······when:1479 ······when:
1480 ······-·'"audit"·in·ansible_facts.packages' 
1481 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1480 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1481 ······-·'"audit"·in·ansible_facts.packages'
1482 ······tags:1482 ······tags:
1483 ······-·CCE-83706-21483 ······-·CCE-83706-2
1484 ······-·CJIS-5.4.1.11484 ······-·CJIS-5.4.1.1
1485 ······-·NIST-800-171-3.1.71485 ······-·NIST-800-171-3.1.7
1486 ······-·NIST-800-53-AC-6(9)1486 ······-·NIST-800-53-AC-6(9)
1487 ······-·NIST-800-53-AU-12(c)1487 ······-·NIST-800-53-AU-12(c)
1488 ······-·NIST-800-53-AU-2(d)1488 ······-·NIST-800-53-AU-2(d)
Offset 1498, 16 lines modifiedOffset 1498, 16 lines modified
1498 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification1498 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
1499 ······find:1499 ······find:
1500 ········paths:·/etc/audit/rules.d1500 ········paths:·/etc/audit/rules.d
1501 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$1501 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
1502 ········patterns:·'*.rules'1502 ········patterns:·'*.rules'
1503 ······register:·find_watch_key1503 ······register:·find_watch_key
1504 ······when:1504 ······when:
1505 ······-·'"audit"·in·ansible_facts.packages' 
1506 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1505 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1506 ······-·'"audit"·in·ansible_facts.packages'
1507 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1507 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1508 ········==·01508 ········==·0
1509 ······tags:1509 ······tags:
1510 ······-·CCE-83706-21510 ······-·CCE-83706-2
1511 ······-·CJIS-5.4.1.11511 ······-·CJIS-5.4.1.1
1512 ······-·NIST-800-171-3.1.71512 ······-·NIST-800-171-3.1.7
1513 ······-·NIST-800-53-AC-6(9)1513 ······-·NIST-800-53-AC-6(9)
Offset 1524, 16 lines modifiedOffset 1524, 16 lines modified
  
1524 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the1524 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
1525 ········recipient·for·the·rule1525 ········recipient·for·the·rule
1526 ······set_fact:1526 ······set_fact:
1527 ········all_files:1527 ········all_files:
1528 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules1528 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
1529 ······when:1529 ······when:
1530 ······-·'"audit"·in·ansible_facts.packages' 
1531 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1530 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1531 ······-·'"audit"·in·ansible_facts.packages'
1532 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1532 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1533 ········is·defined·and·find_existing_watch_rules_d.matched·==·01533 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1534 ······tags:1534 ······tags:
1535 ······-·CCE-83706-21535 ······-·CCE-83706-2
1536 ······-·CJIS-5.4.1.11536 ······-·CJIS-5.4.1.1
1537 ······-·NIST-800-171-3.1.71537 ······-·NIST-800-171-3.1.7
1538 ······-·NIST-800-53-AC-6(9)1538 ······-·NIST-800-53-AC-6(9)
Offset 1549, 16 lines modifiedOffset 1549, 16 lines modified
1549 ······-·restrict_strategy1549 ······-·restrict_strategy
  
1550 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1550 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1551 ······set_fact:1551 ······set_fact:
1552 ········all_files:1552 ········all_files:
1553 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1553 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1554 ······when:1554 ······when:
1555 ······-·'"audit"·in·ansible_facts.packages' 
1556 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1555 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1556 ······-·'"audit"·in·ansible_facts.packages'
1557 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1557 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1558 ········is·defined·and·find_existing_watch_rules_d.matched·==·01558 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1559 ······tags:1559 ······tags:
1560 ······-·CCE-83706-21560 ······-·CCE-83706-2
1561 ······-·CJIS-5.4.1.11561 ······-·CJIS-5.4.1.1
1562 ······-·NIST-800-171-3.1.71562 ······-·NIST-800-171-3.1.7
1563 ······-·NIST-800-53-AC-6(9)1563 ······-·NIST-800-53-AC-6(9)
Offset 1576, 16 lines modifiedOffset 1576, 16 lines modified
1576 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/1576 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 65234/70224 bytes (92.89%) of diff not shown.
178 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-hipaa.yml
Ordering differences only
    
Offset 1334, 16 lines modifiedOffset 1334, 16 lines modified
  
1334 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1334 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1335 ······find:1335 ······find:
1336 ········paths:·/etc/audit/rules.d/1336 ········paths:·/etc/audit/rules.d/
1337 ········patterns:·'*.rules'1337 ········patterns:·'*.rules'
1338 ······register:·find_rules_d1338 ······register:·find_rules_d
1339 ······when:1339 ······when:
1340 ······-·'"audit"·in·ansible_facts.packages' 
1341 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1340 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1341 ······-·'"audit"·in·ansible_facts.packages'
1342 ······tags:1342 ······tags:
1343 ······-·CCE-83716-11343 ······-·CCE-83716-1
1344 ······-·CJIS-5.4.1.11344 ······-·CJIS-5.4.1.1
1345 ······-·NIST-800-171-3.3.11345 ······-·NIST-800-171-3.3.1
1346 ······-·NIST-800-171-3.4.31346 ······-·NIST-800-171-3.4.3
1347 ······-·NIST-800-53-AC-6(9)1347 ······-·NIST-800-53-AC-6(9)
1348 ······-·NIST-800-53-CM-6(a)1348 ······-·NIST-800-53-CM-6(a)
Offset 1359, 16 lines modifiedOffset 1359, 16 lines modified
1359 ······lineinfile:1359 ······lineinfile:
1360 ········path:·'{{·item·}}'1360 ········path:·'{{·item·}}'
1361 ········regexp:·^\s*(?:-e)\s+.*$1361 ········regexp:·^\s*(?:-e)\s+.*$
1362 ········state:·absent1362 ········state:·absent
1363 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1363 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1364 ········}}'1364 ········}}'
1365 ······when:1365 ······when:
1366 ······-·'"audit"·in·ansible_facts.packages' 
1367 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1366 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1367 ······-·'"audit"·in·ansible_facts.packages'
1368 ······tags:1368 ······tags:
1369 ······-·CCE-83716-11369 ······-·CCE-83716-1
1370 ······-·CJIS-5.4.1.11370 ······-·CJIS-5.4.1.1
1371 ······-·NIST-800-171-3.3.11371 ······-·NIST-800-171-3.3.1
1372 ······-·NIST-800-171-3.4.31372 ······-·NIST-800-171-3.4.3
1373 ······-·NIST-800-53-AC-6(9)1373 ······-·NIST-800-53-AC-6(9)
1374 ······-·NIST-800-53-CM-6(a)1374 ······-·NIST-800-53-CM-6(a)
Offset 1386, 16 lines modifiedOffset 1386, 16 lines modified
1386 ········create:·true1386 ········create:·true
1387 ········line:·-e·21387 ········line:·-e·2
1388 ········mode:·o-rwx1388 ········mode:·o-rwx
1389 ······loop:1389 ······loop:
1390 ······-·/etc/audit/audit.rules1390 ······-·/etc/audit/audit.rules
1391 ······-·/etc/audit/rules.d/immutable.rules1391 ······-·/etc/audit/rules.d/immutable.rules
1392 ······when:1392 ······when:
1393 ······-·'"audit"·in·ansible_facts.packages' 
1394 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1393 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1394 ······-·'"audit"·in·ansible_facts.packages'
1395 ······tags:1395 ······tags:
1396 ······-·CCE-83716-11396 ······-·CCE-83716-1
1397 ······-·CJIS-5.4.1.11397 ······-·CJIS-5.4.1.1
1398 ······-·NIST-800-171-3.3.11398 ······-·NIST-800-171-3.3.1
1399 ······-·NIST-800-171-3.4.31399 ······-·NIST-800-171-3.4.3
1400 ······-·NIST-800-53-AC-6(9)1400 ······-·NIST-800-53-AC-6(9)
1401 ······-·NIST-800-53-CM-6(a)1401 ······-·NIST-800-53-CM-6(a)
Offset 1429, 16 lines modifiedOffset 1429, 16 lines modified
1429 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1429 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1430 ······find:1430 ······find:
1431 ········paths:·/etc/audit/rules.d1431 ········paths:·/etc/audit/rules.d
1432 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1432 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1433 ········patterns:·'*.rules'1433 ········patterns:·'*.rules'
1434 ······register:·find_existing_watch_rules_d1434 ······register:·find_existing_watch_rules_d
1435 ······when:1435 ······when:
1436 ······-·'"audit"·in·ansible_facts.packages' 
1437 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1436 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1437 ······-·'"audit"·in·ansible_facts.packages'
1438 ······tags:1438 ······tags:
1439 ······-·CCE-83721-11439 ······-·CCE-83721-1
1440 ······-·CJIS-5.4.1.11440 ······-·CJIS-5.4.1.1
1441 ······-·NIST-800-171-3.1.81441 ······-·NIST-800-171-3.1.8
1442 ······-·NIST-800-53-AU-12(c)1442 ······-·NIST-800-53-AU-12(c)
1443 ······-·NIST-800-53-AU-2(d)1443 ······-·NIST-800-53-AU-2(d)
1444 ······-·NIST-800-53-CM-6(a)1444 ······-·NIST-800-53-CM-6(a)
Offset 1453, 16 lines modifiedOffset 1453, 16 lines modified
1453 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1453 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1454 ······find:1454 ······find:
1455 ········paths:·/etc/audit/rules.d1455 ········paths:·/etc/audit/rules.d
1456 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1456 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1457 ········patterns:·'*.rules'1457 ········patterns:·'*.rules'
1458 ······register:·find_watch_key1458 ······register:·find_watch_key
1459 ······when:1459 ······when:
1460 ······-·'"audit"·in·ansible_facts.packages' 
1461 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1460 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1461 ······-·'"audit"·in·ansible_facts.packages'
1462 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1462 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1463 ········==·01463 ········==·0
1464 ······tags:1464 ······tags:
1465 ······-·CCE-83721-11465 ······-·CCE-83721-1
1466 ······-·CJIS-5.4.1.11466 ······-·CJIS-5.4.1.1
1467 ······-·NIST-800-171-3.1.81467 ······-·NIST-800-171-3.1.8
1468 ······-·NIST-800-53-AU-12(c)1468 ······-·NIST-800-53-AU-12(c)
Offset 1477, 16 lines modifiedOffset 1477, 16 lines modified
1477 ······-·restrict_strategy1477 ······-·restrict_strategy
  
1478 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1478 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1479 ······set_fact:1479 ······set_fact:
1480 ········all_files:1480 ········all_files:
1481 ········-·/etc/audit/rules.d/MAC-policy.rules1481 ········-·/etc/audit/rules.d/MAC-policy.rules
1482 ······when:1482 ······when:
1483 ······-·'"audit"·in·ansible_facts.packages' 
1484 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1483 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1484 ······-·'"audit"·in·ansible_facts.packages'
1485 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1485 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1486 ········is·defined·and·find_existing_watch_rules_d.matched·==·01486 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1487 ······tags:1487 ······tags:
1488 ······-·CCE-83721-11488 ······-·CCE-83721-1
1489 ······-·CJIS-5.4.1.11489 ······-·CJIS-5.4.1.1
1490 ······-·NIST-800-171-3.1.81490 ······-·NIST-800-171-3.1.8
1491 ······-·NIST-800-53-AU-12(c)1491 ······-·NIST-800-53-AU-12(c)
Offset 1501, 16 lines modifiedOffset 1501, 16 lines modified
1501 ······-·restrict_strategy1501 ······-·restrict_strategy
  
1502 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1502 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1503 ······set_fact:1503 ······set_fact:
1504 ········all_files:1504 ········all_files:
1505 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1505 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1506 ······when:1506 ······when:
1507 ······-·'"audit"·in·ansible_facts.packages' 
1508 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1507 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1508 ······-·'"audit"·in·ansible_facts.packages'
1509 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1509 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1510 ········is·defined·and·find_existing_watch_rules_d.matched·==·01510 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1511 ······tags:1511 ······tags:
1512 ······-·CCE-83721-11512 ······-·CCE-83721-1
1513 ······-·CJIS-5.4.1.11513 ······-·CJIS-5.4.1.1
1514 ······-·NIST-800-171-3.1.81514 ······-·NIST-800-171-3.1.8
1515 ······-·NIST-800-53-AU-12(c)1515 ······-·NIST-800-53-AU-12(c)
Offset 1527, 16 lines modifiedOffset 1527, 16 lines modified
1527 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1527 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 177648/182281 bytes (97.46%) of diff not shown.
85.6 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-ism_o.yml
Ordering differences only
    
Offset 4527, 16 lines modifiedOffset 4527, 16 lines modified
4527 ······-·no_reboot_needed4527 ······-·no_reboot_needed
4528 ······-·restrict_strategy4528 ······-·restrict_strategy
  
4529 ····-·name:·Set·architecture·for·audit·tasks4529 ····-·name:·Set·architecture·for·audit·tasks
4530 ······set_fact:4530 ······set_fact:
4531 ········audit_arch:·b644531 ········audit_arch:·b64
4532 ······when:4532 ······when:
4533 ······-·'"audit"·in·ansible_facts.packages' 
4534 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4533 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4534 ······-·'"audit"·in·ansible_facts.packages'
4535 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture4535 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
4536 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"4536 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
4537 ······tags:4537 ······tags:
4538 ······-·CCE-83706-24538 ······-·CCE-83706-2
4539 ······-·CJIS-5.4.1.14539 ······-·CJIS-5.4.1.1
4540 ······-·NIST-800-171-3.1.74540 ······-·NIST-800-171-3.1.7
4541 ······-·NIST-800-53-AC-6(9)4541 ······-·NIST-800-53-AC-6(9)
Offset 4670, 16 lines modifiedOffset 4670, 16 lines modified
4670 ··········path:·'{{·audit_file·}}'4670 ··········path:·'{{·audit_file·}}'
4671 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification4671 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
4672 ··········create:·true4672 ··········create:·true
4673 ··········mode:·o-rwx4673 ··········mode:·o-rwx
4674 ··········state:·present4674 ··········state:·present
4675 ········when:·syscalls_found·|·length·==·04675 ········when:·syscalls_found·|·length·==·0
4676 ······when:4676 ······when:
4677 ······-·'"audit"·in·ansible_facts.packages' 
4678 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4677 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4678 ······-·'"audit"·in·ansible_facts.packages'
4679 ······tags:4679 ······tags:
4680 ······-·CCE-83706-24680 ······-·CCE-83706-2
4681 ······-·CJIS-5.4.1.14681 ······-·CJIS-5.4.1.1
4682 ······-·NIST-800-171-3.1.74682 ······-·NIST-800-171-3.1.7
4683 ······-·NIST-800-53-AC-6(9)4683 ······-·NIST-800-53-AC-6(9)
4684 ······-·NIST-800-53-AU-12(c)4684 ······-·NIST-800-53-AU-12(c)
4685 ······-·NIST-800-53-AU-2(d)4685 ······-·NIST-800-53-AU-2(d)
Offset 4811, 16 lines modifiedOffset 4811, 16 lines modified
4811 ··········path:·'{{·audit_file·}}'4811 ··········path:·'{{·audit_file·}}'
4812 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification4812 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·key=audit_rules_networkconfig_modification
4813 ··········create:·true4813 ··········create:·true
4814 ··········mode:·o-rwx4814 ··········mode:·o-rwx
4815 ··········state:·present4815 ··········state:·present
4816 ········when:·syscalls_found·|·length·==·04816 ········when:·syscalls_found·|·length·==·0
4817 ······when:4817 ······when:
4818 ······-·'"audit"·in·ansible_facts.packages' 
4819 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4818 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4819 ······-·'"audit"·in·ansible_facts.packages'
4820 ······-·audit_arch·==·"b64"4820 ······-·audit_arch·==·"b64"
4821 ······tags:4821 ······tags:
4822 ······-·CCE-83706-24822 ······-·CCE-83706-2
4823 ······-·CJIS-5.4.1.14823 ······-·CJIS-5.4.1.1
4824 ······-·NIST-800-171-3.1.74824 ······-·NIST-800-171-3.1.7
4825 ······-·NIST-800-53-AC-6(9)4825 ······-·NIST-800-53-AC-6(9)
4826 ······-·NIST-800-53-AU-12(c)4826 ······-·NIST-800-53-AU-12(c)
Offset 4837, 16 lines modifiedOffset 4837, 16 lines modified
4837 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/4837 ····-·name:·Check·if·watch·rule·for·/etc/issue·already·exists·in·/etc/audit/rules.d/
4838 ······find:4838 ······find:
4839 ········paths:·/etc/audit/rules.d4839 ········paths:·/etc/audit/rules.d
4840 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+4840 ········contains:·^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
4841 ········patterns:·'*.rules'4841 ········patterns:·'*.rules'
4842 ······register:·find_existing_watch_rules_d4842 ······register:·find_existing_watch_rules_d
4843 ······when:4843 ······when:
4844 ······-·'"audit"·in·ansible_facts.packages' 
4845 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4844 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4845 ······-·'"audit"·in·ansible_facts.packages'
4846 ······tags:4846 ······tags:
4847 ······-·CCE-83706-24847 ······-·CCE-83706-2
4848 ······-·CJIS-5.4.1.14848 ······-·CJIS-5.4.1.1
4849 ······-·NIST-800-171-3.1.74849 ······-·NIST-800-171-3.1.7
4850 ······-·NIST-800-53-AC-6(9)4850 ······-·NIST-800-53-AC-6(9)
4851 ······-·NIST-800-53-AU-12(c)4851 ······-·NIST-800-53-AU-12(c)
4852 ······-·NIST-800-53-AU-2(d)4852 ······-·NIST-800-53-AU-2(d)
Offset 4862, 16 lines modifiedOffset 4862, 16 lines modified
4862 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification4862 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·audit_rules_networkconfig_modification
4863 ······find:4863 ······find:
4864 ········paths:·/etc/audit/rules.d4864 ········paths:·/etc/audit/rules.d
4865 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$4865 ········contains:·^.*(?:-F·key=|-k\s+)audit_rules_networkconfig_modification$
4866 ········patterns:·'*.rules'4866 ········patterns:·'*.rules'
4867 ······register:·find_watch_key4867 ······register:·find_watch_key
4868 ······when:4868 ······when:
4869 ······-·'"audit"·in·ansible_facts.packages' 
4870 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4869 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4870 ······-·'"audit"·in·ansible_facts.packages'
4871 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4871 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4872 ········==·04872 ········==·0
4873 ······tags:4873 ······tags:
4874 ······-·CCE-83706-24874 ······-·CCE-83706-2
4875 ······-·CJIS-5.4.1.14875 ······-·CJIS-5.4.1.1
4876 ······-·NIST-800-171-3.1.74876 ······-·NIST-800-171-3.1.7
4877 ······-·NIST-800-53-AC-6(9)4877 ······-·NIST-800-53-AC-6(9)
Offset 4888, 16 lines modifiedOffset 4888, 16 lines modified
  
4888 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the4888 ····-·name:·Use·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules·as·the
4889 ········recipient·for·the·rule4889 ········recipient·for·the·rule
4890 ······set_fact:4890 ······set_fact:
4891 ········all_files:4891 ········all_files:
4892 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules4892 ········-·/etc/audit/rules.d/audit_rules_networkconfig_modification.rules
4893 ······when:4893 ······when:
4894 ······-·'"audit"·in·ansible_facts.packages' 
4895 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4894 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4895 ······-·'"audit"·in·ansible_facts.packages'
4896 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched4896 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
4897 ········is·defined·and·find_existing_watch_rules_d.matched·==·04897 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4898 ······tags:4898 ······tags:
4899 ······-·CCE-83706-24899 ······-·CCE-83706-2
4900 ······-·CJIS-5.4.1.14900 ······-·CJIS-5.4.1.1
4901 ······-·NIST-800-171-3.1.74901 ······-·NIST-800-171-3.1.7
4902 ······-·NIST-800-53-AC-6(9)4902 ······-·NIST-800-53-AC-6(9)
Offset 4913, 16 lines modifiedOffset 4913, 16 lines modified
4913 ······-·restrict_strategy4913 ······-·restrict_strategy
  
4914 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule4914 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
4915 ······set_fact:4915 ······set_fact:
4916 ········all_files:4916 ········all_files:
4917 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'4917 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
4918 ······when:4918 ······when:
4919 ······-·'"audit"·in·ansible_facts.packages' 
4920 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4919 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4920 ······-·'"audit"·in·ansible_facts.packages'
4921 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched4921 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
4922 ········is·defined·and·find_existing_watch_rules_d.matched·==·04922 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4923 ······tags:4923 ······tags:
4924 ······-·CCE-83706-24924 ······-·CCE-83706-2
4925 ······-·CJIS-5.4.1.14925 ······-·CJIS-5.4.1.1
4926 ······-·NIST-800-171-3.1.74926 ······-·NIST-800-171-3.1.7
4927 ······-·NIST-800-53-AC-6(9)4927 ······-·NIST-800-53-AC-6(9)
Offset 4940, 16 lines modifiedOffset 4940, 16 lines modified
4940 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/4940 ····-·name:·Add·watch·rule·for·/etc/issue·in·/etc/audit/rules.d/
Max diff block lines reached; 82495/87485 bytes (94.30%) of diff not shown.
2.39 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-ospp.yml
Ordering differences only
    
Offset 3442, 16 lines modifiedOffset 3442, 16 lines modified
3442 ······lineinfile:3442 ······lineinfile:
3443 ········dest:·/etc/audit/auditd.conf3443 ········dest:·/etc/audit/auditd.conf
3444 ········regexp:·^\s*flush\s*=\s*.*$3444 ········regexp:·^\s*flush\s*=\s*.*$
3445 ········line:·flush·=·{{·var_auditd_flush·}}3445 ········line:·flush·=·{{·var_auditd_flush·}}
3446 ········state:·present3446 ········state:·present
3447 ········create:·true3447 ········create:·true
3448 ······when:3448 ······when:
3449 ······-·'"audit"·in·ansible_facts.packages' 
3450 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3449 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3450 ······-·'"audit"·in·ansible_facts.packages'
3451 ······tags:3451 ······tags:
3452 ······-·CCE-83685-83452 ······-·CCE-83685-8
3453 ······-·NIST-800-171-3.3.13453 ······-·NIST-800-171-3.3.1
3454 ······-·NIST-800-53-AU-113454 ······-·NIST-800-53-AU-11
3455 ······-·NIST-800-53-CM-6(a)3455 ······-·NIST-800-53-CM-6(a)
3456 ······-·auditd_data_retention_flush3456 ······-·auditd_data_retention_flush
3457 ······-·low_complexity3457 ······-·low_complexity
Offset 3499, 16 lines modifiedOffset 3499, 16 lines modified
3499 ········lineinfile:3499 ········lineinfile:
3500 ··········path:·/etc/audit/auditd.conf3500 ··········path:·/etc/audit/auditd.conf
3501 ··········create:·true3501 ··········create:·true
3502 ··········regexp:·(?i)^\s*freq\s*=\s*3502 ··········regexp:·(?i)^\s*freq\s*=\s*
3503 ··········line:·freq·=·503503 ··········line:·freq·=·50
3504 ··········state:·present3504 ··········state:·present
3505 ······when:3505 ······when:
3506 ······-·'"audit"·in·ansible_facts.packages' 
3507 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3506 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3507 ······-·'"audit"·in·ansible_facts.packages'
3508 ······tags:3508 ······tags:
3509 ······-·CCE-83704-73509 ······-·CCE-83704-7
3510 ······-·NIST-800-53-CM-63510 ······-·NIST-800-53-CM-6
3511 ······-·auditd_freq3511 ······-·auditd_freq
3512 ······-·low_complexity3512 ······-·low_complexity
3513 ······-·low_disruption3513 ······-·low_disruption
3514 ······-·medium_severity3514 ······-·medium_severity
Offset 3555, 16 lines modifiedOffset 3555, 16 lines modified
3555 ········lineinfile:3555 ········lineinfile:
3556 ··········path:·/etc/audit/auditd.conf3556 ··········path:·/etc/audit/auditd.conf
3557 ··········create:·true3557 ··········create:·true
3558 ··········regexp:·(?i)^\s*log_format\s*=\s*3558 ··········regexp:·(?i)^\s*log_format\s*=\s*
3559 ··········line:·log_format·=·ENRICHED3559 ··········line:·log_format·=·ENRICHED
3560 ··········state:·present3560 ··········state:·present
3561 ······when:3561 ······when:
3562 ······-·'"audit"·in·ansible_facts.packages' 
3563 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3562 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3563 ······-·'"audit"·in·ansible_facts.packages'
3564 ······tags:3564 ······tags:
3565 ······-·CCE-83696-53565 ······-·CCE-83696-5
3566 ······-·NIST-800-53-AU-33566 ······-·NIST-800-53-AU-3
3567 ······-·NIST-800-53-CM-63567 ······-·NIST-800-53-CM-6
3568 ······-·auditd_log_format3568 ······-·auditd_log_format
3569 ······-·low_complexity3569 ······-·low_complexity
3570 ······-·low_disruption3570 ······-·low_disruption
Offset 3612, 16 lines modifiedOffset 3612, 16 lines modified
3612 ········lineinfile:3612 ········lineinfile:
3613 ··········path:·/etc/audit/auditd.conf3613 ··········path:·/etc/audit/auditd.conf
3614 ··········create:·true3614 ··········create:·true
3615 ··········regexp:·(?i)^\s*name_format\s*=\s*3615 ··········regexp:·(?i)^\s*name_format\s*=\s*
3616 ··········line:·name_format·=·hostname3616 ··········line:·name_format·=·hostname
3617 ··········state:·present3617 ··········state:·present
3618 ······when:3618 ······when:
3619 ······-·'"audit"·in·ansible_facts.packages' 
3620 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3619 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3620 ······-·'"audit"·in·ansible_facts.packages'
3621 ······tags:3621 ······tags:
3622 ······-·CCE-83686-63622 ······-·CCE-83686-6
3623 ······-·NIST-800-53-AU-33623 ······-·NIST-800-53-AU-3
3624 ······-·NIST-800-53-CM-63624 ······-·NIST-800-53-CM-6
3625 ······-·auditd_name_format3625 ······-·auditd_name_format
3626 ······-·low_complexity3626 ······-·low_complexity
3627 ······-·low_disruption3627 ······-·low_disruption
157 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-pci-dss.yml
Ordering differences only
    
Offset 5087, 16 lines modifiedOffset 5087, 16 lines modified
  
5087 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5087 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5088 ······find:5088 ······find:
5089 ········paths:·/etc/audit/rules.d/5089 ········paths:·/etc/audit/rules.d/
5090 ········patterns:·'*.rules'5090 ········patterns:·'*.rules'
5091 ······register:·find_rules_d5091 ······register:·find_rules_d
5092 ······when:5092 ······when:
5093 ······-·'"audit"·in·ansible_facts.packages' 
5094 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5093 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5094 ······-·'"audit"·in·ansible_facts.packages'
5095 ······tags:5095 ······tags:
5096 ······-·CCE-83716-15096 ······-·CCE-83716-1
5097 ······-·CJIS-5.4.1.15097 ······-·CJIS-5.4.1.1
5098 ······-·NIST-800-171-3.3.15098 ······-·NIST-800-171-3.3.1
5099 ······-·NIST-800-171-3.4.35099 ······-·NIST-800-171-3.4.3
5100 ······-·NIST-800-53-AC-6(9)5100 ······-·NIST-800-53-AC-6(9)
5101 ······-·NIST-800-53-CM-6(a)5101 ······-·NIST-800-53-CM-6(a)
Offset 5112, 16 lines modifiedOffset 5112, 16 lines modified
5112 ······lineinfile:5112 ······lineinfile:
5113 ········path:·'{{·item·}}'5113 ········path:·'{{·item·}}'
5114 ········regexp:·^\s*(?:-e)\s+.*$5114 ········regexp:·^\s*(?:-e)\s+.*$
5115 ········state:·absent5115 ········state:·absent
5116 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5116 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5117 ········}}'5117 ········}}'
5118 ······when:5118 ······when:
5119 ······-·'"audit"·in·ansible_facts.packages' 
5120 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5119 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5120 ······-·'"audit"·in·ansible_facts.packages'
5121 ······tags:5121 ······tags:
5122 ······-·CCE-83716-15122 ······-·CCE-83716-1
5123 ······-·CJIS-5.4.1.15123 ······-·CJIS-5.4.1.1
5124 ······-·NIST-800-171-3.3.15124 ······-·NIST-800-171-3.3.1
5125 ······-·NIST-800-171-3.4.35125 ······-·NIST-800-171-3.4.3
5126 ······-·NIST-800-53-AC-6(9)5126 ······-·NIST-800-53-AC-6(9)
5127 ······-·NIST-800-53-CM-6(a)5127 ······-·NIST-800-53-CM-6(a)
Offset 5139, 16 lines modifiedOffset 5139, 16 lines modified
5139 ········create:·true5139 ········create:·true
5140 ········line:·-e·25140 ········line:·-e·2
5141 ········mode:·o-rwx5141 ········mode:·o-rwx
5142 ······loop:5142 ······loop:
5143 ······-·/etc/audit/audit.rules5143 ······-·/etc/audit/audit.rules
5144 ······-·/etc/audit/rules.d/immutable.rules5144 ······-·/etc/audit/rules.d/immutable.rules
5145 ······when:5145 ······when:
5146 ······-·'"audit"·in·ansible_facts.packages' 
5147 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5146 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5147 ······-·'"audit"·in·ansible_facts.packages'
5148 ······tags:5148 ······tags:
5149 ······-·CCE-83716-15149 ······-·CCE-83716-1
5150 ······-·CJIS-5.4.1.15150 ······-·CJIS-5.4.1.1
5151 ······-·NIST-800-171-3.3.15151 ······-·NIST-800-171-3.3.1
5152 ······-·NIST-800-171-3.4.35152 ······-·NIST-800-171-3.4.3
5153 ······-·NIST-800-53-AC-6(9)5153 ······-·NIST-800-53-AC-6(9)
5154 ······-·NIST-800-53-CM-6(a)5154 ······-·NIST-800-53-CM-6(a)
Offset 5182, 16 lines modifiedOffset 5182, 16 lines modified
5182 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5182 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5183 ······find:5183 ······find:
5184 ········paths:·/etc/audit/rules.d5184 ········paths:·/etc/audit/rules.d
5185 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5185 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5186 ········patterns:·'*.rules'5186 ········patterns:·'*.rules'
5187 ······register:·find_existing_watch_rules_d5187 ······register:·find_existing_watch_rules_d
5188 ······when:5188 ······when:
5189 ······-·'"audit"·in·ansible_facts.packages' 
5190 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5189 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5190 ······-·'"audit"·in·ansible_facts.packages'
5191 ······tags:5191 ······tags:
5192 ······-·CCE-83721-15192 ······-·CCE-83721-1
5193 ······-·CJIS-5.4.1.15193 ······-·CJIS-5.4.1.1
5194 ······-·NIST-800-171-3.1.85194 ······-·NIST-800-171-3.1.8
5195 ······-·NIST-800-53-AU-12(c)5195 ······-·NIST-800-53-AU-12(c)
5196 ······-·NIST-800-53-AU-2(d)5196 ······-·NIST-800-53-AU-2(d)
5197 ······-·NIST-800-53-CM-6(a)5197 ······-·NIST-800-53-CM-6(a)
Offset 5206, 16 lines modifiedOffset 5206, 16 lines modified
5206 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5206 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5207 ······find:5207 ······find:
5208 ········paths:·/etc/audit/rules.d5208 ········paths:·/etc/audit/rules.d
5209 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5209 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5210 ········patterns:·'*.rules'5210 ········patterns:·'*.rules'
5211 ······register:·find_watch_key5211 ······register:·find_watch_key
5212 ······when:5212 ······when:
5213 ······-·'"audit"·in·ansible_facts.packages' 
5214 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5213 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5214 ······-·'"audit"·in·ansible_facts.packages'
5215 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5215 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5216 ········==·05216 ········==·0
5217 ······tags:5217 ······tags:
5218 ······-·CCE-83721-15218 ······-·CCE-83721-1
5219 ······-·CJIS-5.4.1.15219 ······-·CJIS-5.4.1.1
5220 ······-·NIST-800-171-3.1.85220 ······-·NIST-800-171-3.1.8
5221 ······-·NIST-800-53-AU-12(c)5221 ······-·NIST-800-53-AU-12(c)
Offset 5230, 16 lines modifiedOffset 5230, 16 lines modified
5230 ······-·restrict_strategy5230 ······-·restrict_strategy
  
5231 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5231 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5232 ······set_fact:5232 ······set_fact:
5233 ········all_files:5233 ········all_files:
5234 ········-·/etc/audit/rules.d/MAC-policy.rules5234 ········-·/etc/audit/rules.d/MAC-policy.rules
5235 ······when:5235 ······when:
5236 ······-·'"audit"·in·ansible_facts.packages' 
5237 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5236 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5237 ······-·'"audit"·in·ansible_facts.packages'
5238 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5238 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5239 ········is·defined·and·find_existing_watch_rules_d.matched·==·05239 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5240 ······tags:5240 ······tags:
5241 ······-·CCE-83721-15241 ······-·CCE-83721-1
5242 ······-·CJIS-5.4.1.15242 ······-·CJIS-5.4.1.1
5243 ······-·NIST-800-171-3.1.85243 ······-·NIST-800-171-3.1.8
5244 ······-·NIST-800-53-AU-12(c)5244 ······-·NIST-800-53-AU-12(c)
Offset 5254, 16 lines modifiedOffset 5254, 16 lines modified
5254 ······-·restrict_strategy5254 ······-·restrict_strategy
  
5255 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5255 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5256 ······set_fact:5256 ······set_fact:
5257 ········all_files:5257 ········all_files:
5258 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5258 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5259 ······when:5259 ······when:
5260 ······-·'"audit"·in·ansible_facts.packages' 
5261 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5260 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5261 ······-·'"audit"·in·ansible_facts.packages'
5262 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5262 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5263 ········is·defined·and·find_existing_watch_rules_d.matched·==·05263 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5264 ······tags:5264 ······tags:
5265 ······-·CCE-83721-15265 ······-·CCE-83721-1
5266 ······-·CJIS-5.4.1.15266 ······-·CJIS-5.4.1.1
5267 ······-·NIST-800-171-3.1.85267 ······-·NIST-800-171-3.1.8
5268 ······-·NIST-800-53-AU-12(c)5268 ······-·NIST-800-53-AU-12(c)
Offset 5280, 16 lines modifiedOffset 5280, 16 lines modified
5280 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5280 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 156155/160788 bytes (97.12%) of diff not shown.
164 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-stig.yml
Ordering differences only
    
Offset 12055, 16 lines modifiedOffset 12055, 16 lines modified
  
12055 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension12055 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
12056 ······find:12056 ······find:
12057 ········paths:·/etc/audit/rules.d/12057 ········paths:·/etc/audit/rules.d/
12058 ········patterns:·'*.rules'12058 ········patterns:·'*.rules'
12059 ······register:·find_rules_d12059 ······register:·find_rules_d
12060 ······when:12060 ······when:
12061 ······-·'"audit"·in·ansible_facts.packages' 
12062 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12061 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12062 ······-·'"audit"·in·ansible_facts.packages'
12063 ······tags:12063 ······tags:
12064 ······-·CCE-83716-112064 ······-·CCE-83716-1
12065 ······-·CJIS-5.4.1.112065 ······-·CJIS-5.4.1.1
12066 ······-·NIST-800-171-3.3.112066 ······-·NIST-800-171-3.3.1
12067 ······-·NIST-800-171-3.4.312067 ······-·NIST-800-171-3.4.3
12068 ······-·NIST-800-53-AC-6(9)12068 ······-·NIST-800-53-AC-6(9)
12069 ······-·NIST-800-53-CM-6(a)12069 ······-·NIST-800-53-CM-6(a)
Offset 12080, 16 lines modifiedOffset 12080, 16 lines modified
12080 ······lineinfile:12080 ······lineinfile:
12081 ········path:·'{{·item·}}'12081 ········path:·'{{·item·}}'
12082 ········regexp:·^\s*(?:-e)\s+.*$12082 ········regexp:·^\s*(?:-e)\s+.*$
12083 ········state:·absent12083 ········state:·absent
12084 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']12084 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
12085 ········}}'12085 ········}}'
12086 ······when:12086 ······when:
12087 ······-·'"audit"·in·ansible_facts.packages' 
12088 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12087 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12088 ······-·'"audit"·in·ansible_facts.packages'
12089 ······tags:12089 ······tags:
12090 ······-·CCE-83716-112090 ······-·CCE-83716-1
12091 ······-·CJIS-5.4.1.112091 ······-·CJIS-5.4.1.1
12092 ······-·NIST-800-171-3.3.112092 ······-·NIST-800-171-3.3.1
12093 ······-·NIST-800-171-3.4.312093 ······-·NIST-800-171-3.4.3
12094 ······-·NIST-800-53-AC-6(9)12094 ······-·NIST-800-53-AC-6(9)
12095 ······-·NIST-800-53-CM-6(a)12095 ······-·NIST-800-53-CM-6(a)
Offset 12107, 16 lines modifiedOffset 12107, 16 lines modified
12107 ········create:·true12107 ········create:·true
12108 ········line:·-e·212108 ········line:·-e·2
12109 ········mode:·o-rwx12109 ········mode:·o-rwx
12110 ······loop:12110 ······loop:
12111 ······-·/etc/audit/audit.rules12111 ······-·/etc/audit/audit.rules
12112 ······-·/etc/audit/rules.d/immutable.rules12112 ······-·/etc/audit/rules.d/immutable.rules
12113 ······when:12113 ······when:
12114 ······-·'"audit"·in·ansible_facts.packages' 
12115 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12114 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12115 ······-·'"audit"·in·ansible_facts.packages'
12116 ······tags:12116 ······tags:
12117 ······-·CCE-83716-112117 ······-·CCE-83716-1
12118 ······-·CJIS-5.4.1.112118 ······-·CJIS-5.4.1.1
12119 ······-·NIST-800-171-3.3.112119 ······-·NIST-800-171-3.3.1
12120 ······-·NIST-800-171-3.4.312120 ······-·NIST-800-171-3.4.3
12121 ······-·NIST-800-53-AC-6(9)12121 ······-·NIST-800-53-AC-6(9)
12122 ······-·NIST-800-53-CM-6(a)12122 ······-·NIST-800-53-CM-6(a)
Offset 12148, 16 lines modifiedOffset 12148, 16 lines modified
12148 ······-·reboot_required12148 ······-·reboot_required
12149 ······-·restrict_strategy12149 ······-·restrict_strategy
  
12150 ····-·name:·Set·architecture·for·audit·mount·tasks12150 ····-·name:·Set·architecture·for·audit·mount·tasks
12151 ······set_fact:12151 ······set_fact:
12152 ········audit_arch:·b6412152 ········audit_arch:·b64
12153 ······when:12153 ······when:
12154 ······-·'"audit"·in·ansible_facts.packages' 
12155 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12154 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12155 ······-·'"audit"·in·ansible_facts.packages'
12156 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture12156 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
12157 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"12157 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
12158 ······tags:12158 ······tags:
12159 ······-·CCE-83735-112159 ······-·CCE-83735-1
12160 ······-·CJIS-5.4.1.112160 ······-·CJIS-5.4.1.1
12161 ······-·NIST-800-171-3.1.712161 ······-·NIST-800-171-3.1.7
12162 ······-·NIST-800-53-AC-6(9)12162 ······-·NIST-800-53-AC-6(9)
Offset 12289, 16 lines modifiedOffset 12289, 16 lines modified
12289 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012289 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12290 ············-F·auid!=unset·-F·key=perm_mod12290 ············-F·auid!=unset·-F·key=perm_mod
12291 ··········create:·true12291 ··········create:·true
12292 ··········mode:·o-rwx12292 ··········mode:·o-rwx
12293 ··········state:·present12293 ··········state:·present
12294 ········when:·syscalls_found·|·length·==·012294 ········when:·syscalls_found·|·length·==·0
12295 ······when:12295 ······when:
12296 ······-·'"audit"·in·ansible_facts.packages' 
12297 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12296 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12297 ······-·'"audit"·in·ansible_facts.packages'
12298 ······tags:12298 ······tags:
12299 ······-·CCE-83735-112299 ······-·CCE-83735-1
12300 ······-·CJIS-5.4.1.112300 ······-·CJIS-5.4.1.1
12301 ······-·NIST-800-171-3.1.712301 ······-·NIST-800-171-3.1.7
12302 ······-·NIST-800-53-AC-6(9)12302 ······-·NIST-800-53-AC-6(9)
12303 ······-·NIST-800-53-AU-12(c)12303 ······-·NIST-800-53-AU-12(c)
12304 ······-·NIST-800-53-AU-2(d)12304 ······-·NIST-800-53-AU-2(d)
Offset 12428, 16 lines modifiedOffset 12428, 16 lines modified
12428 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012428 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12429 ············-F·auid!=unset·-F·key=perm_mod12429 ············-F·auid!=unset·-F·key=perm_mod
12430 ··········create:·true12430 ··········create:·true
12431 ··········mode:·o-rwx12431 ··········mode:·o-rwx
12432 ··········state:·present12432 ··········state:·present
12433 ········when:·syscalls_found·|·length·==·012433 ········when:·syscalls_found·|·length·==·0
12434 ······when:12434 ······when:
12435 ······-·'"audit"·in·ansible_facts.packages' 
12436 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12435 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12436 ······-·'"audit"·in·ansible_facts.packages'
12437 ······-·audit_arch·==·"b64"12437 ······-·audit_arch·==·"b64"
12438 ······tags:12438 ······tags:
12439 ······-·CCE-83735-112439 ······-·CCE-83735-1
12440 ······-·CJIS-5.4.1.112440 ······-·CJIS-5.4.1.1
12441 ······-·NIST-800-171-3.1.712441 ······-·NIST-800-171-3.1.7
12442 ······-·NIST-800-53-AC-6(9)12442 ······-·NIST-800-53-AC-6(9)
12443 ······-·NIST-800-53-AU-12(c)12443 ······-·NIST-800-53-AU-12(c)
Offset 12467, 16 lines modifiedOffset 12467, 16 lines modified
12467 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/12467 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
12468 ······find:12468 ······find:
12469 ········paths:·/etc/audit/rules.d12469 ········paths:·/etc/audit/rules.d
12470 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+12470 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
12471 ········patterns:·'*.rules'12471 ········patterns:·'*.rules'
12472 ······register:·find_existing_watch_rules_d12472 ······register:·find_existing_watch_rules_d
12473 ······when:12473 ······when:
12474 ······-·'"audit"·in·ansible_facts.packages' 
12475 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12474 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12475 ······-·'"audit"·in·ansible_facts.packages'
12476 ······tags:12476 ······tags:
12477 ······-·CCE-90176-912477 ······-·CCE-90176-9
12478 ······-·audit_rules_sudoers12478 ······-·audit_rules_sudoers
12479 ······-·low_complexity12479 ······-·low_complexity
12480 ······-·low_disruption12480 ······-·low_disruption
12481 ······-·medium_severity12481 ······-·medium_severity
12482 ······-·no_reboot_needed12482 ······-·no_reboot_needed
Offset 12485, 16 lines modifiedOffset 12485, 16 lines modified
12485 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions12485 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 163005/167488 bytes (97.32%) of diff not shown.
164 KB
./usr/share/scap-security-guide/ansible/rhel9-playbook-stig_gui.yml
Ordering differences only
    
Offset 12027, 16 lines modifiedOffset 12027, 16 lines modified
  
12027 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension12027 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
12028 ······find:12028 ······find:
12029 ········paths:·/etc/audit/rules.d/12029 ········paths:·/etc/audit/rules.d/
12030 ········patterns:·'*.rules'12030 ········patterns:·'*.rules'
12031 ······register:·find_rules_d12031 ······register:·find_rules_d
12032 ······when:12032 ······when:
12033 ······-·'"audit"·in·ansible_facts.packages' 
12034 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12033 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12034 ······-·'"audit"·in·ansible_facts.packages'
12035 ······tags:12035 ······tags:
12036 ······-·CCE-83716-112036 ······-·CCE-83716-1
12037 ······-·CJIS-5.4.1.112037 ······-·CJIS-5.4.1.1
12038 ······-·NIST-800-171-3.3.112038 ······-·NIST-800-171-3.3.1
12039 ······-·NIST-800-171-3.4.312039 ······-·NIST-800-171-3.4.3
12040 ······-·NIST-800-53-AC-6(9)12040 ······-·NIST-800-53-AC-6(9)
12041 ······-·NIST-800-53-CM-6(a)12041 ······-·NIST-800-53-CM-6(a)
Offset 12052, 16 lines modifiedOffset 12052, 16 lines modified
12052 ······lineinfile:12052 ······lineinfile:
12053 ········path:·'{{·item·}}'12053 ········path:·'{{·item·}}'
12054 ········regexp:·^\s*(?:-e)\s+.*$12054 ········regexp:·^\s*(?:-e)\s+.*$
12055 ········state:·absent12055 ········state:·absent
12056 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']12056 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
12057 ········}}'12057 ········}}'
12058 ······when:12058 ······when:
12059 ······-·'"audit"·in·ansible_facts.packages' 
12060 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12059 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12060 ······-·'"audit"·in·ansible_facts.packages'
12061 ······tags:12061 ······tags:
12062 ······-·CCE-83716-112062 ······-·CCE-83716-1
12063 ······-·CJIS-5.4.1.112063 ······-·CJIS-5.4.1.1
12064 ······-·NIST-800-171-3.3.112064 ······-·NIST-800-171-3.3.1
12065 ······-·NIST-800-171-3.4.312065 ······-·NIST-800-171-3.4.3
12066 ······-·NIST-800-53-AC-6(9)12066 ······-·NIST-800-53-AC-6(9)
12067 ······-·NIST-800-53-CM-6(a)12067 ······-·NIST-800-53-CM-6(a)
Offset 12079, 16 lines modifiedOffset 12079, 16 lines modified
12079 ········create:·true12079 ········create:·true
12080 ········line:·-e·212080 ········line:·-e·2
12081 ········mode:·o-rwx12081 ········mode:·o-rwx
12082 ······loop:12082 ······loop:
12083 ······-·/etc/audit/audit.rules12083 ······-·/etc/audit/audit.rules
12084 ······-·/etc/audit/rules.d/immutable.rules12084 ······-·/etc/audit/rules.d/immutable.rules
12085 ······when:12085 ······when:
12086 ······-·'"audit"·in·ansible_facts.packages' 
12087 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12086 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12087 ······-·'"audit"·in·ansible_facts.packages'
12088 ······tags:12088 ······tags:
12089 ······-·CCE-83716-112089 ······-·CCE-83716-1
12090 ······-·CJIS-5.4.1.112090 ······-·CJIS-5.4.1.1
12091 ······-·NIST-800-171-3.3.112091 ······-·NIST-800-171-3.3.1
12092 ······-·NIST-800-171-3.4.312092 ······-·NIST-800-171-3.4.3
12093 ······-·NIST-800-53-AC-6(9)12093 ······-·NIST-800-53-AC-6(9)
12094 ······-·NIST-800-53-CM-6(a)12094 ······-·NIST-800-53-CM-6(a)
Offset 12120, 16 lines modifiedOffset 12120, 16 lines modified
12120 ······-·reboot_required12120 ······-·reboot_required
12121 ······-·restrict_strategy12121 ······-·restrict_strategy
  
12122 ····-·name:·Set·architecture·for·audit·mount·tasks12122 ····-·name:·Set·architecture·for·audit·mount·tasks
12123 ······set_fact:12123 ······set_fact:
12124 ········audit_arch:·b6412124 ········audit_arch:·b64
12125 ······when:12125 ······when:
12126 ······-·'"audit"·in·ansible_facts.packages' 
12127 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12126 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12127 ······-·'"audit"·in·ansible_facts.packages'
12128 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture12128 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
12129 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"12129 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
12130 ······tags:12130 ······tags:
12131 ······-·CCE-83735-112131 ······-·CCE-83735-1
12132 ······-·CJIS-5.4.1.112132 ······-·CJIS-5.4.1.1
12133 ······-·NIST-800-171-3.1.712133 ······-·NIST-800-171-3.1.7
12134 ······-·NIST-800-53-AC-6(9)12134 ······-·NIST-800-53-AC-6(9)
Offset 12261, 16 lines modifiedOffset 12261, 16 lines modified
12261 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012261 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12262 ············-F·auid!=unset·-F·key=perm_mod12262 ············-F·auid!=unset·-F·key=perm_mod
12263 ··········create:·true12263 ··········create:·true
12264 ··········mode:·o-rwx12264 ··········mode:·o-rwx
12265 ··········state:·present12265 ··········state:·present
12266 ········when:·syscalls_found·|·length·==·012266 ········when:·syscalls_found·|·length·==·0
12267 ······when:12267 ······when:
12268 ······-·'"audit"·in·ansible_facts.packages' 
12269 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12268 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12269 ······-·'"audit"·in·ansible_facts.packages'
12270 ······tags:12270 ······tags:
12271 ······-·CCE-83735-112271 ······-·CCE-83735-1
12272 ······-·CJIS-5.4.1.112272 ······-·CJIS-5.4.1.1
12273 ······-·NIST-800-171-3.1.712273 ······-·NIST-800-171-3.1.7
12274 ······-·NIST-800-53-AC-6(9)12274 ······-·NIST-800-53-AC-6(9)
12275 ······-·NIST-800-53-AU-12(c)12275 ······-·NIST-800-53-AU-12(c)
12276 ······-·NIST-800-53-AU-2(d)12276 ······-·NIST-800-53-AU-2(d)
Offset 12400, 16 lines modifiedOffset 12400, 16 lines modified
12400 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=100012400 ··········line:·-a·always,exit·-F·arch=b64·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
12401 ············-F·auid!=unset·-F·key=perm_mod12401 ············-F·auid!=unset·-F·key=perm_mod
12402 ··········create:·true12402 ··········create:·true
12403 ··········mode:·o-rwx12403 ··········mode:·o-rwx
12404 ··········state:·present12404 ··········state:·present
12405 ········when:·syscalls_found·|·length·==·012405 ········when:·syscalls_found·|·length·==·0
12406 ······when:12406 ······when:
12407 ······-·'"audit"·in·ansible_facts.packages' 
12408 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12407 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12408 ······-·'"audit"·in·ansible_facts.packages'
12409 ······-·audit_arch·==·"b64"12409 ······-·audit_arch·==·"b64"
12410 ······tags:12410 ······tags:
12411 ······-·CCE-83735-112411 ······-·CCE-83735-1
12412 ······-·CJIS-5.4.1.112412 ······-·CJIS-5.4.1.1
12413 ······-·NIST-800-171-3.1.712413 ······-·NIST-800-171-3.1.7
12414 ······-·NIST-800-53-AC-6(9)12414 ······-·NIST-800-53-AC-6(9)
12415 ······-·NIST-800-53-AU-12(c)12415 ······-·NIST-800-53-AU-12(c)
Offset 12439, 16 lines modifiedOffset 12439, 16 lines modified
12439 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/12439 ····-·name:·Check·if·watch·rule·for·/etc/sudoers·already·exists·in·/etc/audit/rules.d/
12440 ······find:12440 ······find:
12441 ········paths:·/etc/audit/rules.d12441 ········paths:·/etc/audit/rules.d
12442 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+12442 ········contains:·^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
12443 ········patterns:·'*.rules'12443 ········patterns:·'*.rules'
12444 ······register:·find_existing_watch_rules_d12444 ······register:·find_existing_watch_rules_d
12445 ······when:12445 ······when:
12446 ······-·'"audit"·in·ansible_facts.packages' 
12447 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]12446 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 12447 ······-·'"audit"·in·ansible_facts.packages'
12448 ······tags:12448 ······tags:
12449 ······-·CCE-90176-912449 ······-·CCE-90176-9
12450 ······-·audit_rules_sudoers12450 ······-·audit_rules_sudoers
12451 ······-·low_complexity12451 ······-·low_complexity
12452 ······-·low_disruption12452 ······-·low_disruption
12453 ······-·medium_severity12453 ······-·medium_severity
12454 ······-·no_reboot_needed12454 ······-·no_reboot_needed
Offset 12457, 16 lines modifiedOffset 12457, 16 lines modified
12457 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions12457 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·actions
Max diff block lines reached; 163005/167488 bytes (97.32%) of diff not shown.
109 KB
./usr/share/scap-security-guide/ansible/sl7-playbook-pci-dss.yml
Ordering differences only
    
Offset 4494, 16 lines modifiedOffset 4494, 16 lines modified
  
4494 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension4494 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
4495 ······find:4495 ······find:
4496 ········paths:·/etc/audit/rules.d/4496 ········paths:·/etc/audit/rules.d/
4497 ········patterns:·'*.rules'4497 ········patterns:·'*.rules'
4498 ······register:·find_rules_d4498 ······register:·find_rules_d
4499 ······when:4499 ······when:
4500 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4501 ······-·'"audit"·in·ansible_facts.packages'4500 ······-·'"audit"·in·ansible_facts.packages'
 4501 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4502 ······tags:4502 ······tags:
4503 ······-·CJIS-5.4.1.14503 ······-·CJIS-5.4.1.1
4504 ······-·NIST-800-171-3.3.14504 ······-·NIST-800-171-3.3.1
4505 ······-·NIST-800-171-3.4.34505 ······-·NIST-800-171-3.4.3
4506 ······-·NIST-800-53-AC-6(9)4506 ······-·NIST-800-53-AC-6(9)
4507 ······-·NIST-800-53-CM-6(a)4507 ······-·NIST-800-53-CM-6(a)
4508 ······-·PCI-DSS-Req-10.5.24508 ······-·PCI-DSS-Req-10.5.2
Offset 4518, 16 lines modifiedOffset 4518, 16 lines modified
4518 ······lineinfile:4518 ······lineinfile:
4519 ········path:·'{{·item·}}'4519 ········path:·'{{·item·}}'
4520 ········regexp:·^\s*(?:-e)\s+.*$4520 ········regexp:·^\s*(?:-e)\s+.*$
4521 ········state:·absent4521 ········state:·absent
4522 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']4522 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
4523 ········}}'4523 ········}}'
4524 ······when:4524 ······when:
4525 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4526 ······-·'"audit"·in·ansible_facts.packages'4525 ······-·'"audit"·in·ansible_facts.packages'
 4526 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4527 ······tags:4527 ······tags:
4528 ······-·CJIS-5.4.1.14528 ······-·CJIS-5.4.1.1
4529 ······-·NIST-800-171-3.3.14529 ······-·NIST-800-171-3.3.1
4530 ······-·NIST-800-171-3.4.34530 ······-·NIST-800-171-3.4.3
4531 ······-·NIST-800-53-AC-6(9)4531 ······-·NIST-800-53-AC-6(9)
4532 ······-·NIST-800-53-CM-6(a)4532 ······-·NIST-800-53-CM-6(a)
4533 ······-·PCI-DSS-Req-10.5.24533 ······-·PCI-DSS-Req-10.5.2
Offset 4544, 16 lines modifiedOffset 4544, 16 lines modified
4544 ········create:·true4544 ········create:·true
4545 ········line:·-e·24545 ········line:·-e·2
4546 ········mode:·o-rwx4546 ········mode:·o-rwx
4547 ······loop:4547 ······loop:
4548 ······-·/etc/audit/audit.rules4548 ······-·/etc/audit/audit.rules
4549 ······-·/etc/audit/rules.d/immutable.rules4549 ······-·/etc/audit/rules.d/immutable.rules
4550 ······when:4550 ······when:
4551 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4552 ······-·'"audit"·in·ansible_facts.packages'4551 ······-·'"audit"·in·ansible_facts.packages'
 4552 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4553 ······tags:4553 ······tags:
4554 ······-·CJIS-5.4.1.14554 ······-·CJIS-5.4.1.1
4555 ······-·NIST-800-171-3.3.14555 ······-·NIST-800-171-3.3.1
4556 ······-·NIST-800-171-3.4.34556 ······-·NIST-800-171-3.4.3
4557 ······-·NIST-800-53-AC-6(9)4557 ······-·NIST-800-53-AC-6(9)
4558 ······-·NIST-800-53-CM-6(a)4558 ······-·NIST-800-53-CM-6(a)
4559 ······-·PCI-DSS-Req-10.5.24559 ······-·PCI-DSS-Req-10.5.2
Offset 4585, 16 lines modifiedOffset 4585, 16 lines modified
4585 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/4585 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
4586 ······find:4586 ······find:
4587 ········paths:·/etc/audit/rules.d4587 ········paths:·/etc/audit/rules.d
4588 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+4588 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
4589 ········patterns:·'*.rules'4589 ········patterns:·'*.rules'
4590 ······register:·find_existing_watch_rules_d4590 ······register:·find_existing_watch_rules_d
4591 ······when:4591 ······when:
4592 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4593 ······-·'"audit"·in·ansible_facts.packages'4592 ······-·'"audit"·in·ansible_facts.packages'
 4593 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4594 ······tags:4594 ······tags:
4595 ······-·CJIS-5.4.1.14595 ······-·CJIS-5.4.1.1
4596 ······-·NIST-800-171-3.1.84596 ······-·NIST-800-171-3.1.8
4597 ······-·NIST-800-53-AU-12(c)4597 ······-·NIST-800-53-AU-12(c)
4598 ······-·NIST-800-53-AU-2(d)4598 ······-·NIST-800-53-AU-2(d)
4599 ······-·NIST-800-53-CM-6(a)4599 ······-·NIST-800-53-CM-6(a)
4600 ······-·PCI-DSS-Req-10.5.54600 ······-·PCI-DSS-Req-10.5.5
Offset 4608, 16 lines modifiedOffset 4608, 16 lines modified
4608 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy4608 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
4609 ······find:4609 ······find:
4610 ········paths:·/etc/audit/rules.d4610 ········paths:·/etc/audit/rules.d
4611 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$4611 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
4612 ········patterns:·'*.rules'4612 ········patterns:·'*.rules'
4613 ······register:·find_watch_key4613 ······register:·find_watch_key
4614 ······when:4614 ······when:
4615 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4616 ······-·'"audit"·in·ansible_facts.packages'4615 ······-·'"audit"·in·ansible_facts.packages'
 4616 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4617 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched4617 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
4618 ········==·04618 ········==·0
4619 ······tags:4619 ······tags:
4620 ······-·CJIS-5.4.1.14620 ······-·CJIS-5.4.1.1
4621 ······-·NIST-800-171-3.1.84621 ······-·NIST-800-171-3.1.8
4622 ······-·NIST-800-53-AU-12(c)4622 ······-·NIST-800-53-AU-12(c)
4623 ······-·NIST-800-53-AU-2(d)4623 ······-·NIST-800-53-AU-2(d)
Offset 4631, 16 lines modifiedOffset 4631, 16 lines modified
4631 ······-·restrict_strategy4631 ······-·restrict_strategy
  
4632 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule4632 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
4633 ······set_fact:4633 ······set_fact:
4634 ········all_files:4634 ········all_files:
4635 ········-·/etc/audit/rules.d/MAC-policy.rules4635 ········-·/etc/audit/rules.d/MAC-policy.rules
4636 ······when:4636 ······when:
4637 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4638 ······-·'"audit"·in·ansible_facts.packages'4637 ······-·'"audit"·in·ansible_facts.packages'
 4638 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4639 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched4639 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
4640 ········is·defined·and·find_existing_watch_rules_d.matched·==·04640 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4641 ······tags:4641 ······tags:
4642 ······-·CJIS-5.4.1.14642 ······-·CJIS-5.4.1.1
4643 ······-·NIST-800-171-3.1.84643 ······-·NIST-800-171-3.1.8
4644 ······-·NIST-800-53-AU-12(c)4644 ······-·NIST-800-53-AU-12(c)
4645 ······-·NIST-800-53-AU-2(d)4645 ······-·NIST-800-53-AU-2(d)
Offset 4654, 16 lines modifiedOffset 4654, 16 lines modified
4654 ······-·restrict_strategy4654 ······-·restrict_strategy
  
4655 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule4655 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
4656 ······set_fact:4656 ······set_fact:
4657 ········all_files:4657 ········all_files:
4658 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'4658 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
4659 ······when:4659 ······when:
4660 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
4661 ······-·'"audit"·in·ansible_facts.packages'4660 ······-·'"audit"·in·ansible_facts.packages'
 4661 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
4662 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched4662 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
4663 ········is·defined·and·find_existing_watch_rules_d.matched·==·04663 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
4664 ······tags:4664 ······tags:
4665 ······-·CJIS-5.4.1.14665 ······-·CJIS-5.4.1.1
4666 ······-·NIST-800-171-3.1.84666 ······-·NIST-800-171-3.1.8
4667 ······-·NIST-800-53-AU-12(c)4667 ······-·NIST-800-53-AU-12(c)
4668 ······-·NIST-800-53-AU-2(d)4668 ······-·NIST-800-53-AU-2(d)
Offset 4679, 16 lines modifiedOffset 4679, 16 lines modified
4679 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/4679 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 106634/111669 bytes (95.49%) of diff not shown.
85.0 KB
./usr/share/scap-security-guide/ansible/sl7-playbook-standard.yml
Ordering differences only
    
Offset 644, 16 lines modifiedOffset 644, 16 lines modified
644 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/644 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
645 ······find:645 ······find:
646 ········paths:·/etc/audit/rules.d646 ········paths:·/etc/audit/rules.d
647 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+647 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
648 ········patterns:·'*.rules'648 ········patterns:·'*.rules'
649 ······register:·find_existing_watch_rules_d649 ······register:·find_existing_watch_rules_d
650 ······when:650 ······when:
651 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
652 ······-·'"audit"·in·ansible_facts.packages'651 ······-·'"audit"·in·ansible_facts.packages'
 652 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
653 ······tags:653 ······tags:
654 ······-·CJIS-5.4.1.1654 ······-·CJIS-5.4.1.1
655 ······-·NIST-800-171-3.1.8655 ······-·NIST-800-171-3.1.8
656 ······-·NIST-800-53-AU-12(c)656 ······-·NIST-800-53-AU-12(c)
657 ······-·NIST-800-53-AU-2(d)657 ······-·NIST-800-53-AU-2(d)
658 ······-·NIST-800-53-CM-6(a)658 ······-·NIST-800-53-CM-6(a)
659 ······-·PCI-DSS-Req-10.5.5659 ······-·PCI-DSS-Req-10.5.5
Offset 667, 16 lines modifiedOffset 667, 16 lines modified
667 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy667 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
668 ······find:668 ······find:
669 ········paths:·/etc/audit/rules.d669 ········paths:·/etc/audit/rules.d
670 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$670 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
671 ········patterns:·'*.rules'671 ········patterns:·'*.rules'
672 ······register:·find_watch_key672 ······register:·find_watch_key
673 ······when:673 ······when:
674 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
675 ······-·'"audit"·in·ansible_facts.packages'674 ······-·'"audit"·in·ansible_facts.packages'
 675 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
676 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched676 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
677 ········==·0677 ········==·0
678 ······tags:678 ······tags:
679 ······-·CJIS-5.4.1.1679 ······-·CJIS-5.4.1.1
680 ······-·NIST-800-171-3.1.8680 ······-·NIST-800-171-3.1.8
681 ······-·NIST-800-53-AU-12(c)681 ······-·NIST-800-53-AU-12(c)
682 ······-·NIST-800-53-AU-2(d)682 ······-·NIST-800-53-AU-2(d)
Offset 690, 16 lines modifiedOffset 690, 16 lines modified
690 ······-·restrict_strategy690 ······-·restrict_strategy
  
691 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule691 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
692 ······set_fact:692 ······set_fact:
693 ········all_files:693 ········all_files:
694 ········-·/etc/audit/rules.d/MAC-policy.rules694 ········-·/etc/audit/rules.d/MAC-policy.rules
695 ······when:695 ······when:
696 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
697 ······-·'"audit"·in·ansible_facts.packages'696 ······-·'"audit"·in·ansible_facts.packages'
 697 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
698 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched698 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
699 ········is·defined·and·find_existing_watch_rules_d.matched·==·0699 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
700 ······tags:700 ······tags:
701 ······-·CJIS-5.4.1.1701 ······-·CJIS-5.4.1.1
702 ······-·NIST-800-171-3.1.8702 ······-·NIST-800-171-3.1.8
703 ······-·NIST-800-53-AU-12(c)703 ······-·NIST-800-53-AU-12(c)
704 ······-·NIST-800-53-AU-2(d)704 ······-·NIST-800-53-AU-2(d)
Offset 713, 16 lines modifiedOffset 713, 16 lines modified
713 ······-·restrict_strategy713 ······-·restrict_strategy
  
714 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule714 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
715 ······set_fact:715 ······set_fact:
716 ········all_files:716 ········all_files:
717 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'717 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
718 ······when:718 ······when:
719 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
720 ······-·'"audit"·in·ansible_facts.packages'719 ······-·'"audit"·in·ansible_facts.packages'
 720 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
721 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched721 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
722 ········is·defined·and·find_existing_watch_rules_d.matched·==·0722 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
723 ······tags:723 ······tags:
724 ······-·CJIS-5.4.1.1724 ······-·CJIS-5.4.1.1
725 ······-·NIST-800-171-3.1.8725 ······-·NIST-800-171-3.1.8
726 ······-·NIST-800-53-AU-12(c)726 ······-·NIST-800-53-AU-12(c)
727 ······-·NIST-800-53-AU-2(d)727 ······-·NIST-800-53-AU-2(d)
Offset 738, 16 lines modifiedOffset 738, 16 lines modified
738 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/738 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
739 ······lineinfile:739 ······lineinfile:
740 ········path:·'{{·all_files[0]·}}'740 ········path:·'{{·all_files[0]·}}'
741 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy741 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
742 ········create:·true742 ········create:·true
743 ········mode:·'0640'743 ········mode:·'0640'
744 ······when:744 ······when:
745 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
746 ······-·'"audit"·in·ansible_facts.packages'745 ······-·'"audit"·in·ansible_facts.packages'
 746 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
747 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched747 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
748 ········==·0748 ········==·0
749 ······tags:749 ······tags:
750 ······-·CJIS-5.4.1.1750 ······-·CJIS-5.4.1.1
751 ······-·NIST-800-171-3.1.8751 ······-·NIST-800-171-3.1.8
752 ······-·NIST-800-53-AU-12(c)752 ······-·NIST-800-53-AU-12(c)
753 ······-·NIST-800-53-AU-2(d)753 ······-·NIST-800-53-AU-2(d)
Offset 763, 16 lines modifiedOffset 763, 16 lines modified
763 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules763 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules
764 ······find:764 ······find:
765 ········paths:·/etc/audit/765 ········paths:·/etc/audit/
766 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+766 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
767 ········patterns:·audit.rules767 ········patterns:·audit.rules
768 ······register:·find_existing_watch_audit_rules768 ······register:·find_existing_watch_audit_rules
769 ······when:769 ······when:
770 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
771 ······-·'"audit"·in·ansible_facts.packages'770 ······-·'"audit"·in·ansible_facts.packages'
 771 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
772 ······tags:772 ······tags:
773 ······-·CJIS-5.4.1.1773 ······-·CJIS-5.4.1.1
774 ······-·NIST-800-171-3.1.8774 ······-·NIST-800-171-3.1.8
775 ······-·NIST-800-53-AU-12(c)775 ······-·NIST-800-53-AU-12(c)
776 ······-·NIST-800-53-AU-2(d)776 ······-·NIST-800-53-AU-2(d)
777 ······-·NIST-800-53-CM-6(a)777 ······-·NIST-800-53-CM-6(a)
778 ······-·PCI-DSS-Req-10.5.5778 ······-·PCI-DSS-Req-10.5.5
Offset 787, 16 lines modifiedOffset 787, 16 lines modified
787 ······lineinfile:787 ······lineinfile:
788 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy788 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
789 ········state:·present789 ········state:·present
790 ········dest:·/etc/audit/audit.rules790 ········dest:·/etc/audit/audit.rules
791 ········create:·true791 ········create:·true
792 ········mode:·'0640'792 ········mode:·'0640'
793 ······when:793 ······when:
794 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"] 
795 ······-·'"audit"·in·ansible_facts.packages'794 ······-·'"audit"·in·ansible_facts.packages'
 795 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
796 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched796 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
797 ········==·0797 ········==·0
798 ······tags:798 ······tags:
799 ······-·CJIS-5.4.1.1799 ······-·CJIS-5.4.1.1
800 ······-·NIST-800-171-3.1.8800 ······-·NIST-800-171-3.1.8
801 ······-·NIST-800-53-AU-12(c)801 ······-·NIST-800-53-AU-12(c)
802 ······-·NIST-800-53-AU-2(d)802 ······-·NIST-800-53-AU-2(d)
Offset 829, 16 lines modifiedOffset 829, 16 lines modified
829 ······-·reboot_required829 ······-·reboot_required
Max diff block lines reached; 81679/86895 bytes (94.00%) of diff not shown.
854 B
./usr/share/scap-security-guide/ansible/sle15-playbook-anssi_bp28_enhanced.yml
Ordering differences only
    
Offset 6130, 16 lines modifiedOffset 6130, 16 lines modified
6130 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x6130 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
6131 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged6131 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
6132 ··········create:·true6132 ··········create:·true
6133 ··········mode:·o-rwx6133 ··········mode:·o-rwx
6134 ··········state:·present6134 ··········state:·present
6135 ········when:·syscalls_found·|·length·==·06135 ········when:·syscalls_found·|·length·==·0
6136 ······when:6136 ······when:
6137 ······-·'"audit"·in·ansible_facts.packages' 
6138 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6137 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6138 ······-·'"audit"·in·ansible_facts.packages'
6139 ······tags:6139 ······tags:
6140 ······-·CCE-85603-96140 ······-·CCE-85603-9
6141 ······-·DISA-STIG-SLES-15-0305606141 ······-·DISA-STIG-SLES-15-030560
6142 ······-·NIST-800-171-3.1.76142 ······-·NIST-800-171-3.1.7
6143 ······-·NIST-800-53-AC-6(9)6143 ······-·NIST-800-53-AC-6(9)
6144 ······-·NIST-800-53-AU-12(c)6144 ······-·NIST-800-53-AU-12(c)
6145 ······-·NIST-800-53-AU-2(d)6145 ······-·NIST-800-53-AU-2(d)
846 B
./usr/share/scap-security-guide/ansible/sle15-playbook-anssi_bp28_high.yml
Ordering differences only
    
Offset 6403, 16 lines modifiedOffset 6403, 16 lines modified
6403 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x6403 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
6404 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged6404 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
6405 ··········create:·true6405 ··········create:·true
6406 ··········mode:·o-rwx6406 ··········mode:·o-rwx
6407 ··········state:·present6407 ··········state:·present
6408 ········when:·syscalls_found·|·length·==·06408 ········when:·syscalls_found·|·length·==·0
6409 ······when:6409 ······when:
6410 ······-·'"audit"·in·ansible_facts.packages' 
6411 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6410 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6411 ······-·'"audit"·in·ansible_facts.packages'
6412 ······tags:6412 ······tags:
6413 ······-·CCE-85603-96413 ······-·CCE-85603-9
6414 ······-·DISA-STIG-SLES-15-0305606414 ······-·DISA-STIG-SLES-15-030560
6415 ······-·NIST-800-171-3.1.76415 ······-·NIST-800-171-3.1.7
6416 ······-·NIST-800-53-AC-6(9)6416 ······-·NIST-800-53-AC-6(9)
6417 ······-·NIST-800-53-AU-12(c)6417 ······-·NIST-800-53-AU-12(c)
6418 ······-·NIST-800-53-AU-2(d)6418 ······-·NIST-800-53-AU-2(d)
862 B
./usr/share/scap-security-guide/ansible/sle15-playbook-anssi_bp28_intermediary.yml
Ordering differences only
    
Offset 5764, 16 lines modifiedOffset 5764, 16 lines modified
5764 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x5764 ··········line:·-a·always,exit{{·syscalls·|·join(',')·}}·-F·path=/usr/bin/sudo·-F·perm=x
5765 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged5765 ············-F·auid>=1000·-F·auid!=unset·-F·key=privileged
5766 ··········create:·true5766 ··········create:·true
5767 ··········mode:·o-rwx5767 ··········mode:·o-rwx
5768 ··········state:·present5768 ··········state:·present
5769 ········when:·syscalls_found·|·length·==·05769 ········when:·syscalls_found·|·length·==·0
5770 ······when:5770 ······when:
5771 ······-·'"audit"·in·ansible_facts.packages' 
5772 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5771 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5772 ······-·'"audit"·in·ansible_facts.packages'
5773 ······tags:5773 ······tags:
5774 ······-·CCE-85603-95774 ······-·CCE-85603-9
5775 ······-·DISA-STIG-SLES-15-0305605775 ······-·DISA-STIG-SLES-15-030560
5776 ······-·NIST-800-171-3.1.75776 ······-·NIST-800-171-3.1.7
5777 ······-·NIST-800-53-AC-6(9)5777 ······-·NIST-800-53-AC-6(9)
5778 ······-·NIST-800-53-AU-12(c)5778 ······-·NIST-800-53-AU-12(c)
5779 ······-·NIST-800-53-AU-2(d)5779 ······-·NIST-800-53-AU-2(d)
157 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-cis.yml
Ordering differences only
    
Offset 3070, 16 lines modifiedOffset 3070, 16 lines modified
  
3070 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension3070 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
3071 ······find:3071 ······find:
3072 ········paths:·/etc/audit/rules.d/3072 ········paths:·/etc/audit/rules.d/
3073 ········patterns:·'*.rules'3073 ········patterns:·'*.rules'
3074 ······register:·find_rules_d3074 ······register:·find_rules_d
3075 ······when:3075 ······when:
3076 ······-·'"audit"·in·ansible_facts.packages' 
3077 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3076 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3077 ······-·'"audit"·in·ansible_facts.packages'
3078 ······tags:3078 ······tags:
3079 ······-·CCE-85831-63079 ······-·CCE-85831-6
3080 ······-·CJIS-5.4.1.13080 ······-·CJIS-5.4.1.1
3081 ······-·NIST-800-171-3.3.13081 ······-·NIST-800-171-3.3.1
3082 ······-·NIST-800-171-3.4.33082 ······-·NIST-800-171-3.4.3
3083 ······-·NIST-800-53-AC-6(9)3083 ······-·NIST-800-53-AC-6(9)
3084 ······-·NIST-800-53-CM-6(a)3084 ······-·NIST-800-53-CM-6(a)
Offset 3095, 16 lines modifiedOffset 3095, 16 lines modified
3095 ······lineinfile:3095 ······lineinfile:
3096 ········path:·'{{·item·}}'3096 ········path:·'{{·item·}}'
3097 ········regexp:·^\s*(?:-e)\s+.*$3097 ········regexp:·^\s*(?:-e)\s+.*$
3098 ········state:·absent3098 ········state:·absent
3099 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']3099 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
3100 ········}}'3100 ········}}'
3101 ······when:3101 ······when:
3102 ······-·'"audit"·in·ansible_facts.packages' 
3103 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3102 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3103 ······-·'"audit"·in·ansible_facts.packages'
3104 ······tags:3104 ······tags:
3105 ······-·CCE-85831-63105 ······-·CCE-85831-6
3106 ······-·CJIS-5.4.1.13106 ······-·CJIS-5.4.1.1
3107 ······-·NIST-800-171-3.3.13107 ······-·NIST-800-171-3.3.1
3108 ······-·NIST-800-171-3.4.33108 ······-·NIST-800-171-3.4.3
3109 ······-·NIST-800-53-AC-6(9)3109 ······-·NIST-800-53-AC-6(9)
3110 ······-·NIST-800-53-CM-6(a)3110 ······-·NIST-800-53-CM-6(a)
Offset 3122, 16 lines modifiedOffset 3122, 16 lines modified
3122 ········create:·true3122 ········create:·true
3123 ········line:·-e·23123 ········line:·-e·2
3124 ········mode:·o-rwx3124 ········mode:·o-rwx
3125 ······loop:3125 ······loop:
3126 ······-·/etc/audit/audit.rules3126 ······-·/etc/audit/audit.rules
3127 ······-·/etc/audit/rules.d/immutable.rules3127 ······-·/etc/audit/rules.d/immutable.rules
3128 ······when:3128 ······when:
3129 ······-·'"audit"·in·ansible_facts.packages' 
3130 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3129 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3130 ······-·'"audit"·in·ansible_facts.packages'
3131 ······tags:3131 ······tags:
3132 ······-·CCE-85831-63132 ······-·CCE-85831-6
3133 ······-·CJIS-5.4.1.13133 ······-·CJIS-5.4.1.1
3134 ······-·NIST-800-171-3.3.13134 ······-·NIST-800-171-3.3.1
3135 ······-·NIST-800-171-3.4.33135 ······-·NIST-800-171-3.4.3
3136 ······-·NIST-800-53-AC-6(9)3136 ······-·NIST-800-53-AC-6(9)
3137 ······-·NIST-800-53-CM-6(a)3137 ······-·NIST-800-53-CM-6(a)
Offset 3165, 16 lines modifiedOffset 3165, 16 lines modified
3165 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/3165 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
3166 ······find:3166 ······find:
3167 ········paths:·/etc/audit/rules.d3167 ········paths:·/etc/audit/rules.d
3168 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+3168 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
3169 ········patterns:·'*.rules'3169 ········patterns:·'*.rules'
3170 ······register:·find_existing_watch_rules_d3170 ······register:·find_existing_watch_rules_d
3171 ······when:3171 ······when:
3172 ······-·'"audit"·in·ansible_facts.packages' 
3173 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3172 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3173 ······-·'"audit"·in·ansible_facts.packages'
3174 ······tags:3174 ······tags:
3175 ······-·CCE-85830-83175 ······-·CCE-85830-8
3176 ······-·CJIS-5.4.1.13176 ······-·CJIS-5.4.1.1
3177 ······-·NIST-800-171-3.1.83177 ······-·NIST-800-171-3.1.8
3178 ······-·NIST-800-53-AU-12(c)3178 ······-·NIST-800-53-AU-12(c)
3179 ······-·NIST-800-53-AU-2(d)3179 ······-·NIST-800-53-AU-2(d)
3180 ······-·NIST-800-53-CM-6(a)3180 ······-·NIST-800-53-CM-6(a)
Offset 3189, 16 lines modifiedOffset 3189, 16 lines modified
3189 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy3189 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
3190 ······find:3190 ······find:
3191 ········paths:·/etc/audit/rules.d3191 ········paths:·/etc/audit/rules.d
3192 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$3192 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
3193 ········patterns:·'*.rules'3193 ········patterns:·'*.rules'
3194 ······register:·find_watch_key3194 ······register:·find_watch_key
3195 ······when:3195 ······when:
3196 ······-·'"audit"·in·ansible_facts.packages' 
3197 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3196 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3197 ······-·'"audit"·in·ansible_facts.packages'
3198 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3198 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3199 ········==·03199 ········==·0
3200 ······tags:3200 ······tags:
3201 ······-·CCE-85830-83201 ······-·CCE-85830-8
3202 ······-·CJIS-5.4.1.13202 ······-·CJIS-5.4.1.1
3203 ······-·NIST-800-171-3.1.83203 ······-·NIST-800-171-3.1.8
3204 ······-·NIST-800-53-AU-12(c)3204 ······-·NIST-800-53-AU-12(c)
Offset 3213, 16 lines modifiedOffset 3213, 16 lines modified
3213 ······-·restrict_strategy3213 ······-·restrict_strategy
  
3214 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule3214 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
3215 ······set_fact:3215 ······set_fact:
3216 ········all_files:3216 ········all_files:
3217 ········-·/etc/audit/rules.d/MAC-policy.rules3217 ········-·/etc/audit/rules.d/MAC-policy.rules
3218 ······when:3218 ······when:
3219 ······-·'"audit"·in·ansible_facts.packages' 
3220 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3219 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3220 ······-·'"audit"·in·ansible_facts.packages'
3221 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched3221 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
3222 ········is·defined·and·find_existing_watch_rules_d.matched·==·03222 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3223 ······tags:3223 ······tags:
3224 ······-·CCE-85830-83224 ······-·CCE-85830-8
3225 ······-·CJIS-5.4.1.13225 ······-·CJIS-5.4.1.1
3226 ······-·NIST-800-171-3.1.83226 ······-·NIST-800-171-3.1.8
3227 ······-·NIST-800-53-AU-12(c)3227 ······-·NIST-800-53-AU-12(c)
Offset 3237, 16 lines modifiedOffset 3237, 16 lines modified
3237 ······-·restrict_strategy3237 ······-·restrict_strategy
  
3238 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule3238 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
3239 ······set_fact:3239 ······set_fact:
3240 ········all_files:3240 ········all_files:
3241 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'3241 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
3242 ······when:3242 ······when:
3243 ······-·'"audit"·in·ansible_facts.packages' 
3244 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3243 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3244 ······-·'"audit"·in·ansible_facts.packages'
3245 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched3245 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
3246 ········is·defined·and·find_existing_watch_rules_d.matched·==·03246 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3247 ······tags:3247 ······tags:
3248 ······-·CCE-85830-83248 ······-·CCE-85830-8
3249 ······-·CJIS-5.4.1.13249 ······-·CJIS-5.4.1.1
3250 ······-·NIST-800-171-3.1.83250 ······-·NIST-800-171-3.1.8
3251 ······-·NIST-800-53-AU-12(c)3251 ······-·NIST-800-53-AU-12(c)
Offset 3263, 16 lines modifiedOffset 3263, 16 lines modified
3263 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/3263 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 155671/160304 bytes (97.11%) of diff not shown.
157 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-cis_workstation_l2.yml
Ordering differences only
    
Offset 3070, 16 lines modifiedOffset 3070, 16 lines modified
  
3070 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension3070 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
3071 ······find:3071 ······find:
3072 ········paths:·/etc/audit/rules.d/3072 ········paths:·/etc/audit/rules.d/
3073 ········patterns:·'*.rules'3073 ········patterns:·'*.rules'
3074 ······register:·find_rules_d3074 ······register:·find_rules_d
3075 ······when:3075 ······when:
3076 ······-·'"audit"·in·ansible_facts.packages' 
3077 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3076 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3077 ······-·'"audit"·in·ansible_facts.packages'
3078 ······tags:3078 ······tags:
3079 ······-·CCE-85831-63079 ······-·CCE-85831-6
3080 ······-·CJIS-5.4.1.13080 ······-·CJIS-5.4.1.1
3081 ······-·NIST-800-171-3.3.13081 ······-·NIST-800-171-3.3.1
3082 ······-·NIST-800-171-3.4.33082 ······-·NIST-800-171-3.4.3
3083 ······-·NIST-800-53-AC-6(9)3083 ······-·NIST-800-53-AC-6(9)
3084 ······-·NIST-800-53-CM-6(a)3084 ······-·NIST-800-53-CM-6(a)
Offset 3095, 16 lines modifiedOffset 3095, 16 lines modified
3095 ······lineinfile:3095 ······lineinfile:
3096 ········path:·'{{·item·}}'3096 ········path:·'{{·item·}}'
3097 ········regexp:·^\s*(?:-e)\s+.*$3097 ········regexp:·^\s*(?:-e)\s+.*$
3098 ········state:·absent3098 ········state:·absent
3099 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']3099 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
3100 ········}}'3100 ········}}'
3101 ······when:3101 ······when:
3102 ······-·'"audit"·in·ansible_facts.packages' 
3103 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3102 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3103 ······-·'"audit"·in·ansible_facts.packages'
3104 ······tags:3104 ······tags:
3105 ······-·CCE-85831-63105 ······-·CCE-85831-6
3106 ······-·CJIS-5.4.1.13106 ······-·CJIS-5.4.1.1
3107 ······-·NIST-800-171-3.3.13107 ······-·NIST-800-171-3.3.1
3108 ······-·NIST-800-171-3.4.33108 ······-·NIST-800-171-3.4.3
3109 ······-·NIST-800-53-AC-6(9)3109 ······-·NIST-800-53-AC-6(9)
3110 ······-·NIST-800-53-CM-6(a)3110 ······-·NIST-800-53-CM-6(a)
Offset 3122, 16 lines modifiedOffset 3122, 16 lines modified
3122 ········create:·true3122 ········create:·true
3123 ········line:·-e·23123 ········line:·-e·2
3124 ········mode:·o-rwx3124 ········mode:·o-rwx
3125 ······loop:3125 ······loop:
3126 ······-·/etc/audit/audit.rules3126 ······-·/etc/audit/audit.rules
3127 ······-·/etc/audit/rules.d/immutable.rules3127 ······-·/etc/audit/rules.d/immutable.rules
3128 ······when:3128 ······when:
3129 ······-·'"audit"·in·ansible_facts.packages' 
3130 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3129 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3130 ······-·'"audit"·in·ansible_facts.packages'
3131 ······tags:3131 ······tags:
3132 ······-·CCE-85831-63132 ······-·CCE-85831-6
3133 ······-·CJIS-5.4.1.13133 ······-·CJIS-5.4.1.1
3134 ······-·NIST-800-171-3.3.13134 ······-·NIST-800-171-3.3.1
3135 ······-·NIST-800-171-3.4.33135 ······-·NIST-800-171-3.4.3
3136 ······-·NIST-800-53-AC-6(9)3136 ······-·NIST-800-53-AC-6(9)
3137 ······-·NIST-800-53-CM-6(a)3137 ······-·NIST-800-53-CM-6(a)
Offset 3165, 16 lines modifiedOffset 3165, 16 lines modified
3165 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/3165 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
3166 ······find:3166 ······find:
3167 ········paths:·/etc/audit/rules.d3167 ········paths:·/etc/audit/rules.d
3168 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+3168 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
3169 ········patterns:·'*.rules'3169 ········patterns:·'*.rules'
3170 ······register:·find_existing_watch_rules_d3170 ······register:·find_existing_watch_rules_d
3171 ······when:3171 ······when:
3172 ······-·'"audit"·in·ansible_facts.packages' 
3173 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3172 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3173 ······-·'"audit"·in·ansible_facts.packages'
3174 ······tags:3174 ······tags:
3175 ······-·CCE-85830-83175 ······-·CCE-85830-8
3176 ······-·CJIS-5.4.1.13176 ······-·CJIS-5.4.1.1
3177 ······-·NIST-800-171-3.1.83177 ······-·NIST-800-171-3.1.8
3178 ······-·NIST-800-53-AU-12(c)3178 ······-·NIST-800-53-AU-12(c)
3179 ······-·NIST-800-53-AU-2(d)3179 ······-·NIST-800-53-AU-2(d)
3180 ······-·NIST-800-53-CM-6(a)3180 ······-·NIST-800-53-CM-6(a)
Offset 3189, 16 lines modifiedOffset 3189, 16 lines modified
3189 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy3189 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
3190 ······find:3190 ······find:
3191 ········paths:·/etc/audit/rules.d3191 ········paths:·/etc/audit/rules.d
3192 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$3192 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
3193 ········patterns:·'*.rules'3193 ········patterns:·'*.rules'
3194 ······register:·find_watch_key3194 ······register:·find_watch_key
3195 ······when:3195 ······when:
3196 ······-·'"audit"·in·ansible_facts.packages' 
3197 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3196 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3197 ······-·'"audit"·in·ansible_facts.packages'
3198 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3198 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3199 ········==·03199 ········==·0
3200 ······tags:3200 ······tags:
3201 ······-·CCE-85830-83201 ······-·CCE-85830-8
3202 ······-·CJIS-5.4.1.13202 ······-·CJIS-5.4.1.1
3203 ······-·NIST-800-171-3.1.83203 ······-·NIST-800-171-3.1.8
3204 ······-·NIST-800-53-AU-12(c)3204 ······-·NIST-800-53-AU-12(c)
Offset 3213, 16 lines modifiedOffset 3213, 16 lines modified
3213 ······-·restrict_strategy3213 ······-·restrict_strategy
  
3214 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule3214 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
3215 ······set_fact:3215 ······set_fact:
3216 ········all_files:3216 ········all_files:
3217 ········-·/etc/audit/rules.d/MAC-policy.rules3217 ········-·/etc/audit/rules.d/MAC-policy.rules
3218 ······when:3218 ······when:
3219 ······-·'"audit"·in·ansible_facts.packages' 
3220 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3219 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3220 ······-·'"audit"·in·ansible_facts.packages'
3221 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched3221 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
3222 ········is·defined·and·find_existing_watch_rules_d.matched·==·03222 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3223 ······tags:3223 ······tags:
3224 ······-·CCE-85830-83224 ······-·CCE-85830-8
3225 ······-·CJIS-5.4.1.13225 ······-·CJIS-5.4.1.1
3226 ······-·NIST-800-171-3.1.83226 ······-·NIST-800-171-3.1.8
3227 ······-·NIST-800-53-AU-12(c)3227 ······-·NIST-800-53-AU-12(c)
Offset 3237, 16 lines modifiedOffset 3237, 16 lines modified
3237 ······-·restrict_strategy3237 ······-·restrict_strategy
  
3238 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule3238 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
3239 ······set_fact:3239 ······set_fact:
3240 ········all_files:3240 ········all_files:
3241 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'3241 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
3242 ······when:3242 ······when:
3243 ······-·'"audit"·in·ansible_facts.packages' 
3244 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3243 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3244 ······-·'"audit"·in·ansible_facts.packages'
3245 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched3245 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
3246 ········is·defined·and·find_existing_watch_rules_d.matched·==·03246 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3247 ······tags:3247 ······tags:
3248 ······-·CCE-85830-83248 ······-·CCE-85830-8
3249 ······-·CJIS-5.4.1.13249 ······-·CJIS-5.4.1.1
3250 ······-·NIST-800-171-3.1.83250 ······-·NIST-800-171-3.1.8
3251 ······-·NIST-800-53-AU-12(c)3251 ······-·NIST-800-53-AU-12(c)
Offset 3263, 16 lines modifiedOffset 3263, 16 lines modified
3263 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/3263 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 155671/160304 bytes (97.11%) of diff not shown.
177 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-hipaa.yml
Ordering differences only
    
Offset 1303, 16 lines modifiedOffset 1303, 16 lines modified
  
1303 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension1303 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
1304 ······find:1304 ······find:
1305 ········paths:·/etc/audit/rules.d/1305 ········paths:·/etc/audit/rules.d/
1306 ········patterns:·'*.rules'1306 ········patterns:·'*.rules'
1307 ······register:·find_rules_d1307 ······register:·find_rules_d
1308 ······when:1308 ······when:
1309 ······-·'"audit"·in·ansible_facts.packages' 
1310 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1309 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1310 ······-·'"audit"·in·ansible_facts.packages'
1311 ······tags:1311 ······tags:
1312 ······-·CCE-85831-61312 ······-·CCE-85831-6
1313 ······-·CJIS-5.4.1.11313 ······-·CJIS-5.4.1.1
1314 ······-·NIST-800-171-3.3.11314 ······-·NIST-800-171-3.3.1
1315 ······-·NIST-800-171-3.4.31315 ······-·NIST-800-171-3.4.3
1316 ······-·NIST-800-53-AC-6(9)1316 ······-·NIST-800-53-AC-6(9)
1317 ······-·NIST-800-53-CM-6(a)1317 ······-·NIST-800-53-CM-6(a)
Offset 1328, 16 lines modifiedOffset 1328, 16 lines modified
1328 ······lineinfile:1328 ······lineinfile:
1329 ········path:·'{{·item·}}'1329 ········path:·'{{·item·}}'
1330 ········regexp:·^\s*(?:-e)\s+.*$1330 ········regexp:·^\s*(?:-e)\s+.*$
1331 ········state:·absent1331 ········state:·absent
1332 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']1332 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
1333 ········}}'1333 ········}}'
1334 ······when:1334 ······when:
1335 ······-·'"audit"·in·ansible_facts.packages' 
1336 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1335 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1336 ······-·'"audit"·in·ansible_facts.packages'
1337 ······tags:1337 ······tags:
1338 ······-·CCE-85831-61338 ······-·CCE-85831-6
1339 ······-·CJIS-5.4.1.11339 ······-·CJIS-5.4.1.1
1340 ······-·NIST-800-171-3.3.11340 ······-·NIST-800-171-3.3.1
1341 ······-·NIST-800-171-3.4.31341 ······-·NIST-800-171-3.4.3
1342 ······-·NIST-800-53-AC-6(9)1342 ······-·NIST-800-53-AC-6(9)
1343 ······-·NIST-800-53-CM-6(a)1343 ······-·NIST-800-53-CM-6(a)
Offset 1355, 16 lines modifiedOffset 1355, 16 lines modified
1355 ········create:·true1355 ········create:·true
1356 ········line:·-e·21356 ········line:·-e·2
1357 ········mode:·o-rwx1357 ········mode:·o-rwx
1358 ······loop:1358 ······loop:
1359 ······-·/etc/audit/audit.rules1359 ······-·/etc/audit/audit.rules
1360 ······-·/etc/audit/rules.d/immutable.rules1360 ······-·/etc/audit/rules.d/immutable.rules
1361 ······when:1361 ······when:
1362 ······-·'"audit"·in·ansible_facts.packages' 
1363 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1362 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1363 ······-·'"audit"·in·ansible_facts.packages'
1364 ······tags:1364 ······tags:
1365 ······-·CCE-85831-61365 ······-·CCE-85831-6
1366 ······-·CJIS-5.4.1.11366 ······-·CJIS-5.4.1.1
1367 ······-·NIST-800-171-3.3.11367 ······-·NIST-800-171-3.3.1
1368 ······-·NIST-800-171-3.4.31368 ······-·NIST-800-171-3.4.3
1369 ······-·NIST-800-53-AC-6(9)1369 ······-·NIST-800-53-AC-6(9)
1370 ······-·NIST-800-53-CM-6(a)1370 ······-·NIST-800-53-CM-6(a)
Offset 1398, 16 lines modifiedOffset 1398, 16 lines modified
1398 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/1398 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
1399 ······find:1399 ······find:
1400 ········paths:·/etc/audit/rules.d1400 ········paths:·/etc/audit/rules.d
1401 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+1401 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
1402 ········patterns:·'*.rules'1402 ········patterns:·'*.rules'
1403 ······register:·find_existing_watch_rules_d1403 ······register:·find_existing_watch_rules_d
1404 ······when:1404 ······when:
1405 ······-·'"audit"·in·ansible_facts.packages' 
1406 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1405 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1406 ······-·'"audit"·in·ansible_facts.packages'
1407 ······tags:1407 ······tags:
1408 ······-·CCE-85830-81408 ······-·CCE-85830-8
1409 ······-·CJIS-5.4.1.11409 ······-·CJIS-5.4.1.1
1410 ······-·NIST-800-171-3.1.81410 ······-·NIST-800-171-3.1.8
1411 ······-·NIST-800-53-AU-12(c)1411 ······-·NIST-800-53-AU-12(c)
1412 ······-·NIST-800-53-AU-2(d)1412 ······-·NIST-800-53-AU-2(d)
1413 ······-·NIST-800-53-CM-6(a)1413 ······-·NIST-800-53-CM-6(a)
Offset 1422, 16 lines modifiedOffset 1422, 16 lines modified
1422 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy1422 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
1423 ······find:1423 ······find:
1424 ········paths:·/etc/audit/rules.d1424 ········paths:·/etc/audit/rules.d
1425 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$1425 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
1426 ········patterns:·'*.rules'1426 ········patterns:·'*.rules'
1427 ······register:·find_watch_key1427 ······register:·find_watch_key
1428 ······when:1428 ······when:
1429 ······-·'"audit"·in·ansible_facts.packages' 
1430 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1429 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1430 ······-·'"audit"·in·ansible_facts.packages'
1431 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched1431 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
1432 ········==·01432 ········==·0
1433 ······tags:1433 ······tags:
1434 ······-·CCE-85830-81434 ······-·CCE-85830-8
1435 ······-·CJIS-5.4.1.11435 ······-·CJIS-5.4.1.1
1436 ······-·NIST-800-171-3.1.81436 ······-·NIST-800-171-3.1.8
1437 ······-·NIST-800-53-AU-12(c)1437 ······-·NIST-800-53-AU-12(c)
Offset 1446, 16 lines modifiedOffset 1446, 16 lines modified
1446 ······-·restrict_strategy1446 ······-·restrict_strategy
  
1447 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule1447 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
1448 ······set_fact:1448 ······set_fact:
1449 ········all_files:1449 ········all_files:
1450 ········-·/etc/audit/rules.d/MAC-policy.rules1450 ········-·/etc/audit/rules.d/MAC-policy.rules
1451 ······when:1451 ······when:
1452 ······-·'"audit"·in·ansible_facts.packages' 
1453 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1452 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1453 ······-·'"audit"·in·ansible_facts.packages'
1454 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched1454 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
1455 ········is·defined·and·find_existing_watch_rules_d.matched·==·01455 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1456 ······tags:1456 ······tags:
1457 ······-·CCE-85830-81457 ······-·CCE-85830-8
1458 ······-·CJIS-5.4.1.11458 ······-·CJIS-5.4.1.1
1459 ······-·NIST-800-171-3.1.81459 ······-·NIST-800-171-3.1.8
1460 ······-·NIST-800-53-AU-12(c)1460 ······-·NIST-800-53-AU-12(c)
Offset 1470, 16 lines modifiedOffset 1470, 16 lines modified
1470 ······-·restrict_strategy1470 ······-·restrict_strategy
  
1471 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule1471 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
1472 ······set_fact:1472 ······set_fact:
1473 ········all_files:1473 ········all_files:
1474 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'1474 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
1475 ······when:1475 ······when:
1476 ······-·'"audit"·in·ansible_facts.packages' 
1477 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]1476 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 1477 ······-·'"audit"·in·ansible_facts.packages'
1478 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched1478 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
1479 ········is·defined·and·find_existing_watch_rules_d.matched·==·01479 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
1480 ······tags:1480 ······tags:
1481 ······-·CCE-85830-81481 ······-·CCE-85830-8
1482 ······-·CJIS-5.4.1.11482 ······-·CJIS-5.4.1.1
1483 ······-·NIST-800-171-3.1.81483 ······-·NIST-800-171-3.1.8
1484 ······-·NIST-800-53-AU-12(c)1484 ······-·NIST-800-53-AU-12(c)
Offset 1496, 16 lines modifiedOffset 1496, 16 lines modified
1496 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/1496 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 176164/180797 bytes (97.44%) of diff not shown.
184 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-pci-dss-4.yml
Ordering differences only
    
Offset 6869, 16 lines modifiedOffset 6869, 16 lines modified
  
6869 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension6869 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
6870 ······find:6870 ······find:
6871 ········paths:·/etc/audit/rules.d/6871 ········paths:·/etc/audit/rules.d/
6872 ········patterns:·'*.rules'6872 ········patterns:·'*.rules'
6873 ······register:·find_rules_d6873 ······register:·find_rules_d
6874 ······when:6874 ······when:
6875 ······-·'"audit"·in·ansible_facts.packages' 
6876 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6875 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6876 ······-·'"audit"·in·ansible_facts.packages'
6877 ······tags:6877 ······tags:
6878 ······-·CCE-85831-66878 ······-·CCE-85831-6
6879 ······-·CJIS-5.4.1.16879 ······-·CJIS-5.4.1.1
6880 ······-·NIST-800-171-3.3.16880 ······-·NIST-800-171-3.3.1
6881 ······-·NIST-800-171-3.4.36881 ······-·NIST-800-171-3.4.3
6882 ······-·NIST-800-53-AC-6(9)6882 ······-·NIST-800-53-AC-6(9)
6883 ······-·NIST-800-53-CM-6(a)6883 ······-·NIST-800-53-CM-6(a)
Offset 6894, 16 lines modifiedOffset 6894, 16 lines modified
6894 ······lineinfile:6894 ······lineinfile:
6895 ········path:·'{{·item·}}'6895 ········path:·'{{·item·}}'
6896 ········regexp:·^\s*(?:-e)\s+.*$6896 ········regexp:·^\s*(?:-e)\s+.*$
6897 ········state:·absent6897 ········state:·absent
6898 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']6898 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
6899 ········}}'6899 ········}}'
6900 ······when:6900 ······when:
6901 ······-·'"audit"·in·ansible_facts.packages' 
6902 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6901 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6902 ······-·'"audit"·in·ansible_facts.packages'
6903 ······tags:6903 ······tags:
6904 ······-·CCE-85831-66904 ······-·CCE-85831-6
6905 ······-·CJIS-5.4.1.16905 ······-·CJIS-5.4.1.1
6906 ······-·NIST-800-171-3.3.16906 ······-·NIST-800-171-3.3.1
6907 ······-·NIST-800-171-3.4.36907 ······-·NIST-800-171-3.4.3
6908 ······-·NIST-800-53-AC-6(9)6908 ······-·NIST-800-53-AC-6(9)
6909 ······-·NIST-800-53-CM-6(a)6909 ······-·NIST-800-53-CM-6(a)
Offset 6921, 16 lines modifiedOffset 6921, 16 lines modified
6921 ········create:·true6921 ········create:·true
6922 ········line:·-e·26922 ········line:·-e·2
6923 ········mode:·o-rwx6923 ········mode:·o-rwx
6924 ······loop:6924 ······loop:
6925 ······-·/etc/audit/audit.rules6925 ······-·/etc/audit/audit.rules
6926 ······-·/etc/audit/rules.d/immutable.rules6926 ······-·/etc/audit/rules.d/immutable.rules
6927 ······when:6927 ······when:
6928 ······-·'"audit"·in·ansible_facts.packages' 
6929 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6928 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6929 ······-·'"audit"·in·ansible_facts.packages'
6930 ······tags:6930 ······tags:
6931 ······-·CCE-85831-66931 ······-·CCE-85831-6
6932 ······-·CJIS-5.4.1.16932 ······-·CJIS-5.4.1.1
6933 ······-·NIST-800-171-3.3.16933 ······-·NIST-800-171-3.3.1
6934 ······-·NIST-800-171-3.4.36934 ······-·NIST-800-171-3.4.3
6935 ······-·NIST-800-53-AC-6(9)6935 ······-·NIST-800-53-AC-6(9)
6936 ······-·NIST-800-53-CM-6(a)6936 ······-·NIST-800-53-CM-6(a)
Offset 6964, 16 lines modifiedOffset 6964, 16 lines modified
6964 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/6964 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
6965 ······find:6965 ······find:
6966 ········paths:·/etc/audit/rules.d6966 ········paths:·/etc/audit/rules.d
6967 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+6967 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
6968 ········patterns:·'*.rules'6968 ········patterns:·'*.rules'
6969 ······register:·find_existing_watch_rules_d6969 ······register:·find_existing_watch_rules_d
6970 ······when:6970 ······when:
6971 ······-·'"audit"·in·ansible_facts.packages' 
6972 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6971 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6972 ······-·'"audit"·in·ansible_facts.packages'
6973 ······tags:6973 ······tags:
6974 ······-·CCE-85830-86974 ······-·CCE-85830-8
6975 ······-·CJIS-5.4.1.16975 ······-·CJIS-5.4.1.1
6976 ······-·NIST-800-171-3.1.86976 ······-·NIST-800-171-3.1.8
6977 ······-·NIST-800-53-AU-12(c)6977 ······-·NIST-800-53-AU-12(c)
6978 ······-·NIST-800-53-AU-2(d)6978 ······-·NIST-800-53-AU-2(d)
6979 ······-·NIST-800-53-CM-6(a)6979 ······-·NIST-800-53-CM-6(a)
Offset 6988, 16 lines modifiedOffset 6988, 16 lines modified
6988 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy6988 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
6989 ······find:6989 ······find:
6990 ········paths:·/etc/audit/rules.d6990 ········paths:·/etc/audit/rules.d
6991 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$6991 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
6992 ········patterns:·'*.rules'6992 ········patterns:·'*.rules'
6993 ······register:·find_watch_key6993 ······register:·find_watch_key
6994 ······when:6994 ······when:
6995 ······-·'"audit"·in·ansible_facts.packages' 
6996 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6995 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6996 ······-·'"audit"·in·ansible_facts.packages'
6997 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched6997 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
6998 ········==·06998 ········==·0
6999 ······tags:6999 ······tags:
7000 ······-·CCE-85830-87000 ······-·CCE-85830-8
7001 ······-·CJIS-5.4.1.17001 ······-·CJIS-5.4.1.1
7002 ······-·NIST-800-171-3.1.87002 ······-·NIST-800-171-3.1.8
7003 ······-·NIST-800-53-AU-12(c)7003 ······-·NIST-800-53-AU-12(c)
Offset 7012, 16 lines modifiedOffset 7012, 16 lines modified
7012 ······-·restrict_strategy7012 ······-·restrict_strategy
  
7013 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule7013 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
7014 ······set_fact:7014 ······set_fact:
7015 ········all_files:7015 ········all_files:
7016 ········-·/etc/audit/rules.d/MAC-policy.rules7016 ········-·/etc/audit/rules.d/MAC-policy.rules
7017 ······when:7017 ······when:
7018 ······-·'"audit"·in·ansible_facts.packages' 
7019 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7018 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7019 ······-·'"audit"·in·ansible_facts.packages'
7020 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched7020 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
7021 ········is·defined·and·find_existing_watch_rules_d.matched·==·07021 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
7022 ······tags:7022 ······tags:
7023 ······-·CCE-85830-87023 ······-·CCE-85830-8
7024 ······-·CJIS-5.4.1.17024 ······-·CJIS-5.4.1.1
7025 ······-·NIST-800-171-3.1.87025 ······-·NIST-800-171-3.1.8
7026 ······-·NIST-800-53-AU-12(c)7026 ······-·NIST-800-53-AU-12(c)
Offset 7036, 16 lines modifiedOffset 7036, 16 lines modified
7036 ······-·restrict_strategy7036 ······-·restrict_strategy
  
7037 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule7037 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
7038 ······set_fact:7038 ······set_fact:
7039 ········all_files:7039 ········all_files:
7040 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'7040 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
7041 ······when:7041 ······when:
7042 ······-·'"audit"·in·ansible_facts.packages' 
7043 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]7042 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 7043 ······-·'"audit"·in·ansible_facts.packages'
7044 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched7044 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
7045 ········is·defined·and·find_existing_watch_rules_d.matched·==·07045 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
7046 ······tags:7046 ······tags:
7047 ······-·CCE-85830-87047 ······-·CCE-85830-8
7048 ······-·CJIS-5.4.1.17048 ······-·CJIS-5.4.1.1
7049 ······-·NIST-800-171-3.1.87049 ······-·NIST-800-171-3.1.8
7050 ······-·NIST-800-53-AU-12(c)7050 ······-·NIST-800-53-AU-12(c)
Offset 7062, 16 lines modifiedOffset 7062, 16 lines modified
7062 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/7062 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 183949/188582 bytes (97.54%) of diff not shown.
184 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-pci-dss.yml
Ordering differences only
    
Offset 5485, 16 lines modifiedOffset 5485, 16 lines modified
  
5485 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension5485 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
5486 ······find:5486 ······find:
5487 ········paths:·/etc/audit/rules.d/5487 ········paths:·/etc/audit/rules.d/
5488 ········patterns:·'*.rules'5488 ········patterns:·'*.rules'
5489 ······register:·find_rules_d5489 ······register:·find_rules_d
5490 ······when:5490 ······when:
5491 ······-·'"audit"·in·ansible_facts.packages' 
5492 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5491 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5492 ······-·'"audit"·in·ansible_facts.packages'
5493 ······tags:5493 ······tags:
5494 ······-·CCE-85831-65494 ······-·CCE-85831-6
5495 ······-·CJIS-5.4.1.15495 ······-·CJIS-5.4.1.1
5496 ······-·NIST-800-171-3.3.15496 ······-·NIST-800-171-3.3.1
5497 ······-·NIST-800-171-3.4.35497 ······-·NIST-800-171-3.4.3
5498 ······-·NIST-800-53-AC-6(9)5498 ······-·NIST-800-53-AC-6(9)
5499 ······-·NIST-800-53-CM-6(a)5499 ······-·NIST-800-53-CM-6(a)
Offset 5510, 16 lines modifiedOffset 5510, 16 lines modified
5510 ······lineinfile:5510 ······lineinfile:
5511 ········path:·'{{·item·}}'5511 ········path:·'{{·item·}}'
5512 ········regexp:·^\s*(?:-e)\s+.*$5512 ········regexp:·^\s*(?:-e)\s+.*$
5513 ········state:·absent5513 ········state:·absent
5514 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']5514 ······loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
5515 ········}}'5515 ········}}'
5516 ······when:5516 ······when:
5517 ······-·'"audit"·in·ansible_facts.packages' 
5518 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5517 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5518 ······-·'"audit"·in·ansible_facts.packages'
5519 ······tags:5519 ······tags:
5520 ······-·CCE-85831-65520 ······-·CCE-85831-6
5521 ······-·CJIS-5.4.1.15521 ······-·CJIS-5.4.1.1
5522 ······-·NIST-800-171-3.3.15522 ······-·NIST-800-171-3.3.1
5523 ······-·NIST-800-171-3.4.35523 ······-·NIST-800-171-3.4.3
5524 ······-·NIST-800-53-AC-6(9)5524 ······-·NIST-800-53-AC-6(9)
5525 ······-·NIST-800-53-CM-6(a)5525 ······-·NIST-800-53-CM-6(a)
Offset 5537, 16 lines modifiedOffset 5537, 16 lines modified
5537 ········create:·true5537 ········create:·true
5538 ········line:·-e·25538 ········line:·-e·2
5539 ········mode:·o-rwx5539 ········mode:·o-rwx
5540 ······loop:5540 ······loop:
5541 ······-·/etc/audit/audit.rules5541 ······-·/etc/audit/audit.rules
5542 ······-·/etc/audit/rules.d/immutable.rules5542 ······-·/etc/audit/rules.d/immutable.rules
5543 ······when:5543 ······when:
5544 ······-·'"audit"·in·ansible_facts.packages' 
5545 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5544 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5545 ······-·'"audit"·in·ansible_facts.packages'
5546 ······tags:5546 ······tags:
5547 ······-·CCE-85831-65547 ······-·CCE-85831-6
5548 ······-·CJIS-5.4.1.15548 ······-·CJIS-5.4.1.1
5549 ······-·NIST-800-171-3.3.15549 ······-·NIST-800-171-3.3.1
5550 ······-·NIST-800-171-3.4.35550 ······-·NIST-800-171-3.4.3
5551 ······-·NIST-800-53-AC-6(9)5551 ······-·NIST-800-53-AC-6(9)
5552 ······-·NIST-800-53-CM-6(a)5552 ······-·NIST-800-53-CM-6(a)
Offset 5580, 16 lines modifiedOffset 5580, 16 lines modified
5580 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/5580 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
5581 ······find:5581 ······find:
5582 ········paths:·/etc/audit/rules.d5582 ········paths:·/etc/audit/rules.d
5583 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+5583 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
5584 ········patterns:·'*.rules'5584 ········patterns:·'*.rules'
5585 ······register:·find_existing_watch_rules_d5585 ······register:·find_existing_watch_rules_d
5586 ······when:5586 ······when:
5587 ······-·'"audit"·in·ansible_facts.packages' 
5588 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5587 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5588 ······-·'"audit"·in·ansible_facts.packages'
5589 ······tags:5589 ······tags:
5590 ······-·CCE-85830-85590 ······-·CCE-85830-8
5591 ······-·CJIS-5.4.1.15591 ······-·CJIS-5.4.1.1
5592 ······-·NIST-800-171-3.1.85592 ······-·NIST-800-171-3.1.8
5593 ······-·NIST-800-53-AU-12(c)5593 ······-·NIST-800-53-AU-12(c)
5594 ······-·NIST-800-53-AU-2(d)5594 ······-·NIST-800-53-AU-2(d)
5595 ······-·NIST-800-53-CM-6(a)5595 ······-·NIST-800-53-CM-6(a)
Offset 5604, 16 lines modifiedOffset 5604, 16 lines modified
5604 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy5604 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
5605 ······find:5605 ······find:
5606 ········paths:·/etc/audit/rules.d5606 ········paths:·/etc/audit/rules.d
5607 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$5607 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
5608 ········patterns:·'*.rules'5608 ········patterns:·'*.rules'
5609 ······register:·find_watch_key5609 ······register:·find_watch_key
5610 ······when:5610 ······when:
5611 ······-·'"audit"·in·ansible_facts.packages' 
5612 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5611 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5612 ······-·'"audit"·in·ansible_facts.packages'
5613 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched5613 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
5614 ········==·05614 ········==·0
5615 ······tags:5615 ······tags:
5616 ······-·CCE-85830-85616 ······-·CCE-85830-8
5617 ······-·CJIS-5.4.1.15617 ······-·CJIS-5.4.1.1
5618 ······-·NIST-800-171-3.1.85618 ······-·NIST-800-171-3.1.8
5619 ······-·NIST-800-53-AU-12(c)5619 ······-·NIST-800-53-AU-12(c)
Offset 5628, 16 lines modifiedOffset 5628, 16 lines modified
5628 ······-·restrict_strategy5628 ······-·restrict_strategy
  
5629 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule5629 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
5630 ······set_fact:5630 ······set_fact:
5631 ········all_files:5631 ········all_files:
5632 ········-·/etc/audit/rules.d/MAC-policy.rules5632 ········-·/etc/audit/rules.d/MAC-policy.rules
5633 ······when:5633 ······when:
5634 ······-·'"audit"·in·ansible_facts.packages' 
5635 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5634 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5635 ······-·'"audit"·in·ansible_facts.packages'
5636 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched5636 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
5637 ········is·defined·and·find_existing_watch_rules_d.matched·==·05637 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5638 ······tags:5638 ······tags:
5639 ······-·CCE-85830-85639 ······-·CCE-85830-8
5640 ······-·CJIS-5.4.1.15640 ······-·CJIS-5.4.1.1
5641 ······-·NIST-800-171-3.1.85641 ······-·NIST-800-171-3.1.8
5642 ······-·NIST-800-53-AU-12(c)5642 ······-·NIST-800-53-AU-12(c)
Offset 5652, 16 lines modifiedOffset 5652, 16 lines modified
5652 ······-·restrict_strategy5652 ······-·restrict_strategy
  
5653 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule5653 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
5654 ······set_fact:5654 ······set_fact:
5655 ········all_files:5655 ········all_files:
5656 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'5656 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
5657 ······when:5657 ······when:
5658 ······-·'"audit"·in·ansible_facts.packages' 
5659 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]5658 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 5659 ······-·'"audit"·in·ansible_facts.packages'
5660 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched5660 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
5661 ········is·defined·and·find_existing_watch_rules_d.matched·==·05661 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
5662 ······tags:5662 ······tags:
5663 ······-·CCE-85830-85663 ······-·CCE-85830-8
5664 ······-·CJIS-5.4.1.15664 ······-·CJIS-5.4.1.1
5665 ······-·NIST-800-171-3.1.85665 ······-·NIST-800-171-3.1.8
5666 ······-·NIST-800-53-AU-12(c)5666 ······-·NIST-800-53-AU-12(c)
Offset 5678, 16 lines modifiedOffset 5678, 16 lines modified
5678 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/5678 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
Max diff block lines reached; 183897/188530 bytes (97.54%) of diff not shown.
238 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-pcs-hardening-sap.yml
Ordering differences only
    
Offset 3666, 16 lines modifiedOffset 3666, 16 lines modified
3666 ······-·medium_severity3666 ······-·medium_severity
3667 ······-·no_reboot_needed3667 ······-·no_reboot_needed
3668 ······-·restrict_strategy3668 ······-·restrict_strategy
  
3669 ····-·name:·Service·facts3669 ····-·name:·Service·facts
3670 ······service_facts:·null3670 ······service_facts:·null
3671 ······when:3671 ······when:
3672 ······-·'"audit"·in·ansible_facts.packages' 
3673 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3672 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3673 ······-·'"audit"·in·ansible_facts.packages'
3674 ······tags:3674 ······tags:
3675 ······-·CCE-85706-03675 ······-·CCE-85706-0
3676 ······-·DISA-STIG-SLES-15-0308203676 ······-·DISA-STIG-SLES-15-030820
3677 ······-·NIST-800-53-CM-6(b)3677 ······-·NIST-800-53-CM-6(b)
3678 ······-·NIST-800-53-CM-6.1(iv)3678 ······-·NIST-800-53-CM-6.1(iv)
3679 ······-·audit_rules_enable_syscall_auditing3679 ······-·audit_rules_enable_syscall_auditing
3680 ······-·low_complexity3680 ······-·low_complexity
Offset 3684, 16 lines modifiedOffset 3684, 16 lines modified
3684 ······-·no_reboot_needed3684 ······-·no_reboot_needed
3685 ······-·restrict_strategy3685 ······-·restrict_strategy
  
3686 ····-·name:·Check·the·rules·script·being·used3686 ····-·name:·Check·the·rules·script·being·used
3687 ······command:·grep·-E·'^(ExecStartPost|Requires)'·/usr/lib/systemd/system/auditd.service3687 ······command:·grep·-E·'^(ExecStartPost|Requires)'·/usr/lib/systemd/system/auditd.service
3688 ······register:·check_rules_scripts_result3688 ······register:·check_rules_scripts_result
3689 ······when:3689 ······when:
3690 ······-·'"audit"·in·ansible_facts.packages' 
3691 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3690 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3691 ······-·'"audit"·in·ansible_facts.packages'
3692 ······tags:3692 ······tags:
3693 ······-·CCE-85706-03693 ······-·CCE-85706-0
3694 ······-·DISA-STIG-SLES-15-0308203694 ······-·DISA-STIG-SLES-15-030820
3695 ······-·NIST-800-53-CM-6(b)3695 ······-·NIST-800-53-CM-6(b)
3696 ······-·NIST-800-53-CM-6.1(iv)3696 ······-·NIST-800-53-CM-6.1(iv)
3697 ······-·audit_rules_enable_syscall_auditing3697 ······-·audit_rules_enable_syscall_auditing
3698 ······-·low_complexity3698 ······-·low_complexity
Offset 3705, 16 lines modifiedOffset 3705, 16 lines modified
3705 ····-·name:·Find·audit·rules·in·/etc/audit/rules.d3705 ····-·name:·Find·audit·rules·in·/etc/audit/rules.d
3706 ······find:3706 ······find:
3707 ········paths:·/etc/audit/rules.d3707 ········paths:·/etc/audit/rules.d
3708 ········file_type:·file3708 ········file_type:·file
3709 ········follow:·true3709 ········follow:·true
3710 ······register:·find_audit_rules_result3710 ······register:·find_audit_rules_result
3711 ······when:3711 ······when:
3712 ······-·'"audit"·in·ansible_facts.packages' 
3713 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3712 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3713 ······-·'"audit"·in·ansible_facts.packages'
3714 ······-·'"auditd.service"·in·ansible_facts.services'3714 ······-·'"auditd.service"·in·ansible_facts.services'
3715 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'3715 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
3716 ······tags:3716 ······tags:
3717 ······-·CCE-85706-03717 ······-·CCE-85706-0
3718 ······-·DISA-STIG-SLES-15-0308203718 ······-·DISA-STIG-SLES-15-030820
3719 ······-·NIST-800-53-CM-6(b)3719 ······-·NIST-800-53-CM-6(b)
3720 ······-·NIST-800-53-CM-6.1(iv)3720 ······-·NIST-800-53-CM-6.1(iv)
Offset 3728, 16 lines modifiedOffset 3728, 16 lines modified
3728 ····-·name:·Enable·syscall·auditing·(augenrules)3728 ····-·name:·Enable·syscall·auditing·(augenrules)
3729 ······lineinfile:3729 ······lineinfile:
3730 ········path:·'{{·item.path·}}'3730 ········path:·'{{·item.path·}}'
3731 ········regex:·^(?i)(\s*-a\s+task,never)\s*$3731 ········regex:·^(?i)(\s*-a\s+task,never)\s*$
3732 ········line:·'#-a·task,never'3732 ········line:·'#-a·task,never'
3733 ······with_items:·'{{·find_audit_rules_result.files·}}'3733 ······with_items:·'{{·find_audit_rules_result.files·}}'
3734 ······when:3734 ······when:
3735 ······-·'"audit"·in·ansible_facts.packages' 
3736 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3735 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3736 ······-·'"audit"·in·ansible_facts.packages'
3737 ······-·'"auditd.service"·in·ansible_facts.services'3737 ······-·'"auditd.service"·in·ansible_facts.services'
3738 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'3738 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
3739 ······register:·augenrules_syscall_auditing_rule_update_result3739 ······register:·augenrules_syscall_auditing_rule_update_result
3740 ······tags:3740 ······tags:
3741 ······-·CCE-85706-03741 ······-·CCE-85706-0
3742 ······-·DISA-STIG-SLES-15-0308203742 ······-·DISA-STIG-SLES-15-030820
3743 ······-·NIST-800-53-CM-6(b)3743 ······-·NIST-800-53-CM-6(b)
Offset 3751, 16 lines modifiedOffset 3751, 16 lines modified
  
3751 ····-·name:·Enable·syscall·auditing·(auditctl)3751 ····-·name:·Enable·syscall·auditing·(auditctl)
3752 ······lineinfile:3752 ······lineinfile:
3753 ········path:·/etc/audit/audit.rules3753 ········path:·/etc/audit/audit.rules
3754 ········regex:·^(?i)(\s*-a\s+task,never)\s*$3754 ········regex:·^(?i)(\s*-a\s+task,never)\s*$
3755 ········line:·'#-a·task,never'3755 ········line:·'#-a·task,never'
3756 ······when:3756 ······when:
3757 ······-·'"audit"·in·ansible_facts.packages' 
3758 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3757 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3758 ······-·'"audit"·in·ansible_facts.packages'
3759 ······-·'"auditd.service"·in·ansible_facts.services'3759 ······-·'"auditd.service"·in·ansible_facts.services'
3760 ······-·'"auditctl"·in·check_rules_scripts_result.stdout'3760 ······-·'"auditctl"·in·check_rules_scripts_result.stdout'
3761 ······register:·auditctl_syscall_auditing_rule_update_result3761 ······register:·auditctl_syscall_auditing_rule_update_result
3762 ······tags:3762 ······tags:
3763 ······-·CCE-85706-03763 ······-·CCE-85706-0
3764 ······-·DISA-STIG-SLES-15-0308203764 ······-·DISA-STIG-SLES-15-030820
3765 ······-·NIST-800-53-CM-6(b)3765 ······-·NIST-800-53-CM-6(b)
Offset 3773, 16 lines modifiedOffset 3773, 16 lines modified
3773 ······-·restrict_strategy3773 ······-·restrict_strategy
  
3774 ····-·name:·Restart·auditd.service3774 ····-·name:·Restart·auditd.service
3775 ······systemd:3775 ······systemd:
3776 ········name:·auditd.service3776 ········name:·auditd.service
3777 ········state:·restarted3777 ········state:·restarted
3778 ······when:3778 ······when:
3779 ······-·'"audit"·in·ansible_facts.packages' 
3780 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3779 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3780 ······-·'"audit"·in·ansible_facts.packages'
3781 ······-·ansible_facts.services["auditd.service"].state·==·"running"3781 ······-·ansible_facts.services["auditd.service"].state·==·"running"
3782 ······-·(augenrules_syscall_auditing_rule_update_result.changed·or·auditctl_syscall_auditing_rule_update_result.changed)3782 ······-·(augenrules_syscall_auditing_rule_update_result.changed·or·auditctl_syscall_auditing_rule_update_result.changed)
3783 ······tags:3783 ······tags:
3784 ······-·CCE-85706-03784 ······-·CCE-85706-0
3785 ······-·DISA-STIG-SLES-15-0308203785 ······-·DISA-STIG-SLES-15-030820
3786 ······-·NIST-800-53-CM-6(b)3786 ······-·NIST-800-53-CM-6(b)
3787 ······-·NIST-800-53-CM-6.1(iv)3787 ······-·NIST-800-53-CM-6.1(iv)
Offset 3814, 16 lines modifiedOffset 3814, 16 lines modified
  
3814 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension3814 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
3815 ······find:3815 ······find:
3816 ········paths:·/etc/audit/rules.d/3816 ········paths:·/etc/audit/rules.d/
3817 ········patterns:·'*.rules'3817 ········patterns:·'*.rules'
3818 ······register:·find_rules_d3818 ······register:·find_rules_d
3819 ······when:3819 ······when:
3820 ······-·'"audit"·in·ansible_facts.packages' 
3821 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3820 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3821 ······-·'"audit"·in·ansible_facts.packages'
3822 ······tags:3822 ······tags:
3823 ······-·CCE-85831-63823 ······-·CCE-85831-6
3824 ······-·CJIS-5.4.1.13824 ······-·CJIS-5.4.1.1
3825 ······-·NIST-800-171-3.3.13825 ······-·NIST-800-171-3.3.1
3826 ······-·NIST-800-171-3.4.33826 ······-·NIST-800-171-3.4.3
3827 ······-·NIST-800-53-AC-6(9)3827 ······-·NIST-800-53-AC-6(9)
3828 ······-·NIST-800-53-CM-6(a)3828 ······-·NIST-800-53-CM-6(a)
Offset 3839, 16 lines modifiedOffset 3839, 16 lines modified
3839 ······lineinfile:3839 ······lineinfile:
Max diff block lines reached; 238652/243260 bytes (98.11%) of diff not shown.
238 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-pcs-hardening.yml
Ordering differences only
    
Offset 3703, 16 lines modifiedOffset 3703, 16 lines modified
3703 ······-·medium_severity3703 ······-·medium_severity
3704 ······-·no_reboot_needed3704 ······-·no_reboot_needed
3705 ······-·restrict_strategy3705 ······-·restrict_strategy
  
3706 ····-·name:·Service·facts3706 ····-·name:·Service·facts
3707 ······service_facts:·null3707 ······service_facts:·null
3708 ······when:3708 ······when:
3709 ······-·'"audit"·in·ansible_facts.packages' 
3710 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3709 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3710 ······-·'"audit"·in·ansible_facts.packages'
3711 ······tags:3711 ······tags:
3712 ······-·CCE-85706-03712 ······-·CCE-85706-0
3713 ······-·DISA-STIG-SLES-15-0308203713 ······-·DISA-STIG-SLES-15-030820
3714 ······-·NIST-800-53-CM-6(b)3714 ······-·NIST-800-53-CM-6(b)
3715 ······-·NIST-800-53-CM-6.1(iv)3715 ······-·NIST-800-53-CM-6.1(iv)
3716 ······-·audit_rules_enable_syscall_auditing3716 ······-·audit_rules_enable_syscall_auditing
3717 ······-·low_complexity3717 ······-·low_complexity
Offset 3721, 16 lines modifiedOffset 3721, 16 lines modified
3721 ······-·no_reboot_needed3721 ······-·no_reboot_needed
3722 ······-·restrict_strategy3722 ······-·restrict_strategy
  
3723 ····-·name:·Check·the·rules·script·being·used3723 ····-·name:·Check·the·rules·script·being·used
3724 ······command:·grep·-E·'^(ExecStartPost|Requires)'·/usr/lib/systemd/system/auditd.service3724 ······command:·grep·-E·'^(ExecStartPost|Requires)'·/usr/lib/systemd/system/auditd.service
3725 ······register:·check_rules_scripts_result3725 ······register:·check_rules_scripts_result
3726 ······when:3726 ······when:
3727 ······-·'"audit"·in·ansible_facts.packages' 
3728 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3727 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3728 ······-·'"audit"·in·ansible_facts.packages'
3729 ······tags:3729 ······tags:
3730 ······-·CCE-85706-03730 ······-·CCE-85706-0
3731 ······-·DISA-STIG-SLES-15-0308203731 ······-·DISA-STIG-SLES-15-030820
3732 ······-·NIST-800-53-CM-6(b)3732 ······-·NIST-800-53-CM-6(b)
3733 ······-·NIST-800-53-CM-6.1(iv)3733 ······-·NIST-800-53-CM-6.1(iv)
3734 ······-·audit_rules_enable_syscall_auditing3734 ······-·audit_rules_enable_syscall_auditing
3735 ······-·low_complexity3735 ······-·low_complexity
Offset 3742, 16 lines modifiedOffset 3742, 16 lines modified
3742 ····-·name:·Find·audit·rules·in·/etc/audit/rules.d3742 ····-·name:·Find·audit·rules·in·/etc/audit/rules.d
3743 ······find:3743 ······find:
3744 ········paths:·/etc/audit/rules.d3744 ········paths:·/etc/audit/rules.d
3745 ········file_type:·file3745 ········file_type:·file
3746 ········follow:·true3746 ········follow:·true
3747 ······register:·find_audit_rules_result3747 ······register:·find_audit_rules_result
3748 ······when:3748 ······when:
3749 ······-·'"audit"·in·ansible_facts.packages' 
3750 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3749 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3750 ······-·'"audit"·in·ansible_facts.packages'
3751 ······-·'"auditd.service"·in·ansible_facts.services'3751 ······-·'"auditd.service"·in·ansible_facts.services'
3752 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'3752 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
3753 ······tags:3753 ······tags:
3754 ······-·CCE-85706-03754 ······-·CCE-85706-0
3755 ······-·DISA-STIG-SLES-15-0308203755 ······-·DISA-STIG-SLES-15-030820
3756 ······-·NIST-800-53-CM-6(b)3756 ······-·NIST-800-53-CM-6(b)
3757 ······-·NIST-800-53-CM-6.1(iv)3757 ······-·NIST-800-53-CM-6.1(iv)
Offset 3765, 16 lines modifiedOffset 3765, 16 lines modified
3765 ····-·name:·Enable·syscall·auditing·(augenrules)3765 ····-·name:·Enable·syscall·auditing·(augenrules)
3766 ······lineinfile:3766 ······lineinfile:
3767 ········path:·'{{·item.path·}}'3767 ········path:·'{{·item.path·}}'
3768 ········regex:·^(?i)(\s*-a\s+task,never)\s*$3768 ········regex:·^(?i)(\s*-a\s+task,never)\s*$
3769 ········line:·'#-a·task,never'3769 ········line:·'#-a·task,never'
3770 ······with_items:·'{{·find_audit_rules_result.files·}}'3770 ······with_items:·'{{·find_audit_rules_result.files·}}'
3771 ······when:3771 ······when:
3772 ······-·'"audit"·in·ansible_facts.packages' 
3773 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3772 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3773 ······-·'"audit"·in·ansible_facts.packages'
3774 ······-·'"auditd.service"·in·ansible_facts.services'3774 ······-·'"auditd.service"·in·ansible_facts.services'
3775 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'3775 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
3776 ······register:·augenrules_syscall_auditing_rule_update_result3776 ······register:·augenrules_syscall_auditing_rule_update_result
3777 ······tags:3777 ······tags:
3778 ······-·CCE-85706-03778 ······-·CCE-85706-0
3779 ······-·DISA-STIG-SLES-15-0308203779 ······-·DISA-STIG-SLES-15-030820
3780 ······-·NIST-800-53-CM-6(b)3780 ······-·NIST-800-53-CM-6(b)
Offset 3788, 16 lines modifiedOffset 3788, 16 lines modified
  
3788 ····-·name:·Enable·syscall·auditing·(auditctl)3788 ····-·name:·Enable·syscall·auditing·(auditctl)
3789 ······lineinfile:3789 ······lineinfile:
3790 ········path:·/etc/audit/audit.rules3790 ········path:·/etc/audit/audit.rules
3791 ········regex:·^(?i)(\s*-a\s+task,never)\s*$3791 ········regex:·^(?i)(\s*-a\s+task,never)\s*$
3792 ········line:·'#-a·task,never'3792 ········line:·'#-a·task,never'
3793 ······when:3793 ······when:
3794 ······-·'"audit"·in·ansible_facts.packages' 
3795 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3794 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3795 ······-·'"audit"·in·ansible_facts.packages'
3796 ······-·'"auditd.service"·in·ansible_facts.services'3796 ······-·'"auditd.service"·in·ansible_facts.services'
3797 ······-·'"auditctl"·in·check_rules_scripts_result.stdout'3797 ······-·'"auditctl"·in·check_rules_scripts_result.stdout'
3798 ······register:·auditctl_syscall_auditing_rule_update_result3798 ······register:·auditctl_syscall_auditing_rule_update_result
3799 ······tags:3799 ······tags:
3800 ······-·CCE-85706-03800 ······-·CCE-85706-0
3801 ······-·DISA-STIG-SLES-15-0308203801 ······-·DISA-STIG-SLES-15-030820
3802 ······-·NIST-800-53-CM-6(b)3802 ······-·NIST-800-53-CM-6(b)
Offset 3810, 16 lines modifiedOffset 3810, 16 lines modified
3810 ······-·restrict_strategy3810 ······-·restrict_strategy
  
3811 ····-·name:·Restart·auditd.service3811 ····-·name:·Restart·auditd.service
3812 ······systemd:3812 ······systemd:
3813 ········name:·auditd.service3813 ········name:·auditd.service
3814 ········state:·restarted3814 ········state:·restarted
3815 ······when:3815 ······when:
3816 ······-·'"audit"·in·ansible_facts.packages' 
3817 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3816 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3817 ······-·'"audit"·in·ansible_facts.packages'
3818 ······-·ansible_facts.services["auditd.service"].state·==·"running"3818 ······-·ansible_facts.services["auditd.service"].state·==·"running"
3819 ······-·(augenrules_syscall_auditing_rule_update_result.changed·or·auditctl_syscall_auditing_rule_update_result.changed)3819 ······-·(augenrules_syscall_auditing_rule_update_result.changed·or·auditctl_syscall_auditing_rule_update_result.changed)
3820 ······tags:3820 ······tags:
3821 ······-·CCE-85706-03821 ······-·CCE-85706-0
3822 ······-·DISA-STIG-SLES-15-0308203822 ······-·DISA-STIG-SLES-15-030820
3823 ······-·NIST-800-53-CM-6(b)3823 ······-·NIST-800-53-CM-6(b)
3824 ······-·NIST-800-53-CM-6.1(iv)3824 ······-·NIST-800-53-CM-6.1(iv)
Offset 3851, 16 lines modifiedOffset 3851, 16 lines modified
  
3851 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension3851 ····-·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
3852 ······find:3852 ······find:
3853 ········paths:·/etc/audit/rules.d/3853 ········paths:·/etc/audit/rules.d/
3854 ········patterns:·'*.rules'3854 ········patterns:·'*.rules'
3855 ······register:·find_rules_d3855 ······register:·find_rules_d
3856 ······when:3856 ······when:
3857 ······-·'"audit"·in·ansible_facts.packages' 
3858 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3857 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3858 ······-·'"audit"·in·ansible_facts.packages'
3859 ······tags:3859 ······tags:
3860 ······-·CCE-85831-63860 ······-·CCE-85831-6
3861 ······-·CJIS-5.4.1.13861 ······-·CJIS-5.4.1.1
3862 ······-·NIST-800-171-3.3.13862 ······-·NIST-800-171-3.3.1
3863 ······-·NIST-800-171-3.4.33863 ······-·NIST-800-171-3.4.3
3864 ······-·NIST-800-53-AC-6(9)3864 ······-·NIST-800-53-AC-6(9)
3865 ······-·NIST-800-53-CM-6(a)3865 ······-·NIST-800-53-CM-6(a)
Offset 3876, 16 lines modifiedOffset 3876, 16 lines modified
3876 ······lineinfile:3876 ······lineinfile:
Max diff block lines reached; 238654/243262 bytes (98.11%) of diff not shown.
86.2 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-standard.yml
Ordering differences only
    
Offset 3879, 16 lines modifiedOffset 3879, 16 lines modified
3879 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/3879 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/rules.d/
3880 ······find:3880 ······find:
3881 ········paths:·/etc/audit/rules.d3881 ········paths:·/etc/audit/rules.d
3882 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+3882 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
3883 ········patterns:·'*.rules'3883 ········patterns:·'*.rules'
3884 ······register:·find_existing_watch_rules_d3884 ······register:·find_existing_watch_rules_d
3885 ······when:3885 ······when:
3886 ······-·'"audit"·in·ansible_facts.packages' 
3887 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3886 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3887 ······-·'"audit"·in·ansible_facts.packages'
3888 ······tags:3888 ······tags:
3889 ······-·CCE-85830-83889 ······-·CCE-85830-8
3890 ······-·CJIS-5.4.1.13890 ······-·CJIS-5.4.1.1
3891 ······-·NIST-800-171-3.1.83891 ······-·NIST-800-171-3.1.8
3892 ······-·NIST-800-53-AU-12(c)3892 ······-·NIST-800-53-AU-12(c)
3893 ······-·NIST-800-53-AU-2(d)3893 ······-·NIST-800-53-AU-2(d)
3894 ······-·NIST-800-53-CM-6(a)3894 ······-·NIST-800-53-CM-6(a)
Offset 3903, 16 lines modifiedOffset 3903, 16 lines modified
3903 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy3903 ····-·name:·Search·/etc/audit/rules.d·for·other·rules·with·specified·key·MAC-policy
3904 ······find:3904 ······find:
3905 ········paths:·/etc/audit/rules.d3905 ········paths:·/etc/audit/rules.d
3906 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$3906 ········contains:·^.*(?:-F·key=|-k\s+)MAC-policy$
3907 ········patterns:·'*.rules'3907 ········patterns:·'*.rules'
3908 ······register:·find_watch_key3908 ······register:·find_watch_key
3909 ······when:3909 ······when:
3910 ······-·'"audit"·in·ansible_facts.packages' 
3911 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3910 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3911 ······-·'"audit"·in·ansible_facts.packages'
3912 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3912 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3913 ········==·03913 ········==·0
3914 ······tags:3914 ······tags:
3915 ······-·CCE-85830-83915 ······-·CCE-85830-8
3916 ······-·CJIS-5.4.1.13916 ······-·CJIS-5.4.1.1
3917 ······-·NIST-800-171-3.1.83917 ······-·NIST-800-171-3.1.8
3918 ······-·NIST-800-53-AU-12(c)3918 ······-·NIST-800-53-AU-12(c)
Offset 3927, 16 lines modifiedOffset 3927, 16 lines modified
3927 ······-·restrict_strategy3927 ······-·restrict_strategy
  
3928 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule3928 ····-·name:·Use·/etc/audit/rules.d/MAC-policy.rules·as·the·recipient·for·the·rule
3929 ······set_fact:3929 ······set_fact:
3930 ········all_files:3930 ········all_files:
3931 ········-·/etc/audit/rules.d/MAC-policy.rules3931 ········-·/etc/audit/rules.d/MAC-policy.rules
3932 ······when:3932 ······when:
3933 ······-·'"audit"·in·ansible_facts.packages' 
3934 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3933 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3934 ······-·'"audit"·in·ansible_facts.packages'
3935 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched3935 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·==·0·and·find_existing_watch_rules_d.matched
3936 ········is·defined·and·find_existing_watch_rules_d.matched·==·03936 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3937 ······tags:3937 ······tags:
3938 ······-·CCE-85830-83938 ······-·CCE-85830-8
3939 ······-·CJIS-5.4.1.13939 ······-·CJIS-5.4.1.1
3940 ······-·NIST-800-171-3.1.83940 ······-·NIST-800-171-3.1.8
3941 ······-·NIST-800-53-AU-12(c)3941 ······-·NIST-800-53-AU-12(c)
Offset 3951, 16 lines modifiedOffset 3951, 16 lines modified
3951 ······-·restrict_strategy3951 ······-·restrict_strategy
  
3952 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule3952 ····-·name:·Use·matched·file·as·the·recipient·for·the·rule
3953 ······set_fact:3953 ······set_fact:
3954 ········all_files:3954 ········all_files:
3955 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'3955 ········-·'{{·find_watch_key.files·|·map(attribute=''path'')·|·list·|·first·}}'
3956 ······when:3956 ······when:
3957 ······-·'"audit"·in·ansible_facts.packages' 
3958 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3957 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3958 ······-·'"audit"·in·ansible_facts.packages'
3959 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched3959 ······-·find_watch_key.matched·is·defined·and·find_watch_key.matched·>·0·and·find_existing_watch_rules_d.matched
3960 ········is·defined·and·find_existing_watch_rules_d.matched·==·03960 ········is·defined·and·find_existing_watch_rules_d.matched·==·0
3961 ······tags:3961 ······tags:
3962 ······-·CCE-85830-83962 ······-·CCE-85830-8
3963 ······-·CJIS-5.4.1.13963 ······-·CJIS-5.4.1.1
3964 ······-·NIST-800-171-3.1.83964 ······-·NIST-800-171-3.1.8
3965 ······-·NIST-800-53-AU-12(c)3965 ······-·NIST-800-53-AU-12(c)
Offset 3977, 16 lines modifiedOffset 3977, 16 lines modified
3977 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/3977 ····-·name:·Add·watch·rule·for·/etc/selinux/·in·/etc/audit/rules.d/
3978 ······lineinfile:3978 ······lineinfile:
3979 ········path:·'{{·all_files[0]·}}'3979 ········path:·'{{·all_files[0]·}}'
3980 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy3980 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
3981 ········create:·true3981 ········create:·true
3982 ········mode:·'0640'3982 ········mode:·'0640'
3983 ······when:3983 ······when:
3984 ······-·'"audit"·in·ansible_facts.packages' 
3985 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]3984 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 3985 ······-·'"audit"·in·ansible_facts.packages'
3986 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched3986 ······-·find_existing_watch_rules_d.matched·is·defined·and·find_existing_watch_rules_d.matched
3987 ········==·03987 ········==·0
3988 ······tags:3988 ······tags:
3989 ······-·CCE-85830-83989 ······-·CCE-85830-8
3990 ······-·CJIS-5.4.1.13990 ······-·CJIS-5.4.1.1
3991 ······-·NIST-800-171-3.1.83991 ······-·NIST-800-171-3.1.8
3992 ······-·NIST-800-53-AU-12(c)3992 ······-·NIST-800-53-AU-12(c)
Offset 4003, 16 lines modifiedOffset 4003, 16 lines modified
4003 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules4003 ····-·name:·Check·if·watch·rule·for·/etc/selinux/·already·exists·in·/etc/audit/audit.rules
4004 ······find:4004 ······find:
4005 ········paths:·/etc/audit/4005 ········paths:·/etc/audit/
4006 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+4006 ········contains:·^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
4007 ········patterns:·audit.rules4007 ········patterns:·audit.rules
4008 ······register:·find_existing_watch_audit_rules4008 ······register:·find_existing_watch_audit_rules
4009 ······when:4009 ······when:
4010 ······-·'"audit"·in·ansible_facts.packages' 
4011 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4010 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4011 ······-·'"audit"·in·ansible_facts.packages'
4012 ······tags:4012 ······tags:
4013 ······-·CCE-85830-84013 ······-·CCE-85830-8
4014 ······-·CJIS-5.4.1.14014 ······-·CJIS-5.4.1.1
4015 ······-·NIST-800-171-3.1.84015 ······-·NIST-800-171-3.1.8
4016 ······-·NIST-800-53-AU-12(c)4016 ······-·NIST-800-53-AU-12(c)
4017 ······-·NIST-800-53-AU-2(d)4017 ······-·NIST-800-53-AU-2(d)
4018 ······-·NIST-800-53-CM-6(a)4018 ······-·NIST-800-53-CM-6(a)
Offset 4028, 16 lines modifiedOffset 4028, 16 lines modified
4028 ······lineinfile:4028 ······lineinfile:
4029 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy4029 ········line:·-w·/etc/selinux/·-p·wa·-k·MAC-policy
4030 ········state:·present4030 ········state:·present
4031 ········dest:·/etc/audit/audit.rules4031 ········dest:·/etc/audit/audit.rules
4032 ········create:·true4032 ········create:·true
4033 ········mode:·'0640'4033 ········mode:·'0640'
4034 ······when:4034 ······when:
4035 ······-·'"audit"·in·ansible_facts.packages' 
4036 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]4035 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 4036 ······-·'"audit"·in·ansible_facts.packages'
4037 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched4037 ······-·find_existing_watch_audit_rules.matched·is·defined·and·find_existing_watch_audit_rules.matched
4038 ········==·04038 ········==·0
4039 ······tags:4039 ······tags:
4040 ······-·CCE-85830-84040 ······-·CCE-85830-8
4041 ······-·CJIS-5.4.1.14041 ······-·CJIS-5.4.1.1
4042 ······-·NIST-800-171-3.1.84042 ······-·NIST-800-171-3.1.8
4043 ······-·NIST-800-53-AU-12(c)4043 ······-·NIST-800-53-AU-12(c)
Offset 4072, 16 lines modifiedOffset 4072, 16 lines modified
4072 ······-·reboot_required4072 ······-·reboot_required
Max diff block lines reached; 83233/88061 bytes (94.52%) of diff not shown.
173 KB
./usr/share/scap-security-guide/ansible/sle15-playbook-stig.yml
Ordering differences only
    
Offset 6079, 16 lines modifiedOffset 6079, 16 lines modified
6079 ······-·medium_severity6079 ······-·medium_severity
6080 ······-·no_reboot_needed6080 ······-·no_reboot_needed
6081 ······-·restrict_strategy6081 ······-·restrict_strategy
  
6082 ····-·name:·Service·facts6082 ····-·name:·Service·facts
6083 ······service_facts:·null6083 ······service_facts:·null
6084 ······when:6084 ······when:
6085 ······-·'"audit"·in·ansible_facts.packages' 
6086 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6085 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6086 ······-·'"audit"·in·ansible_facts.packages'
6087 ······tags:6087 ······tags:
6088 ······-·CCE-85706-06088 ······-·CCE-85706-0
6089 ······-·DISA-STIG-SLES-15-0308206089 ······-·DISA-STIG-SLES-15-030820
6090 ······-·NIST-800-53-CM-6(b)6090 ······-·NIST-800-53-CM-6(b)
6091 ······-·NIST-800-53-CM-6.1(iv)6091 ······-·NIST-800-53-CM-6.1(iv)
6092 ······-·audit_rules_enable_syscall_auditing6092 ······-·audit_rules_enable_syscall_auditing
6093 ······-·low_complexity6093 ······-·low_complexity
Offset 6097, 16 lines modifiedOffset 6097, 16 lines modified
6097 ······-·no_reboot_needed6097 ······-·no_reboot_needed
6098 ······-·restrict_strategy6098 ······-·restrict_strategy
  
6099 ····-·name:·Check·the·rules·script·being·used6099 ····-·name:·Check·the·rules·script·being·used
6100 ······command:·grep·-E·'^(ExecStartPost|Requires)'·/usr/lib/systemd/system/auditd.service6100 ······command:·grep·-E·'^(ExecStartPost|Requires)'·/usr/lib/systemd/system/auditd.service
6101 ······register:·check_rules_scripts_result6101 ······register:·check_rules_scripts_result
6102 ······when:6102 ······when:
6103 ······-·'"audit"·in·ansible_facts.packages' 
6104 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6103 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6104 ······-·'"audit"·in·ansible_facts.packages'
6105 ······tags:6105 ······tags:
6106 ······-·CCE-85706-06106 ······-·CCE-85706-0
6107 ······-·DISA-STIG-SLES-15-0308206107 ······-·DISA-STIG-SLES-15-030820
6108 ······-·NIST-800-53-CM-6(b)6108 ······-·NIST-800-53-CM-6(b)
6109 ······-·NIST-800-53-CM-6.1(iv)6109 ······-·NIST-800-53-CM-6.1(iv)
6110 ······-·audit_rules_enable_syscall_auditing6110 ······-·audit_rules_enable_syscall_auditing
6111 ······-·low_complexity6111 ······-·low_complexity
Offset 6118, 16 lines modifiedOffset 6118, 16 lines modified
6118 ····-·name:·Find·audit·rules·in·/etc/audit/rules.d6118 ····-·name:·Find·audit·rules·in·/etc/audit/rules.d
6119 ······find:6119 ······find:
6120 ········paths:·/etc/audit/rules.d6120 ········paths:·/etc/audit/rules.d
6121 ········file_type:·file6121 ········file_type:·file
6122 ········follow:·true6122 ········follow:·true
6123 ······register:·find_audit_rules_result6123 ······register:·find_audit_rules_result
6124 ······when:6124 ······when:
6125 ······-·'"audit"·in·ansible_facts.packages' 
6126 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6125 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6126 ······-·'"audit"·in·ansible_facts.packages'
6127 ······-·'"auditd.service"·in·ansible_facts.services'6127 ······-·'"auditd.service"·in·ansible_facts.services'
6128 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'6128 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
6129 ······tags:6129 ······tags:
6130 ······-·CCE-85706-06130 ······-·CCE-85706-0
6131 ······-·DISA-STIG-SLES-15-0308206131 ······-·DISA-STIG-SLES-15-030820
6132 ······-·NIST-800-53-CM-6(b)6132 ······-·NIST-800-53-CM-6(b)
6133 ······-·NIST-800-53-CM-6.1(iv)6133 ······-·NIST-800-53-CM-6.1(iv)
Offset 6141, 16 lines modifiedOffset 6141, 16 lines modified
6141 ····-·name:·Enable·syscall·auditing·(augenrules)6141 ····-·name:·Enable·syscall·auditing·(augenrules)
6142 ······lineinfile:6142 ······lineinfile:
6143 ········path:·'{{·item.path·}}'6143 ········path:·'{{·item.path·}}'
6144 ········regex:·^(?i)(\s*-a\s+task,never)\s*$6144 ········regex:·^(?i)(\s*-a\s+task,never)\s*$
6145 ········line:·'#-a·task,never'6145 ········line:·'#-a·task,never'
6146 ······with_items:·'{{·find_audit_rules_result.files·}}'6146 ······with_items:·'{{·find_audit_rules_result.files·}}'
6147 ······when:6147 ······when:
6148 ······-·'"audit"·in·ansible_facts.packages' 
6149 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6148 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6149 ······-·'"audit"·in·ansible_facts.packages'
6150 ······-·'"auditd.service"·in·ansible_facts.services'6150 ······-·'"auditd.service"·in·ansible_facts.services'
6151 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'6151 ······-·'"augenrules"·in·check_rules_scripts_result.stdout'
6152 ······register:·augenrules_syscall_auditing_rule_update_result6152 ······register:·augenrules_syscall_auditing_rule_update_result
6153 ······tags:6153 ······tags:
6154 ······-·CCE-85706-06154 ······-·CCE-85706-0
6155 ······-·DISA-STIG-SLES-15-0308206155 ······-·DISA-STIG-SLES-15-030820
6156 ······-·NIST-800-53-CM-6(b)6156 ······-·NIST-800-53-CM-6(b)
Offset 6164, 16 lines modifiedOffset 6164, 16 lines modified
  
6164 ····-·name:·Enable·syscall·auditing·(auditctl)6164 ····-·name:·Enable·syscall·auditing·(auditctl)
6165 ······lineinfile:6165 ······lineinfile:
6166 ········path:·/etc/audit/audit.rules6166 ········path:·/etc/audit/audit.rules
6167 ········regex:·^(?i)(\s*-a\s+task,never)\s*$6167 ········regex:·^(?i)(\s*-a\s+task,never)\s*$
6168 ········line:·'#-a·task,never'6168 ········line:·'#-a·task,never'
6169 ······when:6169 ······when:
6170 ······-·'"audit"·in·ansible_facts.packages' 
6171 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6170 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6171 ······-·'"audit"·in·ansible_facts.packages'
6172 ······-·'"auditd.service"·in·ansible_facts.services'6172 ······-·'"auditd.service"·in·ansible_facts.services'
6173 ······-·'"auditctl"·in·check_rules_scripts_result.stdout'6173 ······-·'"auditctl"·in·check_rules_scripts_result.stdout'
6174 ······register:·auditctl_syscall_auditing_rule_update_result6174 ······register:·auditctl_syscall_auditing_rule_update_result
6175 ······tags:6175 ······tags:
6176 ······-·CCE-85706-06176 ······-·CCE-85706-0
6177 ······-·DISA-STIG-SLES-15-0308206177 ······-·DISA-STIG-SLES-15-030820
6178 ······-·NIST-800-53-CM-6(b)6178 ······-·NIST-800-53-CM-6(b)
Offset 6186, 16 lines modifiedOffset 6186, 16 lines modified
6186 ······-·restrict_strategy6186 ······-·restrict_strategy
  
6187 ····-·name:·Restart·auditd.service6187 ····-·name:·Restart·auditd.service
6188 ······systemd:6188 ······systemd:
6189 ········name:·auditd.service6189 ········name:·auditd.service
6190 ········state:·restarted6190 ········state:·restarted
6191 ······when:6191 ······when:
6192 ······-·'"audit"·in·ansible_facts.packages' 
6193 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6192 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6193 ······-·'"audit"·in·ansible_facts.packages'
6194 ······-·ansible_facts.services["auditd.service"].state·==·"running"6194 ······-·ansible_facts.services["auditd.service"].state·==·"running"
6195 ······-·(augenrules_syscall_auditing_rule_update_result.changed·or·auditctl_syscall_auditing_rule_update_result.changed)6195 ······-·(augenrules_syscall_auditing_rule_update_result.changed·or·auditctl_syscall_auditing_rule_update_result.changed)
6196 ······tags:6196 ······tags:
6197 ······-·CCE-85706-06197 ······-·CCE-85706-0
6198 ······-·DISA-STIG-SLES-15-0308206198 ······-·DISA-STIG-SLES-15-030820
6199 ······-·NIST-800-53-CM-6(b)6199 ······-·NIST-800-53-CM-6(b)
6200 ······-·NIST-800-53-CM-6.1(iv)6200 ······-·NIST-800-53-CM-6.1(iv)
Offset 6227, 16 lines modifiedOffset 6227, 16 lines modified
6227 ······-·reboot_required6227 ······-·reboot_required
6228 ······-·restrict_strategy6228 ······-·restrict_strategy
  
6229 ····-·name:·Set·architecture·for·audit·mount·tasks6229 ····-·name:·Set·architecture·for·audit·mount·tasks
6230 ······set_fact:6230 ······set_fact:
6231 ········audit_arch:·b646231 ········audit_arch:·b64
6232 ······when:6232 ······when:
6233 ······-·'"audit"·in·ansible_facts.packages' 
6234 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]6233 ······-·ansible_virtualization_type·not·in·["docker",·"lxc",·"openvz",·"podman",·"container"]
 6234 ······-·'"audit"·in·ansible_facts.packages'
6235 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture6235 ······-·ansible_architecture·==·"aarch64"·or·ansible_architecture·==·"ppc64"·or·ansible_architecture
6236 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"6236 ········==·"ppc64le"·or·ansible_architecture·==·"s390x"·or·ansible_architecture·==·"x86_64"
6237 ······tags:6237 ······tags:
6238 ······-·CCE-85718-56238 ······-·CCE-85718-5
6239 ······-·CJIS-5.4.1.16239 ······-·CJIS-5.4.1.1
6240 ······-·DISA-STIG-SLES-15-0303506240 ······-·DISA-STIG-SLES-15-030350
6241 ······-·NIST-800-171-3.1.76241 ······-·NIST-800-171-3.1.7
Offset 6369, 16 lines modifiedOffset 6369, 16 lines modified
6369 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=10006369 ··········line:·-a·always,exit·-F·arch=b32·-S·{{·syscalls·|·join(',')·}}·-F·auid>=1000
Max diff block lines reached; 172121/176918 bytes (97.29%) of diff not shown.
1.14 KB
./usr/share/scap-security-guide/tailoring/rhel7_stig_delta_tailoring.xml
1.0 KB
./usr/share/scap-security-guide/tailoring/rhel7_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2024-02-07T02:39:05.410032">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2024-02-07T05:42:50.084285">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·7</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·7</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·V3R9.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·V3R9.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·7,·DISA·recognizes·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·7,·DISA·recognizes·this
9 configuration·baseline·as·applicable·to·the·operating·system·tier·of9 configuration·baseline·as·applicable·to·the·operating·system·tier·of
1.15 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
1.0 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2024-02-07T02:39:12.371492">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2024-02-07T05:42:58.330129">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V1R8.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V1R8.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·DISA·recognizes·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·DISA·recognizes·this
9 configuration·baseline·as·applicable·to·the·operating·system·tier·of9 configuration·baseline·as·applicable·to·the·operating·system·tier·of
1.17 MB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds-1.2.xml
1.17 MB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds-1.2.xml
Max HTML report size reached
1.17 MB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
1.17 MB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
Max HTML report size reached
1.06 MB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
1.06 MB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
Max HTML report size reached
66.2 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-xccdf.xml
66.1 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-xccdf.xml
    
Offset 47, 117 lines modifiedOffset 47, 117 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/> 
63 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
64 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
65 ····<cpe-lang:platform·id="yum">64 ····<cpe-lang:platform·id="login_defs">
66 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
67 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
68 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
69 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
70 ····<cpe-lang:platform·id="sudo">69 ····<cpe-lang:platform·id="chrony">
71 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
72 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
73 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
74 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
75 ····<cpe-lang:platform·id="aarch64_arch">74 ····<cpe-lang:platform·id="yum">
76 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
77 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>
78 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="s390x_arch">79 ····<cpe-lang:platform·id="audit">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
83 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="machine">84 ····<cpe-lang:platform·id="not_s390x_arch">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
88 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="chrony">89 ····<cpe-lang:platform·id="ntp">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
93 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="grub2">94 ····<cpe-lang:platform·id="pam">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
98 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="audit">99 ····<cpe-lang:platform·id="machine_and_partition-tmp">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>101 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 102 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
103 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="postfix">105 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 108 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
108 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="sssd">111 ····<cpe-lang:platform·id="aarch64_arch">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>113 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
113 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="gdm">116 ····<cpe-lang:platform·id="postfix">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>118 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
118 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="ntp">121 ····<cpe-lang:platform·id="machine_and_chrony_or_ntp">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 123 ········<cpe-lang:logical-test·operator="OR"·negate="false">
 124 ··········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
122 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>125 ··········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
 126 ········</cpe-lang:logical-test>
 127 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
123 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="non-uefi">130 ····<cpe-lang:platform·id="non-uefi">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>132 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
128 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="not_s390x_arch">135 ····<cpe-lang:platform·id="uefi">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>137 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
133 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="machine_and_partition-tmp">140 ····<cpe-lang:platform·id="sudo">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">141 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>142 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
138 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/> 
139 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="uefi">145 ····<cpe-lang:platform·id="grub2">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">146 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>147 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
144 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="login_defs">150 ····<cpe-lang:platform·id="s390x_arch">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>152 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
149 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="machine_and_chrony_or_ntp">155 ····<cpe-lang:platform·id="machine">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:logical-test·operator="OR"·negate="false"> 
154 ··········<cpe-lang:fact-ref·name="cpe:/a:chrony"/> 
155 ··········<cpe-lang:fact-ref·name="cpe:/a:ntp"/> 
156 ········</cpe-lang:logical-test> 
157 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>157 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
158 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
160 ··</cpe-lang:platform-specification>160 ··</cpe-lang:platform-specification>
161 ··<xccdf-1.2:platform·idref="cpe:/o:alinux:alibaba_cloud_linux:2"/>161 ··<xccdf-1.2:platform·idref="cpe:/o:alinux:alibaba_cloud_linux:2"/>
162 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>162 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
163 ··<xccdf-1.2:metadata>163 ··<xccdf-1.2:metadata>
Offset 12627, 16 lines modifiedOffset 12627, 16 lines modified
  
12627 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension12627 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
12628 ··find:12628 ··find:
Max diff block lines reached; 60153/67618 bytes (88.96%) of diff not shown.
1.16 MB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds-1.2.xml
1.16 MB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds-1.2.xml
Max HTML report size reached
1.16 MB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
1.16 MB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
Max HTML report size reached
1.04 MB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
1.04 MB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
Max HTML report size reached
74.5 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-xccdf.xml
74.4 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-xccdf.xml
    
Offset 47, 114 lines modifiedOffset 47, 114 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/> 
63 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
64 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
65 ····<cpe-lang:platform·id="yum">64 ····<cpe-lang:platform·id="login_defs">
66 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
67 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
68 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
69 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
70 ····<cpe-lang:platform·id="wifi-iface">69 ····<cpe-lang:platform·id="chrony">
71 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
72 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
73 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
74 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
75 ····<cpe-lang:platform·id="sudo">74 ····<cpe-lang:platform·id="yum">
76 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
77 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>
78 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="aarch64_arch">79 ····<cpe-lang:platform·id="audit">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
83 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="s390x_arch">84 ····<cpe-lang:platform·id="not_s390x_arch">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
88 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="machine">89 ····<cpe-lang:platform·id="ntp">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
93 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="chrony">94 ····<cpe-lang:platform·id="pam">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
98 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="grub2">99 ····<cpe-lang:platform·id="machine_and_partition-tmp">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>101 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 102 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
103 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="audit">105 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 108 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
108 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="postfix">111 ····<cpe-lang:platform·id="aarch64_arch">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>113 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
113 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="sssd">116 ····<cpe-lang:platform·id="postfix">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>118 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
118 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="gdm">121 ····<cpe-lang:platform·id="wifi-iface">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>123 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
123 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="ntp">126 ····<cpe-lang:platform·id="non-uefi">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>128 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
128 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="non-uefi">131 ····<cpe-lang:platform·id="uefi">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>133 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
133 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="not_s390x_arch">136 ····<cpe-lang:platform·id="sudo">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>138 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
138 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="machine_and_partition-tmp">141 ····<cpe-lang:platform·id="grub2">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>143 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
143 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/> 
144 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="uefi">146 ····<cpe-lang:platform·id="s390x_arch">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>148 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
149 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="login_defs">151 ····<cpe-lang:platform·id="machine">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>153 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
154 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
156 ··</cpe-lang:platform-specification>156 ··</cpe-lang:platform-specification>
157 ··<xccdf-1.2:platform·idref="cpe:/o:alinux:alibaba_cloud_linux:3"/>157 ··<xccdf-1.2:platform·idref="cpe:/o:alinux:alibaba_cloud_linux:3"/>
158 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>158 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
159 ··<xccdf-1.2:metadata>159 ··<xccdf-1.2:metadata>
160 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>160 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 12492, 16 lines modifiedOffset 12492, 16 lines modified
  
12492 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension12492 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
12493 ··find:12493 ··find:
12494 ····paths:·/etc/audit/rules.d/12494 ····paths:·/etc/audit/rules.d/
12495 ····patterns:·'*.rules'12495 ····patterns:·'*.rules'
12496 ··register:·find_rules_d12496 ··register:·find_rules_d
12497 ··when:12497 ··when:
12498 ··-·'&quot;audit&quot;·in·ansible_facts.packages' 
12499 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]12498 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
 12499 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
Max diff block lines reached; 68560/76121 bytes (90.07%) of diff not shown.
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds-1.2.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds-1.2.xml
Max HTML report size reached
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
1.01 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
Max HTML report size reached
976 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
976 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
Max HTML report size reached
14.4 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-xccdf.xml
14.3 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-xccdf.xml
    
Offset 47, 102 lines modifiedOffset 47, 102 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="yum">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="wifi-iface">64 ····<cpe-lang:platform·id="login_defs">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
67 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="sudo">69 ····<cpe-lang:platform·id="chrony">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
72 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="aarch64_arch">74 ····<cpe-lang:platform·id="yum">
75 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>
77 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
78 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
79 ····<cpe-lang:platform·id="s390x_arch">79 ····<cpe-lang:platform·id="audit">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
82 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="machine">84 ····<cpe-lang:platform·id="not_s390x_arch">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="chrony">89 ····<cpe-lang:platform·id="ntp">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="grub2">94 ····<cpe-lang:platform·id="pam">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="audit">99 ····<cpe-lang:platform·id="aarch64_arch">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>101 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="postfix">104 ····<cpe-lang:platform·id="postfix">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>106 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="sssd">109 ····<cpe-lang:platform·id="wifi-iface">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>111 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="gdm">114 ····<cpe-lang:platform·id="non-uefi">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>116 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="ntp">119 ····<cpe-lang:platform·id="uefi">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>121 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
122 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="non-uefi">124 ····<cpe-lang:platform·id="sudo">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>126 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
127 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="not_s390x_arch">129 ····<cpe-lang:platform·id="grub2">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>131 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
132 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="uefi">134 ····<cpe-lang:platform·id="s390x_arch">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>136 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
137 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="login_defs">139 ····<cpe-lang:platform·id="machine">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>141 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
142 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
144 ··</cpe-lang:platform-specification>144 ··</cpe-lang:platform-specification>
145 ··<xccdf-1.2:platform·idref="cpe:/o:anolis:anolis_os:8"/>145 ··<xccdf-1.2:platform·idref="cpe:/o:anolis:anolis_os:8"/>
146 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>146 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
147 ··<xccdf-1.2:metadata>147 ··<xccdf-1.2:metadata>
148 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>148 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 26661, 15 lines modifiedOffset 26661, 15 lines modified
26661 ············The26661 ············The
26662 ············<html:code>root</html:code>26662 ············<html:code>root</html:code>
26663 ············group·is·a·highly-privileged·group.·Furthermore,·the·group-owner·of·this26663 ············group·is·a·highly-privileged·group.·Furthermore,·the·group-owner·of·this
26664 file·should·not·have·any·access·privileges·anyway.26664 file·should·not·have·any·access·privileges·anyway.
26665 ··········</xccdf-1.2:rationale>26665 ··········</xccdf-1.2:rationale>
26666 ··········<xccdf-1.2:platform·idref="#machine"/>26666 ··········<xccdf-1.2:platform·idref="#machine"/>
26667 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="file_groupowner_efi_grub2_cfg"·complexity="low"·disruption="low"·reboot="false"·strategy="configure">#·Remediation·is·applicable·only·in·certain·platforms26667 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:sh"·id="file_groupowner_efi_grub2_cfg"·complexity="low"·disruption="low"·reboot="false"·strategy="configure">#·Remediation·is·applicable·only·in·certain·platforms
26668 if·[·-f·/sys/firmware/efi·]·&amp;&amp;·rpm·--quiet·-q·grub2-common·&amp;&amp;·{·[·!·-f·/.dockerenv·]·&amp;&amp;·[·!·-f·/run/.containerenv·];·};·then26668 if·rpm·--quiet·-q·grub2-common·&amp;&amp;·[·-f·/sys/firmware/efi·]·&amp;&amp;·{·[·!·-f·/.dockerenv·]·&amp;&amp;·[·!·-f·/run/.containerenv·];·};·then
  
26669 chgrp·0·/boot/grub2/grub.cfg26669 chgrp·0·/boot/grub2/grub.cfg
  
26670 else26670 else
26671 ····&gt;&amp;2·echo·'Remediation·is·not·applicable,·nothing·was·done'26671 ····&gt;&amp;2·echo·'Remediation·is·not·applicable,·nothing·was·done'
26672 fi</xccdf-1.2:fix>26672 fi</xccdf-1.2:fix>
26673 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="file_groupowner_efi_grub2_cfg"·complexity="low"·disruption="low"·reboot="false"·strategy="configure">-·name:·Gather·the·package·facts26673 ··········<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="file_groupowner_efi_grub2_cfg"·complexity="low"·disruption="low"·reboot="false"·strategy="configure">-·name:·Gather·the·package·facts
Offset 26689, 16 lines modifiedOffset 26689, 16 lines modified
26689 ··-·no_reboot_needed26689 ··-·no_reboot_needed
  
26690 -·name:·Test·for·existence·/boot/grub2/grub.cfg26690 -·name:·Test·for·existence·/boot/grub2/grub.cfg
26691 ··stat:26691 ··stat:
26692 ····path:·/boot/grub2/grub.cfg26692 ····path:·/boot/grub2/grub.cfg
26693 ··register:·file_exists26693 ··register:·file_exists
26694 ··when:26694 ··when:
26695 ··-·'&quot;/boot/efi&quot;·in·ansible_mounts·|·map(attribute=&quot;mount&quot;)·|·list' 
Max diff block lines reached; 6940/14507 bytes (47.84%) of diff not shown.
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-centos7-ds-1.2.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-centos7-ds-1.2.xml
Max HTML report size reached
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-centos7-ds.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-centos7-ds.xml
Max HTML report size reached
986 KB
./usr/share/xml/scap/ssg/content/ssg-centos7-xccdf.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-centos7-xccdf.xml
Max HTML report size reached
4.11 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds-1.2.xml
4.11 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds-1.2.xml
Max HTML report size reached
4.11 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
4.11 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
Max HTML report size reached
950 KB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
949 KB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
Max HTML report size reached
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds-1.2.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds-1.2.xml
Max HTML report size reached
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
Max HTML report size reached
880 KB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
880 KB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
Max HTML report size reached
2.62 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds-1.2.xml
2.62 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds-1.2.xml
Max HTML report size reached
2.62 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
2.62 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
Max HTML report size reached
1.79 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
1.79 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
Max HTML report size reached
768 KB
./usr/share/xml/scap/ssg/content/ssg-fedora-xccdf.xml
768 KB
./usr/share/xml/scap/ssg/content/ssg-fedora-xccdf.xml
Max HTML report size reached
3.21 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-cpe-oval.xml
3.11 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-cpe-oval.xml
Ordering differences only
    
Offset 2742, 27 lines modifiedOffset 2742, 27 lines modified
2742 ······<ind:subexpression·datatype="string"·operation="pattern·match">^s390x$</ind:subexpression>2742 ······<ind:subexpression·datatype="string"·operation="pattern·match">^s390x$</ind:subexpression>
2743 ····</ind:textfilecontent54_state>2743 ····</ind:textfilecontent54_state>
2744 ····<unix:uname_state·comment="64·bit·architecture"·id="oval:ssg-state_system_info_architecture_ppcle_64:ste:1"·version="1">2744 ····<unix:uname_state·comment="64·bit·architecture"·id="oval:ssg-state_system_info_architecture_ppcle_64:ste:1"·version="1">
2745 ······<unix:processor_type·operation="equals">ppc64le</unix:processor_type>2745 ······<unix:processor_type·operation="equals">ppc64le</unix:processor_type>
2746 ····</unix:uname_state>2746 ····</unix:uname_state>
2747 ··</oval-def:states>2747 ··</oval-def:states>
2748 ··<oval-def:variables>2748 ··<oval-def:variables>
 2749 ····<oval-def:local_variable·id="oval:ssg-ocp4_node_network_file_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·network·file·to·scan."·version="1">
 2750 ······<oval-def:literal_component>/etc/kubernetes/cni/net.d/00-multus.conf</oval-def:literal_component>
 2751 ····</oval-def:local_variable>
 2752 ····<oval-def:local_variable·id="oval:ssg-ocp4_hypershift_dump_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·file·to·scan."·version="1">
 2753 ······<oval-def:literal_component>/kubernetes-api-resources/hypershift/version</oval-def:literal_component>
 2754 ····</oval-def:local_variable>
2749 ····<oval-def:local_variable·id="oval:ssg-ocp4_infra_dump_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·infra·file·to·scan."·version="1">2755 ····<oval-def:local_variable·id="oval:ssg-ocp4_infra_dump_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·infra·file·to·scan."·version="1">
2750 ······<oval-def:literal_component>/kubernetes-api-resources/apis/config.openshift.io/v1/infrastructures/cluster</oval-def:literal_component>2756 ······<oval-def:literal_component>/kubernetes-api-resources/apis/config.openshift.io/v1/infrastructures/cluster</oval-def:literal_component>
2751 ····</oval-def:local_variable>2757 ····</oval-def:local_variable>
2752 ····<oval-def:local_variable·id="oval:ssg-ocp4_network_dump_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·network·file·to·scan."·version="1">2758 ····<oval-def:local_variable·id="oval:ssg-ocp4_network_dump_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·network·file·to·scan."·version="1">
2753 ······<oval-def:literal_component>/kubernetes-api-resources/apis/config.openshift.io/v1/networks/cluster</oval-def:literal_component>2759 ······<oval-def:literal_component>/kubernetes-api-resources/apis/config.openshift.io/v1/networks/cluster</oval-def:literal_component>
2754 ····</oval-def:local_variable>2760 ····</oval-def:local_variable>
2755 ····<oval-def:local_variable·id="oval:ssg-hypershift_hosted_cluster_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·file·to·scan."·version="1">2761 ····<oval-def:local_variable·id="oval:ssg-hypershift_hosted_cluster_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·file·to·scan."·version="1">
2756 ······<oval-def:literal_component>/kubernetes-api-resources/apis/apiextensions.k8s.io/v1/customresourcedefinitions/hostedclusters.hypershift.openshift.io</oval-def:literal_component>2762 ······<oval-def:literal_component>/kubernetes-api-resources/apis/apiextensions.k8s.io/v1/customresourcedefinitions/hostedclusters.hypershift.openshift.io</oval-def:literal_component>
2757 ····</oval-def:local_variable>2763 ····</oval-def:local_variable>
2758 ····<oval-def:local_variable·id="oval:ssg-ocp4_dump_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·file·to·scan."·version="1">2764 ····<oval-def:local_variable·id="oval:ssg-ocp4_dump_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·file·to·scan."·version="1">
2759 ······<oval-def:literal_component>/kubernetes-api-resources/ocp/version</oval-def:literal_component>2765 ······<oval-def:literal_component>/kubernetes-api-resources/ocp/version</oval-def:literal_component>
2760 ····</oval-def:local_variable>2766 ····</oval-def:local_variable>
2761 ····<oval-def:local_variable·id="oval:ssg-ocp4_node_network_file_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·network·file·to·scan."·version="1"> 
2762 ······<oval-def:literal_component>/etc/kubernetes/cni/net.d/00-multus.conf</oval-def:literal_component> 
2763 ····</oval-def:local_variable> 
2764 ····<oval-def:local_variable·id="oval:ssg-ocp4_hypershift_dump_location:var:1"·datatype="string"·comment="The·actual·filepath·of·the·file·to·scan."·version="1"> 
2765 ······<oval-def:literal_component>/kubernetes-api-resources/hypershift/version</oval-def:literal_component> 
2766 ····</oval-def:local_variable> 
2767 ··</oval-def:variables>2767 ··</oval-def:variables>
2768 </oval-def:oval_definitions>2768 </oval-def:oval_definitions>
917 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds-1.2.xml
917 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds-1.2.xml
Max HTML report size reached
917 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
917 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
Max HTML report size reached
871 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
871 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
Max HTML report size reached
9.48 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-xccdf.xml
9.38 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-xccdf.xml
Ordering differences only
    
Offset 47, 117 lines modifiedOffset 47, 117 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.6_or_ocp4.7_or_ocp4.8_or_ocp4.9"> 
55 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
56 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.10"/> 
57 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.6"/> 
58 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.7"/> 
59 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.8"/> 
60 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.9"/> 
61 ······</cpe-lang:logical-test> 
62 ····</cpe-lang:platform> 
63 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7">54 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7">
64 ······<cpe-lang:logical-test·operator="OR"·negate="false">55 ······<cpe-lang:logical-test·operator="OR"·negate="false">
65 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.6"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.6"/>
66 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.7"/>57 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.7"/>
67 ······</cpe-lang:logical-test>58 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>59 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="not_s390x_arch_and_ocp4-node">60 ····<cpe-lang:platform·id="ocp4">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">61 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/> 
72 ········<cpe-lang:fact-ref·name="cpe:/o:redhat:openshift_container_platform_node:4"/>62 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.1"/>
73 ······</cpe-lang:logical-test>63 ······</cpe-lang:logical-test>
74 ····</cpe-lang:platform>64 ····</cpe-lang:platform>
75 ····<cpe-lang:platform·id="ocp4-on-aws">65 ····<cpe-lang:platform·id="ocp4-on-gcp">
76 ······<cpe-lang:logical-test·operator="AND"·negate="false">66 ······<cpe-lang:logical-test·operator="AND"·negate="false">
77 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_on_aws:4"/>67 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_on_gcp:4"/>
78 ······</cpe-lang:logical-test>68 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>69 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="ocp4.6">70 ····<cpe-lang:platform·id="ocp4-on-aws">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">71 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.6"/>72 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_on_aws:4"/>
83 ······</cpe-lang:logical-test>73 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>74 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="ocp4-on-gcp">75 ····<cpe-lang:platform·id="ocp4-master-node">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">76 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_on_gcp:4"/>77 ········<cpe-lang:fact-ref·name="cpe:/a:ocp4-master-node"/>
88 ······</cpe-lang:logical-test>78 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>79 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="ocp4.11_or_ocp4.12">80 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.11_or_ocp4.12_or_ocp4.9">
91 ······<cpe-lang:logical-test·operator="OR"·negate="false">81 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 82 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.10"/>
92 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.11"/>83 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.11"/>
93 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.12"/>84 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.12"/>
 85 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.9"/>
94 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.8_or_ocp4.9">88 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.6_or_ocp4.7_or_ocp4.8_or_ocp4.9">
97 ······<cpe-lang:logical-test·operator="OR"·negate="false">89 ······<cpe-lang:logical-test·operator="OR"·negate="false">
98 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.10"/>90 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.10"/>
 91 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.6"/>
 92 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.7"/>
99 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.8"/>93 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.8"/>
100 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.9"/>94 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.9"/>
101 ······</cpe-lang:logical-test>95 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>96 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="ocp4-on-azure">97 ····<cpe-lang:platform·id="ocp4.6">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">98 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_on_azure:4"/>99 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.6"/>
106 ······</cpe-lang:logical-test>100 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>101 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">102 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.8_or_ocp4.9">
109 ······<cpe-lang:logical-test·operator="OR"·negate="false">103 ······<cpe-lang:logical-test·operator="OR"·negate="false">
110 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.6"/>104 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.10"/>
111 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.7"/> 
112 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.8"/>105 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.8"/>
 106 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.9"/>
113 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="ocp4-node-on-sdn">109 ····<cpe-lang:platform·id="ocp4-node-on-sdn">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_node_on_sdn:4"/>111 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_node_on_sdn:4"/>
118 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="ocp4">114 ····<cpe-lang:platform·id="ocp4-node_and_s390x_arch">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.1"/>116 ········<cpe-lang:fact-ref·name="cpe:/o:redhat:openshift_container_platform_node:4"/>
 117 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
123 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
 120 ····<cpe-lang:platform·id="ocp4.11_or_ocp4.12">
 121 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 122 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.11"/>
 123 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.12"/>
 124 ······</cpe-lang:logical-test>
 125 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="ocp4-node-on-ovn">126 ····<cpe-lang:platform·id="ocp4-on-azure">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_node_on_ovn:4"/>128 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_on_azure:4"/>
128 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.11_or_ocp4.12_or_ocp4.9">131 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">
131 ······<cpe-lang:logical-test·operator="OR"·negate="false">132 ······<cpe-lang:logical-test·operator="OR"·negate="false">
132 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.10"/> 
133 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.11"/> 
134 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.12"/> 
135 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.9"/>133 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.6"/>
 134 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.7"/>
 135 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform:4.8"/>
136 ······</cpe-lang:logical-test>136 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>137 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="ocp4-node_and_s390x_arch">138 ····<cpe-lang:platform·id="ocp4-on-sdn">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">139 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:fact-ref·name="cpe:/o:redhat:openshift_container_platform_node:4"/>140 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_on_sdn:4"/>
141 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/> 
142 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="ocp4-node">143 ····<cpe-lang:platform·id="ocp4-node">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:fact-ref·name="cpe:/o:redhat:openshift_container_platform_node:4"/>145 ········<cpe-lang:fact-ref·name="cpe:/o:redhat:openshift_container_platform_node:4"/>
147 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="ocp4-on-sdn">148 ····<cpe-lang:platform·id="not_s390x_arch_and_ocp4-node">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 150 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
151 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_on_sdn:4"/>151 ········<cpe-lang:fact-ref·name="cpe:/o:redhat:openshift_container_platform_node:4"/>
152 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="ocp4-master-node">154 ····<cpe-lang:platform·id="ocp4-node-on-ovn">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
156 ········<cpe-lang:fact-ref·name="cpe:/a:ocp4-master-node"/>156 ········<cpe-lang:fact-ref·name="cpe:/a:redhat:openshift_container_platform_node_on_ovn:4"/>
157 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
158 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
Max diff block lines reached; 348/9476 bytes (3.67%) of diff not shown.
2.82 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds-1.2.xml
2.82 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds-1.2.xml
Max HTML report size reached
2.82 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
2.82 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
Max HTML report size reached
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
Max HTML report size reached
782 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
782 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
Max HTML report size reached
3.09 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds-1.2.xml
3.09 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds-1.2.xml
Max HTML report size reached
3.09 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
3.09 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
Max HTML report size reached
2.23 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
2.23 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
Max HTML report size reached
782 KB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
782 KB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
Max HTML report size reached
1.85 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds-1.2.xml
1.85 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds-1.2.xml
Max HTML report size reached
1.85 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
1.85 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
Max HTML report size reached
1.61 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
1.61 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
Max HTML report size reached
171 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
171 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
    
Offset 47, 150 lines modifiedOffset 47, 150 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="tmux">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:tmux"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="pam">59 ····<cpe-lang:platform·id="chrony_or_ntp">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 61 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
61 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>62 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
62 ······</cpe-lang:logical-test>63 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>64 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">65 ····<cpe-lang:platform·id="gdm">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">66 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>67 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
67 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/> 
68 ······</cpe-lang:logical-test>68 ······</cpe-lang:logical-test>
69 ····</cpe-lang:platform>69 ····</cpe-lang:platform>
70 ····<cpe-lang:platform·id="yum">70 ····<cpe-lang:platform·id="login_defs">
71 ······<cpe-lang:logical-test·operator="AND"·negate="false">71 ······<cpe-lang:logical-test·operator="AND"·negate="false">
72 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>72 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
73 ······</cpe-lang:logical-test>73 ······</cpe-lang:logical-test>
74 ····</cpe-lang:platform>74 ····</cpe-lang:platform>
75 ····<cpe-lang:platform·id="wifi-iface">75 ····<cpe-lang:platform·id="chrony">
76 ······<cpe-lang:logical-test·operator="AND"·negate="false">76 ······<cpe-lang:logical-test·operator="AND"·negate="false">
77 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>77 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
78 ······</cpe-lang:logical-test>78 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>79 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="sudo">80 ····<cpe-lang:platform·id="yum">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>82 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>
83 ······</cpe-lang:logical-test>83 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>84 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="aarch64_arch">85 ····<cpe-lang:platform·id="audit">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/> 
88 ······</cpe-lang:logical-test> 
89 ····</cpe-lang:platform> 
90 ····<cpe-lang:platform·id="chrony_or_ntp"> 
91 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
92 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/> 
93 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>87 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
94 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="s390x_arch">90 ····<cpe-lang:platform·id="not_s390x_arch">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>92 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
99 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="machine">95 ····<cpe-lang:platform·id="ntp">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>97 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
104 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="chrony">100 ····<cpe-lang:platform·id="pam">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>102 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
109 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="grub2">105 ····<cpe-lang:platform·id="machine_and_partition-tmp">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 108 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
114 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="systemd">111 ····<cpe-lang:platform·id="systemd">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>113 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>
119 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="audit">116 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>118 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 119 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
124 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="postfix">122 ····<cpe-lang:platform·id="aarch64_arch">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>124 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
129 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="usbguard">127 ····<cpe-lang:platform·id="libuser">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:fact-ref·name="cpe:/a:usbguard"/>129 ········<cpe-lang:fact-ref·name="cpe:/a:libuser"/>
134 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="sssd">132 ····<cpe-lang:platform·id="postfix">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>134 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
139 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="not_aarch64_arch">137 ····<cpe-lang:platform·id="krb5_workstation_older_than_1_17-18">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:fact-ref·name="cpe:/a:not_aarch64_arch"/>139 ········<cpe-lang:fact-ref·name="cpe:/a:krb5_workstation_older_than_1_17-18"/>
144 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="gdm">142 ····<cpe-lang:platform·id="wifi-iface">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>144 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
149 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="ntp">147 ····<cpe-lang:platform·id="tmux">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>149 ········<cpe-lang:fact-ref·name="cpe:/a:tmux"/>
154 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="libuser">152 ····<cpe-lang:platform·id="usbguard">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:fact-ref·name="cpe:/a:libuser"/>154 ········<cpe-lang:fact-ref·name="cpe:/a:usbguard"/>
159 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="non-uefi">157 ····<cpe-lang:platform·id="non-uefi">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>159 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
164 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="not_s390x_arch">162 ····<cpe-lang:platform·id="uefi">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>164 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
169 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
Max diff block lines reached; 167644/175386 bytes (95.59%) of diff not shown.
723 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds-1.2.xml
723 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds-1.2.xml
    
Offset 155, 92 lines modifiedOffset 155, 92 lines modified
155 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>155 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
156 ······</xccdf-1.2:front-matter>156 ······</xccdf-1.2:front-matter>
157 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered157 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
158 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other158 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
159 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their159 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
160 respective·companies.</xccdf-1.2:rear-matter>160 respective·companies.</xccdf-1.2:rear-matter>
161 ······<cpe-lang:platform-specification>161 ······<cpe-lang:platform-specification>
162 ········<cpe-lang:platform·id="pam">162 ········<cpe-lang:platform·id="sssd">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
164 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>164 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
165 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="sudo">167 ········<cpe-lang:platform·id="gdm">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>169 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
170 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="aarch64_arch">172 ········<cpe-lang:platform·id="login_defs">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>174 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
175 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="s390x_arch">177 ········<cpe-lang:platform·id="chrony">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>179 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
180 ··········</cpe-lang:logical-test>180 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>181 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="machine">182 ········<cpe-lang:platform·id="audit">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>184 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>
185 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="chrony">187 ········<cpe-lang:platform·id="not_s390x_arch">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>189 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
190 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
191 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
192 ········<cpe-lang:platform·id="grub2">192 ········<cpe-lang:platform·id="ntp">
193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
194 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>194 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
195 ··········</cpe-lang:logical-test>195 ··········</cpe-lang:logical-test>
196 ········</cpe-lang:platform>196 ········</cpe-lang:platform>
197 ········<cpe-lang:platform·id="audit">197 ········<cpe-lang:platform·id="pam">
198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
199 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>199 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>
200 ··········</cpe-lang:logical-test>200 ··········</cpe-lang:logical-test>
201 ········</cpe-lang:platform>201 ········</cpe-lang:platform>
202 ········<cpe-lang:platform·id="postfix">202 ········<cpe-lang:platform·id="aarch64_arch">
203 ··········<cpe-lang:logical-test·operator="AND"·negate="false">203 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
204 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>204 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
205 ··········</cpe-lang:logical-test>205 ··········</cpe-lang:logical-test>
206 ········</cpe-lang:platform>206 ········</cpe-lang:platform>
207 ········<cpe-lang:platform·id="sssd">207 ········<cpe-lang:platform·id="postfix">
208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
209 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>209 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
210 ··········</cpe-lang:logical-test>210 ··········</cpe-lang:logical-test>
211 ········</cpe-lang:platform>211 ········</cpe-lang:platform>
212 ········<cpe-lang:platform·id="gdm">212 ········<cpe-lang:platform·id="non-uefi">
213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
214 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>214 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
215 ··········</cpe-lang:logical-test>215 ··········</cpe-lang:logical-test>
216 ········</cpe-lang:platform>216 ········</cpe-lang:platform>
217 ········<cpe-lang:platform·id="ntp">217 ········<cpe-lang:platform·id="uefi">
218 ··········<cpe-lang:logical-test·operator="AND"·negate="false">218 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
219 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>219 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
220 ··········</cpe-lang:logical-test>220 ··········</cpe-lang:logical-test>
221 ········</cpe-lang:platform>221 ········</cpe-lang:platform>
222 ········<cpe-lang:platform·id="non-uefi">222 ········<cpe-lang:platform·id="sudo">
223 ··········<cpe-lang:logical-test·operator="AND"·negate="false">223 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
224 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>224 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
225 ··········</cpe-lang:logical-test>225 ··········</cpe-lang:logical-test>
226 ········</cpe-lang:platform>226 ········</cpe-lang:platform>
227 ········<cpe-lang:platform·id="not_s390x_arch">227 ········<cpe-lang:platform·id="grub2">
228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
229 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>229 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
230 ··········</cpe-lang:logical-test>230 ··········</cpe-lang:logical-test>
231 ········</cpe-lang:platform>231 ········</cpe-lang:platform>
232 ········<cpe-lang:platform·id="uefi">232 ········<cpe-lang:platform·id="s390x_arch">
233 ··········<cpe-lang:logical-test·operator="AND"·negate="false">233 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
234 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>234 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
235 ··········</cpe-lang:logical-test>235 ··········</cpe-lang:logical-test>
236 ········</cpe-lang:platform>236 ········</cpe-lang:platform>
237 ········<cpe-lang:platform·id="login_defs">237 ········<cpe-lang:platform·id="machine">
238 ··········<cpe-lang:logical-test·operator="AND"·negate="false">238 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
239 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>239 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
240 ··········</cpe-lang:logical-test>240 ··········</cpe-lang:logical-test>
241 ········</cpe-lang:platform>241 ········</cpe-lang:platform>
242 ······</cpe-lang:platform-specification>242 ······</cpe-lang:platform-specification>
243 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:15.0"/>243 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:15.0"/>
244 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.1"/>244 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.1"/>
245 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.2"/>245 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.2"/>
246 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.3"/>246 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.3"/>
Offset 6906, 16 lines modifiedOffset 6906, 16 lines modified
  
6906 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension6906 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
6907 ··find:6907 ··find:
6908 ····paths:·/etc/audit/rules.d/6908 ····paths:·/etc/audit/rules.d/
6909 ····patterns:·'*.rules'6909 ····patterns:·'*.rules'
6910 ··register:·find_rules_d6910 ··register:·find_rules_d
6911 ··when:6911 ··when:
6912 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
6913 ··-·'&quot;audit&quot;·in·ansible_facts.packages'6912 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 6913 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
6914 ··tags:6914 ··tags:
6915 ··-·CJIS-5.4.1.16915 ··-·CJIS-5.4.1.1
6916 ··-·NIST-800-171-3.3.16916 ··-·NIST-800-171-3.3.1
6917 ··-·NIST-800-171-3.4.36917 ··-·NIST-800-171-3.4.3
6918 ··-·NIST-800-53-AC-6(9)6918 ··-·NIST-800-53-AC-6(9)
6919 ··-·NIST-800-53-CM-6(a)6919 ··-·NIST-800-53-CM-6(a)
6920 ··-·PCI-DSS-Req-10.5.26920 ··-·PCI-DSS-Req-10.5.2
Offset 6930, 16 lines modifiedOffset 6930, 16 lines modified
6930 ··lineinfile:6930 ··lineinfile:
6931 ····path:·'{{·item·}}'6931 ····path:·'{{·item·}}'
6932 ····regexp:·^\s*(?:-e)\s+.*$6932 ····regexp:·^\s*(?:-e)\s+.*$
6933 ····state:·absent6933 ····state:·absent
6934 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']6934 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
6935 ····}}'6935 ····}}'
6936 ··when:6936 ··when:
6937 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
6938 ··-·'&quot;audit&quot;·in·ansible_facts.packages'6937 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 6938 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
6939 ··tags:6939 ··tags:
6940 ··-·CJIS-5.4.1.16940 ··-·CJIS-5.4.1.1
6941 ··-·NIST-800-171-3.3.16941 ··-·NIST-800-171-3.3.1
6942 ··-·NIST-800-171-3.4.36942 ··-·NIST-800-171-3.4.3
6943 ··-·NIST-800-53-AC-6(9)6943 ··-·NIST-800-53-AC-6(9)
6944 ··-·NIST-800-53-CM-6(a)6944 ··-·NIST-800-53-CM-6(a)
Max diff block lines reached; 732360/739792 bytes (99.00%) of diff not shown.
723 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
723 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
    
Offset 155, 92 lines modifiedOffset 155, 92 lines modified
155 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>155 ········<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
156 ······</xccdf-1.2:front-matter>156 ······</xccdf-1.2:front-matter>
157 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered157 ······<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
158 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other158 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
159 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their159 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
160 respective·companies.</xccdf-1.2:rear-matter>160 respective·companies.</xccdf-1.2:rear-matter>
161 ······<cpe-lang:platform-specification>161 ······<cpe-lang:platform-specification>
162 ········<cpe-lang:platform·id="pam">162 ········<cpe-lang:platform·id="sssd">
163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">163 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
164 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>164 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
165 ··········</cpe-lang:logical-test>165 ··········</cpe-lang:logical-test>
166 ········</cpe-lang:platform>166 ········</cpe-lang:platform>
167 ········<cpe-lang:platform·id="sudo">167 ········<cpe-lang:platform·id="gdm">
168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">168 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
169 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>169 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
170 ··········</cpe-lang:logical-test>170 ··········</cpe-lang:logical-test>
171 ········</cpe-lang:platform>171 ········</cpe-lang:platform>
172 ········<cpe-lang:platform·id="aarch64_arch">172 ········<cpe-lang:platform·id="login_defs">
173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">173 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
174 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>174 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
175 ··········</cpe-lang:logical-test>175 ··········</cpe-lang:logical-test>
176 ········</cpe-lang:platform>176 ········</cpe-lang:platform>
177 ········<cpe-lang:platform·id="s390x_arch">177 ········<cpe-lang:platform·id="chrony">
178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">178 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
179 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>179 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
180 ··········</cpe-lang:logical-test>180 ··········</cpe-lang:logical-test>
181 ········</cpe-lang:platform>181 ········</cpe-lang:platform>
182 ········<cpe-lang:platform·id="machine">182 ········<cpe-lang:platform·id="audit">
183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">183 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
184 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>184 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>
185 ··········</cpe-lang:logical-test>185 ··········</cpe-lang:logical-test>
186 ········</cpe-lang:platform>186 ········</cpe-lang:platform>
187 ········<cpe-lang:platform·id="chrony">187 ········<cpe-lang:platform·id="not_s390x_arch">
188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">188 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
189 ············<cpe-lang:fact-ref·name="cpe:/a:chrony"/>189 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
190 ··········</cpe-lang:logical-test>190 ··········</cpe-lang:logical-test>
191 ········</cpe-lang:platform>191 ········</cpe-lang:platform>
192 ········<cpe-lang:platform·id="grub2">192 ········<cpe-lang:platform·id="ntp">
193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">193 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
194 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>194 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
195 ··········</cpe-lang:logical-test>195 ··········</cpe-lang:logical-test>
196 ········</cpe-lang:platform>196 ········</cpe-lang:platform>
197 ········<cpe-lang:platform·id="audit">197 ········<cpe-lang:platform·id="pam">
198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">198 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
199 ············<cpe-lang:fact-ref·name="cpe:/a:audit"/>199 ············<cpe-lang:fact-ref·name="cpe:/a:pam"/>
200 ··········</cpe-lang:logical-test>200 ··········</cpe-lang:logical-test>
201 ········</cpe-lang:platform>201 ········</cpe-lang:platform>
202 ········<cpe-lang:platform·id="postfix">202 ········<cpe-lang:platform·id="aarch64_arch">
203 ··········<cpe-lang:logical-test·operator="AND"·negate="false">203 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
204 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>204 ············<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
205 ··········</cpe-lang:logical-test>205 ··········</cpe-lang:logical-test>
206 ········</cpe-lang:platform>206 ········</cpe-lang:platform>
207 ········<cpe-lang:platform·id="sssd">207 ········<cpe-lang:platform·id="postfix">
208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">208 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
209 ············<cpe-lang:fact-ref·name="cpe:/a:sssd"/>209 ············<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
210 ··········</cpe-lang:logical-test>210 ··········</cpe-lang:logical-test>
211 ········</cpe-lang:platform>211 ········</cpe-lang:platform>
212 ········<cpe-lang:platform·id="gdm">212 ········<cpe-lang:platform·id="non-uefi">
213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">213 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
214 ············<cpe-lang:fact-ref·name="cpe:/a:gdm"/>214 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
215 ··········</cpe-lang:logical-test>215 ··········</cpe-lang:logical-test>
216 ········</cpe-lang:platform>216 ········</cpe-lang:platform>
217 ········<cpe-lang:platform·id="ntp">217 ········<cpe-lang:platform·id="uefi">
218 ··········<cpe-lang:logical-test·operator="AND"·negate="false">218 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
219 ············<cpe-lang:fact-ref·name="cpe:/a:ntp"/>219 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
220 ··········</cpe-lang:logical-test>220 ··········</cpe-lang:logical-test>
221 ········</cpe-lang:platform>221 ········</cpe-lang:platform>
222 ········<cpe-lang:platform·id="non-uefi">222 ········<cpe-lang:platform·id="sudo">
223 ··········<cpe-lang:logical-test·operator="AND"·negate="false">223 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
224 ············<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>224 ············<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
225 ··········</cpe-lang:logical-test>225 ··········</cpe-lang:logical-test>
226 ········</cpe-lang:platform>226 ········</cpe-lang:platform>
227 ········<cpe-lang:platform·id="not_s390x_arch">227 ········<cpe-lang:platform·id="grub2">
228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">228 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
229 ············<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>229 ············<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
230 ··········</cpe-lang:logical-test>230 ··········</cpe-lang:logical-test>
231 ········</cpe-lang:platform>231 ········</cpe-lang:platform>
232 ········<cpe-lang:platform·id="uefi">232 ········<cpe-lang:platform·id="s390x_arch">
233 ··········<cpe-lang:logical-test·operator="AND"·negate="false">233 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
234 ············<cpe-lang:fact-ref·name="cpe:/a:uefi"/>234 ············<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
235 ··········</cpe-lang:logical-test>235 ··········</cpe-lang:logical-test>
236 ········</cpe-lang:platform>236 ········</cpe-lang:platform>
237 ········<cpe-lang:platform·id="login_defs">237 ········<cpe-lang:platform·id="machine">
238 ··········<cpe-lang:logical-test·operator="AND"·negate="false">238 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
239 ············<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>239 ············<cpe-lang:fact-ref·name="cpe:/a:machine"/>
240 ··········</cpe-lang:logical-test>240 ··········</cpe-lang:logical-test>
241 ········</cpe-lang:platform>241 ········</cpe-lang:platform>
242 ······</cpe-lang:platform-specification>242 ······</cpe-lang:platform-specification>
243 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:15.0"/>243 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:15.0"/>
244 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.1"/>244 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.1"/>
245 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.2"/>245 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.2"/>
246 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.3"/>246 ······<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.3"/>
Offset 6906, 16 lines modifiedOffset 6906, 16 lines modified
  
6906 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension6906 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
6907 ··find:6907 ··find:
6908 ····paths:·/etc/audit/rules.d/6908 ····paths:·/etc/audit/rules.d/
6909 ····patterns:·'*.rules'6909 ····patterns:·'*.rules'
6910 ··register:·find_rules_d6910 ··register:·find_rules_d
6911 ··when:6911 ··when:
6912 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
6913 ··-·'&quot;audit&quot;·in·ansible_facts.packages'6912 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 6913 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
6914 ··tags:6914 ··tags:
6915 ··-·CJIS-5.4.1.16915 ··-·CJIS-5.4.1.1
6916 ··-·NIST-800-171-3.3.16916 ··-·NIST-800-171-3.3.1
6917 ··-·NIST-800-171-3.4.36917 ··-·NIST-800-171-3.4.3
6918 ··-·NIST-800-53-AC-6(9)6918 ··-·NIST-800-53-AC-6(9)
6919 ··-·NIST-800-53-CM-6(a)6919 ··-·NIST-800-53-CM-6(a)
6920 ··-·PCI-DSS-Req-10.5.26920 ··-·PCI-DSS-Req-10.5.2
Offset 6930, 16 lines modifiedOffset 6930, 16 lines modified
6930 ··lineinfile:6930 ··lineinfile:
6931 ····path:·'{{·item·}}'6931 ····path:·'{{·item·}}'
6932 ····regexp:·^\s*(?:-e)\s+.*$6932 ····regexp:·^\s*(?:-e)\s+.*$
6933 ····state:·absent6933 ····state:·absent
6934 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']6934 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
6935 ····}}'6935 ····}}'
6936 ··when:6936 ··when:
6937 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
6938 ··-·'&quot;audit&quot;·in·ansible_facts.packages'6937 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 6938 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
6939 ··tags:6939 ··tags:
6940 ··-·CJIS-5.4.1.16940 ··-·CJIS-5.4.1.1
6941 ··-·NIST-800-171-3.3.16941 ··-·NIST-800-171-3.3.1
6942 ··-·NIST-800-171-3.4.36942 ··-·NIST-800-171-3.4.3
6943 ··-·NIST-800-53-AC-6(9)6943 ··-·NIST-800-53-AC-6(9)
6944 ··-·NIST-800-53-CM-6(a)6944 ··-·NIST-800-53-CM-6(a)
Max diff block lines reached; 732360/739792 bytes (99.00%) of diff not shown.
641 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
640 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
Ordering differences only
    
Offset 3, 2871 lines modifiedOffset 3, 2871 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
11 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title>11 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1"> 
17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
 23 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
29 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>29 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">
41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>44 ······</ocil:actions>
45 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1"> 
47 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
48 ······<ocil:actions>48 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>50 ······</ocil:actions>
51 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>52 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·TIPC·Support</ocil:title>
54 ······<ocil:actions>54 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>56 ······</ocil:actions>
57 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
59 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>59 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
60 ······<ocil:actions>60 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>62 ······</ocil:actions>
63 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_name_format_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
65 ······<ocil:title>Set·hostname·as·computer·node·name·in·audit·logs</ocil:title>65 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
66 ······<ocil:actions>66 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_name_format_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>68 ······</ocil:actions>
69 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Recovery·Booting</ocil:title>71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
72 ······<ocil:actions>72 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>74 ······</ocil:actions>
75 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
77 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>77 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1"> 
83 ······<ocil:title>Disable·IA32·emulation</ocil:title>82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
 83 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
89 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">
95 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>95 ······<ocil:title>Kernel·panic·on·oops</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
101 ······<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>107 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>116 ······</ocil:actions>
117 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
119 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>118 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">
 119 ······<ocil:title>Verify·Permissions·on·group·File</ocil:title>
120 ······<ocil:actions>120 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 643303/655711 bytes (98.11%) of diff not shown.
52.7 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-xccdf.xml
52.6 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-xccdf.xml
    
Offset 47, 92 lines modifiedOffset 47, 92 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="sudo">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="aarch64_arch">64 ····<cpe-lang:platform·id="login_defs">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
67 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="s390x_arch">69 ····<cpe-lang:platform·id="chrony">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
72 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="machine">74 ····<cpe-lang:platform·id="audit">
75 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
77 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
78 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
79 ····<cpe-lang:platform·id="chrony">79 ····<cpe-lang:platform·id="not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
82 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="grub2">84 ····<cpe-lang:platform·id="ntp">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="audit">89 ····<cpe-lang:platform·id="pam">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="postfix">94 ····<cpe-lang:platform·id="aarch64_arch">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="sssd">99 ····<cpe-lang:platform·id="postfix">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>101 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="gdm">104 ····<cpe-lang:platform·id="non-uefi">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>106 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="ntp">109 ····<cpe-lang:platform·id="uefi">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>111 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="non-uefi">114 ····<cpe-lang:platform·id="sudo">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>116 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="not_s390x_arch">119 ····<cpe-lang:platform·id="grub2">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>121 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
122 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="uefi">124 ····<cpe-lang:platform·id="s390x_arch">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>126 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
127 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="login_defs">129 ····<cpe-lang:platform·id="machine">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>131 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
132 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
134 ··</cpe-lang:platform-specification>134 ··</cpe-lang:platform-specification>
135 ··<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:15.0"/>135 ··<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:15.0"/>
136 ··<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.1"/>136 ··<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.1"/>
137 ··<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.2"/>137 ··<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.2"/>
138 ··<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.3"/>138 ··<xccdf-1.2:platform·idref="cpe:/o:opensuse:leap:42.3"/>
Offset 6798, 16 lines modifiedOffset 6798, 16 lines modified
  
6798 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension6798 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
6799 ··find:6799 ··find:
6800 ····paths:·/etc/audit/rules.d/6800 ····paths:·/etc/audit/rules.d/
6801 ····patterns:·'*.rules'6801 ····patterns:·'*.rules'
6802 ··register:·find_rules_d6802 ··register:·find_rules_d
6803 ··when:6803 ··when:
6804 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
6805 ··-·'&quot;audit&quot;·in·ansible_facts.packages'6804 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 6805 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
6806 ··tags:6806 ··tags:
6807 ··-·CJIS-5.4.1.16807 ··-·CJIS-5.4.1.1
6808 ··-·NIST-800-171-3.3.16808 ··-·NIST-800-171-3.3.1
6809 ··-·NIST-800-171-3.4.36809 ··-·NIST-800-171-3.4.3
6810 ··-·NIST-800-53-AC-6(9)6810 ··-·NIST-800-53-AC-6(9)
6811 ··-·NIST-800-53-CM-6(a)6811 ··-·NIST-800-53-CM-6(a)
6812 ··-·PCI-DSS-Req-10.5.26812 ··-·PCI-DSS-Req-10.5.2
Offset 6822, 16 lines modifiedOffset 6822, 16 lines modified
6822 ··lineinfile:6822 ··lineinfile:
6823 ····path:·'{{·item·}}'6823 ····path:·'{{·item·}}'
6824 ····regexp:·^\s*(?:-e)\s+.*$6824 ····regexp:·^\s*(?:-e)\s+.*$
6825 ····state:·absent6825 ····state:·absent
6826 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']6826 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
6827 ····}}'6827 ····}}'
6828 ··when:6828 ··when:
6829 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
6830 ··-·'&quot;audit&quot;·in·ansible_facts.packages'6829 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 6830 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
6831 ··tags:6831 ··tags:
6832 ··-·CJIS-5.4.1.16832 ··-·CJIS-5.4.1.1
6833 ··-·NIST-800-171-3.3.16833 ··-·NIST-800-171-3.3.1
6834 ··-·NIST-800-171-3.4.36834 ··-·NIST-800-171-3.4.3
6835 ··-·NIST-800-53-AC-6(9)6835 ··-·NIST-800-53-AC-6(9)
6836 ··-·NIST-800-53-CM-6(a)6836 ··-·NIST-800-53-CM-6(a)
Max diff block lines reached; 46805/53751 bytes (87.08%) of diff not shown.
1.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds-1.2.xml
1.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds-1.2.xml
Max HTML report size reached
1.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
1.41 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
Max HTML report size reached
1.34 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
1.34 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
Max HTML report size reached
20.7 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
20.6 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
Ordering differences only
    
Offset 47, 149 lines modifiedOffset 47, 149 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="tmux">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
 57 ······</cpe-lang:logical-test>
 58 ····</cpe-lang:platform>
 59 ····<cpe-lang:platform·id="chrony_or_ntp">
 60 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 61 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
56 ········<cpe-lang:fact-ref·name="cpe:/a:tmux"/>62 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
57 ······</cpe-lang:logical-test>63 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>64 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="polkit">65 ····<cpe-lang:platform·id="polkit">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">66 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:polkit"/>67 ········<cpe-lang:fact-ref·name="cpe:/a:polkit"/>
62 ······</cpe-lang:logical-test>68 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>69 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="pam">70 ····<cpe-lang:platform·id="gdm">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">71 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>72 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
67 ······</cpe-lang:logical-test>73 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>74 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">75 ····<cpe-lang:platform·id="login_defs">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">76 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>77 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
72 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/> 
73 ······</cpe-lang:logical-test>78 ······</cpe-lang:logical-test>
74 ····</cpe-lang:platform>79 ····</cpe-lang:platform>
75 ····<cpe-lang:platform·id="wifi-iface">80 ····<cpe-lang:platform·id="chrony">
76 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
77 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>82 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
78 ······</cpe-lang:logical-test>83 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>84 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="sudo">85 ····<cpe-lang:platform·id="audit">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>87 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
83 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="aarch64_arch">90 ····<cpe-lang:platform·id="not_s390x_arch">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>92 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
88 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="chrony_or_ntp">95 ····<cpe-lang:platform·id="ntp">
91 ······<cpe-lang:logical-test·operator="OR"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/> 
93 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>97 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
94 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="s390x_arch">100 ····<cpe-lang:platform·id="pam">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>102 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
99 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="machine">105 ····<cpe-lang:platform·id="machine_and_partition-tmp">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
104 ······</cpe-lang:logical-test> 
105 ····</cpe-lang:platform> 
106 ····<cpe-lang:platform·id="chrony"> 
107 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
108 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>108 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
109 ······</cpe-lang:logical-test> 
110 ····</cpe-lang:platform> 
111 ····<cpe-lang:platform·id="grub2"> 
112 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
113 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/> 
114 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="systemd">111 ····<cpe-lang:platform·id="systemd">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>113 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>
119 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="audit">116 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>118 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 119 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
124 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="postfix">122 ····<cpe-lang:platform·id="aarch64_arch">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>124 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
129 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="usbguard">127 ····<cpe-lang:platform·id="postfix">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:fact-ref·name="cpe:/a:usbguard"/>129 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
134 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="sssd">132 ····<cpe-lang:platform·id="machine_and_chrony_or_ntp">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 134 ········<cpe-lang:logical-test·operator="OR"·negate="false">
 135 ··········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
138 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>136 ··········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
 137 ········</cpe-lang:logical-test>
 138 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
139 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="gdm">141 ····<cpe-lang:platform·id="wifi-iface">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>143 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
144 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="ntp">146 ····<cpe-lang:platform·id="tmux">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>148 ········<cpe-lang:fact-ref·name="cpe:/a:tmux"/>
149 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">151 ····<cpe-lang:platform·id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:fact-ref·name="cpe:/a:krb5_server_older_than_1_17-18"/>153 ········<cpe-lang:fact-ref·name="cpe:/a:krb5_server_older_than_1_17-18"/>
154 ········<cpe-lang:fact-ref·name="cpe:/a:krb5_workstation_older_than_1_17-18"/>154 ········<cpe-lang:fact-ref·name="cpe:/a:krb5_workstation_older_than_1_17-18"/>
155 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
 157 ····<cpe-lang:platform·id="usbguard">
 158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 159 ········<cpe-lang:fact-ref·name="cpe:/a:usbguard"/>
 160 ······</cpe-lang:logical-test>
 161 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="non-uefi">162 ····<cpe-lang:platform·id="non-uefi">
Max diff block lines reached; 13695/20929 bytes (65.44%) of diff not shown.
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-rhel7-ds-1.2.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-rhel7-ds-1.2.xml
Max HTML report size reached
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-rhel7-ds.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-rhel7-ds.xml
Max HTML report size reached
2.76 MB
./usr/share/xml/scap/ssg/content/ssg-rhel7-ocil.xml
2.76 MB
./usr/share/xml/scap/ssg/content/ssg-rhel7-ocil.xml
Max HTML report size reached
985 KB
./usr/share/xml/scap/ssg/content/ssg-rhel7-xccdf.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-rhel7-xccdf.xml
Max HTML report size reached
4.11 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds-1.2.xml
4.1 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds-1.2.xml
Max HTML report size reached
4.11 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
4.1 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
Max HTML report size reached
3.05 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
3.05 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
Max HTML report size reached
947 KB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
947 KB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
Max HTML report size reached
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds-1.2.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds-1.2.xml
Max HTML report size reached
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
Max HTML report size reached
2.87 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
2.87 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
Max HTML report size reached
878 KB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
878 KB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
Max HTML report size reached
1.69 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds-1.2.xml
1.69 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds-1.2.xml
Max HTML report size reached
1.69 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
1.69 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
Max HTML report size reached
1.49 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
1.49 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
Max HTML report size reached
133 KB
./usr/share/xml/scap/ssg/content/ssg-rhv4-xccdf.xml
133 KB
./usr/share/xml/scap/ssg/content/ssg-rhv4-xccdf.xml
    
Offset 47, 141 lines modifiedOffset 47, 141 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="polkit">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:polkit"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="pam">59 ····<cpe-lang:platform·id="chrony_or_ntp">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 61 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
61 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>62 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
62 ······</cpe-lang:logical-test>63 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>64 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="yum">65 ····<cpe-lang:platform·id="polkit">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">66 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>67 ········<cpe-lang:fact-ref·name="cpe:/a:polkit"/>
67 ······</cpe-lang:logical-test>68 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>69 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="wifi-iface">70 ····<cpe-lang:platform·id="gdm">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">71 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>72 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
72 ······</cpe-lang:logical-test>73 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>74 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="sudo">75 ····<cpe-lang:platform·id="login_defs">
75 ······<cpe-lang:logical-test·operator="AND"·negate="false">76 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>77 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
77 ······</cpe-lang:logical-test>78 ······</cpe-lang:logical-test>
78 ····</cpe-lang:platform>79 ····</cpe-lang:platform>
79 ····<cpe-lang:platform·id="aarch64_arch">80 ····<cpe-lang:platform·id="chrony">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>82 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
82 ······</cpe-lang:logical-test>83 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>84 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="chrony_or_ntp">85 ····<cpe-lang:platform·id="yum">
85 ······<cpe-lang:logical-test·operator="OR"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/> 
87 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>87 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>
88 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="s390x_arch">90 ····<cpe-lang:platform·id="audit">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>92 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
93 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="machine">95 ····<cpe-lang:platform·id="not_s390x_arch">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>97 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
98 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="chrony">100 ····<cpe-lang:platform·id="ntp">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>102 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
103 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="grub2">105 ····<cpe-lang:platform·id="pam">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
108 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="systemd">110 ····<cpe-lang:platform·id="systemd">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>112 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>
113 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="audit">115 ····<cpe-lang:platform·id="aarch64_arch">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>117 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
118 ······</cpe-lang:logical-test>118 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>119 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="postfix">120 ····<cpe-lang:platform·id="libuser">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">121 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>122 ········<cpe-lang:fact-ref·name="cpe:/a:libuser"/>
123 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="sssd">125 ····<cpe-lang:platform·id="postfix">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>127 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
128 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="gdm">130 ····<cpe-lang:platform·id="machine_and_chrony_or_ntp">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 132 ········<cpe-lang:logical-test·operator="OR"·negate="false">
 133 ··········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
 134 ··········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
 135 ········</cpe-lang:logical-test>
132 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>136 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
133 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="ntp">139 ····<cpe-lang:platform·id="wifi-iface">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>141 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
138 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="libuser">144 ····<cpe-lang:platform·id="tftp-server">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">145 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:fact-ref·name="cpe:/a:libuser"/>146 ········<cpe-lang:fact-ref·name="cpe:/a:tftp-server"/>
143 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="non-uefi">149 ····<cpe-lang:platform·id="non-uefi">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>151 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
148 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="tftp-server">154 ····<cpe-lang:platform·id="uefi">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:fact-ref·name="cpe:/a:tftp-server"/>156 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
153 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="not_s390x_arch">159 ····<cpe-lang:platform·id="sudo">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>161 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
158 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="nss-pam-ldapd">164 ····<cpe-lang:platform·id="grub2">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:fact-ref·name="cpe:/a:nss-pam-ldapd"/>166 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
163 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="uefi">169 ····<cpe-lang:platform·id="nss-pam-ldapd">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>171 ········<cpe-lang:fact-ref·name="cpe:/a:nss-pam-ldapd"/>
168 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
Max diff block lines reached; 128607/136265 bytes (94.38%) of diff not shown.
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-sl7-ds-1.2.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-sl7-ds-1.2.xml
Max HTML report size reached
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-sl7-ds.xml
3.85 MB
./usr/share/xml/scap/ssg/content/ssg-sl7-ds.xml
Max HTML report size reached
986 KB
./usr/share/xml/scap/ssg/content/ssg-sl7-xccdf.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-sl7-xccdf.xml
Max HTML report size reached
1.53 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds-1.2.xml
1.53 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds-1.2.xml
Max HTML report size reached
1.53 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
1.53 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
Max HTML report size reached
1.46 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
1.46 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
Max HTML report size reached
10.4 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
10.3 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
Ordering differences only
    
Offset 47, 130 lines modifiedOffset 47, 130 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">59 ····<cpe-lang:platform·id="chrony_or_ntp">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="OR"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
62 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>62 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
63 ······</cpe-lang:logical-test>63 ······</cpe-lang:logical-test>
64 ····</cpe-lang:platform>64 ····</cpe-lang:platform>
65 ····<cpe-lang:platform·id="yum">65 ····<cpe-lang:platform·id="gdm">
66 ······<cpe-lang:logical-test·operator="AND"·negate="false">66 ······<cpe-lang:logical-test·operator="AND"·negate="false">
67 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>67 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
68 ······</cpe-lang:logical-test>68 ······</cpe-lang:logical-test>
69 ····</cpe-lang:platform>69 ····</cpe-lang:platform>
70 ····<cpe-lang:platform·id="wifi-iface">70 ····<cpe-lang:platform·id="login_defs">
71 ······<cpe-lang:logical-test·operator="AND"·negate="false">71 ······<cpe-lang:logical-test·operator="AND"·negate="false">
72 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>72 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
73 ······</cpe-lang:logical-test>73 ······</cpe-lang:logical-test>
74 ····</cpe-lang:platform>74 ····</cpe-lang:platform>
75 ····<cpe-lang:platform·id="sudo">75 ····<cpe-lang:platform·id="chrony">
76 ······<cpe-lang:logical-test·operator="AND"·negate="false">76 ······<cpe-lang:logical-test·operator="AND"·negate="false">
77 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>77 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
78 ······</cpe-lang:logical-test>78 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>79 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="aarch64_arch">80 ····<cpe-lang:platform·id="yum">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/> 
83 ······</cpe-lang:logical-test> 
84 ····</cpe-lang:platform> 
85 ····<cpe-lang:platform·id="chrony_or_ntp"> 
86 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
87 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/> 
88 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>82 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>
89 ······</cpe-lang:logical-test>83 ······</cpe-lang:logical-test>
90 ····</cpe-lang:platform>84 ····</cpe-lang:platform>
91 ····<cpe-lang:platform·id="s390x_arch">85 ····<cpe-lang:platform·id="audit">
92 ······<cpe-lang:logical-test·operator="AND"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
93 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>87 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
94 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="not_s390x_arch">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>92 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
99 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="zypper">95 ····<cpe-lang:platform·id="ntp">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:fact-ref·name="cpe:/a:zypper"/>97 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
104 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="chrony">100 ····<cpe-lang:platform·id="pam">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>102 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
109 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="grub2">105 ····<cpe-lang:platform·id="machine_and_partition-tmp">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 108 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
114 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="audit">111 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>113 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 114 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
119 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="postfix">117 ····<cpe-lang:platform·id="aarch64_arch">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>119 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
124 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="sssd">122 ····<cpe-lang:platform·id="zypper">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>124 ········<cpe-lang:fact-ref·name="cpe:/a:zypper"/>
129 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="gdm">127 ····<cpe-lang:platform·id="libuser">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>129 ········<cpe-lang:fact-ref·name="cpe:/a:libuser"/>
134 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="ntp">132 ····<cpe-lang:platform·id="postfix">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>134 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
139 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="libuser">137 ····<cpe-lang:platform·id="wifi-iface">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:fact-ref·name="cpe:/a:libuser"/>139 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
144 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="non-uefi">142 ····<cpe-lang:platform·id="non-uefi">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>144 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
149 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="not_s390x_arch">147 ····<cpe-lang:platform·id="uefi">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>149 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
154 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="machine_and_partition-tmp">152 ····<cpe-lang:platform·id="sudo">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>154 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
159 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/> 
160 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="uefi">157 ····<cpe-lang:platform·id="grub2">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>159 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
165 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="login_defs">162 ····<cpe-lang:platform·id="s390x_arch">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 164 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
 165 ······</cpe-lang:logical-test>
 166 ····</cpe-lang:platform>
Max diff block lines reached; 2612/10467 bytes (24.95%) of diff not shown.
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds-1.2.xml
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds-1.2.xml
Max HTML report size reached
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
Max HTML report size reached
1.61 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
1.61 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
Max HTML report size reached
432 KB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
432 KB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
    
Offset 47, 135 lines modifiedOffset 47, 135 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">59 ····<cpe-lang:platform·id="chrony_or_ntp">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="OR"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
62 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>62 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
63 ······</cpe-lang:logical-test>63 ······</cpe-lang:logical-test>
64 ····</cpe-lang:platform>64 ····</cpe-lang:platform>
65 ····<cpe-lang:platform·id="yum">65 ····<cpe-lang:platform·id="gdm">
66 ······<cpe-lang:logical-test·operator="AND"·negate="false">66 ······<cpe-lang:logical-test·operator="AND"·negate="false">
67 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>67 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
68 ······</cpe-lang:logical-test>68 ······</cpe-lang:logical-test>
69 ····</cpe-lang:platform>69 ····</cpe-lang:platform>
70 ····<cpe-lang:platform·id="wifi-iface">70 ····<cpe-lang:platform·id="login_defs">
71 ······<cpe-lang:logical-test·operator="AND"·negate="false">71 ······<cpe-lang:logical-test·operator="AND"·negate="false">
72 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>72 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
73 ······</cpe-lang:logical-test>73 ······</cpe-lang:logical-test>
74 ····</cpe-lang:platform>74 ····</cpe-lang:platform>
75 ····<cpe-lang:platform·id="sudo">75 ····<cpe-lang:platform·id="chrony">
76 ······<cpe-lang:logical-test·operator="AND"·negate="false">76 ······<cpe-lang:logical-test·operator="AND"·negate="false">
77 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>77 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
78 ······</cpe-lang:logical-test>78 ······</cpe-lang:logical-test>
79 ····</cpe-lang:platform>79 ····</cpe-lang:platform>
80 ····<cpe-lang:platform·id="aarch64_arch">80 ····<cpe-lang:platform·id="yum">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
82 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/> 
83 ······</cpe-lang:logical-test> 
84 ····</cpe-lang:platform> 
85 ····<cpe-lang:platform·id="chrony_or_ntp"> 
86 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
87 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/> 
88 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>82 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>
89 ······</cpe-lang:logical-test>83 ······</cpe-lang:logical-test>
90 ····</cpe-lang:platform>84 ····</cpe-lang:platform>
91 ····<cpe-lang:platform·id="s390x_arch">85 ····<cpe-lang:platform·id="audit">
92 ······<cpe-lang:logical-test·operator="AND"·negate="false">86 ······<cpe-lang:logical-test·operator="AND"·negate="false">
93 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>87 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
94 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="machine">90 ····<cpe-lang:platform·id="not_s390x_arch">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>92 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
99 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="zypper">95 ····<cpe-lang:platform·id="ntp">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:fact-ref·name="cpe:/a:zypper"/>97 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
104 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="chrony">100 ····<cpe-lang:platform·id="pam">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>102 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
109 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="grub2">105 ····<cpe-lang:platform·id="machine_and_partition-tmp">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>107 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 108 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/>
114 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="systemd">111 ····<cpe-lang:platform·id="systemd">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>113 ········<cpe-lang:fact-ref·name="cpe:/a:systemd"/>
119 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="audit">116 ····<cpe-lang:platform·id="machine_and_partition-var-tmp">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>118 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
 119 ········<cpe-lang:fact-ref·name="cpe:/a:partition-var-tmp"/>
124 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="postfix">122 ····<cpe-lang:platform·id="aarch64_arch">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>124 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
129 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="sssd">127 ····<cpe-lang:platform·id="zypper">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>129 ········<cpe-lang:fact-ref·name="cpe:/a:zypper"/>
134 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="gdm">132 ····<cpe-lang:platform·id="libuser">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>134 ········<cpe-lang:fact-ref·name="cpe:/a:libuser"/>
139 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="ntp">137 ····<cpe-lang:platform·id="postfix">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>139 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
144 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="libuser">142 ····<cpe-lang:platform·id="wifi-iface">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:fact-ref·name="cpe:/a:libuser"/>144 ········<cpe-lang:fact-ref·name="cpe:/a:wifi-iface"/>
149 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="non-uefi">147 ····<cpe-lang:platform·id="non-uefi">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>149 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
154 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="not_s390x_arch">152 ····<cpe-lang:platform·id="uefi">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>154 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
159 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="machine_and_partition-tmp">157 ····<cpe-lang:platform·id="sudo">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>159 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
164 ········<cpe-lang:fact-ref·name="cpe:/a:partition-tmp"/> 
165 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="uefi">162 ····<cpe-lang:platform·id="grub2">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>164 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
170 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
Max diff block lines reached; 434856/442569 bytes (98.26%) of diff not shown.
779 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-ds-1.2.xml
779 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-ds-1.2.xml
Max HTML report size reached
779 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-ds.xml
779 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-ds.xml
Max HTML report size reached
694 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-ocil.xml
694 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-ocil.xml
Ordering differences only
    
Offset 3, 2829 lines modifiedOffset 3, 2829 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.65</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>7 ····<ocil:timestamp>2022-12-20T09:54:05</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·Randomized·Layout·of·Virtual·Address·Space</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>11 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"> 
23 ······<ocil:title>Verify·Permissions·on·SSH·Server·Public·*.pub·Key·Files</ocil:title>16 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
 17 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·setxattr</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
29 ······<ocil:title>Configure·Speculative·Store·Bypass·Mitigation</ocil:title>23 ······<ocil:title>A·remote·time·server·for·Chrony·is·configured</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
35 ······<ocil:title>Ensure·rsyslog·is·Installed</ocil:title>29 ······<ocil:title>Enable·Encrypted·X11·Forwarding</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"> 
41 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·removexattr</ocil:title>34 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
 35 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">
47 ······<ocil:title>Prefer·to·use·a·64-bit·Operating·System·when·supported</ocil:title>41 ······<ocil:title>Ensure·auditd·Collects·Information·on·the·Use·of·Privileged·Commands</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"> 
53 ······<ocil:title>Ensure·debug-shell·service·is·not·enabled·during·boot</ocil:title>46 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
 47 ······<ocil:title>Ensure·auditd·Collects·File·Deletion·Events·by·User·-·unlink</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
59 ······<ocil:title>Record·Attempts·to·Alter·Time·Through·stime</ocil:title>53 ······<ocil:title>Disable·TIPC·Support</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-auditd_name_format_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
65 ······<ocil:title>Set·hostname·as·computer·node·name·in·audit·logs</ocil:title>59 ······<ocil:title>Enable·checks·on·linked·list·manipulation</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-auditd_name_format_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
71 ······<ocil:title>Disable·Recovery·Booting</ocil:title>65 ······<ocil:title>Enable·systemd-journald·Service</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1"> 
77 ······<ocil:title>Set·SSH·Daemon·LogLevel·to·VERBOSE</ocil:title>70 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
 71 ······<ocil:title>Record·Events·that·Modify·the·System's·Discretionary·Access·Controls·-·fchown</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
83 ······<ocil:title>Disable·IA32·emulation</ocil:title>77 ······<ocil:title>Ensure·syslog-ng·is·Installed</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
89 ······<ocil:title>Verify·User·Who·Owns·/var/log/messages·File</ocil:title>83 ······<ocil:title>Verify·Permissions·on·Backup·group·File</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
95 ······<ocil:title>Disable·/dev/kmem·virtual·device·support</ocil:title>89 ······<ocil:title>Verify·Group·Who·Owns·/var/log·Directory</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">
101 ······<ocil:title>Enable·seccomp·to·safely·compute·untrusted·bytecode</ocil:title>95 ······<ocil:title>Kernel·panic·on·oops</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·Users·Re-Authenticate·for·Privilege·Escalation·-·sudo·!authenticate</ocil:title>101 ······<ocil:title>Ensure·auditd·Collects·Information·on·Exporting·to·Media·(successful)</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"> 
113 ······<ocil:title>Ensure·Rsyslog·Authenticates·Off-Loaded·Audit·Records</ocil:title>106 ····<ocil:questionnaire·id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
 107 ······<ocil:title>Configure·auditd·to·use·audispd's·syslog·plugin</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"> 
119 ······<ocil:title>Configure·auditd·space_left·Action·on·Low·Disk·Space</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
 113 ······<ocil:title>Ensure·/var/log/audit·Located·On·Separate·Partition</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
Max diff block lines reached; 698287/710796 bytes (98.24%) of diff not shown.
53.0 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-xccdf.xml
52.9 KB
./usr/share/xml/scap/ssg/content/ssg-uos20-xccdf.xml
    
Offset 47, 97 lines modifiedOffset 47, 97 lines modified
47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>47 ····<html:a·href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
48 ··</xccdf-1.2:front-matter>48 ··</xccdf-1.2:front-matter>
49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered49 ··<xccdf-1.2:rear-matter>Red·Hat·and·Red·Hat·Enterprise·Linux·are·either·registered
50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other50 trademarks·or·trademarks·of·Red·Hat,·Inc.·in·the·United·States·and·other
51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their51 countries.·All·other·names·are·registered·trademarks·or·trademarks·of·their
52 respective·companies.</xccdf-1.2:rear-matter>52 respective·companies.</xccdf-1.2:rear-matter>
53 ··<cpe-lang:platform-specification>53 ··<cpe-lang:platform-specification>
54 ····<cpe-lang:platform·id="pam">54 ····<cpe-lang:platform·id="sssd">
55 ······<cpe-lang:logical-test·operator="AND"·negate="false">55 ······<cpe-lang:logical-test·operator="AND"·negate="false">
56 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>56 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>
57 ······</cpe-lang:logical-test>57 ······</cpe-lang:logical-test>
58 ····</cpe-lang:platform>58 ····</cpe-lang:platform>
59 ····<cpe-lang:platform·id="yum">59 ····<cpe-lang:platform·id="gdm">
60 ······<cpe-lang:logical-test·operator="AND"·negate="false">60 ······<cpe-lang:logical-test·operator="AND"·negate="false">
61 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>61 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>
62 ······</cpe-lang:logical-test>62 ······</cpe-lang:logical-test>
63 ····</cpe-lang:platform>63 ····</cpe-lang:platform>
64 ····<cpe-lang:platform·id="sudo">64 ····<cpe-lang:platform·id="login_defs">
65 ······<cpe-lang:logical-test·operator="AND"·negate="false">65 ······<cpe-lang:logical-test·operator="AND"·negate="false">
66 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>66 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>
67 ······</cpe-lang:logical-test>67 ······</cpe-lang:logical-test>
68 ····</cpe-lang:platform>68 ····</cpe-lang:platform>
69 ····<cpe-lang:platform·id="aarch64_arch">69 ····<cpe-lang:platform·id="chrony">
70 ······<cpe-lang:logical-test·operator="AND"·negate="false">70 ······<cpe-lang:logical-test·operator="AND"·negate="false">
71 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>71 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>
72 ······</cpe-lang:logical-test>72 ······</cpe-lang:logical-test>
73 ····</cpe-lang:platform>73 ····</cpe-lang:platform>
74 ····<cpe-lang:platform·id="s390x_arch">74 ····<cpe-lang:platform·id="yum">
75 ······<cpe-lang:logical-test·operator="AND"·negate="false">75 ······<cpe-lang:logical-test·operator="AND"·negate="false">
76 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>76 ········<cpe-lang:fact-ref·name="cpe:/a:yum"/>
77 ······</cpe-lang:logical-test>77 ······</cpe-lang:logical-test>
78 ····</cpe-lang:platform>78 ····</cpe-lang:platform>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="audit">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
81 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>81 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>
82 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="chrony">84 ····<cpe-lang:platform·id="not_s390x_arch">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:fact-ref·name="cpe:/a:chrony"/>86 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="grub2">89 ····<cpe-lang:platform·id="ntp">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>91 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="audit">94 ····<cpe-lang:platform·id="pam">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:fact-ref·name="cpe:/a:audit"/>96 ········<cpe-lang:fact-ref·name="cpe:/a:pam"/>
97 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="postfix">99 ····<cpe-lang:platform·id="aarch64_arch">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>101 ········<cpe-lang:fact-ref·name="cpe:/a:aarch64_arch"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="sssd">104 ····<cpe-lang:platform·id="postfix">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:fact-ref·name="cpe:/a:sssd"/>106 ········<cpe-lang:fact-ref·name="cpe:/a:postfix"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="gdm">109 ····<cpe-lang:platform·id="non-uefi">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:fact-ref·name="cpe:/a:gdm"/>111 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="ntp">114 ····<cpe-lang:platform·id="uefi">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:fact-ref·name="cpe:/a:ntp"/>116 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="non-uefi">119 ····<cpe-lang:platform·id="sudo">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:fact-ref·name="cpe:/a:non-uefi"/>121 ········<cpe-lang:fact-ref·name="cpe:/a:sudo"/>
122 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="not_s390x_arch">124 ····<cpe-lang:platform·id="grub2">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:fact-ref·name="cpe:/a:not_s390x_arch"/>126 ········<cpe-lang:fact-ref·name="cpe:/a:grub2"/>
127 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="uefi">129 ····<cpe-lang:platform·id="s390x_arch">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:fact-ref·name="cpe:/a:uefi"/>131 ········<cpe-lang:fact-ref·name="cpe:/a:s390x_arch"/>
132 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="login_defs">134 ····<cpe-lang:platform·id="machine">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:fact-ref·name="cpe:/a:login_defs"/>136 ········<cpe-lang:fact-ref·name="cpe:/a:machine"/>
137 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
139 ··</cpe-lang:platform-specification>139 ··</cpe-lang:platform-specification>
140 ··<xccdf-1.2:platform·idref="cpe:/o:uos:uniontech_os_server:20"/>140 ··<xccdf-1.2:platform·idref="cpe:/o:uos:uniontech_os_server:20"/>
141 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>141 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.65</xccdf-1.2:version>
142 ··<xccdf-1.2:metadata>142 ··<xccdf-1.2:metadata>
143 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>143 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 7848, 16 lines modifiedOffset 7848, 16 lines modified
  
7848 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension7848 -·name:·Collect·all·files·from·/etc/audit/rules.d·with·.rules·extension
7849 ··find:7849 ··find:
7850 ····paths:·/etc/audit/rules.d/7850 ····paths:·/etc/audit/rules.d/
7851 ····patterns:·'*.rules'7851 ····patterns:·'*.rules'
7852 ··register:·find_rules_d7852 ··register:·find_rules_d
7853 ··when:7853 ··when:
7854 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
7855 ··-·'&quot;audit&quot;·in·ansible_facts.packages'7854 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 7855 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
7856 ··tags:7856 ··tags:
7857 ··-·CJIS-5.4.1.17857 ··-·CJIS-5.4.1.1
7858 ··-·NIST-800-171-3.3.17858 ··-·NIST-800-171-3.3.1
7859 ··-·NIST-800-171-3.4.37859 ··-·NIST-800-171-3.4.3
7860 ··-·NIST-800-53-AC-6(9)7860 ··-·NIST-800-53-AC-6(9)
7861 ··-·NIST-800-53-CM-6(a)7861 ··-·NIST-800-53-CM-6(a)
7862 ··-·PCI-DSS-Req-10.5.27862 ··-·PCI-DSS-Req-10.5.2
Offset 7872, 16 lines modifiedOffset 7872, 16 lines modified
7872 ··lineinfile:7872 ··lineinfile:
7873 ····path:·'{{·item·}}'7873 ····path:·'{{·item·}}'
7874 ····regexp:·^\s*(?:-e)\s+.*$7874 ····regexp:·^\s*(?:-e)\s+.*$
7875 ····state:·absent7875 ····state:·absent
7876 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']7876 ··loop:·'{{·find_rules_d.files·|·map(attribute=''path'')·|·list·+·[''/etc/audit/audit.rules'']
7877 ····}}'7877 ····}}'
7878 ··when:7878 ··when:
7879 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;] 
7880 ··-·'&quot;audit&quot;·in·ansible_facts.packages'7879 ··-·'&quot;audit&quot;·in·ansible_facts.packages'
 7880 ··-·ansible_virtualization_type·not·in·[&quot;docker&quot;,·&quot;lxc&quot;,·&quot;openvz&quot;,·&quot;podman&quot;,·&quot;container&quot;]
7881 ··tags:7881 ··tags:
Max diff block lines reached; 46939/54081 bytes (86.79%) of diff not shown.